Privacy Policy

Effective: 2026-04-27

Last updated: 2026-04-27

Introduction

At TableSnap, we respect your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our restaurant menu management and ordering platform. Please read this policy carefully.

What We Collect

We collect the following types of information:

  • Restaurant owner accounts: Email address, hashed password (Argon2 encryption), display name, and menu management data.
  • Customer (anonymous) data: Device ID, table number, order history, and order preferences.
  • Menu images: Photos of physical menus uploaded to Cloudflare R2 secure storage.
  • Usage analytics: First-party analytics only (no third-party trackers). This includes page views, feature usage, and error events.

How We Use It

  • Account creation, authentication, and account management.
  • Delivery and operation of the platform.
  • Transactional emails via Resend (account confirmations, order notifications, password resets).
  • Understanding product usage, improving features, and diagnosing technical issues.
  • Security, fraud prevention, and compliance with legal obligations.
  • Enforcement of our terms and other legal rights.

Lawful Basis (GDPR)

We process your personal data under one or more of these lawful bases:

  • Performance of a contract with you (restaurant account creation and menu management).
  • Compliance with legal obligations (payment processing, tax reporting, data retention laws).
  • Our legitimate interests (improving product security, preventing fraud, analytics).
  • Your explicit consent (where required, such as marketing communications).

How Long We Keep Your Data

We retain your data for as long as necessary to provide the service and comply with legal obligations:

  • Account credentials and profile information: retained while your account is active. After deletion, permanently removed within 30 days.
  • Order history: retained for 7 years (to comply with tax and restaurant record-keeping requirements).
  • Menu images: retained while the menu is published. Deletion on request or after 90 days of account inactivity.
  • Encrypted backups: retained for 30 days, then permanently deleted.

Who We Share Data With

We do not sell your personal data. We only share data with trusted service providers necessary to operate the platform:

  • Google OAuth: OAuth sign-in. Google does not receive menu or order data.
  • Resend: Transactional email delivery. Resend receives only email address and message content (no menu or order details).
  • Firebase Cloud Messaging: Push notifications for admin alerts. Firebase receives user ID only (no email, menu, or order data).
  • Cloudflare R2: Menu image hosting. Cloudflare stores encrypted images; content is private to your restaurant.

We do not share personal data with advertisers, brokers, or any third parties for marketing purposes.

Your GDPR Rights

You have the right to:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data (subject to legal retention requirements).
  • Restriction: Limit how we use your data while we investigate a dispute.
  • Portability: Receive your data in a portable, machine-readable format.
  • Objection: Opt out of certain processing activities, such as profiling or marketing.
  • Withdraw consent: If processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact support@tablesnap.io with your request. You can also use the API endpoint GET /api/v1/auth/me to view your account data, or request account deletion via our account settings page.

Cookies and Tracking

We do not use third-party cookies or tracking scripts. All analytics are first-party and anonymized.

We use essential cookies only to maintain your session and authentication state. These cookies are necessary for the platform to function and cannot be disabled.

International Data Transfers

Your data is stored on AWS Lightsail in the Singapore region (Asia-Southeast-1). If you are in the EU, this constitutes an international transfer. We rely on Standard Contractual Clauses (SCCs) to ensure adequate data protection.

Children

TableSnap is not intended for users under 13 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13, we will immediately delete it.

Changes to This Privacy Policy

We may update this policy periodically. We will notify you of material changes by email or by posting the updated policy on our website. Your continued use of the platform constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy, our privacy practices, or wish to exercise your rights, please contact us at:

TableSnap uses essential cookies to keep you signed in. With your consent we also use first-party measurement to improve the product. We never sell your data and we never run third-party trackers.

Read the full cookie policy