Legal
Privacy Notice
In short
- FoodTab builds the till software and online ordering used by independent food businesses. When you order from a shop, the shop is responsible for your order and your data; FoodTab processes it on the shop's behalf and runs the account, payment and security layer underneath.
- We collect what an order needs: your name, phone, email, delivery address, what you ordered and any notes you type. We never see your card number. Card payments are handled by Stripe.
- Marketing messages only go to people who have ordered and not opted out. Reply STOP to any message, or untick the box at checkout, and they stop.
- Data is stored in the United Kingdom (AWS London). A small number of providers outside the UK are listed below, with the safeguards we rely on.
- You can ask for a copy of your data, correct it, or have it deleted: privacy@foodtab.io.
- Who we are
- Who is responsible for your data
- If you order from a shop
- If you work at a shop
- If you are a sales partner
- If you visit foodtab.io
- Why we use data and our legal grounds
- Who we share data with
- International transfers
- How long we keep data
- Marketing messages
- Cookies and device storage
- Security
- Your rights
- Complaints about how we handle your data
- Children
- Changes to this notice
- Contact and the ICO
1. Who we are
FoodTab is operated by FOODTAB TECHNOLOGIES LTD, a company registered in England and Wales (company number 17319250), registered office 1 Sea Cornflower Way, Jaywick, Clacton-on-Sea, CO15 2EF. We are registered with the Information Commissioner's Office (ICO) as a fee payer (registration reference to follow once issued).
FoodTab provides: an online ordering storefront for each shop (for example shopname.foodtab.io, or the shop's own domain), a till app used by shop staff, a management dashboard, a WhatsApp assistant for shop owners, and a partner portal for people who introduce shops to FoodTab.
Our data protection contact is Alex Bowgen, Director: privacy@foodtab.io.
2. Who is responsible for your data
Data protection law distinguishes between a controller (who decides why and how data is used) and a processor (who acts on the controller's instructions). On FoodTab both roles exist, and which one applies depends on what the data is for.
| Activity | Controller | FoodTab's role |
|---|---|---|
| Taking, preparing, delivering and refunding your order; the shop's own customer records; marketing sent by the shop | The shop you ordered from | Processor, acting on the shop's instructions under our Data Processing Addendum |
| Your FoodTab customer account: login, saved addresses, order history across shops, contact preferences | FoodTab | Controller |
| Payment processing | Stripe (as an independent controller for card data) and the shop (merchant of record) | We receive the payment status and reference only |
| Platform security, fraud prevention, billing the shop, service analytics, legal compliance | FoodTab | Controller |
| Shop staff accounts, till diagnostics, WhatsApp owner assistant | FoodTab (account layer) and the shop (employment relationship) | Controller for the account; processor for shop-directed use |
Where the shop is the controller, its own privacy notice also applies. If you contact us about data the shop controls, we will help and, where needed, pass your request to the shop.
3. If you order from a shop
What we collect
- Contact and delivery details: name, phone number, email address, delivery address, and any address book entries you save.
- Order details: items, options, prices, fees, tips, payment method and status, order times, and free-text notes you type (for example "no onions" or "ring the bell"). Please only put in notes what the shop needs to fulfil your order.
- Allergy and health details (special category data): if you type an allergy, intolerance or other health detail into a notes box, that is health data. We ask for your explicit consent at the point you enter it, and it is used only to prepare and deliver that order safely, by the shop and by FoodTab's systems. It is never used for marketing, profiling or analytics, and it is not sent to our AI assistant provider. You can order without giving it; if you do, please also tell the shop by phone.
- Payment references: the Stripe payment identifier, amount, and outcome. Card numbers are entered on Stripe's secure page and are never sent to or stored by FoodTab.
- Account data if you create one: login identifier, one-time codes sent to your phone or email, and account settings.
- Phone-order data: if you telephone a shop that uses FoodTab's caller-ID feature, the till may show the shop your number and previous orders from that number so staff can serve you faster.
