This Privacy Policy explains how MesaFlow (“we”, “us”) collects, uses, and protects personal data when restaurants and their guests use the MesaFlow tap-to-order platform (the “Service”).
1. Who is responsible for your data
For Operator account data (staff accounts, menus, restaurant settings), MesaFlow acts as the data controller. For Guestordering activity at a specific restaurant, the restaurant is the controller of that order data and MesaFlow processes it on the restaurant’s behalf.
2. What we collect
| Category | Examples | From whom |
|---|---|---|
| Account data | Name, email, hashed password, staff role | Operators |
| Restaurant data | Menu items, prices, tables, tag identifiers, branding | Operators |
| Order data | Items ordered, table number, timestamps, order status | Guests |
| Technical data | Device/browser type, IP address, session identifiers | All users |
Guests do not create accounts and we do not ask guests for names or contact details to place an order.
3. How we use data
- To operate the Service — authenticate staff, display menus, route orders to the kitchen and floor;
- To verify NFC tags cryptographically so cloned or tampered tags are rejected;
- To provide Operators with sales and order analytics for their own restaurant;
- To secure the Service, prevent abuse, and debug problems;
- To comply with legal obligations.
4. Legal bases
Where applicable law (such as the GDPR) requires it, we rely on: performance of a contract (running the Service), legitimate interests (security, analytics for Operators), consent (non-essential cookies), and legal obligations.
5. Sharing
We share data with service providers who host and support the platform (for example cloud hosting and database providers), and with the relevant restaurant for orders placed at its tables. We do not sell personal data. We may disclose data where required by law.
6. Retention
Account and restaurant data are kept for as long as the account is active. Order data is retained as needed to provide analytics and meet the restaurant’s record-keeping needs, then deleted or anonymized. Technical logs are kept for a limited period for security.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise them, contact us at privacy@mesaflow.app. Guests should contact the restaurant they ordered from for order-specific requests; we will assist that restaurant as its processor.
8. Security
We use industry-standard measures including encryption in transit, hashed passwords, scoped staff permissions, and cryptographically signed NFC tags. No system is perfectly secure, but we work to protect your data.
9. Cookies
We use a small number of cookies and similar technologies. See our Cookie Policy for details and to manage your choices.
10. Changes and contact
We may update this policy; the “Last updated” date reflects the latest version. Contact: privacy@mesaflow.app.