Privacy Policy

Version
2026-08-20
In effect from

What changed in this version

First published version.

This policy explains what happens to your personal data when you scan a Tavlo QR code, browse a restaurant's menu, order at a table, or hold a Tavlo account. It applies to the Tavlo website (tavlo.eu), the Tavlo guest app, and the ordering interface you reach from a QR code.

Restaurant staff and venue owners using the Tavlo partner app or dashboard are covered by this policy too, in the sections that concern their accounts.

1. Who is responsible for your data

The controller of the personal data described in this policy is:

"Tavlo", "we" and "us" in this policy mean that controller.

We have not appointed a data protection officer. We are not required to have one, because neither large-scale monitoring nor large-scale processing of special-category data is our core activity. If that changes, we will appoint one and say so here.

The restaurant is responsible for its own data. When you order at a venue, that venue decides how it uses the order information it receives — to prepare your food, to issue your receipt, and to keep the records Romanian tax law requires of it. For those purposes the venue is its own controller and you should contact the venue directly. Tavlo is responsible for operating the platform: your account, the app, the menus, and the analytics described below.

If Tavlo is transferred to a company. Tavlo is not yet operated by an incorporated company. When the operating company is registered, or if the Tavlo business is sold, merged or otherwise transferred, personal data forms part of the transferred business and the new controller takes over the processing described here. We will tell you before that happens, we will publish the new controller's identity in this policy, and the new controller will honour the choices you have already made.

2. What we collect, why, and on what legal basis

DataWhy we process itLegal basis
Menu browsing — which venue and menu you opened, the language you read it inShow you the venue's menu in your language, with prices and allergen informationLegitimate interest (Art. 6(1)(f)) — operating the service you asked for without requiring an account
Guest session identifier — a random id generated on your deviceKeep your basket and your place in an order across page loads, without asking you to create an accountContract (Art. 6(1)(b)) — this is what makes ordering possible
Account details — email address, password, display name, language, profile picture; optionally first and last name and phone numberCreate and secure your account, sign you in, let you recover access, show you your order historyContract (Art. 6(1)(b)); the security measures around it rest on legitimate interest (Art. 6(1)(f))
Orders — items, quantities, notes, table, the other guests sharing the order, totals, taxes, tipsSend your order to the kitchen, split and settle the bill, show you what you orderedContract (Art. 6(1)(b))
Payment records — amount, currency, method, status, timestamps, and a payment reference where a card is usedSettle your bill and prove that it was settledContract (Art. 6(1)(b)); keeping the record afterwards is a legal obligation (Art. 6(1)(c))
Dietary and allergen preferences you save to your profileFilter menus so that dishes containing what you exclude are hidden or flaggedExplicit consent (Art. 9(2)(a)) — see section 3
QR scan analytics — which QR code was scanned, when, device type, operating system, browser, language, and a daily-rotating pseudonymous visitor hashTell venues which tables and printed materials actually get used, detect abuse of a QR code, and plan capacityLegitimate interest (Art. 6(1)(f)) — understanding how the physical entry points to our service are used, in a form that cannot follow you across days
Technical logs — IP address, request time, user agent, error tracesKeep the service available, investigate faults, and detect attacks and fraudLegitimate interest (Art. 6(1)(f)) — security and reliability of the service
Service messages — email verification, password resets, security alerts, staff invitationsOperate and secure your accountContract (Art. 6(1)(b)), and legal obligation for security notifications (Art. 6(1)(c))
Marketing messages and personalised offersTell you about Tavlo features or venue offers you asked to hear aboutConsent (Art. 6(1)(a)) — never sent without it, withdrawable at any time

The legitimate interests we rely on

Where the table says "legitimate interest", the interest is named in the same row. In each case we weighed it against your interests and rights and limited the processing accordingly: scan analytics use a hash that is unusable after 24 hours rather than a device identifier; logs are kept only as long as they are useful for security; menu browsing needs no account and no advertising identifier. You can object to any processing based on legitimate interest — see section 8.

What we do not do

  • We do not sell personal data, and we do not share it with advertising networks.
  • We do not run advertising or third-party analytics trackers on the QR menu pages.
  • We do not make decisions about you by purely automated means that produce legal effects or similarly significantly affect you, and we do not build advertising profiles. If we introduce personalisation or recommendations, we will describe them here first, say what signals they use, and let you object.

3. Allergen and dietary preferences

If you save an allergen or dietary preference to your profile — "no dairy", "no gluten" — that is information about your health, and European law treats it as a special category of personal data. We therefore process it only on the basis of your explicit consent, which we ask for separately at the moment you save the preference. It is not bundled into these terms or into account creation.

We use it for one thing: filtering menus. It is not used for marketing, for recommendations or for any kind of profiling, and it is not disclosed to venues unless you attach a note to an order yourself.

You can withdraw this consent at any time by deleting the saved preferences in the app. Filtering then stops using them, and you can still filter a single menu without saving anything.

Allergen information about the food itself is the venue's responsibility. Tavlo displays what the venue enters. Always tell staff about a serious allergy — a filter is a convenience, not a safety guarantee.

4. When somebody else adds you to an order

Tavlo lets several guests share one table order. If another guest starts an order at your table and you join it, the other participants can see the items on the shared order and how the bill is split. Your display name — the name on your account, or the one you choose when joining — is visible to them.

Where we receive information about you from another guest or from a venue rather than from you directly, the categories are the same as those in section 2 (order items, table, display name), the source is the guest who created the order or the venue's staff, and this policy is the information required by Article 14 GDPR.