- Marketing preferences: whether you have opted out, when, and from which shop.
- Technical data: IP address, browser type, device identifiers set by us, pages viewed, and error logs.
Where it comes from
Directly from you at checkout or when you call the shop; from the shop if staff enter your order at the till; from Stripe about the payment outcome; and from address lookup services when you enter a postcode.
4. If you work at a shop
If a shop gives you a FoodTab login, we hold your name, email address, phone number, role and permissions, PIN, login history, the actions you take in the till and dashboard (for the shop's audit trail), and diagnostic logs from the till device (app version, printer and connection events). If you are an owner who links WhatsApp, we hold your WhatsApp number and the messages exchanged with the FoodTab assistant, which the FoodTab team can read for support and quality purposes. If you are a delivery driver and the shop uses live driver tracking, the driver app sends your location while you are on shift so the shop and the customer can see the delivery's progress; positions are kept for 12 hours and then deleted. Tracking stops when you go off shift or close the app.
5. If you are a sales partner
If you introduce shops to FoodTab through the partner programme, we hold your name, contact details, the shops you introduced, commission accruals and payout history, and the identifiers of the Stripe account we pay you through. Bank details are collected and held by Stripe, not by FoodTab.
6. If you visit foodtab.io
Our marketing website uses no analytics cookies or tracking pixels. If you send the contact form we receive the details you enter and email them to our team. Our hosting provider (Cloudflare) records standard request logs, including IP address, for security and performance.
7. Why we use data and our legal grounds
| Purpose | Legal basis (UK GDPR Article 6) |
|---|---|
| Taking and fulfilling your order, sending order confirmations and status updates, handling refunds | Performance of a contract (with the shop, which we support as processor) |
| Running your FoodTab account, remembering addresses, showing order history | Performance of a contract with you |
| Payment processing, receipts, payment links | Performance of a contract; legal obligation (accounting and tax records) |
| Showing shops who is calling (caller ID) and their previous orders | Legitimate interests of the shop in serving returning customers quickly; you can ask the shop to remove your record |
| Marketing messages from a shop you have ordered from | Legitimate interests, relying on the "soft opt-in" in the Privacy and Electronic Communications Regulations; you can opt out at any time |
| Security, fraud and abuse prevention, rate limiting, audit logs | Legitimate interests in keeping the platform safe; legal obligation |
| Support, diagnosing faults, improving the service, aggregate statistics | Legitimate interests; statistics are aggregated so individuals are not identified |
| AI assistant for shops (answering staff questions about orders, menus and settings) | Legitimate interests of the shop in running its business; see section 8 for the provider and what it receives |
| Using allergy or health details you type into an order | Performance of the contract (Article 6(1)(b)) together with your explicit consent (Article 9(2)(a)), which you can withdraw by contacting the shop or us; the order may then not be safe to fulfil |
| Keeping records we are legally required to keep, responding to lawful requests | Legal obligation |
Where we rely on legitimate interests we have balanced them against your rights. You can object at any time (see section 14).
8. Who we share data with
We do not sell personal data. We share it only with the shop you deal with, and with the providers below who process it for us under contract.
