Draft — being finalised before launch; this text will be reviewed by a solicitor.

Privacy Policy

Last updated: 28 September 2026

1. Who we are

TalkTable (operator details will be added before launch) provides a QR-code menu, ordering and AI assistant service to restaurants at talktable.app.

  • Legal name: [LEGAL NAME]
  • Registered address: [REGISTERED ADDRESS]
  • Company registration (CRO) number: [CRO NUMBER]
  • Privacy contact: privacy@talktable.app

We are not currently required to appoint a Data Protection Officer [TO CONFIRM]. Questions about this policy or your data go to the privacy contact above.

2. Our role: controller or processor

Under the EU General Data Protection Regulation (GDPR) we play two different roles:

  • Controller for restaurant accounts (owners, managers and staff who sign in to TalkTable), for the optional TalkTable diner account described in section 4, and for running and securing the service itself.
  • Processor for the restaurant when a diner uses a restaurant's table page to browse, chat with the AI assistant, order or call staff. The restaurant decides why and how that data is used; we handle it on the restaurant's instructions under a data processing agreement [DPA TO BE PUBLISHED].

If you are a diner and want to exercise your rights over an order you placed at a restaurant, you can contact that restaurant directly, or contact us and we will pass your request on and help the restaurant respond.

3. Data about restaurant users

When a restaurant signs up or invites team members, we collect and store:

  • Name, email address, role (owner/admin or staff) and staff type (waiter, chef, manager).
  • A password hash (bcrypt). We never store your password in readable form.
  • Restaurant details: name, web address (slug), timezone, currency, language, plan and trial status.
  • Sign-in sessions (a random token and its expiry), password-reset tokens and staff invites (the invitee's name, email and role).
  • An activity log of actions taken in the dashboard — for example menu or price changes, orders marked preparing/served, staff invited — linked to the user who did them.
  • Conversations with the admin AI assistant (your messages and its replies), menu photos you upload for the AI to read, and menu item images.

Why and on what legal basis

  • To provide the service you signed up for — performance of a contract (Art. 6(1)(b) GDPR).
  • To keep the service secure, prevent abuse, debug problems and understand usage — our legitimate interests (Art. 6(1)(f)).
  • To send service emails such as invites and password resets — performance of a contract. We do not send marketing emails today; if we start, we will ask first where the law requires it.

4. Data about diners

Diners do not need an account to use a restaurant's table page. When you scan a table QR code, we process the following on the restaurant's behalf:

  • Table session and orders: the table, the items, sizes, options and quantities you order, notes you add (for example “no onions” or an allergy note), order status and timestamps.
  • Optional name: if you type a name when placing an order, it is shown to the restaurant's staff with the order and kept with the order and table session.
  • AI assistant chats: the messages you type to the AI waiter, its replies, and questions you ask about a specific dish. These are stored so the conversation can continue and so the restaurant can review how the assistant is performing.
  • Voice ordering: if you use the microphone, the recording is sent to our AI provider for transcription. We do not store the audio recording; we keep the resulting text.
  • Service requests and feedback: calls for a waiter or the bill, table-change requests and any note you add, plus feedback on AI answers (for example which suggestions you tapped, added or removed).
  • Activity events: a record of what happened on the page (menu searches, items viewed or added, AI messages sent, orders placed). Each event may carry the text involved (for example a search term or message). To protect privacy we do not store your IP address: we store a one-way, salted hash of it, plus a coarse device category such as “Safari Mobile · iOS”, to help detect abuse. A random identifier kept in your browser links events from the same visit.

Optional diner account

You can choose to sign in with a one-time email link (“magic link”). This account is provided by TalkTable and works across every restaurant that uses TalkTable, so for it we act as controller. It stores:

  • Your email address and, if you add them, your name and preferred language.
  • Dietary preferences, favourite foods and allergies you choose to record. Allergy and dietary information can reveal health information, which is a special category of data; we only store it because you enter it, and we rely on your explicit consent (Art. 9(2)(a) GDPR). You can remove it at any time from your account page.
  • A visit history: the restaurant name, items and total for orders you place while signed in.

If the restaurant has personalised suggestions switched on, your name, preferences, allergies and recent visits (including visits to other TalkTable restaurants) are given to the AI assistant so it can make relevant, allergy-aware suggestions. They are not shown to restaurant staff.

Why and on what legal basis

  • Orders, service requests and chats: processed for the restaurant, which relies on performing its contract with you (taking your order) and its legitimate interests (running and improving its service).
  • Diner account: performance of a contract with you, and your explicit consent for allergy and dietary data.
  • Security and abuse prevention (for example the hashed IP): our and the restaurant's legitimate interests.

Please do not type sensitive information you do not need to share (such as health details beyond an allergy note, or payment details) into chats or order notes.

5. How the AI features use data

TalkTable uses OpenAI's API to power the AI waiter, reading menu photos, translating menus and transcribing voice orders. When you use these features, the relevant text, image or audio — together with the restaurant's menu and, for signed-in diners, the account context described above — is sent to OpenAI to generate a response.

