Role-based access control (RBAC) to limit permissions by user role.
Support for strong authentication methods (password policies, optional SSO/SSO federation if available).
Data protection and privacy
Data encryption at rest and in transit (TLS for data in transit; encryption standards for stored data).
Secure handling of payment data in compliance with PCI-DSS requirements (scope may be limited by PCI integration approach).
Data residency and governance
Options for data residency depending on region or regulatory needs.
Audit logs and change histories to track who did what and when
Compliance framework
Security best practices aligned with common standards; certifications may vary by vendor region.
Regular vulnerability assessments and patching of the platform as part of maintenance.
Updates
FoodStorm typically performs regular product updates (monthly to quarterly) with ongoing minor improvements and bug fixes.
Major releases may occur a few times per year, introducing new modules or significant changes.
How updates are delivered
Cloud/SaaS model: updates are deployed by FoodStorm to the hosted environment, with no on-premises install required.
Customer-facing release notes outlining new features, changes, and any deprecations
Change management for customers
Scheduled maintenance windows and advance notice of planned downtime or behavioral changes.
Feature toggles or phased rollout options for customers who want to test new capabilities before full adoption.
Compatibility guidance for integrations and customizations during major releases.
Data Ownership and Portability
Data ownership
Typically, the customer retains ownership of their data that is entered into FoodStorm (menus, orders, customer records, event details, delivery data, etc.).
FoodStorm often acts as a data processor/hosting provider, with responsibilities defined in a data processing addendum (DPA) or equivalent.
Data access and export
Customers should have ongoing access to their data via secure interfaces (admin portal, API, or data export tools).
Data portability options usually include: export of core data (customers, orders, menus, products, events) in common formats (CSV, JSON) and, where applicable, archived historical records.
For catering/event modules or specialized data (e.g., routing, driver logs), ensure there are export options or API access to retrieve relevant datasets.
Data retention and deletion
Contracts typically specify data retention periods after contract termination and processes for secure data deletion or return.
Scaling Up / Down
Elastic scalability
Most SaaS deals offer scalable licensing based on locations, users, order volume, or feature tier. You should be able to scale by adding locations, users, or modules without a full re-quote.
There may be minimum/maximum limits or tier-based pricing adjustments when scaling mid-term.
Change process
Changes typically require a formal change request, impact assessment (cost, implementation effort, timelines), and updated billing for the new scope.
For large scale changes (e.g., moving from 1 to 10 locations or adding major modules like advanced catering), a revised implementation plan and new contract rider may be needed.
Timeframes
Scaling actions usually have defined lead times (e.g., 2–4 weeks for provisioning new locations or users) and may trigger pro-rated billing or a new term alignment.
Cancelation/downsizing during term
Some contracts allow mid-term downsizing with notice, often with a minimum non-cancelable period or penalties for abrupt reductions that affect committed capacity.
Data access and export rights generally remain intact through the termination window.
The terms & conditions for contract renewal and cancellation
Renewal structure
Automatic renewal vs. opt-in renewal with notice period.
Renewal notice window: how far in advance you must commit to renew (e.g., 60–90 days).
Term length and renewal options
Common term lengths: 1 year, 3 years, or multi-year; options to extend or switch plans at renewal.
Rights to switch product tiers or add/remove modules at renewal.
Cancellation rights
Notice requirements for non-renewal or early termination (e.g., 60–90 days’ written notice).
Early termination penalties or fees, if any (e.g., unamortized deployment costs, remaining term fees).
Termination for cause (breach of contract, non-payment) vs. termination for convenience (rare in SaaS; may incur fees or data return obligations).
Compliance
SOC 2 Type II (Security and Operational Trust Services): evaluates controls around security, availability, processing integrity, confidentiality, and privacy.
ISO 27001: information security management system certification for structured risk management.
PCI-DSS compliance scope: relevant if FoodStorm handles or processes cardholder data. Clarify if scope includes full PCI DSS compliance or delegated/segmented scope via PCI-compliant integrations.
GDPR/CPRA (for customers in or dealing with EU/UK/California residents): data processing agreements, data subject rights handling, and cross-border transfer mechanisms.
Data localization/residency options: whether data can be stored in specific regions or countries.
HIPAA/other sector-specific standards: only if FoodStorm targets healthcare/regulated sectors (less common in foodservice, but relevant for some enterprise customers).
Subprocessors and transparency
List of subprocessor categories (cloud providers, payment processors, email/SMS providers) and the ability to receive updates when subprocessors change.