TablePulse Privacy Policy

Effective Date: August 11, 2026

TablePulse (β€œwe”, β€œour”, or β€œus”) operates the TablePulse website, product, and related services (the β€œServices”). This Privacy Policy describes how we collect, use, and share information.

It applies to:

  • Restaurant operators and staff using TablePulse;
  • Guests who scan a restaurant QR code or open a demo menu;
  • People who apply for the pilot or otherwise contact us;
  • Visitors to tablepulse.co.

This policy describes the product as it works today. We do not currently offer self-serve billing, guest checkout payments, reservations, loyalty programs, or POS / delivery integrations.

1. Information We Collect

1.1 Information you give us

Restaurant and operator accounts

Operators sign in with email one-time code or Google. We store the user id on organizations we create. We do not store passwords. We may receive your email and, if you use Google, your name from the identity provider.

Restaurant profile information may include:

  • Restaurant and organization name;
  • Logo;
  • Address collected during setup;
  • Contact email;
  • Currency and default language;
  • Menus, item photos, prices, tags, and related content you upload.

We do not currently collect GST numbers, tax identifiers, or billing addresses.

Pilot and contact forms

The website waitlist collects your email. Optional fields (name, phone, restaurant name) may be accepted by the API if provided. We use this to follow up about the pilot.

In-app feedback

If you submit feedback from Help, we receive your message, category, page URL, and the email/name on your account.

Guests

Guests do not create accounts and do not need to give a name, phone number, or email to browse or place an order. Guests may choose dietary and allergen filters, add items to a cart, and submit an order with optional notes.

1.2 Information collected automatically

When you use the Services we may collect:

  • Device and browser information (including user-agent);
  • Approximate country from the hosting provider, used to set the market/currency cookie;
  • Log data needed to operate and secure the Services;
  • Operator activity in the product (for example, pages visited and menu edits), tied to your user id.

On restaurant QR menus we may also collect:

  • A visitor id stored in the browser (localStorage) so return visits can be linked on that device;
  • A session id stored in sessionStorage;
  • QR interactions such as views, searches (query length only), cart actions, and checkout;
  • A one-way hash of the guest IP address (we do not store the raw IP on analytics events);
  • Dietary and allergen filter ids the guest selected;
  • Optional guest session id on the order, used to connect the order to analytics.

Demo menus on the marketing site keep a cart in the browser only. They do not create server orders or guest analytics events.

1.3 Staff and operations

Restaurants may add staff names and roles, floor/kitchen console settings, and a numeric console PIN. PINs are stored so the restaurant can manage them. Treat them like shared workplace credentials.

2. How We Use Information

We use information to:

  • Provide digital menus, QR guest flows, orders, floor and kitchen tools, and insights;
  • Authenticate operators and protect accounts;
  • Parse uploaded menus and generate insight suggestions;
  • Respond to pilot applications and support requests;
  • Monitor reliability, abuse, and security;
  • Improve the product using aggregated or de-identified data.

We do not sell personal information.

3. AI Processing

We use Google Gemini to parse uploaded menu files (including PDF and image bytes) and to draft restaurant insight tips from aggregated visit and order statistics, restaurant name, and menu item names.

We do not send guest names, emails, or phone numbers to Gemini. Those fields are not collected on the guest flow. AI output can be wrong. Restaurants should review it before acting.

4. Cookies and Browser Storage

We use:

  • Session cookies and a browser-stored session token to keep operators signed in;
  • A market-country cookie so the website can show the right currency;
  • Browser localStorage and sessionStorage for guest visitor/session ids, cart, and welcome filters.

We do not currently use advertising pixels or third-party product analytics SDKs (such as Google Analytics). There is no cookie banner today because we only use cookies needed to run the site and product. You can clear cookies and site data in your browser; doing so may sign you out or reset guest session state.

5. How We Share Information

We share information with service providers who help us operate the Services, and only as needed for that purpose:

  • Vercel β€” website hosting;
  • Render β€” API, worker, database hosting, and operator authentication;
  • Amazon Web Services (S3) β€” uploaded menu and demo files;
  • Google β€” operator sign-in when you choose Continue with Google;
  • Google Gemini β€” menu parsing and insight drafting;
  • HubSpot β€” pilot waitlist contacts and feedback notes;
  • Resend β€” sending in-app feedback email to our team;
  • ip-api.com β€” approximate city for a waitlist submission, derived from IP.

We may also share information if required by law, to protect the Services, or as part of a merger, financing, or sale of assets.

We do not currently share data with POS systems, delivery platforms, SMS or WhatsApp providers, reservation products, or payment processors.

6. Roles

For operator accounts, website visitors, and pilot inquiries, TablePulse decides how that information is processed.

For guest orders, dietary filters, and QR analytics generated when a diner uses a restaurant's menu, the restaurant decides what to collect through the product. TablePulse processes that information to provide the Services. Restaurants are responsible for diner-facing notices and any required consents.

7. Retention

We keep information while an account is active and as needed to provide the Services, resolve disputes, and meet legal obligations. Guest analytics events are append-only and are not self-serve deletable in the product today.

To request access, correction, or deletion, email contact@tablepulse.co. We may need to verify the request. Some information may be retained where we have a legal or security reason to keep it.

8. Security

We use standard access controls, encrypted connections, and provider security features. No system is completely secure. You are responsible for operator account access, staff console PINs, and devices used to reach the Services.

9. International Transfers

Our providers may process information in India, the United States, and other countries. By using the Services you understand that information may be transferred to those locations.

10. Children

The Services are built for restaurants and adult operators, not for children. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

11. Allergens and Dietary Filters

Menu tags and guest filters (for example vegetarian or dairy) are operational labels, not medical records. Guests and staff may also type free-text notes, including allergy notes. Restaurants remain responsible for allergen accuracy and how they use that information.

12. Your Choices

Depending on applicable law, you may ask us to:

  • Access personal information we hold about you;
  • Correct inaccurate information;
  • Delete information;
  • Object to or restrict certain processing.

There is no in-product data-export or delete flow today. Use the contact email below. Operators can also request account changes through the contact email.

13. Changes

We may update this policy as the product changes. The effective date above will change when we do. Continued use after an update means you accept the revised policy. Material changes to how we handle personal information will be called out on this page.

14. Contact