Privacy Policy
Executive Privacy Commitment: TableServe is an enterprise SaaS restaurant operating system. We do not sell customer or merchant data, do not run invasive third-party advertising trackers, and process information strictly to provide ordering, kitchen display, and POS billing services.
1. Scope & Applicability
This Privacy Policy governs the collection, processing, and protection of information across:
- TableServe Merchant Console (
/console) used by restaurant owners and managers. - TableServe Captain App (
/captain) used by restaurant floor waitstaff. - TableServe Diner Web App (
/m/:slugand/t/:tableId) accessed by restaurant guests via table QR codes. - TableServe Platform Administration (
/platform).
2. Information We Collect
We strictly minimize the data collected to what is technically necessary to operate restaurant dining and billing:
- Merchant Account Data: Restaurant business name, owner name, login credentials (passwords stored using one-way
scryptcryptographic hashes), business address, phone number, GSTIN, and optional FSSAI license numbers. - Menu & Catalog Data: Categories, dishes, descriptions, prices, dietary tags (Veg / Non-Veg / Vegan), and item photographs uploaded by the restaurant.
- Floor Operational Data: Table configurations, open table sessions, floor orders placed via QR or Captain app, cooking notes, timestamps, order fulfillment status, and payment method indicators (e.g. Cash, UPI, Card).
- Staff Profiles: Staff member names, roles (Manager, Captain), and 4-digit security PIN hashes.
- Technical Diagnostics: Server uptime telemetry, local Bluetooth thermal printer pairing MAC addresses (stored purely in local client storage), and sanitized application error logs.
3. Information We Never Collect or Sell
In accordance with our zero-tracking architecture:
- No Payment Card / Banking Credentials: TableServe does not store credit card numbers, CVVs, expiration dates, or bank PINs. Payments in physical restaurants are recorded as settlement method labels.
- No Mandatory Diner Tracking: Diners can view menus and order without being forced to create an account, install an app, or surrender phone numbers or email addresses.
- No Third-Party Ad Brokers: We never monetize, rent, or sell merchant sales data or consumer dining habits to data brokers or advertising networks.
4. Data Storage, Security & Cryptography
TableServe implements enterprise-grade technical and organizational safeguards:
- Transport Layer Encryption (TLS): All HTTP and WebSocket communications are encrypted in transit using modern TLS 1.3 / HTTPS.
- Cryptographic Password & PIN Hashing: Passwords and staff PINs are hashed using salted
scryptwith cryptographic timing-safe comparisons to prevent dictionary and rainbow-table attacks. - Multi-Tenant Vault Isolation: All database queries strictly partition access by
restaurant_id, enforced at the SQL database layer. Cross-tenant data leakage is cryptographically and logically blocked. - Local Storage Hardening: Android client packages enforce
allowBackup="false"to prevent unauthorized USB file extraction. Browser storage is isolated under the Web Same-Origin Policy (SOP).
5. Data Retention & Account Deletion
We adhere to strict data minimization and lifecycle management:
- Active Accounts: Operational data is retained during the active lifecycle of the restaurant subscription to power historical sales analytics and GST Rule 46 compliant record keeping.
- Account Deletion: When an account is terminated or upon explicit request from the restaurant owner, all associated tables, sessions, orders, staff records, menu catalogs, and uploaded images are permanently and atomically purged from the primary database using relational
ON DELETE CASCADEconstraints. - Nightly Backup Rotation: Encrypted disaster recovery snapshots are rotated and purged automatically after 30 days.
- Error Logs: Operational server error logs are capped at 5MB and rotated on a rolling basis.
6. Merchant Rights & Data Ownership
Restaurants retain 100% intellectual property and commercial ownership of their menus, pricing, customer order records, and sales history. Merchant owners may:
- Export comprehensive sales and order reports to CSV/Excel formats at any time via the Console Reports tab.
- Modify or delete staff accounts, menu items, or tables instantly.
- Request complete account export or permanent erasure by contacting platform support.
7. Legal Compliance
This policy complies with applicable data protection laws, including the Digital Personal Data Protection (DPDP) Act 2023 and the Information Technology Act 2000. Financial record preservation complies with GST Rule 46 tax invoice regulations.
8. Contact & Data Protection Officer
For privacy inquiries, data deletion requests, or security audits, contact:
TableServe Data Protection & Support:
📱 Phone / WhatsApp: +91 70764 77348
✉️ Email: sudipdev09@gmail.com
🌐 Website: https://tableserve.in