Privacy Policy

Last updated 16 August 2026

This explains what TapTap Table collects through TapTap Table, why, and what you can do about it. It covers two different groups of people: the restaurants that hold accounts, and the guests who scan a QR code.

01If you run a restaurant

When you create an account we collect:

  • your name and email address, and a password stored only as a salted hash — never as text we can read;
  • your restaurant's name, address, phone, website and social links;
  • the menu, photos, logo and branding you upload;
  • billing records: which plan, when it was paid, and the payment reference from Razorpay.

We use it to run your account, show your menu to your guests, take payment, and email you about your subscription or a service problem. We do not sell it, and we do not send marketing to it without asking you first.

02If you scanned a QR code at a table

The restaurant you are visiting decides how much is collected. At most:

  • Your phone number and name, if the restaurant has switched on the check-in screen and you choose to enter them. It is optional — you can skip it and still see the menu.
  • Booking details — name, phone, email, date, party size — if you book a table.
  • Anonymous usage counts — that a table's code was scanned, and which dishes were opened. This is not tied to your name or number.
You are never asked to create an account, install an app, or give a payment detail to view a menu.

The restaurant is the owner of this information; we hold it for them. To have it removed, ask the restaurant directly, or email us and we will pass the request on and confirm when it is done.

03Cookies

We set no advertising or tracking cookies. What we do set:

  • a session cookie after you sign in, so you stay signed in. It is httpOnly, so page scripts cannot read it, and it expires when the session ends;
  • a small local preference for light or dark mode, stored in your own browser and never sent to us.

04Where it is stored, and who else touches it

Data is stored in a Postgres database hosted in Mumbai, India. These are the only other companies involved, each doing one job:

  • Supabase — the database itself (Mumbai region).
  • Vercel — runs the website and its servers.
  • Razorpay — takes subscription payments. Card and UPI details go straight to them; they never reach us.
  • Anthropic — the AI model behind menu import and description writing. Only the menu text or image you submit is sent, and it is not used to train their models.

We do not sell data or share it with advertisers, data brokers or anyone else.

05How long we keep it

  • Account and menu data: for as long as your account is open, then deleted from live systems within 30 days of closure.
  • Guest phone numbers and bookings: kept until the restaurant deletes them or closes its account.
  • Payment records: retained for as long as tax and accounting law in India requires, currently eight years.
  • Scan and view counts: aggregated, and not linked to an individual.

06Security

  • Everything travels over HTTPS.
  • Passwords are stored as scrypt hashes with a per-user salt — a stolen database does not reveal them.
  • Each restaurant's data is walled off; one account cannot read another's.
  • Staff access to production data is limited to what a support request needs, and administrative actions are logged.

No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority without undue delay.

07Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Email taptaptable.in@gmail.com from your account address and we will respond within one working day. There is no charge.

08Children

TapTap Table is for businesses. We do not knowingly collect information from anyone under 18. Viewing a menu requires nothing at all.

09Changes

If this policy changes materially we will email account holders before it takes effect. The date at the top always shows the current version.