Privacy Policy
Last updated: June 4, 2026
This Privacy Policy explains how TabQ ("we", "us") collects, uses, and protects personal data when you use our QR ordering and restaurant management Service.
1. Information we collect
- Business account data: owner name, business name, email, phone, and login credentials.
- Operational data: menus, tables, orders, order items, sessions, and subscription status you create in the Service.
- Customer order data: the items a diner selects and the table they order from. We do not require customers to create an account or provide personal identity to place an order.
- Device & usage data: a device identifier for authorized kitchen screens, plus basic logs needed to operate and secure the Service.
2. How we use information
We use data to provide the Service (authenticate users, route orders to the kitchen and staff, calculate totals and tax, generate receipts), to manage subscriptions and billing, to secure the platform, and to improve our features.
3. Legal bases
Where applicable, we process data to perform our contract with you, to comply with legal obligations, and based on our legitimate interest in operating and securing the Service.
4. Sharing & processors
We use trusted infrastructure providers (including Google Firebase for authentication, database, and hosting) to process data on our behalf. We do not sell personal data. We may disclose data where required by law.
5. Data retention
We retain account and operational data for as long as your subscription is active and for a reasonable period afterward, then delete or anonymize it unless a longer period is required by law (for example, tax records).
6. Security
We apply role-based access controls, scope each business's data to its own tenant, device-lock kitchen screens, and rely on encrypted connections. No system is perfectly secure, but we work to protect your data.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights.
8. Cookies & local storage
We use essential cookies and browser local storage to keep you signed in and to remember a kitchen device's identifier. These are necessary for the Service to function.
9. Children
The Service is intended for businesses and is not directed at children.
10. Changes & contact
We may update this policy and will note the new effective date above. For privacy questions or requests, see our contact page.
This document is a general template and not legal advice. Replace the company details and jurisdiction-specific clauses (e.g. GDPR/DPDP) and have it reviewed by a qualified lawyer before launch.