Terms
Every clause here describes something the product actually does. Where it does not do the thing a terms page usually promises, the clause says that instead.
These terms are between the entity operating ROSFlow and the venue or group that opens an account. "You" is that business, not the individual who typed the form — the account belongs to the venue, and the person who opened it is its first owner.
Opening an account creates a venue and makes you its owner. From there you create your own staff, choose what each role may press, and issue terminal PINs. Everything those people do under your venue is your responsibility; what the product owes you is that the record of it is accurate and cannot be quietly rewritten.
Two-factor authentication is compulsory for owners and managers, and an account in one of those roles that has not enrolled is held on the account screen and cannot reach the rest of the console. That is not a nudge: these are the roles that can void a bill and release a table with money owed.
A terminal PIN is deliberately a different secret from a password. A password is typed once per shift in a back office; a PIN is typed on a tablet in front of guests, where it will be watched. Keep them different, and rotate the PIN freely — it is cheap to change and it is meant to be.
Twenty-one days, no card, and the whole product rather than a cut-down version of it. Nothing is charged during it: where a subscription is set up before the trial ends, it is scheduled to begin on the day the trial does, so the first charge falls after the twenty-one days and not before.
When a trial ends without a subscription the account is marked past due and the console says so. Nothing is suspended, locked or made read-only. The till keeps taking orders, the kitchen keeps printing and bills keep settling — a restaurant losing its till mid-service because a job ran at three in the morning is not a collections strategy, and that escalation is a conversation rather than something a script decides.
A venue with a live subscription is left alone whatever its trial dates say. The subscription answers "are they paying"; the trial date is only the question.
The price is whatever the plan row says, and the comparison page reads those same rows rather than quoting a copy of them. That is deliberate: a price quoted from a copy is a price that will eventually be a lie, and this product has been on the wrong end of exactly that.
Refunds and cancellation have their own page: Refund & cancellation policy.
Moving between tiers is a conversation rather than a switch. We size it with you and adjust the invoice by hand.
That sentence used to read "pro-rated to the day", and it was false. There is no proration in this system. Changing a plan from the operations console updates which plan a venue is on and touches nothing else — it does not tell the payment gateway, so an upgraded venue would receive the larger plan and go on being charged the smaller price, and a downgraded one would lose the features and keep paying the higher amount.
Rather than half-do it, the product refuses. A venue on a live subscription cannot be moved from that screen at all; the refusal names the plan they are billed for and says to cancel and resubscribe, which is the only path that keeps the gateway and our records saying the same thing.
Doing it properly needs proration and, on a downgrade, a credit note — and there is no credit note in this system. The refund page explains what that means for you in practice.
Your venue's data is yours. For the personal data of your own guests you are the Data Fiduciary and we are the Processor acting on your instruction — the privacy policy sets that out in full.
Support cannot walk into your venue. Getting in is the most dangerous capability any platform has, so it is constrained hard and every constraint below is enforced in code rather than in a policy document.
An operator asks; an owner of your venue approves with their own second factor. Only an owner can. The request lapses if nobody answers within fifteen minutes.
The grant expires on its own and is checked on every request, so a session cannot outlive its approval by waiting for a sweep.
The controls that end a session keep working from inside the session, which is the whole point — a control the subject cannot operate is not consent.
Recording a payment, voiding, refunding, cancelling a settled bill, releasing a table unpaid and adjusting a drawer are all refused while an operator is in your venue, whatever role they are wearing.
Where no owner is reachable, a second operator must co-sign, the session may look and never touch, and it lasts fifteen minutes instead of thirty.
The request, the approval or the refusal, the entry and the exit — in your venue's ledger, where you see it, not only in ours.
Run your venue with it. Do not use it to break the law, to hold data you have no basis to hold, or to reach another venue's records — the last of those is enforced at the query layer rather than trusted to good manners, and an attempt is a security incident rather than a support ticket.
Good-faith security research is welcome and is covered by the safe harbour on the Security page, which also sets out its two conditions.
There is no uptime commitment
Not a low one — none. Nothing in this product measures uptime, so no percentage of anything could be promised honestly, and a number here would be invention dressed as telemetry.
The same reasoning removed a "99.98% uptime, 90 days" figure from the home page. It was a literal typed into the markup, and the operations console had been deliberately withholding an uptime figure for years on the grounds that nothing measures it. When there is a measurement, there can be a commitment.
What the product does instead is refuse to depend on us being reachable. The till writes locally first and replays when the line comes back, so a service continues through an outage of ours or of your own broadband. That is a design property you can test on your own network, which is worth more than a percentage in a contract.
Support has published first-response targets and they are on the Contact page. They are targets the queue is measured against, not a contracted service level.
You may stop at any time. Cancellation, what happens to the remainder of a paid period, and what is and is not refundable are all on the Refund & cancellation policy, which is honest about the parts that are still an open decision.
We may suspend an account for non-payment or for a breach of the section above. Suspension is a deliberate act with a recorded reason, taken by a person — there is no automatic path from an unpaid invoice to a dark restaurant.
These clauses are not drafted here, and nothing plausible has been put in their place. A limitation of liability has to name the party being limited, and a governing-law clause has to name a forum, or it decides nothing at all.
Until both are published, treat this page as a description of how the product behaves rather than as a contract.
Changes are published on this page. We do not promise to email you about them, because a promise to notify is only worth what the notification path is worth, and ours is not something to lean a term on today. If that changes, this paragraph changes with it.