5. Who we share data with

We share personal data only with the following categories of recipients, and only as far as each one needs it:

  • The venue you order from — your order, the table, your display name and any notes you attach. The venue is an independent controller for what it does with that information.
  • Payment providers — where an online card payment is offered, the payment provider processes your card data as its own controller under its own privacy policy. Tavlo never sees or stores full card numbers. Payments made in cash or on the venue's own card terminal are recorded in Tavlo by the venue's staff as an amount and a method, with no card data at all.
  • Google Ireland Limited — Firebase Hosting serves tavlo.eu, and Cloud Firestore holds live order state so that your table and the kitchen see the same order at the same moment.
  • Our infrastructure, database and email-delivery providers — they host the service and deliver service emails on our instructions, as processors under Article 28 contracts.
  • Apple and Google — only if you install a Tavlo app from their stores. They process data as the store operator under their own policies; Tavlo does not receive your store account details.
  • Professional advisers, authorities and courts — where we are legally obliged to disclose, or where we need to establish or defend a legal claim.

On request under Article 15 GDPR we will name the specific recipients of your data, not only these categories.

6. Where your data is stored, and transfers outside the EEA

Tavlo's own systems and databases are located in the European Union.

Some of the providers above are, or are affiliated with, companies outside the EEA. Where that results in a transfer of personal data outside the EEA, it takes place either under the European Commission's adequacy decision for the EU–US Data Privacy Framework, where the recipient is certified under it, or under the Commission's standard contractual clauses together with an assessment of the protection available in the destination country, plus technical measures such as encryption in transit and at rest. You can ask us for a copy of the safeguards that apply to a specific transfer.

7. How long we keep it

DataRetention
Account dataFor as long as your account exists. Deleted, or irreversibly anonymised, when you delete your account
Orders, bills, payments and tax recordsFor the period Romanian accounting and tax law requires — as a rule 5 years from the end of the financial year, and 10 years for the underlying accounting records. These records survive account deletion, because the law requires the venue and us to keep them; they are detached from your profile
Dietary and allergen preferencesUntil you delete them or delete your account; immediately on withdrawal of consent
QR scan analyticsThe pseudonymous visitor hash cannot be linked across days by design. Individual scan records are kept for at most 14 months, then aggregated into counts that identify nobody
Technical and security logsUp to 12 months, and longer only for a specific incident under investigation
Support and complaint correspondence3 years from the last message, matching the general limitation period for claims

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectify data that is inaccurate or incomplete;
  • erase your data ("right to be forgotten"), except where we must keep it — most often the fiscal records in section 7;
  • restrict processing while a dispute about accuracy or legitimate interest is resolved;
  • portability — receive the data you gave us in a machine-readable format, or have it sent to another controller where technically feasible;
  • object to processing based on legitimate interest, and at any time and for any reason where the processing is for direct marketing;
  • withdraw consent at any time, as easily as you gave it, without affecting the lawfulness of what was done before you withdrew it;
  • not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you — we do not make such decisions.

To exercise any of these, write to support@tavlo.eu. We answer within one month, and tell you in advance if a complex request needs longer. We do not charge for this.

Deleting your account does not require writing to us: you can do it in the app, under your profile, and also from the account deletion page without installing anything. What is deleted and what is kept is described in section 7.

9. Complaints

If you believe we are handling your data unlawfully, please tell us first at support@tavlo.eu — most issues are quicker to fix directly.

You also have the right to lodge a complaint with the Romanian supervisory authority:

Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucureşti, Romania — dataprotection.ro.

If you live in another EU or EEA country, you may also complain to your own national authority.

10. Do you have to give us this data?

Browsing a menu requires no account and no personal data.

To place an order you must give us the items you want, the table you are at, and a display name, and the venue must receive them — without that there is no order to fulfil. To hold an account you must give a valid email address, so that you can sign in and recover access. Everything else — your name, phone number, profile picture, saved preferences — is optional, and leaving it out only means the corresponding feature is unavailable.

11. Children

Tavlo accounts are for people aged 16 and over, which is the age of digital consent in Romania. We do not knowingly create accounts for children under 16. If you believe a child under 16 holds an account with us, write to support@tavlo.eu and we will delete it.

Browsing a menu requires no account and is not restricted.

12. Cookies and what we store on your device

The QR menu and ordering pages use only what is strictly necessary to work:

  • a language cookie (tavlo_ui_lang), remembering the language you read in;
  • local storage on your device, holding your guest session identifier, your basket and your sign-in token.

None of these are advertising or analytics identifiers, and none of them are shared with third parties, so no consent banner is required for them. If we ever add analytics or marketing cookies to tavlo.eu, we will ask for your consent before setting them and publish a separate cookie policy.

13. Security

Passwords are stored hashed, never in readable form. Traffic between your device and our servers is encrypted with TLS. Access to production data is restricted to the people who need it. Sessions can be invalidated across all your devices at once when you change your password.

If a personal data breach is likely to result in a risk to your rights, we notify the ANSPDCP within 72 hours and, where the risk is high, we tell you directly.

14. Changes to this policy

The version and effective date of the text you are reading are shown at the top of this page, and every earlier version stays published at its own address, linked at the bottom.

If we make a change that materially affects you — a new purpose, a change of controller, or a change in how you exercise your rights — we will tell you in advance, through a notice in the app or by email to account holders, with enough time to consider it and to object or withdraw consent before it takes effect. Where a change requires your consent, we will ask for it before the new processing starts, not after.

We will never ask you to check this page periodically to find out what changed.

15. Contact

Questions about this policy, or about your data: support@tavlo.eu — Tavlo Team, Timișoara, județul Timiș, România.

See also the Terms of Use and the Legal Notice.