Privacy Policy
Last updated June 29, 2026. This policy describes the Measured HRIS app used by restaurant groups for HR, payroll, benefits, tax, and treasury workflows.
Who this policy covers
Measured HRIS is an employer-administered HRIS and payroll application. The app processes information for restaurant groups, their employees, contractors, managers, platform support users, and payroll/benefits administrators.
Account, authentication, and workspace data
End users sign in with email and password. The app collects account profile fields such as first name, last name, email, role, group membership, workspace assignments, access-level assignments, and entity assignments used for tenant isolation and role-based access. The app does not provide end-user social OAuth login. Integration OAuth tokens and API credentials are for connected services only and are stored in encrypted integration configuration records.
HR and payroll records collected
The data model includes employee identity and job records, including employee code, name, email, phone, department, manager, work location, EIN, pay group, cost center, hire and termination dates, hourly rate, tipped status, address, emergency contact, pay schedule, ACA status, and punch PIN.
- Time, payroll, and compensation records: shifts, punches, timecards, tip pools and allocations, pay periods, payroll runs, paychecks, wages, tips, gross pay, taxes, net pay, PTO hours, compensation-history changes, and final-pay or correction records.
- Tax and compliance records: W-4, IT-2104, NYC withholding settings, filing status, dependents, allowances, additional withholding, exemptions, tax deposits, filings, employee tax documents such as W-2, W-2C, 1095-C, and 1099 records, wage notices, labor notices, and document expirations.
- Garnishment records: order type, priority, amount owed, amount withheld, per-check withholding, status, and related payroll-remittance tracking.
- Benefits and leave records: benefit plans, benefit groups, benefit enrollments, coverage tier, employee and employer cost, effective and end dates, PTO balances, PTO requests, life events, COBRA records, DBL/DI carrier and claim records, disability dates, weekly benefit amounts, certifications, and benefit payments.
- Dependent records: dependent first and last name, relationship, date of birth, SSN last four, disability indicator, and age-out date.
- Documents and HR workflow records: onboarding tasks, documents, document templates, signatures, hiring records, candidate and job-opening records, performance reviews, coaching records, disciplinary records, support messages, Ask HR tickets and messages, notifications, and action items.
Banking, payments, and treasury data
Payment-method workflows may collect bank name, account type, account last four, allocation instructions, prenote status, Plaid processor tokens, and bank routing/account details needed to set up direct deposit or employer funding. Raw bank details are not displayed back to users. Modern Treasury receives the banking details and payroll metadata required to create counterparties, external accounts, funding events, payment orders, ledger entries, webhook events, returns, and reconciliation records. Modern Treasury payment data is sandbox-first until live-money approval is explicitly enabled.
Cookies and analytics
The Benmore framework provides an anonymous _bm_vid analytics cookie. It is set only after a visitor accepts the cookie banner. It is used for pageview counts and session timing for this app only. Measured HRIS does not use third-party trackers or cross-site advertising trackers. Public pages load web fonts from Google Fonts (fonts.googleapis.com), which receives the visitor's browser IP address to serve the font files; it is listed on our Subprocessors page. The app is hosted on the Benmore platform, which runs on Amazon Web Services.
Email, SMS, and connected services
The current integration configuration identifies AWS SES for outbound email and Twilio for SMS. Tenant integrations may also connect services such as Toast, QuickBooks, Plaid, Checkr, and Modern Treasury. Those providers receive only the information needed to perform the requested integration task, such as sending a message, verifying a bank account, running a background-check workflow, syncing payroll/accounting data, or originating a payment order. The full, maintained list of subprocessors — with purpose, data categories, processing location, and DPA status — is published on our Subprocessors page.
Security, audit, and sensitive-access logging
Measured HRIS uses tenant isolation through group membership, role-based access control, secure read flows for sensitive tables, MFA for platform-privileged roles, and step-up authentication for sensitive actions. Security records include ActivityLog entries with actor, action, object, changes, IP address, and timestamp; StepUpEvent entries with actor, tier, method, success, IP address, and timestamp; SensitiveFieldAccessLog entries for access to sensitive fields; and LitigationHold records for legal holds, custodians, scope, counsel contact, release, and preservation actions.
Retention and data requests
Employment, payroll, tax, benefits, audit, and legal-hold records may be retained for the periods required by payroll, tax, employment, benefits, litigation, and customer-contract obligations. To request access, correction, export, or deletion, contact your employer's HR or payroll administrator through Measured HRIS support or the support channel in your workspace. Some records cannot be deleted immediately when retention is legally required, when they are part of payroll/tax reporting, or when a litigation hold is active. The current data-request handling runbook is published at Data Requests & Retention.