Permissions & privacy
Who can connect
Section titled “Who can connect”| Role in the shop | Can connect? | Sees |
|---|---|---|
| Shop owner (owner position in the shop’s staff register) | ✅ always | Everything available, including cost and profit |
| Staff with the “View reports” right | ✅ | Sales, bills, shifts, stock and the other shop topics — never cost, profit or information about other staff (table below) |
| Staff without the “View reports” right | ❌ | The shop does not appear on the shop picker |
| Deactivated staff, or accounts not in the shop’s staff register | ❌ | — |
| Franchise head office (on the franchise’s staff list, with the “1.4 Overview” right on the franchise website) | ✅ every branch of that franchise | Counted as the owner of every branch, as on the franchise website — including cost, profit and staff information ¹ |
| Branch investor (branches head office linked to this account) | ✅ only the linked branches | Counted as the owner of those branches ¹ |
| Head-office accounts without the “1.4 Overview” right | ❌ | Branches do not appear on the shop picker (except branches where the account is itself in the staff register) |
| System admins · ScanFood team | ❌ | Closed on purpose — only people of the shop or franchise can connect it to an AI |
¹ If the account is also in that branch’s own staff register, the role in the branch register comes first (e.g. listed as staff = no cost for that branch) — the same as on the website. The shop picker shows each shop’s role label before you press Allow.
The “View reports” right is the same right used for reports in the ScanFood app — the shop owner grants it to each staff member.
Cost and profit = shop owner only
Section titled “Cost and profit = shop owner only”“Owner” on this page includes franchise head office and branch investors as in the table above · It is decided per shop — a connection with several shops may see cost for one shop but not for another where the account is staff. This is decided on every question, not remembered from when you connected. If the person who connected is not the shop owner, cost, profit, waste value and ingredient unit cost are removed before anything leaves ScanFood — the AI never receives them, so they cannot leak into an answer.
Staff information = shop owner only
Section titled “Staff information = shop owner only”Names of staff and what they did are sent only to a connection made by the shop owner: who closed a bill, who cancelled a bill or an item, who opened and closed a shift, clock-in times, cheer-sale per person, who received or adjusted stock, and who changed an ingredient cost. For anyone else these fields are left out before anything leaves ScanFood, or the whole topic is refused.
Who sees what
Section titled “Who sees what”| Topic | Shop owner | Staff with “View reports” |
|---|---|---|
| Sales summary · bills · best sellers · sales by hour, category, table and option | ✅ | ✅ without cost/profit · without the cashier’s name on bills |
| Sales by cashier · sales by seller | ✅ | ❌ |
| Discounts · VAT & service charge · GP estimate | ✅ | ✅ |
| Cancellations | ✅ with who cancelled | ✅ without who cancelled |
| Current shift · shift history (cash over/short) | ✅ with who opened/closed and shift notes | ✅ amounts only |
| Open tables · kitchen backlog | ✅ | ✅ |
| Member totals · promotions · customer deposits · prepaid deposits | ✅ | ✅ |
| Menu and prices | ✅ | ✅ |
| Ingredient stock · stock loss | ✅ with cost | ✅ without cost |
| Ingredient movements | ✅ with value and who did it | ✅ quantities only |
| Purchase orders | ✅ | ❌ (order prices are costs) |
| Staff attendance · cheer-sale per staff member | ✅ | ❌ |
| Ingredient cost changes | ✅ | ❌ |
Permissions are checked live on every question
Section titled “Permissions are checked live on every question”Every time the AI fetches data, ScanFood checks again that the account is still in the shop, still active and still has the reports right. So if a staff member leaves, is deactivated or loses the “View reports” right, their connection stops working from the very next question. (The same applies to head office removed from the franchise or losing the “1.4 Overview” right · in a connection with several shops, only the shop that lost access stops working.) Nobody has to remember to cancel it.
