← The Craft Standard

Privacy Policy

Last updated: July 18, 2026

Who we are

The Craft Standard (thecraftstandard.app) is a staff-training platform for restaurants and bars. Your workplace signs up for the service; team member accounts are created by invitation from your employer. Questions about this policy: Daniel@thecraftstandard.app.

What we collect

  • Account details — your name, work email, role, and work location, provided when your employer invites you.
  • Training activity — quiz and scenario attempts, scores, completion dates, and badges earned.
  • Business content— menus, wine lists, service standards, announcements, and daily sales figures entered by your workplace's managers.
  • Technical basics — login cookies (required for the service to work) and error logs. We do not run advertising or tracking cookies.

How we use it

To run the service: delivering training, recording results, and showing progress to the managers and owners at your workplace. Training results are visible to your employer — that is the product. Each business's data is isolated from every other business on the platform. We do not sell personal data, and we do not use it for advertising.

AI-generated content

Menu and standards text may be processed by an AI service (Anthropic) to generate training questions. We send the business content being converted — not staff personal details or training records.

Who else touches the data

We use a small set of service providers to run the platform: Supabase (database hosting), Vercel (web hosting), Resend (transactional email), Sentry (error monitoring), and Anthropic (AI content generation, as described above). Each receives only what it needs to do its job.

Keeping and deleting data

We keep data for as long as your workplace has an active account. Business owners can request export or deletion of their organization's data at any time. If you are a team member and want your personal data corrected or removed, ask your employer or email us and we will work it out with them.

Security

Data is encrypted in transit, access is role-based (staff can never see answer keys or other people's results beyond what the product shows), and every organization's data is partitioned from every other's at the database level.

Changes

If this policy changes in a way that matters, we will note the new date at the top of this page and let account owners know. This service is intended for workplace use and is not directed at children.