Privacy Policy
Effective: August 30, 2026 · Version 2026-08-30
This notice applies to ramaops.com, app.ramaops.com, and Rama OS services that link to it.
1. Who we are and when we act for customers
Rama OS is operated by Maya Coffee Company LLC, Hammond, Indiana. We act as a controller for Rama account administration, direct communications, billing, security, support, and our own product operations. When a hospitality business uses Rama to process employee, applicant, guest, reservation, order, or other operational data, that business generally decides why and how the data is used and Rama processes it on the business's behalf. The business must provide its own notices and obtain any consent required for its activities.
2. Information we process
- Public-site and support data: name, work email, business, role, location count, request topic, message, and correspondence.
- Accounts and security: name, email, organization, role, authentication, session, device, IP, audit, and security-event data.
- Workforce and applicants: contact details, applications, documents, wages, schedules, attendance, training, certifications, and related records.
- Guests and hospitality operations: contact details, reservations, visits, preferences, notes, loyalty activity, consent records, orders, and communications.
- Commerce and finance: orders, transaction references, invoices, billing, accounting, tax, and fraud-prevention records. Rama does not intentionally store raw card numbers.
- Voice: caller number, call metadata, transcripts, consent evidence, and audio only when recording is enabled and permitted.
- Vision: camera snapshots, zone and occupancy events, safety events, and configured derived identifiers.
- AI: prompts, selected operational context, tool results, outputs, usage, and safety metadata when an AI feature is used.
- Uploads and integrations: submitted files and metadata, provider identifiers, and data authorized from connected services.
- Telemetry: route, device, browser, performance, error, and masked error-session replay data.
3. Sources
We receive information from you, your organization, guests or employees who interact with a customer's service, connected systems authorized by the customer, browsers and devices, and service providers that report delivery, security, payment, or integration events.
4. Purposes and legal bases
We process information to provide and secure Rama, fulfill requests, operate enabled features, support customers, communicate transactional information, improve reliability, prevent fraud and abuse, comply with law, and send product communications where permitted.
Depending on the context and applicable law, our basis may be performance of a contract, steps requested before a contract, legitimate interests, compliance with legal obligations, or consent. Consent is specific to the processing for which it is requested and may be withdrawn without treating acceptance of unrelated terms as privacy consent.
5. Artificial intelligence
AI features may send prompts and the minimum operational context needed for the requested result to an approved model provider. Rama's currently configured providers include Anthropic and OpenAI for different features. Adding a credential alone does not authorize a provider for tenant data; provider approval and data-egress rules also apply. AI output may be inaccurate and should be reviewed before consequential use. Customers must not use Rama AI as the sole basis for employment, credit, health, or similarly significant decisions.
See the product privacy details for feature-specific roles, recipients, and retention context.
6. Disclosures and subprocessors
We disclose information to service providers that host, secure, monitor, communicate, process payments, provide AI or speech functions, or operate customer-authorized integrations. We also may disclose information when required by law, to protect rights and safety, or as part of a business transaction subject to appropriate safeguards.
See the current subprocessor list. We do not sell personal information or use it for cross-context behavioral advertising.
7. Cookies, local storage, and telemetry
Rama uses authentication cookies and similar storage needed for login, security, preferences, and requested functionality. We use Vercel platform logs and Sentry for error monitoring, performance traces, and replay of sessions that encounter an error. Replay is configured to mask text and block media, but telemetry can still include device, route, timing, IP, and error context. We do not use advertising cookies on these Rama domains.
Read the current cookies and telemetry details.
8. Retention and deletion
We keep information only for the period reasonably necessary for the stated purpose, customer instructions, security, disputes, and legal obligations. Periods vary by category: account and support records follow the relationship and closure process; tenant operational data follows customer instructions and product configuration; short-lived Voice, Vision, upload, and AI artifacts follow feature-specific schedules; and payment, payroll, tax, and audit evidence may require longer retention. Backups expire under provider schedules. When deletion is not legally permitted or would destroy required audit evidence, we restrict use and minimize or pseudonymize identifiers where appropriate.
9. Your privacy rights
Depending on your location and our role, you may request access, correction, deletion, portability, restriction or objection, withdrawal of consent, or information about recipients and automated processing. You may also have rights to opt out of sale, sharing for targeted advertising, or certain profiling; Rama does not currently conduct those activities. You will not be discriminated against for exercising a right.
Submit a request through our privacy request form or email privacy@ramaops.com. We may verify your identity and authority proportionately. If we deny a request, you may appeal by replying with “Privacy appeal” and the request reference. You may also complain to the privacy regulator or attorney general in your jurisdiction.
If Rama processes data solely for a customer, we may direct the request to that customer and assist it as required by our agreement and applicable law.
10. International transfers
Providers may process information outside your state or country. Where required, we use contractual safeguards such as data-processing agreements and standard contractual clauses. Contact us to request information about applicable safeguards.
11. Security
We use safeguards designed for the nature of the information, including encrypted transport, provider encryption at rest, access controls, tenant-scoped application controls, private storage for sensitive uploads, monitoring, and incident response. No system is completely secure. Report suspected security issues to security@ramaops.com.
12. Children
Rama is a business service and is not directed to children under 13. Customer workforce or guest use involving minors must be authorized and noticed by the customer. Contact us if you believe a child's information was provided improperly.
13. Changes and contact
We will post the updated version and effective date here. For a material change, we will use a reasonable additional notice appropriate to the relationship and obtain consent when required.
Version dates and change summaries are available in the privacy notice archive.
Maya Coffee Company LLC · Hammond, Indiana · privacy@ramaops.com