| Provider | What they do | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, file storage, login services, email and SMS delivery | United Kingdom (London region) |
| Cloudflare | Content delivery, website hosting, real-time messaging between our servers and tills, security filtering | Global network; data may transit through EU/US points of presence |
| Stripe (Stripe Payments Europe Ltd, Stripe Payments UK Ltd, Stripe, Inc.) | Card payments, payouts to shops and partners, refunds, disputes. Stripe is an independent controller for payment data, under its own privacy policy | Ireland, UK and US; Stripe's own transfer safeguards |
| Meta Platforms (WhatsApp Business) | Delivering WhatsApp messages to shop owners and, where a shop uses it, to customers who have not opted out | EU/US |
| OpenAI, L.L.C. | Powers the FoodTab assistant used by shop staff. Staff questions and the order, menu and settings data needed to answer them are sent to OpenAI's API: order numbers, items, totals, times and, where an order has one, the customer's name. Order notes, addresses, phone numbers and payment details are not sent. OpenAI does not use API data to train its models; it may keep API logs for up to 30 days for abuse monitoring. | United States |
| Ideal Postcodes; postcodes.io | Address lookup from a postcode | United Kingdom |
| Mapbox | Maps in the till app (delivery view) | United States |
| Professional advisers, insurers, regulators, courts | Where required to comply with law, enforce our terms, or protect rights | United Kingdom |
If FoodTab is sold or merges with another business, data may be transferred to the new owner under the same protections.
9. International transfers
Your data is stored in the United Kingdom. Some providers process data outside the UK:
- Cloudflare, Meta and Stripe entities in the EU: covered by the UK's adequacy regulations for the European Economic Area.
- OpenAI, Mapbox, Cloudflare Inc. and Stripe Inc. in the United States: covered by the UK Addendum to the EU Standard Contractual Clauses in each provider's data processing agreement, and, where the provider holds a current certification under the UK Extension to the EU-US Data Privacy Framework, by the UK-US data bridge.
Before relying on any of these we assess, as UK law requires, that the protection your data receives after transfer is not materially lower than in the UK, and we review that assessment when a provider or the law changes. Copies of the relevant safeguards are available on request.
10. How long we keep data
| Data | Retention |
|---|---|
| Orders, receipts, payment references, refunds | At least 6 years from the end of the financial year of the order, to meet tax and accounting law and to handle disputes. The shop you ordered from can ask us to delete or return its order records when it stops using FoodTab; we keep only the transaction record (amounts, fees, dates, order number) after that |
| Customer account and saved addresses | While the account is active, and deleted on request. We are introducing automatic deletion after 3 years without an order; until that is live, deletion is on request |
| Marketing opt-out records | Indefinitely, so that we keep honouring your choice |
| Caller-ID call log at a shop (numbers that rang the shop) | 48 hours; the match to your customer record persists as part of your order history |
| Driver location while on shift | 12 hours |
| Till diagnostic logs | 7 days |
| Assistant conversations (till and WhatsApp) | 12 months |
| Security and audit logs | 6 months |
| One-time login codes and link codes | Minutes; deleted on use or expiry |
| Staff accounts | While employed at the shop plus 12 months, then removed from the shop's audit trail by name |
11. Marketing messages
A shop you have ordered from may send you offers about its own food and services by WhatsApp, SMS or email. This is allowed under the "soft opt-in" in the Privacy and Electronic Communications Regulations: you gave your details when buying from that shop, you were given a clear chance to refuse at checkout (the "send me offers" box, which you can untick), and every message identifies the shop and tells you how to stop, free of charge. The shop is the sender; FoodTab provides the tool and enforces your choice. Each shop's list is separate: opting out of one shop does not affect others unless you tell us to stop everything.
To stop: untick the box at checkout, reply STOP to any WhatsApp or SMS message, use the unsubscribe link in any email, or email privacy@foodtab.io. Order confirmations and status updates are not marketing and continue.
FoodTab itself does not send marketing to shop customers. We may email shop owners and staff about the service they use.
