Legal

Privacy Policy

Last updated: August 24, 2026
Draft notice: This document is a structured draft reflecting how Tabl0's platform actually collects and processes data today. Fields shown as [bracketed placeholders] need your registered entity details and a named contact. It should be reviewed by a qualified lawyer — ideally one familiar with Egypt's Personal Data Protection Law (Law 151/2020) and, if you serve customers outside Egypt, the relevant regime there (e.g. GDPR) — before publishing. It is not legal advice.
Contents
  1. Who we are
  2. Who this policy covers
  3. Data we collect
  4. How we collect it
  5. Why we process it
  6. Who we share it with
  7. International data transfers
  8. How long we keep it
  9. Security
  10. Cookies & similar technology
  11. Your rights
  12. Children's privacy
  13. Data breach notification
  14. Changes to this policy
  15. Contact & complaints

1. Who we are

[Tabl0 legal entity name] ("Tabl0", "we", "us"), registered at [registered address], is the data controller for personal data processed through the Tabl0 platform, except where a café independently determines the purposes of processing its own customers' loyalty data, in which case the café acts as controller and Tabl0 acts as its processor (see Section 5).

2. Who this policy covers

This policy applies to three groups of people who interact with the Service:

3. Data we collect

CategoryWhatFrom whom
Order dataItems ordered, quantities, selected variants, order total, table and café identifiers, order status and timestampsCustomers (no account required)
Loyalty & identity dataPhone number (for one-time SMS sign-in), optional display name, order history used for reward calculationCustomers who opt in to sign-in
Café account dataEmail address, café name and address, menu content and photos, table configuration, staff invitations and rolesCafé owners & staff
Billing dataSelected billing plan, subscription status, and payment-gateway-issued tokens used to reference a saved card for auto-renewal — we do not receive or store full card numbersCafé owners, via the connected payment gateway
Payment-gateway credentialsAPI keys/integration IDs a café enters to connect their own payment gateway account, stored so orders can be routed to their accountCafé owners
Support dataSupport ticket subject, message content, and any information you choose to includeCafé owners & staff
Technical & security dataIP address, device/browser information, and bot-verification signals collected by Cloudflare Turnstile when placing an orderAll users, automatically

We deliberately do not collect full payment card numbers, CVVs, or bank credentials at any point — those are entered directly into the payment gateway's own hosted checkout page or iframe, never into Tabl0's own forms.

4. How we collect it

5. Why we process it

We process personal data to:

6. Who we share it with

We share personal data only as needed to operate the Service:

We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.

7. International data transfers

Tabl0 operates from and serves café customers primarily in Egypt, but our database infrastructure (Supabase) is hosted in the European Union (Ireland). Cloudflare's network operates globally to serve the Service quickly wherever a request comes from. Where personal data is transferred outside the country in which it was collected, we rely on our providers' standard contractual safeguards (such as Supabase's and Cloudflare's own data processing agreements and standard contractual clauses) to protect it.

8. How long we keep it

9. Security

We apply access controls (including row-level security on our database, and least-privilege service credentials for backend functions), encryption in transit (HTTPS/TLS throughout the Service), and bot/abuse protection (Cloudflare Turnstile on order placement) to protect personal data. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard measures appropriate to the sensitivity of the data involved.

10. Cookies & similar technology

The Service uses limited local browser storage to keep you signed in between visits (for customers who opt in to phone sign-in) and to operate Cloudflare Turnstile's bot-verification check. We do not currently use third-party advertising or cross-site tracking cookies. If this changes, we will update this policy and provide any consent controls required by law.

11. Your rights

Subject to applicable law — including Egypt's Personal Data Protection Law and, where applicable, the EU General Data Protection Regulation — you may have the right to:

To exercise any of these rights, contact us at [privacy contact email]. We will respond within the timeframe required by applicable law.

12. Children's privacy

The Service is not directed at children, and café account holders must be at least 18. We do not knowingly collect personal data from children beyond what is incidentally necessary to place a food order (e.g. a menu item selection) without any persistent identifier. If you believe a child has provided us with personal data inappropriately, contact us and we will address it.

13. Data breach notification

If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users and, where legally required, the competent supervisory authority, without undue delay and in line with applicable law.

14. Changes to this policy

We may update this policy from time to time. Material changes will be notified to café account holders by email or in-console notice at least [e.g. 14 days] before taking effect. The "Last updated" date at the top of this page always reflects the current version.

15. Contact & complaints

Questions, requests, or complaints about this policy or how your data is handled can be sent to [privacy contact email]. If you are not satisfied with our response, you may have the right to lodge a complaint with Egypt's Personal Data Protection Center or, if applicable, your local data protection authority.