MOST CMS legal
MOST CMS Privacy Policy
Effective date 29 September 2026
Provided by MOST AI Labs on behalf of Bite of Balkan
Contact: info@mostailabs.com
1 Scope and responsibility
This policy covers the Bite of Balkan deployment of MOST CMS, including its connected business accounts and related support. MOST AI Labs provides and manages the service on behalf of Bite of Balkan. Bite of Balkan determines the purposes for its business content and customer enquiries and controls its business accounts. MOST processes that information on the business’s instructions and also handles account, support and security records needed to operate the service. This policy covers the CMS and its integrations; it does not replace Bite of Balkan’s notice about its wider restaurant activities. Neither organisation’s responsibilities under applicable law are removed by this arrangement.
2 Information we handle
Depending on the features enabled, we handle authorised users’ names, email addresses, roles and authentication records; business content such as menus, prices, photographs and promotions; records of approvals and changes; and support correspondence. Operational records may include network addresses, device or browser information, timestamps and error information needed for security and troubleshooting. Photographs or messages supplied by a client may contain personal information. Clients should provide only information necessary for the service.
3 Facebook and Instagram connections
When an authorised person connects business assets through Facebook Login for Business, the enabled permissions determine the information received. This may include selected Page, professional Instagram account and business identifiers and names; an authorising account identifier; connection credentials, granted permissions and available expiry information; and publishing records, content identifiers, status messages and aggregate performance metrics. We use this information to connect the selected assets, publish approved content, show publishing results and insights, and maintain connection health. We do not request the person’s Facebook or Instagram password. Comment or message management is outside the initial CMS social integration; any later collection for those features will be explained before activation.
4 Other connections and enquiries
Where enabled, the read-only Clover connection handles merchant identifiers and business details needed to identify the connected account; authorisation credentials, granted permissions and connection status; and catalogue information such as items, prices, categories, modifiers and availability. These are used to maintain the authorised connection and synchronise the restaurant’s menu. The initial menu integration does not request customer profiles or payment-card details. An order-reporting feature will require an updated description of the data accessed before activation. Customer enquiries submitted through the restaurant’s website may include names, contact details, event details and messages, processed on Bite of Balkan’s behalf to respond. An enquiry does not by itself enrol a customer in marketing.
5 Purposes and choices
We use information to provide the agreed features, manage access, deliver requested notifications, support users, protect the service and meet legal obligations. The client controls its content and authorises connected-platform activity. A person may withdraw consent where applicable by contacting us, subject to legal or contractual restrictions explained at the time. Withdrawing information or access necessary for a feature may prevent that feature from working. We do not sell personal information or use connected-platform data to build advertising profiles.
6 AI assisted features
Where AI-assisted drafting is enabled, the content selected for drafting and relevant business context may be sent to an external AI service to generate suggestions. Users must review suggestions before publication. Connected-platform credentials are not inputs to drafting. Customer enquiries, private messages and other customer personal information are outside the intended drafting inputs. Any proposed use of connected-platform personal information for AI processing will require a separate assessment of permission and platform requirements and an updated notice before activation. We do not use connected-platform data to train our own machine-learning models.
7 Disclosure and service providers
We disclose information to authorised client users and to connected platforms as necessary to carry out authorised actions, including public publishing. We use service providers for hosting, storage, delivery of content, operational email, background processing, support and security monitoring, and AI drafting where enabled. Providers receive information needed for their functions and are subject to applicable contractual safeguards. We may also disclose information where required or permitted by law, including to respond to valid legal process or protect legal rights. Contact us for information about providers relevant to your data.
8 Processing outside Canada
Personal information is stored and processed in the United States, including our primary database, and may be accessed in Canada for service administration and support. Other service providers or their authorised processors may process information in other countries depending on the enabled service. Information processed outside Canada may be accessible to courts, law enforcement or public authorities under local laws. Contact us for current information about the locations relevant to your information. MOST remains responsible for its applicable privacy obligations when using service providers.
