Your restaurant data belongs to you.
We protect it like our own business depends on it — because it does. Here is exactly how TakoRos keeps your data safe, private, and completely isolated from every other restaurant on the platform.
Complete data isolation between restaurants
Row-level securityEvery restaurant on TakoRos has its own completely isolated data environment. This is enforced at the database level using row-level security (RLS) — not just at the application level. This means that even in the event of a bug or misconfiguration, one restaurant cannot access, see, or affect another restaurant's data. Your orders, staff, customers, and revenue are visible only to your account.
Encrypted connections — always
TLS + at-rest encryptionAll communication between your devices and TakoRos servers uses HTTPS with TLS encryption. Data is encrypted in transit on every request — the POS, the dashboard, the KDS, and the online ordering plugin. Data is encrypted at rest in the database. There is no unencrypted path to your data.
Payment data never touches our servers
Paddle PCI-DSSTakoRos uses Paddle for all payment processing. When you upgrade your plan or process a subscription, your card details go directly to Paddle — a PCI-DSS compliant payment processor. TakoRos never stores, sees, or has access to your card numbers or payment credentials. Restaurant transaction data (your customer orders and payments) is stored securely in your isolated tenant environment.
Offline data stays on your device
Local-firstWhen TakoRos operates offline, order data is stored locally on your tablet or device. This local data is accessible only to the device it was created on and the authenticated TakoRos account. When your connection returns, data syncs securely to your tenant environment. Offline operation does not create any shared or exposed data state.
Regular security reviews and updates
OngoingThe TakoRos codebase receives regular dependency updates to address known vulnerabilities. Row-level security policies are reviewed when new features are added. Infrastructure providers (Railway, Vercel, Supabase) are audited and reputable platforms with their own security programmes. We do not wait for incidents to review security — it is part of every build cycle.
We do not sell or share your data
No data salesTakoRos does not sell restaurant data, menu data, customer data, or operational data to any third party. We do not use your restaurant's data for advertising. Aggregated, anonymised product analytics may be used internally to improve TakoRos — never identifiable data, never sold. Your data is yours.
Infrastructure
Built on reputable, audited platforms.
TakoRos is not hosted on unknown infrastructure. Every provider below has its own security programme, uptime SLA, and compliance certifications.
Supabase
Database & authentication
PostgreSQL database with row-level security. SOC 2 Type II compliant. Data encrypted at rest.
Railway
Backend hosting
Node.js API server. Automatic deployments. Isolated container environment per service.
Vercel
Frontend hosting
Next.js landing and dashboard. Global CDN. Automatic HTTPS. DDoS protection included.
Shared responsibility
What we handle. What you handle.
TakoRos handles
- Data encryption in transit and at rest
- Tenant isolation via row-level security
- Infrastructure uptime and reliability
- Regular security and dependency reviews
- Payment processing security via Paddle
- Secure offline data sync
You handle
- Keep staff PINs private and secure
- Use strong passwords for your account
- Keep your devices physically secure
- Log out on shared or public devices
- Report any suspicious activity promptly
- Keep your contact email up to date
Found a security issue?
If you discover a vulnerability or have a security concern, please contact us directly. We take every report seriously and will respond promptly.
Last reviewed: August 2026