The AI can only see the shops you chose
Section titled “The AI can only see the shops you chose”When you press Allow you tick the shops the AI may read (several are fine), or choose Whole franchise — that set is pinned on the ScanFood side. The AI can only say “which shop in this set” it wants. On every question ScanFood checks two things: the shop is in the set you chose, and the account still has access to it right now. Failing either gives the same message — the shop is not part of this connection (without revealing whether the shop exists). ⇒ Even if someone types another shop’s ID in the chat, or text in a menu tries to steer the AI to another shop, it can never reach beyond the shops you ticked yourself.
- Whole franchise = branches your account gains access to later are included automatically (checked live every time) · branches the account cannot view are not included
- One connection holds up to 200 shops and 20 franchises
- When a connection covers several shops, the AI must name the shop each time — if it doesn’t, ScanFood sends back the list of shops so the AI asks you (it never guesses a shop)
- Every per-shop answer carries the name of the shop the numbers belong to
Franchise-wide totals
Section titled “Franchise-wide totals”With Whole franchise chosen, the AI can ask for combined sales of every branch (what you can ask)
- Only branches this account can view are included, and every answer says how many branches were counted out of how many
- Cost in the total is shown only when the account is the owner (per the table above) of every branch included — if any branch is staff-only, cost is removed from the whole total with the reason stated (a half-counted cost would mislead)
Read-only
Section titled “Read-only”- ScanFood gives the AI read commands only — there is no command to create, edit or delete shop data.
- Every command is labelled read-only so the AI app can see it too.
- The connection is granted the “read” scope only.
Data never sent to the AI
Section titled “Data never sent to the AI”Not to the shop owner, not to staff — these are left out of every answer:
- Passwords and PINs — yours and your staff’s. You sign in on the ScanFood page; the AI app never sees your password.
- Customers’ personal details — names, phone numbers, emails, addresses, customer tax-invoice details and bill notes; the names, phone numbers, notes and photos on deposit and prepaid-deposit slips; the customer name, address and notes on orders; and member lists (members on a bill appear only as a masked ID, and member topics give totals only).
- Staff contact details and rights — phone numbers, emails, positions, rights, and clock-in photos. Staff names go to the shop owner’s connection only (see above).
- Supplier contact details — phone numbers, addresses and bank accounts. Purchase orders show only the supplier name written on the order.
- Bank account numbers, PromptPay IDs and integration keys of the shop.
What is sent and worth knowing: menu names, ingredient names, cancellation reasons and other text your shop typed are sent as typed, and shift history includes the cash counted at shift close.
Where the data goes
Section titled “Where the data goes”Data the AI reads to answer you is sent for processing to the AI provider you chose (OpenAI for ChatGPT · Anthropic for Claude · xAI for Grok), possibly on servers outside Thailand, and is covered by that provider’s data policies and your account settings — for example, whether chats may be used to improve models. Set this in your account with that AI app.
Expiry
Section titled “Expiry”| What | Lifetime | What it means for you |
|---|---|---|
| Connection request (while signing in and picking a shop) | 10 minutes | Too slow = “link no longer valid”; start again from the AI app |
| The pass the AI uses to ask for data | 1 hour | The AI app renews it in the background; nothing for you to do |
| The connection | 60 days from the last renewal | Keep using it = it never lapses · unused for more than 60 days = connect again |
Protections ScanFood applies
Section titled “Protections ScanFood applies”- Passes are stored only as one-way hashes — even if stored data leaked, it could not be used to act as you.
- If a renewal pass that was already used is presented again (a sign of theft), ScanFood cancels that whole connection immediately.
- The sign-in result can only be returned to AI apps on ScanFood’s approved list — a look-alike site cannot capture access.
- The allow page cannot be embedded inside another site (prevents trick clicks).
- Each connection is limited to 60 requests per minute — stops an AI from looping endlessly.
- Text your shop typed (menu names, notes) is flagged to the AI as data, not instructions.