9 Safeguards
We use reasonable administrative, technical and physical safeguards appropriate to the sensitivity of the information, including access restrictions and protection of connection credentials. Access is limited to people and service providers with a legitimate operational need. No system can guarantee absolute security. Report suspected unauthorised access to the contact address below.
10 Retention and deletion
We retain personal information only as long as needed for the purposes described here, the client’s authorised service, and applicable legal requirements. Connection credentials are removed when no longer needed following disconnection or offboarding. Revocation on an external platform may require notification or detection before corresponding local records are removed. Requests for deletion can be submitted at any time, without ending the client’s agreement.
Client content and operational records are reviewed for deletion or return during offboarding. Enquiry records, where enabled, follow the client’s disclosed retention schedule; MOST does not retain them indefinitely simply because an account remains active. Limited records may need to be kept for legal obligations, resolving disputes or documenting the handling of a privacy request. Such retention is restricted to what is necessary and must comply with applicable platform requirements. Backup copies may persist until replaced under the applicable backup cycle and are not used for routine business processing. We explain applicable timing and exceptions when handling a deletion request. See MOST CMS Data Deletion Instructions or email us for assistance.
11 Access correction and complaints
You may ask for access to your personal information, request correction, withdraw consent where applicable, or request deletion by contacting us. We may reasonably verify identity and authority before acting. Requests concerning information managed for a client may require coordination with that client. We respond within the time required by applicable law and explain any lawful extension or refusal. Applicable privacy laws include British Columbia’s Personal Information Protection Act and, where applicable, Canada’s Personal Information Protection and Electronic Documents Act. You may raise unresolved concerns with the Office of the Information and Privacy Commissioner for British Columbia at oipc.bc.ca, or the Office of the Privacy Commissioner of Canada at priv.gc.ca, as appropriate.
12 Changes and contact
We will update this policy when our practices materially change, show the effective date and notify affected client businesses where appropriate. For privacy questions or requests, contact MOST AI Labs, attention Privacy, at info@mostailabs.com. Our location is Vancouver, British Columbia, Canada.
13 Google API data
Where Google Business Profile access is enabled, the service handles the authorised business account and location identifiers, profile information needed for the enabled functions, connection credentials and permissions, and content and status records for approved publishing. Performance information is accessed only where an enabled reporting feature requires it. Review text, reviewer information or additional Google data will not be collected for a new feature without an updated disclosure and any required consent. Google data is used to provide the prominently described, user-facing features authorised by the business.
MOST CMS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its applicable Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy. Such data is not sold or used for advertising, creditworthiness decisions or unrelated profiling. Where Limited Use applies, transfers are limited to permitted purposes: providing or improving disclosed user-facing features with consent, security, compliance with law, or an eligible business transfer with explicit prior consent. Human access is limited to the exceptions allowed by that policy, including affirmative agreement to view specific data, necessary security or legal access, and permitted aggregated internal operations. General support access does not override these restrictions.
Any permitted caching of content obtained through the Google Business Profile APIs is limited to the purposes and conditions Google allows, including temporary storage for no more than 30 calendar days, secure handling and restrictions on manipulation and aggregation. This limit concerns Google API content; it does not automatically apply to original content supplied independently by Bite of Balkan. Platform-specific restrictions take precedence over general retention descriptions in this policy. Google access can be revoked through the Google account’s third-party connections controls or by contacting MOST at info@mostailabs.com.
14 Platform deletion and assistance
Meta data is processed only for the disclosed, authorised purposes. We will delete applicable Meta platform data without undue delay when required by Meta’s terms, including in response to a valid user deletion request or when it is no longer necessary for the permitted service, subject only to retention allowed by those terms and applicable law. A general reference to backups or dispute records does not create a right to retain platform data contrary to platform requirements. We will arrange necessary deletion with processors that hold the affected data.
For information processed on Bite of Balkan’s behalf, MOST will coordinate requests with the business and reasonably assist it in fulfilling applicable privacy obligations. For data held independently by Clover, its own privacy notice and request process apply: https://www.clover.com/privacy-policy. Requests can always be initiated through info@mostailabs.com; no active CMS account is required.