Privacy Policy
We value your privacy and we want to be totally transparent about how we handle and protect yours, your teams and your customers data.
1. What data we collect
1.1 Venue account data (we are controller)
Name, job title, business name, email address, phone number, billing address, and payment/subscription metadata (see section 4 on Stripe — we do not receive or store full card numbers).
1.2 Staff data (venue is controller, we are processor)
Name, contact details, role, shift schedules, clock-in/clock-out timestamps, and device location at the moment of clock-in/clock-out, used to verify staff are on-site when starting or ending a shift. This is a point-in-time location check, not continuous or background tracking — location is only captured when a staff member actively clocks in or out through the app.
1.3 Guest/diner data (venue is controller, we are processor)
Name, phone number, email address, booking details (date, time, party size, table), and any notes the venue records against a booking, which may include dietary requirements or allergy information. Allergy/health-related information is “special category data” under UK GDPR — venues are responsible for having an appropriate lawful basis (typically explicit consent from the guest) before recording it.
1.4 Technical and usage data
IP address, browser/device type, log data, and analytics/diagnostic data generated by use of the Service, collected automatically for security, debugging, and service improvement.
2. How we use data
We use personal data to:
- provide, operate, and maintain the Service (accounts, bookings, scheduling, floor-plan management);
- process subscription payments via Stripe;
- send transactional communications: booking confirmations/reminders to guests, and shift/schedule notifications to staff, via email (Resend), SMS (Twilio), and push notifications (Firebase Cloud Messaging / web push);
- verify staff clock-in/clock-out location, on the venue’s instructions;
- provide support to venue admins and staff via our support chat (Chatwoot);
- maintain the security, integrity, and performance of the Service;
- comply with legal obligations.
We do not sell personal data, and we do not use guest or staff personal data processed on behalf of venues for our own marketing or advertising purposes.
3. Legal basis for processing (UK GDPR)
Where we act as controller (venue account data, section 1.1), we rely on: performance of a contract (providing the Service to you), legitimate interests (service security, improvement, and support), and legal obligation (e.g. tax/accounting records).
Where we act as processor (staff and guest data, sections 1.2–1.3), the venue is responsible for identifying its own lawful basis (e.g. consent, contract, employment law, legitimate interest) — we process this data only on the venue’s documented instructions, as set out in the Data Processing Addendum referenced in our Terms of Service.
4. Subprocessors and third-party services
We use the following subprocessors to provide the Service. Each is bound by a data processing agreement requiring appropriate security and confidentiality:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting | All data transmitted through the Service |
| Neon | PostgreSQL database hosting | All data stored in the Service (accounts, bookings, schedules) |
| Stripe | Subscription payment processing | Venue billing/payment data (we never receive full card numbers) |
| Resend | Transactional email delivery | Recipient email address, message content (booking/shift notifications) |
| Twilio | SMS delivery | Recipient phone number, message content (booking confirmations/reminders) |
| Firebase Cloud Messaging | Push notifications | Device push token, notification content |
| UploadThing | File storage (e.g. uploaded images/documents) | Files uploaded by venues/staff |
| Chatwoot | Support chat | Contact details and message content of venue admins/staff contacting support (not used for guest-facing chat) |
We may add or change subprocessors from time to time; material changes will be reflected here and, where required by our Data Processing Addendum, notified to venue account holders in advance.
5. International data transfers
Our infrastructure (hosting and database) is currently configured to keep data within the UK/EU. Some subprocessors above (e.g. Stripe, Twilio, Firebase) are US-headquartered global providers; where personal data is transferred outside the UK/EEA as part of their service delivery, we rely on appropriate safeguards such as the UK International Data Transfer Addendum or equivalent Standard Contractual Clauses.
6. Data retention
- Venue account data: retained for the duration of your subscription and for a reasonable period afterward for legal, accounting, and dispute-resolution purposes.
- Staff and guest data: retained in line with the venue’s own retention settings and instructions, and in any event no longer than needed to provide the Service, subject to the venue’s obligation to manage retention for their own staff/guest records.
- On account cancellation, see the export/deletion terms in our Terms of Service — data not exported before cancellation is processed may not be recoverable.
7. Security
We use appropriate technical and organisational measures (e.g. encryption in transit, access controls, hosting provider security) to protect personal data. No system is completely secure, and we cannot guarantee absolute security of data transmitted to or stored within the Service.
8. Your rights
If we are the controller of your data (venue account holders, section 1.1), you have the right, subject to UK GDPR, to request access to, correction of, deletion of, or restriction on the processing of your personal data, and to data portability and objection to processing based on legitimate interests. Contact us at info@taybl.food to exercise these rights.
If you are a staff member or guest of a venue (sections 1.2–1.3), please direct data rights requests to the venue directly, as they are the controller of your data. We will support venues in responding to such requests where required by our Data Processing Addendum.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.
9. Children
The Service is not directed at children, and we do not knowingly collect personal data directly from children. Booking data may occasionally reference a party that includes children (e.g. party size), but this policy does not apply to marketing to or direct data collection from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app notice at least 14 days before they take effect.
11. Contact us
Questions about this Privacy Policy, or requests to exercise your data rights, can be sent to info@taybl.food, or by post to 3 Caxton Road, Preston, PR2 9ZZ.