12. Cookies and device storage
The ordering storefront uses only what it needs to work, plus one first-party statistics cookie described below. We do not use advertising cookies or any third-party analytics.
| Name / type | Purpose | Lifetime |
|---|---|---|
| Session and login tokens (browser storage) | Keep you signed in and protect your account | Until you sign out, or up to 30 days |
| Cart (browser storage) | Remember what you have added | Until the order is placed or cleared |
Address book cookie on foodtab.io | Remember addresses you have entered so you need not retype them at other shops on FoodTab | 12 months |
| Theme and layout preferences | Remember display choices | 12 months |
QR scan statistics cookie (ft_dev) | A random id set when you open a shop's site by scanning one of its printed QR codes (bag insert, window sticker, counter card), so we can count how many people each printed item reaches and whether the same device comes back. First-party only, never shared, never used for advertising. Linked to your customer record only if you go on to place an order, so the shop's statistics can show how many orders a printed item produced | 12 months |
QR scan marker (ft_scan) | Remembers which printed code brought you here so an order you place is credited to it | 7 days |
Scan opt-out (ft_noscan) | Records that you asked us not to count scans from this device | 12 months |
| Cloudflare security cookies | Bot and abuse protection | Session |
The session, cart and address book storage is strictly necessary to provide the ordering service you asked for (it keeps a record of the selections and details you enter), and the security cookies protect that service, so the law does not require consent for them. Theme and layout preferences only change how the site looks; you can object to those by clearing them in your browser or switching the preference off, with no effect on ordering. The QR scan statistics cookie is used solely for our own and the shop's statistics about printed material, which the law permits without consent provided we tell you about it here and give you a simple way to object: choose "Don't count my scans" in the footer of any shop's site and the id is deleted and no further scans from that device are counted, with no effect on ordering. Scan records are kept for 13 months and then deleted; the daily totals that remain contain no personal data. No consent banner is shown because nothing here tracks you across other sites. If we introduce advertising cookies or third-party analytics in future we will ask for consent first.
13. Security
Data is encrypted in transit (TLS) and at rest. Access is limited to staff and systems that need it, controlled by role-based permissions and audited. Card data never touches our systems. Tills and dashboards use time-limited tokens and per-device sign-in. We test and monitor the platform and keep backups in the UK. No system is perfectly secure; if a breach affecting you occurs we will tell you and the ICO where the law requires it.
14. Your rights
Under UK GDPR you can ask us to: give you a copy of your data (access); correct it; delete it; restrict how we use it; provide it in a portable format; and stop processing based on legitimate interests, including direct marketing, which we will always stop. You can withdraw any consent you have given. You will not be charged and we will respond within one month.
Email privacy@foodtab.io. We may ask you to confirm your identity; the one-month period runs from when we have what we reasonably need to identify you and understand the request, and can be extended by up to two further months for complex or numerous requests, in which case we will tell you within the first month. Where the shop is the controller, we will pass your request to it within 5 working days and help it respond. Some data must be kept even after a deletion request (for example, order records needed for tax law); we will tell you what and why.
We do not make decisions about you by automated means that have legal or similarly significant effects.
15. Complaints about how we handle your data
If you think we have handled your personal data in a way that breaks data protection law, you can complain to us directly. Email privacy@foodtab.io with "Data protection complaint" in the subject line, or write to the address in section 18. Tell us what happened and what you would like us to do.
We will acknowledge your complaint within 30 days of receiving it, look into it without undue delay, keep you informed of progress, and tell you the outcome. If the complaint concerns data a shop controls, we will pass it to the shop and help it respond. You can also complain to the ICO at any time (section 18).
16. Children
Ordering requires a payment method or a delivery address and is intended for adults ordering food for themselves or their household. We have assessed that the storefront is not likely to be accessed by children in the sense of the ICO's Children's Code, and we do not knowingly hold children's data. We apply high-privacy defaults for everyone regardless (no advertising cookies, no profiling, no sharing beyond the shop and the providers listed above). If you believe a child has provided data through FoodTab, contact us and we will remove it.
17. Changes to this notice
We will post updates here with a new version number and date. If a change materially affects how we use your data we will tell you through the service or by email before it takes effect.
18. Contact and the ICO
FOODTAB TECHNOLOGIES LTD, 1 Sea Cornflower Way, Jaywick, Clacton-on-Sea, CO15 2EF. Email privacy@foodtab.io.
If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to resolve it first.