The Owner account
What this covers
What makes the Owner account different from every other, why it should not be a shared shift login, and
how to hand a restaurant over. Requires the manage-users permission to see the staff list.
What is special about it
| The Owner | Detail |
|---|---|
| Has every permission | All sixteen. There is nothing in the app an Owner cannot reach |
| Is the only role that can touch billing | The
manage-billing permission belongs to Owner alone — not even a Manager has it |
| Cannot be deleted | Not from the staff list, and not from its own profile page |
| Is the billing identity | The subscription, the payment method and the invoices belong to it |
That billing exclusivity is worth understanding, because it is the one thing you cannot delegate. A Manager can change your operating hours, add staff and edit every booking — but cannot see an invoice, change the card, buy SMS credits or change plan. If you want someone else able to do those things, the only route is to make them an Owner too (link Roles and what each one can do).
Why it cannot be deleted
Two reasons, and both are protecting you. It is the identity your subscription is attached to, so deleting it would orphan the billing relationship. And the restaurant must always have at least one account that can reach everything — otherwise a mistake could leave a workspace nobody can administer.
If you genuinely want to close the account, the route is to cancel the subscription, not to delete the Owner. The refusal message says exactly that (link Cancelling and resuming).
Do not use it as a shift login
The most common mistake a new restaurant makes is leaving the Owner signed in on the host stand so anybody can use it. It is understandable — it always works — and it costs you four things:
- Your audit log becomes useless. Every change is attributed to "the Owner", so you can never tell who did anything (link The audit log).
- Everyone gets full access, including billing, your card details and the ability to delete staff.
- You cannot remove one person's access without changing a password everybody uses.
- One careless click is unlimited. An Owner can cancel your subscription or wipe your settings; a Host cannot.
Give the host stand its own Host account. It takes two minutes and it is the single highest-value thing you can do for your account's safety (link Adding staff accounts).
Should there be more than one Owner?
Usually not. One Owner plus one or two Managers suits nearly every restaurant.
A second Owner makes sense in two situations: genuine co-owners who both need billing access, or a business partner who must be able to act if you are unreachable. In both cases they should be someone you would trust with your bank card, because functionally that is what you are doing.
Handing a restaurant over
When the business changes hands, or the person who set the account up leaves:
- Create an account for the new owner with the Owner role.
- Have them sign in and confirm they can reach Subscription and see the billing details.
- Have them update the payment method to theirs (link Your payment method).
- Check the restaurant's contact details on the profile — the email there receives guest replies (link Restaurant profile).
- Then delete the old Owner's account, which is possible once another Owner exists.
- Rotate the credentials the departing owner knew — API keys, phone trigger URLs, bypass codes (link Editing and removing staff).
Do it in that order. Creating the new Owner before removing the old one means there is never a moment with nobody in charge, and the deletion is only permitted once a second Owner exists.
If the Owner's email is no longer reachable
This is the situation worth preparing for, because it is the one you cannot solve yourself.
If the Owner's email address no longer works — the person left, the mailbox was closed, the domain lapsed — then password reset is unavailable, because reset links go to that address. And if nobody knows the password either, there is no self-service route back in.
What to do
- If another Owner or a Manager can still sign in, they can change the stranded account's email address and password from the staff list. Solve it that way and you need nobody's help (link Editing and removing staff).
- If nobody can sign in at all, contact support. You will need to prove you are entitled to the account — expect to be asked about the billing details and the subscription (link Reporting a problem).
Preventing it
- Use an email address that outlives individuals — a shared business address rather than one person's personal mailbox.
- Keep a second Manager account, so one lost password is never a locked-out restaurant.
- Keep the Owner's recovery codes somewhere safe if it has two-factor enabled — losing the phone without them is its own version of this problem (link Two-factor authentication).
Good to know
The Owner can be locked out by failed sign-ins like anyone else. A Manager can unlock them, which is a good reason to have one (link Unlocking a locked-out account).
Support can sign in as you to help, and when they do a banner makes it obvious (link When support signs in to help).