Last updated 13 September 2026

Privacy Policy

Your supplier pricing is commercially sensitive. This policy sets out exactly what we collect, who else sees it, and what you can make us do about it.

Who we are

DishCost is operated by Pramesh Singh, trading as DishCost (ABN 11 821 612 396), based in New South Wales, Australia. In this policy “we” and “us” mean that business.

We handle personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).

What we collect

  • Account data — your name, email address and organisation, collected through our authentication provider when you sign up.
  • Business data — the suppliers, ingredients, recipes, invoices and prices you enter or upload. This is your commercial data, not personal information about you, but we treat it as confidential either way.
  • Invoice documents — photographs and PDFs of supplier invoices you choose to scan. See How we use AI below.
  • Sales data — if you connect a point-of-sale system, the order and item data we pull from it.
  • Technical data — request paths, status codes, performance timings and error diagnostics. We do not log request bodies, so the contents of your invoices and recipes do not appear in our error reports.

We do not buy contact lists or enrich your details from third-party data brokers.

How we use it

To run the service: costing your recipes, cascading supplier price changes through dependent dishes, producing your reports, taking payment, and supporting you when something breaks. We do not run product analytics or behavioural tracking, so we have no record of which screens you visit or how long you spend on them.

We do not sell your data. We do not use your business data to train AI models — not ours, and not anyone else’s.

How we use AI

DishCost can read a supplier invoice from a photo or PDF. When you use that feature, the document you upload is sent to Anthropic’s API in the United States, where a Claude model extracts the supplier, dates, line items and totals. The extraction is returned to you as a draft for review.

Three commitments on invoice scanning:

  • The uploaded image or PDF is kept only while the draft is open for review. It is permanently deleted the moment you approve or discard that draft.
  • Your documents are not used to train Anthropic’s models, or ours.
  • Nothing an AI extracts reaches your costing until a human has reviewed and approved it. The model never writes to your data unattended.

Automated extraction can be wrong. You are responsible for checking a draft before approving it, and we build the review step in for exactly that reason.

Where your data lives, and who else touches it

Your business data is stored in PostgreSQL in Sydney, Australia (ap-southeast-2). Some of the providers we depend on operate outside Australia, which means some information is disclosed overseas:

RecipientWhat forWhere
NeonDatabase hosting — all of your business dataSydney, Australia
VercelApplication hosting and content deliveryUnited States (global edge)
ClerkAuthentication — your name, email, organisationUnited States
StripePayment processing — we never see your card detailsUnited States, Australia
AnthropicAI invoice extraction — only documents you scanUnited States
SquareSales sync — only if you connect itUnited States
SentryError monitoring — diagnostics, no request bodiesUnited States
UpstashRate limiting — user identifiers onlyUnited States

We take reasonable steps to ensure these providers handle your information consistently with the APPs, but by using DishCost you agree to this overseas disclosure.

How long we keep it

Business data is kept while your account is open. Scanned invoice images are deleted on approval or discard, as above.

To close your account, email us and we will delete your data within 30 days. There is no self-service delete button — we do it by hand, on request, so that an irreversible deletion is never one mis-click away. We keep records we are legally required to keep, such as tax and payment records, which Australian law requires us to hold for five years.

Your rights

You can export your own data at any time from Settings → Your data — a spreadsheet with a tab per table, or a complete JSON copy. You can also ask us to give you a copy, correct it, or delete it. Email support@dishcost.com.au and we will respond within 30 days.

If you are unhappy with how we have handled your information, tell us first and we will try to fix it. You can also complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Security

Data is encrypted in transit. Point-of-sale access tokens are encrypted at rest. Every request is scoped to your organisation, so one venue’s data cannot be read by another. We take reasonable technical and organisational measures to protect your information, but no system connected to the internet can be guaranteed secure.

Cookies

We use first-party cookies for signing you in and remembering a small amount of interface state. We do not use advertising or cross-site tracking cookies, and we do not run third-party ad trackers on this site.

Children

DishCost is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.

Changes to this policy

If our practices change we will update this page and change the date at the top. For material changes — a new category of data, or a new overseas recipient — we will email account holders before the change takes effect.