Privacy Policy

Last updated: October 03, 2026

1. Data Controller

The data controller for this Service is:

  • Company Name: RestoAI
  • Registered Address: [Company Registration Address]
  • Privacy Contact Email: privacy@restoai.com
  • Data Protection Officer: [Name/Contact, or "Not applicable"]

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email, password (encrypted), and other registration fields
  • Payment Information: Transaction amount, payment status. We do not store complete card numbers — card data is processed by our payment processor (see Section 5)
  • Communication Records: Emails, support tickets, and feedback you send to support
  • Restaurant Data: Restaurant name, address, phone number, cuisine type, operating hours, menu items (names, descriptions, prices, photos, allergen information)
  • Business Configuration: Reservation settings, table capacity, availability rules
  • Third-Party Connections: When you connect WhatsApp, Facebook, Instagram, or other services

2.2 Information We Collect Automatically

  • Device and Network: IP address, device model, operating system, browser type, timezone
  • Usage Behavior: Page visits, feature usage, operation logs, session duration
  • Log Data: Request timestamps, error logs, performance data
  • API Usage: Usage metrics for quota management

2.3 End Customer Data (Restaurant Operators)

As a restaurant SaaS platform, we also process data that your end customers provide when interacting with your restaurant through our Service, including reservation details, order history, and chat conversations with the AI assistant. This data is processed on your behalf as a data processor.

3. How We Use Your Information

Purpose Legal Basis
Providing and maintaining the ServiceContract performance
Generating and hosting your restaurant websiteContract performance
Processing reservations and online ordersContract performance
Powering AI chat responsesContract performance
Billing and payment processingContract performance
Customer supportContract performance / Legitimate interest
Service notifications (billing, security, policy updates)Legitimate interest
Security and fraud preventionLegitimate interest
Product optimization and analyticsLegitimate interest
Legal complianceLegal obligation
Marketing (optional)User consent

We may aggregate or de-identify data for statistical analysis. Such data cannot be traced to specific individuals.

4. Cookies and Tracking Technologies

Type Purpose Can be disabled
Strictly NecessaryMaintain login, core functionalityNo
FunctionalLanguage preferences, personalized settingsYes
AnalyticsAnonymous usage statistics, product optimizationYes
Marketing (optional)Targeted advertising and performance measurementYes

Analytics tools used: [Insert tool name and link to its privacy policy, e.g., Google Analytics]. You can adjust preferences through browser settings or our Cookie Preference Center.

5. Sharing and Disclosure of Personal Information

We do not sell your personal information, including "selling" as defined by applicable laws such as CCPA. We only share information in the following circumstances:

  • Service Providers: Cloud computing, payment, customer support, analytics, and other suppliers, under confidentiality agreements. Payment card data is processed exclusively by our PCI-DSS compliant payment processor (Waffo Pancake) and is not stored on our servers
  • Business Partners: [If applicable, describe types of collaboration and data scope; otherwise delete]
  • Legal and Regulatory Requirements: As required by law, court orders, or legitimate government requests
  • Business Transactions: In cases of merger, acquisition, etc., with advance notice and ensuring protection obligations continue
  • With Your Consent: For other purposes with your explicit prior consent

6. Data Security Measures

  • Transmission Encryption: TLS / HTTPS
  • Storage Security: Sensitive data such as passwords is encrypted or hashed
  • Access Control: Principle of least privilege; employees sign confidentiality agreements
  • Regular Security Audits: Periodic security audits and vulnerability scanning
  • Additional Measures: [Other security measures such as ISO 27001, SOC 2, etc.]

In the event of a security incident affecting your rights, we will notify you and relevant regulatory authorities within [timeframe, e.g., "72 hours of discovery"] as required by law. Please keep your account credentials safe and do not share them with others.

7. Data Retention Period

Data Type Retention Period Action on Expiry
Account InformationDuring active period; [X] years after account deletionDelete or anonymize
Transaction RecordsAs required by law, typically [X] yearsDelete or archive
Customer Support Records[X] yearsSecure deletion
Security Audit Logs[X] monthsSecure deletion
Restaurant Data (Menus, Reservations)During subscription; 90 days after cancellationDelete per your request or archive

8. Your Data Rights

To exercise the following rights, please contact us. We will process your request within [e.g., "30 calendar days"].

Right Description
Right to be informedUnderstand what data we collect and how we use it
Right of accessObtain a copy of your personal data
Right to rectificationCorrect inaccurate or incomplete information
Right to erasureRequest data deletion under specific conditions
Right to restrict processingPause data processing under specific circumstances
Right to data portabilityObtain your data in machine-readable format
Right to objectObject to processing based on legitimate interests or marketing
Right to withdraw consentWithdraw consent for processing based on consent

If you believe we have not properly handled your data, you have the right to lodge a complaint with your local data protection authority.

9. Marketing Communications and Opt-Out

With your consent, we may send marketing information related to [describe types of marketing content] via email, SMS, or in-app notifications. You may unsubscribe at any time: click the "unsubscribe" link in emails, disable marketing notifications in account settings, or contact us. Opting out does not affect service-essential notifications (such as billing, security reminders).

10. International Data Transfers

Our servers and partners may be located in [insert major regions, e.g., Singapore, United States]. For cross-border transfers, we ensure data security through:

  • Data processing agreements incorporating EU Standard Contractual Clauses (SCC)
  • Transfers only to recipients with equivalent protection levels
  • [Other safeguards such as adequacy decisions, BCR, etc.]

11. Children's Privacy

This Service is intended for users who are at least [13 / 16 / 18] years of age. We do not knowingly collect information from minors below this age. If you believe your child has provided us with information, please contact us immediately and we will delete it as soon as possible.

12. Third-Party Links and Services

This Service may contain links to third-party websites or integration with third-party services. This Policy applies only to information we collect directly. We are not responsible for third parties' data practices and recommend reviewing their policies before using them.

13. Policy Changes

For material changes, we will notify you at least [X, e.g., 15] days in advance via platform announcements or your registered email, and update the "Last Updated" date at the top of this page. Continued use after the effective date constitutes acceptance.

14. Contact Us

  • Privacy Contact Email: privacy@restoai.com
  • Customer Support Email: support@restoai.com
  • Company Name: RestoAI
  • Mailing Address: [Mailing Address]
  • Service Hours: [e.g., Monday to Friday 09:00–18:00 UTC+8]