Privacy Policy for Tabres
Effective Date: August 29, 2026
Last Updated: August 29, 2026
This Privacy Policy explains how Tabres ("Tabres," "we," "our," or "us"), based in Amsterdam, the Netherlands, collects, uses, shares, and protects personal data when you visit our websites (including tabres.com and its subdomains), use our hospitality management platform (including the dashboard, Point of Sale (POS), Kitchen Display System (KDS), and ordering products), or view or order from a digital menu that a restaurant publishes through us (together, the "Services").
This Policy is drafted to meet the requirements of the EU General Data Protection Regulation (GDPR) and the UK GDPR. Section 10 applies in addition if you are a resident of a US state whose privacy law applies to us. Our Terms and Conditions govern your use of the Services and contain our data processing terms for restaurant data (Section 9 of the Terms).
1. Who We Are and Our Role
- As a data controller: We are the controller of the personal data of account holders and their representatives, visitors of our websites, people who contact us, and the technical and analytics data described in this Policy that we collect for our own purposes, including on the public menu pages of restaurants that use Tabres.
- As a data processor: When a restaurant or other business (a "Merchant") uses the Services to take orders, reservations, or payments, to publish menus, or to manage its staff, the Merchant is the controller of the personal data of its guests and staff ("Merchant Data"), and we process that data only on the Merchant’s behalf and instructions. If you are a guest or a staff member of a Merchant, the Merchant’s own privacy notice applies to that data, and you should direct requests about it to the Merchant. We will assist the Merchant in responding.
- Contact: Questions and requests about personal data can be sent to privacy@tabres.com. Our full contact details are in Section 15.
2. Personal Data We Collect
- Account and business information: Name, email address, phone number, business name, business type, country, and the details of each branch you set up, such as its legal name, tax number, and address. We do not use account passwords: you sign in with a one-time code that we email to you, or through a third-party sign-in provider (such as Google, Facebook, GitHub, or Apple), in which case we receive the identifier and basic profile information (such as your name and email address) that the provider shares with us. Staff PIN codes used within the platform are stored as hashes. Providing this information is necessary to create and operate an account; without it, we cannot provide the Services to you.
- Billing and payment information: If you purchase AI credits or activate the optional payment processing feature, we collect billing details and keep records of the fees you pay. Payment card details are entered directly with, and processed by, our payment service provider under its own privacy policy. We receive transaction records (such as amount, date, status, and payment method) but not your full card number. Activating payment processing may require the payment service provider to verify your identity and business under anti-money-laundering laws; the provider acts as an independent controller for that verification.
- Content and operational data: Menus, images, product videos, branding, inventory, table layouts, staff records and schedules, orders, reservations, and other information that you or your staff enter into the Services. To the extent this includes personal data of your guests or staff, it is Merchant Data that we process on your behalf.
- Usage and technical data: IP address, browser and device type, operating system, language, referring page, pages and features used, timestamps, and error and diagnostic logs, collected automatically when you use the websites or the platform.
- Communications: The content of emails, support requests, feedback, and messages you send us, including through WhatsApp if you choose to contact us that way.
- Guest data (as processor): When a guest orders, reserves, or pays through a Merchant’s menu, we process the data the guest provides, such as name, contact details, table or delivery details, order contents, and order notes, which may include allergy or dietary information. The Merchant is the controller of this data.
3. Why We Use Personal Data and on What Legal Basis
We use personal data for the purposes below. For each purpose we indicate the legal basis under Article 6 GDPR on which we rely.
- Providing the Services: Creating and managing your account, operating the platform, displaying your menus and ordering pages, transmitting orders to your POS and KDS, and providing support. Legal basis: performance of a contract with you (Article 6(1)(b)), or our legitimate interest in operating the Services where you act on behalf of a business (Article 6(1)(f)).
- Billing and payments: Charging the fees you agree to, issuing invoices, and keeping accounting records. Legal basis: performance of a contract (Article 6(1)(b)) and compliance with our legal obligations, including tax law (Article 6(1)(c)).
- AI Features: Generating menu translations and analytics at your request. Legal basis: performance of a contract (Article 6(1)(b)). Where Merchant Data is involved, we act on your instructions as processor.
- Security, fraud prevention, and troubleshooting: Keeping the Services secure, detecting abuse and fraud, and diagnosing and fixing errors. Legal basis: our legitimate interest in protecting the Services, our users, and ourselves (Article 6(1)(f)).
