This Privacy Policy explains how MesaFlow (“we”, “us”) handles personal data. What we collect, why, and who is legally responsible for it all change depending on how you meet us, so this policy is split the same way our Terms of Useare: a common part, then one part per audience.
1. Which part applies to you
| You are a… | Read | Who controls that data |
|---|---|---|
| Visitor — browsing the public website | Part A + Part B | MesaFlow |
| Operator — restaurant or staff signed in to the platform | Part A + Part C | MesaFlow, for account and restaurant records |
| Guest — ordering at a table | Part A + Part D | The restaurant. MesaFlow is its processor |
That last row is the important one: for an order placed at a table, the restaurant decides why the data exists and MesaFlow only handles it on the restaurant’s instructions. Requests about a specific order go to that restaurant first.
Part A — Applies to everyone
A1. Data we hold about every user
| Category | Examples | Why |
|---|---|---|
| Technical data | IP address, browser and device type, language, time of request | Serving pages, security, rate limiting, debugging |
| Security logs | Failed sign-ins, rejected NFC verifications, refresh-token reuse | Detecting abuse and cloned tags |
A2. Sharing
We share data with service providers who run the platform for us — cloud hosting, database and cache providers, email delivery, error and performance monitoring — under contracts that limit them to our instructions. We do not sell personal data and we do not use it for advertising. We may disclose data where the law requires it, or to protect the rights and safety of users.
A3. International transfers
Our providers may process data outside your country. Where that happens from the UK/EEA we rely on an adequacy decision or on standard contractual clauses with appropriate safeguards.
A4. Security
Encryption in transit, passwords stored only as salted hashes, short-lived access tokens with rotating refresh tokens and reuse detection, role-scoped staff permissions, and cryptographically signed NFC tags. No system is perfectly secure, but we work to protect your data and will notify affected users and regulators of a breach where required.
A5. Your rights
Depending on where you live you may have rights to access, correct, delete, port, or restrict your personal data, to object to processing based on legitimate interests, and to withdraw consent. Where the UK GDPR or EU GDPR applies you may also complain to your supervisory authority. To exercise a right, write to privacy@mesaflow.app — and see the note in Part D if the request is about an order at a restaurant.
A6. Children
The Service is not directed at children. Operator accounts are for adults. A Guest menu needs no account and no personal details, so we do not knowingly collect a child’s personal data.
A7. Changes and contact
We may update this policy; the “Last updated” date reflects the latest version, and material changes for Operators are notified in the product. Contact: privacy@mesaflow.app.
Part B — If you are a Visitor (public website)
B1. What we collect
- Nothing you have to give us. You can read the entire website without an account and without submitting anything.
- Enquiry form data — if you contact us: the name, business name, email, phone, and message you choose to type.
- Consent choice — whether you accepted or rejected non-essential cookies, stored on your device.
- Aggregate usage — page views and performance timings, only where you have accepted analytics cookies.
B2. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and assessing fit | Legitimate interests, and steps towards a contract at your request |
| Keeping the site up, fast, and free of abuse | Legitimate interests |
| Analytics and any non-essential storage | Consent — withdrawable at any time |
B3. How long we keep it
Enquiries are kept while we are in conversation and for up to 24 months afterwards so we can pick a thread back up, then deleted. Server and security logs are kept for a limited period. See the Cookie Policy for storage lifetimes on your device.
B4. What we never do to Visitors
No advertising or cross-site tracking cookies, no data brokers, no profiling that produces a legal effect on you, and no marketing email unless you asked us to get in touch.
Part C — If you are an Operator (restaurants and their staff)
C1. What we collect
| Category | Examples |
|---|---|
| Account data | Name, work email, hashed password, staff role and permissions, email verification state |
| Session data | Access and refresh token records, device and session identifiers, sign-in times |
| Restaurant data | Menus, prices, photographs, branding, floor layouts, tables, NFC tag identifiers, opening settings |
| Operational data | Orders handled, table state changes, waiter calls, bill requests, action logs |
| Billing data | Subscription status, plan, and the provider-side records tied to your restaurant |
| Support data | Messages you send us through the in-product support and contact screens |
C2. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Running the Service — authentication, menus, routing orders to kitchen and floor | Performance of a contract |
| Restaurant-level sales and order analytics for your own venue | Performance of a contract, legitimate interests |
| Verifying NFC tags so cloned or tampered tags are rejected | Legitimate interests |
| Security, abuse prevention, audit logs, debugging | Legitimate interests, legal obligation |
| Billing, subscription administration, and record keeping | Performance of a contract, legal obligation |
C3. Who inside MesaFlow can see it
Provider administrators can see restaurant accounts, subscription state, and support threads in order to run the platform, and can act on behalf of an account for support. Such action is recorded in the account’s logs and, while it is happening, shown in the interface.
C4. How long we keep it
Account and restaurant data are kept while the account is active. After termination they remain available for export for a reasonable period and are then deleted or anonymised, except where we must keep records for tax, accounting, or legal reasons. Audit and security logs are kept for a limited retention window.
C5. Your responsibility as a controller
For your Guests’ order data you are the controller and we are your processor — see Part D and section C7 of the Terms. You need your own lawful basis and your own privacy notice for your Guests, and you must keep staff permissions tight enough that only the right people see order history.
Part D — If you are a Guest (ordering at a table)
D1. The short version
You do not sign up, and we do not ask for your name, email, or phone number to place an order. What exists is a record that one table ordered particular items at a particular time.
D2. What is collected
| Category | Examples | Where it lives |
|---|---|---|
| Order data | Items, quantities, options, notes you type, table number, timestamps, order status | The restaurant’s records |
| Table session | Which table is currently open, tag tap events used to verify the tag | Short-lived server state |
| On your device | Your basket and your chosen menu language | Your browser only — see the Cookie Policy |
| Technical data | IP address, device and browser type | Server logs, briefly |
Anything you type into an order note goes to that restaurant’s staff, so treat it as a message to the kitchen rather than a private field.
D3. Who is responsible, and how to exercise a right
The restaurant is the controller for your order data and decides how long to keep it. Send access, correction, or deletion requests to that restaurant; we will support them as their processor. If you cannot reach them, contact privacy@mesaflow.app and we will help route the request.
D4. What we never do to Guests
No advertising cookies, no tracking you between restaurants, no building a profile of you across the web, and no selling your data. Ordering at one venue tells another venue nothing about you.
D5. Payments
MesaFlow does not take payment for your meal and does not receive or store your card details. Payment happens with the restaurant, by whatever means it offers.