Under OpenAI's API terms, data sent through the API is not used to train OpenAI's models by default. OpenAI may keep API data for a limited period for abuse monitoring [TO CONFIRM retention period and zero-data-retention eligibility].

The AI does not make decisions that have legal or similarly significant effects on you. Its answers are suggestions; a diner always confirms an order, and staff handle it.

6. Who we share data with

We do not sell personal data and we do not use advertising or analytics trackers. We share data only with:

  • The restaurant you are ordering from: its staff see your orders, notes, optional name, service requests, and its admins can see chats and activity for their restaurant.
  • Amazon Web Services (AWS) — hosting, database, file storage and sending email (Amazon SES).
  • OpenAI — AI chat, menu photo reading, translation and voice transcription.
  • Namecheap — our domain registrar only; it does not receive diner or restaurant data through the service.
  • Authorities or others where required by law, or to protect our rights, users or the public.
  • A buyer or successor if the business is sold or reorganised, under the same protections.

We will update this list, and notify restaurant customers, before adding a new sub-processor.

7. International transfers

Our AWS infrastructure is currently located in the United States (region us-east-1). We plan to move it to the EU (Ireland, eu-west-1) [TO CONFIRM migration date]. OpenAI processes data in the United States.

Where personal data is transferred outside the European Economic Area, we rely on the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission's Standard Contractual Clauses, together with the providers' security measures [TO CONFIRM each provider's certification / SCC status].

8. How long we keep data

We keep personal data only as long as needed. Current defaults:

  • Restaurant accounts and their data: for as long as the account is active, then deleted within [TO CONFIRM — e.g. 90 days] of closure, except where we must keep records for legal or tax reasons.
  • Sign-in sessions: 30 days for restaurant users, 90 days for diner accounts, or until you sign out. Expired sessions, sign-in links and password-reset links are deleted 7 days after they expire.
  • Diner email sign-in links: valid for 30 minutes and single-use.
  • Staff invitations that are never accepted: deleted 30 days after they expire.
  • Orders and table sessions: kept for the restaurant as its records, but the name and any notes typed by the diner (on the order, its items, waiter or bill requests, and the table) are removed after 90 days. Items, prices and totals are kept.
  • AI chats with diners: deleted 90 days after the last message. Restaurant staff's saved assistant chats: deleted 12 months after the last message.
  • AI chat statistics (which dishes were suggested, clicked or ordered): the diner's typed text is removed after 30 days and the record is deleted after 90 days.
  • Activity events: after 30 days, any text you typed (searches, messages, notes, voice transcripts), the name you gave and the hashed IP address are removed; the event itself is deleted after 13 months. Restaurant admins can also delete events older than 7, 30 or 90 days at any time.
  • AI usage and cost records (token counts and costs, no chat text): deleted after 12 months.
  • Diner accounts: until you delete the account.
  • Voice recordings: not stored by us.

9. Cookies and local storage

We use only what is strictly necessary for the service to work, so we do not show a cookie banner. We use no advertising or analytics cookies.

  • qts_session — keeps restaurant staff signed in (HTTP-only, 30 days).
  • qts_diner — keeps a diner signed in to their optional account (HTTP-only, 90 days).
  • talktable.lang.<table> — remembers the menu language you chose at that table (1 year).

Your browser's local/session storage is used on the table page to:

  • keep a random session identifier for the AI chat and for linking activity events to one visit;
  • remember the name you typed for orders, so you are not asked again;
  • remember which menu section you were viewing, and small UI reminders.

You can clear these at any time in your browser settings.

10. Security

We use encryption in transit (HTTPS), hashed passwords, random session tokens, per-restaurant access controls, and restrict access to production systems. Text typed by diners (and diner identifiers) is redacted or pseudonymised in our internal platform-wide activity view; only the restaurant sees it. No system is perfectly secure; if a breach affects your data, we will notify you and the regulator where the law requires.

11. Your rights

Under the GDPR you have the right to:

  • Access your data. Signed-in diners can see their activity history from their account page.
  • Rectification — correct inaccurate data (for example in your profile).
  • Erasure. Signed-in diners can use “Delete my account & data” on their account page. This permanently deletes the diner account, its preferences and allergies, visit history and sign-in links, and anonymises activity events linked to the account: the account link is removed and any text you typed (searches, AI messages, notes, voice transcripts) is removed from those events. Orders you placed remain with the restaurant as its records. Restaurant users can ask us to delete their account by email.
  • Portability — receive data you gave us in a machine-readable format.
  • Object to processing based on legitimate interests, and restrict processing in some cases.
  • Withdraw consent at any time, for example by removing allergy information.

To exercise any right, email privacy@talktable.app. We will reply within one month. We may need to verify your identity first.

You can also complain to the Data Protection Commission (Ireland) at www.dataprotection.ie, or to the supervisory authority where you live or work. We would appreciate the chance to address your concern first.

12. Children

TalkTable is not directed at children under 16, and we do not knowingly create accounts for them. A child may use a table page with a parent or guardian, who is responsible for the order. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We will update this page when our practices change and change the “Last updated” date. For significant changes we will notify restaurant account holders by email in advance.