- Analytics and improvement: Understanding, in aggregate, how our websites and menu pages are used so that we can improve them. Legal basis: our legitimate interest in improving the Services (Article 6(1)(f)), using the cookieless analytics described in Section 4.
- Communications: Sending service messages (such as security notices, changes to the Terms, and information about your account) and responding to your enquiries. Legal basis: performance of a contract and our legitimate interest in communicating with our users (Article 6(1)(b) and (f)). We may also send existing customers information about our own similar products and features; you can opt out at any time using the link in the message or by emailing us.
- Advertising measurement: Only with your consent (Article 6(1)(a)), as described in Section 4. You can withdraw consent at any time.
- Legal compliance and claims: Complying with laws, court orders, and requests from competent authorities, and establishing, exercising, or defending legal claims. Legal basis: compliance with legal obligations (Article 6(1)(c)) and our legitimate interests (Article 6(1)(f)).
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You can ask us for more information about that assessment, and you have the right to object (see Section 9).
4. Cookies, Local Storage, and Analytics
We take a privacy-first approach. Our websites and menu pages do not set advertising or cross-site tracking cookies of our own. We use the following technologies:
- Strictly necessary storage: The platform uses session and authentication tokens to keep you signed in, and our websites use browser local storage to remember settings such as your language and whether you have seen our cookie notice. These are required for the Services to work and do not need your consent.
- Security cookies: Our content delivery and security provider, Cloudflare, may set cookies that are necessary to protect the Services against bots and attacks. These cookies do not track you across websites.
- Cookieless analytics: We use Plausible Analytics, hosted on our own infrastructure, on our websites and on public menu pages. Plausible does not use cookies and does not store IP addresses or persistent identifiers. Your IP address and browser details are processed transiently to compute an anonymised, daily-rotating identifier, and only aggregated statistics (such as page views, referrers, countries, and device types) are kept. We do not share this data with third parties.
- Advertising pixels: We do not load advertising or social media pixels (such as the Meta Pixel) without your prior consent. If we run an advertising campaign and wish to measure it, we will ask for your consent through a consent banner before any pixel is loaded, and we will update this Policy to describe it. You can withdraw consent at any time.
- Google Maps: Public menu pages load Google Maps to show a restaurant’s location and to support delivery address entry. When the map loads, Google LLC receives your IP address and browser details and may set its own cookies, under Google’s privacy policy. We rely on our and the Merchant’s legitimate interest in showing the restaurant’s location (Article 6(1)(f)).
- Do Not Track: Because we do not sell personal data or use it for cross-site advertising, there is nothing to opt out of, and we do not change our behaviour in response to browser "Do Not Track" signals.
5. Who We Share Personal Data With
We do not sell personal data, and we do not share it with third parties for their own marketing. We share personal data only with the following categories of recipients, and only to the extent needed:
- Cloudflare: Content delivery network, DNS, and security services. Cloudflare processes IP addresses and request metadata on its global network to route and protect traffic.
- Amazon Web Services (AWS): File storage (AWS S3) in an EU region for the images, videos, and files you upload.
- Payment service providers: If you activate payment processing, the provider named at activation processes payment and, where required, identity verification data as an independent controller under its own privacy policy.
- AI providers: To deliver AI Features, we may send the content needed for the feature you use (such as menu text to be translated) to third-party AI model providers acting as our sub-processors. We send only what the feature requires.
- Email delivery providers: To send one-time login codes and account, security, and service emails (such as Brevo and Resend).
- Sign-in providers: If you sign in through Google, Facebook, GitHub, or Apple, that provider processes your sign-in as an independent controller under its own privacy policy and shares basic profile information with us.
- Google LLC: Google Maps on public menu pages, as described in Section 4.
- Meta Platforms: Only if you choose to contact us through WhatsApp, in which case WhatsApp processes your messages under its own terms and privacy policy.
- Merchants: If you are a guest, the Merchant you order from receives the data you provide with your order or reservation, as the controller of that data.
- Professional advisers, authorities, and successors: Lawyers, auditors, and accountants where needed; courts, regulators, and law enforcement where the law requires or permits it; and a successor or acquirer if our business is transferred, in which case this Policy continues to apply to your data.
Error and operational logs are kept on infrastructure that we host ourselves; we do not send them to third-party monitoring services. Sub-processors that process Merchant Data on our behalf are bound by data protection obligations that are substantially equivalent to those in our Terms and Conditions, and we inform Merchants of changes to them in advance.
