Draft notice: This document is a structured draft reflecting how Tabl0's platform actually collects and processes data today. Fields shown as [bracketed placeholders] need your registered entity details and a named contact. It should be reviewed by a qualified lawyer — ideally one familiar with Egypt's Personal Data Protection Law (Law 151/2020) and, if you serve customers outside Egypt, the relevant regime there (e.g. GDPR) — before publishing. It is not legal advice.
1. Who we are
[Tabl0 legal entity name] ("Tabl0", "we", "us"), registered at [registered address], is the data controller for personal data processed through the Tabl0 platform, except where a café independently determines the purposes of processing its own customers' loyalty data, in which case the café acts as controller and Tabl0 acts as its processor (see Section 5).
2. Who this policy covers
This policy applies to three groups of people who interact with the Service:
- Customers/diners — people who scan a table's QR code to view a menu and place an order, with or without signing in.
- Café owners & staff — people who create or are invited into a Café Console account to manage a café's menu, tables, orders, and billing.
- Platform administrators — Tabl0's own team members with restricted access to platform-wide administration tools.
3. Data we collect
| Category | What | From whom |
| Order data | Items ordered, quantities, selected variants, order total, table and café identifiers, order status and timestamps | Customers (no account required) |
| Loyalty & identity data | Phone number (for one-time SMS sign-in), optional display name, order history used for reward calculation | Customers who opt in to sign-in |
| Café account data | Email address, café name and address, menu content and photos, table configuration, staff invitations and roles | Café owners & staff |
| Billing data | Selected billing plan, subscription status, and payment-gateway-issued tokens used to reference a saved card for auto-renewal — we do not receive or store full card numbers | Café owners, via the connected payment gateway |
| Payment-gateway credentials | API keys/integration IDs a café enters to connect their own payment gateway account, stored so orders can be routed to their account | Café owners |
| Support data | Support ticket subject, message content, and any information you choose to include | Café owners & staff |
| Technical & security data | IP address, device/browser information, and bot-verification signals collected by Cloudflare Turnstile when placing an order | All users, automatically |
We deliberately do not collect full payment card numbers, CVVs, or bank credentials at any point — those are entered directly into the payment gateway's own hosted checkout page or iframe, never into Tabl0's own forms.
4. How we collect it
- Directly from you, when you fill in a form, place an order, sign up a café, or contact support.
- Automatically, through the Service's use of Cloudflare (network/security signals, bot-check verification) as you use the Service.
- From payment gateways, in the form of transaction status updates and, where a café enables auto-renewal, a tokenized reference to a saved card (not the card number itself).
5. Why we process it
We process personal data to:
- Take and fulfill orders, and display order status to the customer and café (performance of a contract).
- Operate optional loyalty programs on behalf of participating cafés, who determine their own program's terms (processing on a café's behalf, as their processor).
- Operate café accounts, subscription billing, and the Café Console (performance of a contract).
- Detect and prevent fraud, abuse, and bot traffic, including via Cloudflare Turnstile (legitimate interest / legal obligation).
- Provide customer and merchant support (performance of a contract / legitimate interest).
- Comply with applicable tax, accounting, and legal obligations.
- Send you a one-time SMS verification code when you choose to sign in (consent, for that specific purpose).
6. Who we share it with
We share personal data only as needed to operate the Service:
- Payment gateways (Paymob, Kashier, PayTabs, Fawry, Stripe, depending on what a café has connected) — to process order payments and café subscription payments. Each gateway processes payment data under its own privacy policy as an independent controller for that processing.
- Supabase — our database, authentication, and backend-function provider, acting as a data processor on our behalf.
- Cloudflare — our hosting, content-delivery, and bot-protection provider (including Turnstile), acting as a data processor for network-level security signals.
- The café you order from — order details and, if you sign in, your phone number and loyalty status are visible to that café's staff through the Café Console, so they can prepare and serve your order and administer their loyalty program.
- Legal & safety — where required to comply with a legal obligation, enforce our Terms, or protect the rights, safety, or property of Tabl0, our users, or the public.
We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.
7. International data transfers
Tabl0 operates from and serves café customers primarily in Egypt, but our database infrastructure (Supabase) is hosted in the European Union (Ireland). Cloudflare's network operates globally to serve the Service quickly wherever a request comes from. Where personal data is transferred outside the country in which it was collected, we rely on our providers' standard contractual safeguards (such as Supabase's and Cloudflare's own data processing agreements and standard contractual clauses) to protect it.
8. How long we keep it
- Order data is retained for as long as the café's account is active, plus a reasonable period afterward for accounting and dispute-resolution purposes, or as required by Egyptian tax law.
- Loyalty/phone sign-in data is retained until you ask to be forgotten or the associated café account is closed, whichever is earlier.
- Café account and billing data is retained for the duration of the account plus any period required by applicable financial record-keeping law.
- Support tickets are retained for as long as reasonably needed to resolve the matter and for a limited period afterward for quality and audit purposes.
9. Security
We apply access controls (including row-level security on our database, and least-privilege service credentials for backend functions), encryption in transit (HTTPS/TLS throughout the Service), and bot/abuse protection (Cloudflare Turnstile on order placement) to protect personal data. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard measures appropriate to the sensitivity of the data involved.
10. Cookies & similar technology
The Service uses limited local browser storage to keep you signed in between visits (for customers who opt in to phone sign-in) and to operate Cloudflare Turnstile's bot-verification check. We do not currently use third-party advertising or cross-site tracking cookies. If this changes, we will update this policy and provide any consent controls required by law.
11. Your rights
Subject to applicable law — including Egypt's Personal Data Protection Law and, where applicable, the EU General Data Protection Regulation — you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to our legal obligation to retain certain records.
- Object to, or request that we restrict, certain processing.
- Request a portable copy of data you provided to us.
- Withdraw consent at any time where processing is based on consent (e.g. phone sign-in), without affecting processing carried out before withdrawal.
To exercise any of these rights, contact us at [privacy contact email]. We will respond within the timeframe required by applicable law.
12. Children's privacy
The Service is not directed at children, and café account holders must be at least 18. We do not knowingly collect personal data from children beyond what is incidentally necessary to place a food order (e.g. a menu item selection) without any persistent identifier. If you believe a child has provided us with personal data inappropriately, contact us and we will address it.
13. Data breach notification
If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users and, where legally required, the competent supervisory authority, without undue delay and in line with applicable law.
14. Changes to this policy
We may update this policy from time to time. Material changes will be notified to café account holders by email or in-console notice at least [e.g. 14 days] before taking effect. The "Last updated" date at the top of this page always reflects the current version.