Privacy Policy

Last updated: June 4, 2026

This Privacy Policy explains how TabQ ("we", "us") collects, uses, and protects personal data when you use our QR ordering and restaurant management Service.

1. Information we collect

2. How we use information

We use data to provide the Service (authenticate users, route orders to the kitchen and staff, calculate totals and tax, generate receipts), to manage subscriptions and billing, to secure the platform, and to improve our features.

3. Legal bases

Where applicable, we process data to perform our contract with you, to comply with legal obligations, and based on our legitimate interest in operating and securing the Service.

4. Sharing & processors

We use trusted infrastructure providers (including Google Firebase for authentication, database, and hosting) to process data on our behalf. We do not sell personal data. We may disclose data where required by law.

5. Data retention

We retain account and operational data for as long as your subscription is active and for a reasonable period afterward, then delete or anonymize it unless a longer period is required by law (for example, tax records).

6. Security

We apply role-based access controls, scope each business's data to its own tenant, device-lock kitchen screens, and rely on encrypted connections. No system is perfectly secure, but we work to protect your data.

7. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights.

8. Cookies & local storage

We use essential cookies and browser local storage to keep you signed in and to remember a kitchen device's identifier. These are necessary for the Service to function.

9. Children

The Service is intended for businesses and is not directed at children.

10. Changes & contact

We may update this policy and will note the new effective date above. For privacy questions or requests, see our contact page.

This document is a general template and not legal advice. Replace the company details and jurisdiction-specific clauses (e.g. GDPR/DPDP) and have it reviewed by a qualified lawyer before launch.