6. International Transfers
We host the platform and store your data on servers located in the European Economic Area (EEA). Some of the providers listed in Section 5 (for example Cloudflare, Google, payment service providers, and AI providers) may process personal data outside the EEA or the UK, including in the United States. Where that happens, we rely on appropriate safeguards under Chapter V of the GDPR: an adequacy decision of the European Commission (including, for the UK, the UK adequacy decision and, for certified US companies, the EU-U.S. Data Privacy Framework) or the European Commission’s standard contractual clauses, supplemented where necessary by additional measures. You can request further information about these safeguards by contacting us.
7. How Long We Keep Personal Data
We keep personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law. In particular:
- Account data: For as long as your account is active. After your account is closed, you may request an export of your data for 30 days, after which we delete or anonymise it within a reasonable time, as described in Section 17 of the Terms.
- Merchant Data: For as long as the Merchant instructs us through its use of the Services, and after the end of the Services as described in the Terms. Merchants may delete Merchant Data at any time using the platform.
- Invoices and accounting records: For the period required by Dutch tax and accounting law, which is currently seven years.
- Usage, security, and error logs: For limited periods needed for security, fraud prevention, and troubleshooting, after which they are deleted or anonymised.
- Communications: For as long as needed to handle your enquiry and, where relevant, for the applicable limitation period for legal claims.
- Analytics: Only aggregated statistics that do not identify you are retained.
- Backups: Copies in routine backups are overwritten in the ordinary course of our backup cycle.
8. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption of data in transit (TLS), hashed storage of staff PIN codes and session secrets, access controls based on least privilege, logging and monitoring, regular backups, and hosting in the EEA. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs, we will notify the affected Merchants without undue delay and will notify the supervisory authority and affected individuals where the law requires it. You are responsible for keeping your account credentials confidential.
9. Your Rights
If you are in the EEA, the UK, or another jurisdiction that grants similar rights, you have the following rights regarding the personal data for which we are the controller:
- Access: To obtain confirmation that we process your personal data and a copy of it.
- Rectification: To have inaccurate or incomplete data corrected.
- Erasure: To have your personal data deleted where there is no longer a valid reason for us to keep it.
- Restriction: To have processing restricted in certain circumstances.
- Portability: To receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection: To object to processing based on our legitimate interests, and to object at any time to direct marketing.
- Withdrawal of consent: Where we rely on your consent, to withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint: To lodge a complaint with a supervisory authority. Our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl). You may also complain to the authority of the EU country where you live or work, or, in the UK, to the Information Commissioner’s Office (ICO).
To exercise any of these rights, email privacy@tabres.com. We may ask you to verify your identity. We respond within one month, which may be extended by up to two further months for complex requests, in which case we will tell you. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive. If your request concerns data that we process on behalf of a Merchant, we will forward it to the Merchant and assist the Merchant in responding.
10. Additional Information for US State Residents
This Section applies if you are a resident of a US state with a comprehensive consumer privacy law (such as California) and that law applies to us. In the preceding twelve months, we have not sold personal information and have not shared it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for purposes other than providing the Services. Subject to applicable law and verification of your identity, you have the right to know what personal information we collect, use, and disclose; to access, correct, and delete it; to opt out of any sale or sharing (which we do not carry out); and not to be discriminated against for exercising your rights. You may designate an authorised agent to submit a request on your behalf. To exercise these rights, email privacy@tabres.com. The categories of personal information we collect and the purposes for which we use them are described in Sections 2, 3, and 5.
11. Children
Our websites and platform are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16 for our own purposes. Where a Merchant allows guests to order through its menu, the Merchant is responsible for the personal data of its guests, including any age-related requirements that apply to it.
12. Automated Decision-Making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
13. Third-Party Websites and Social Media
Our websites contain links to third-party websites and to our social media profiles. We are not responsible for the privacy practices of those third parties, and their own privacy policies apply when you visit them.
14. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, the Services, or the law. We will post the updated Policy on this page and update the dates at the top. If a change materially affects how we use personal data for which we are the controller, we will also notify account holders by email or through the platform dashboard before the change takes effect.
15. Contact Us
If you have any questions about this Policy or our data practices, or wish to exercise your rights, please contact us at:
Tabres
Amsterdam, the Netherlands
Data protection: privacy@tabres.com
General enquiries: contact@tabres.com
Website: https://tabres.com