Overview
Mise ("Mise," "we," "us," or "our") operates a hospitality marketplace platform that connects independent service workers with restaurant and hospitality venues, and collects guest feedback through QR-code survey experiences.
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Mise platform — including the Mise mobile application, the admin portal at mise-admin.pages.dev, and the guest survey interface at mise-survey.pages.dev.
We operate under a multi-tenant architecture. If your employer or a venue operator has provided you access to Mise, they may have their own privacy notices governing your use in that context. This policy covers Mise's data practices as platform operator.
Information We Collect
We collect information in the following ways:
Information you provide directly
- Account registration: Display name, email address, phone number, and password when you create a Mise account.
- Worker profiles: Professional information including work history, skills, and any documents required for shift eligibility.
- Business profiles: Organization name, location addresses, billing contacts, and operational details provided by restaurant operators.
- Payment onboarding: Information submitted through Stripe Connect for identity verification, tax compliance, and payouts (see Section 5 – Payment Data).
- Guest survey responses: Ratings, written feedback, and optional contact information submitted through QR code survey pages.
- Support communications: Any messages, emails, or forms submitted to Mise support.
Information collected automatically
- Usage data: Pages viewed, features used, timestamps, session duration, and in-app actions.
- Device information: Device type, operating system version, unique device identifiers, and mobile network information (mobile app).
- Location data: With your permission, approximate or precise location may be used to show nearby shifts or verify shift attendance.
- Log data: IP addresses, browser type, referrer URLs, and error logs generated by our servers.
Information from third parties
- QuickBooks integration: When a venue connects QuickBooks, we create and manage isolated "TT_"-prefixed employee records and receive timekeeping and hours data exclusively for those Mise-managed entries to automate earnings calculations.
- Sign In with Apple: If you authenticate via Apple, we receive a unique user token and optionally an email address per Apple's privacy framework.
| Data Category | Examples | Source |
|---|---|---|
| Identity | Name, email, phone | You |
| Financial | Bank account (tokenized), earnings, tip amounts | You / QuickBooks |
| Professional | Work history, shift applications, ratings | You / Venues |
| Device & Technical | IP, device ID, OS version | Automatic |
| Guest Feedback | Survey ratings, written comments | Restaurant guests |
How We Use Information
We use the information we collect to:
- Operate the platform: Create and manage accounts, post and fill shifts, process applications, and deliver survey results to venue operators.
- Process payments: Calculate shift earnings, process weekly payouts to workers, and manage venue balance accounts through Stripe Connect.
- Communicate with you: Send shift confirmations, application updates, payout notifications, and platform announcements via email or push notification.
- Provide AI analytics: Analyze guest survey text with sentiment analysis to surface actionable insights for venue operators.
- Improve the platform: Analyze usage patterns, diagnose technical issues, and inform product development.
- Comply with legal obligations: Tax reporting, fraud prevention, identity verification, and responses to lawful government requests.
- Enforce our Terms of Service: Detect and prevent abuse, unauthorized access, and policy violations.
We do not sell your personal information to third parties for their own marketing purposes.
Sharing of Information
We share your information only in the following circumstances:
Within the platform
Venue operators can view worker profiles, shift applications, and performance-related ratings for workers in their organization. Workers can view shift details posted by venues. Guest survey responses are shared with the specific venue that collected them, not with unrelated third parties.
Service providers
We engage trusted third-party vendors who process data on our behalf under appropriate data processing agreements:
- Supabase – Database hosting and authentication infrastructure
- Stripe / Stripe Connect – Payment processing and worker payouts
- Resend – Transactional email delivery
- Cloudflare – Web hosting and CDN
- OpenAI – Survey text sentiment analysis (anonymized where possible)
- QuickBooks / Intuit – Accounting and timekeeping integration for participating venues
- Mercury – Business banking for platform accounts
QuickBooks integration
When a venue connects QuickBooks, Mise operates with minimal, narrowly scoped OAuth permissions: employee write access (to create TT_-prefixed entries only) and time-activity read access (to read hours for those same TT_ entries). We never access payroll, invoices, banking, customer data, or information about the venue's regular (non-TT_) employees.
Legal requirements
We may disclose information if required to do so by law, court order, or government request, or if we believe disclosure is necessary to protect the rights, property, or safety of Mise, our users, or the public.
Business transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred. We will notify you via email or prominent platform notice before your information becomes subject to a different privacy policy.
Payment Data
Mise uses Stripe and Stripe Connect to process all financial transactions. When you complete payment onboarding as a worker or venue operator:
- Sensitive financial information (bank account numbers, SSNs, tax IDs) is collected and stored directly by Stripe, not by Mise.
- Mise receives tokenized references and account status information from Stripe to display your account status and earnings.
- Payout records, transaction histories, and earnings summaries are stored in Mise's database for your access and our accounting obligations.
Mise maintains two categories of financial accounts: platform revenue accounts and pass-through labor cost accounts. These are kept structurally separate to ensure clean financial operations and proper tax reporting.
Please refer to Stripe's Privacy Policy for details on how Stripe processes your financial data.
QuickBooks Integration
Venue operators may connect their QuickBooks account to Mise to automate timekeeping and earnings workflows. When a venue enables this integration:
- TT_ employee records: Mise automatically creates isolated employee entries in the venue's QuickBooks account using a "TT_" prefix (e.g., "TT_11 – Sarah Johnson"). These entries exist solely for Mise shift workers and are completely separate from the venue's regular staff.
- Minimal OAuth scopes: Mise requests only two permissions from QuickBooks — the ability to create TT_-prefixed employees and the ability to read time activity for those same employees. We never request or access payroll data, invoices, banking, customers, vendors, or any information about your regular workforce.
- Clock-in credentials: Workers receive a TT_ code and 4-digit PIN via email to clock in and out using the QuickBooks Time app. Mise stores this mapping in our database to sync hours back to worker earnings records.
- Sync logs: We maintain records of each sync operation (worker count, entry count, errors) for audit and troubleshooting purposes.
Disconnecting the QuickBooks integration will stop future syncing but will not automatically delete historical TT_ employee records in QuickBooks. Venue operators are responsible for removing those records from their QuickBooks account if desired.
Please refer to Intuit's Privacy Statement for details on how QuickBooks handles data.
Mobile App & Device Permissions
The Mise mobile app (available on iOS via TestFlight and the App Store) may request the following device permissions:
- Push notifications: To send shift updates, application decisions, and payout confirmations. You can disable this in device settings at any time.
- Location: To show you nearby shifts. Location access is requested only when relevant features are used and is not tracked continuously in the background.
- Camera / Photo library: If you upload a profile photo or identity document. These images are transmitted securely and are not accessed otherwise.
You may revoke any permission at any time through your device's Settings app. Revoking certain permissions (e.g., push notifications) may limit some platform functionality.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Specific retention periods:
- Active accounts: Retained for the life of your account plus a reasonable wind-down period.
- Inactive accounts: We may delete inactive accounts after 24 months of inactivity, following advance notice.
- Financial records: Transaction and earnings records are retained for a minimum of 7 years to comply with tax and accounting obligations.
- Survey responses: Retained as long as the associated venue account is active, unless earlier deletion is requested by the venue operator.
- Log data: Server logs are typically retained for 90 days.
When you request account deletion, we will delete or anonymize your personal information within 30 days, except where retention is required by law.
Security
We implement industry-standard security measures to protect your information:
- Encryption in transit: All data transmitted between your device and our servers is encrypted via TLS/HTTPS.
- Encryption at rest: Database content is encrypted at rest on Supabase-managed infrastructure.
- Row-Level Security (RLS): Our database enforces strict access controls at the row level, ensuring users and organizations can only access their own data.
- Multi-tenant isolation: Organization data is isolated using org_id scoping across all database queries and Edge Functions.
- Invite-only access: Platform accounts are created via invitation only, reducing unauthorized access risk.
- Authentication: We use Supabase Auth with secure session management. Passwords are hashed and never stored in plaintext.
No method of transmission or storage is 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and personal data, subject to legal retention obligations.
- Portability: Request a machine-readable export of your data.
- Objection / Restriction: Object to or request restriction of certain processing activities.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us using the information in Section 12. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
California residents may have additional rights under the California Consumer Privacy Act (CCPA). Please contact us to make a CCPA request.
How to delete your account: Open the Mise app and go to Profile → Delete Account to permanently delete your account and associated personal data directly from your device — no reinstall required. You may also request deletion by emailing hello@rebootmedia.us. Once a deletion request is made, we delete or anonymize your personal information within 30 days, except where retention is required by law (e.g., financial records retained for tax compliance, as described in Section 8).
Children's Privacy
Mise is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Updating the "Last updated" date at the top of this page;
- Sending an email notification to registered account holders; and/or
- Displaying a notice in the Mise app or admin portal.
Your continued use of Mise after a policy change constitutes acceptance of the updated policy. If you disagree with any changes, you may close your account.
Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:
Mise Privacy Team
We aim to respond to all privacy inquiries within 5 business days.