TabChef
TermsOwner sign in

Privacy notice

Your data, in plain language.

TabChef keeps restaurant operations separate from guest contact details and uses personal data only to run accounts, bookings, security and billing.

Last updated21 July 2026

On this page

01Who is responsible02What TabChef processes03Why it is used04Providers and processing locations05How long data is kept06Your choices and rights07Security and changes

Questions? Open support

01

Who is responsible

The TabChef operator is responsible for venue-account, platform and billing data. You can contact the operator at david@strics.at.

For a guest reservation, the restaurant shown on the booking page is responsible for the guest information. TabChef processes that information to provide the restaurant's booking service. Each live restaurant page must identify that restaurant and link to its own privacy notice.

The Demo Restaurant page is a product preview. It does not persist reservation submissions.

02

What TabChef processes

The venue account includes the owner's name, email address, sign-in and security information. Permitted-device records include registered-device information and access state.

Venue operations include restaurant settings, tables, menu items, immutable order commands, kitchen tickets, reservation state and audit events. Guest names, phone numbers and notes are kept in a separate contact record from the operational reservation. Kitchen roles cannot read that contact record.

Subscription records include the Firebase account identifier, selected plan, product, entitlement and billing status. Stripe handles web payments, the App Store handles native purchases, and RevenueCat coordinates subscription access. TabChef does not receive full payment-card details.

Providers may also process technical information such as IP address, browser or device information and request metadata to authenticate users, deliver the service and prevent abuse.

03

Why it is used

Account and venue data is used to provide the service requested by restaurant owners and staff. Reservation data is used to accept, manage and fulfil a booking for the restaurant. Security records are used to protect accounts, prevent abuse and keep an operational audit trail.

Billing information is used to provide the selected subscription, reconcile entitlement events and meet applicable accounting or legal duties. TabChef does not use reservation contact details for advertising, and the MVP contains no advertising SDKs.

04

Providers and processing locations

TabChef uses Google Firebase for authentication, database and trusted backend operations; Vercel for the website and server routes; RevenueCat for subscription entitlements; Stripe for web billing; and Apple for App Store billing.

The operational Firestore database is configured in the eur3 EU multi-region. Firebase Authentication and other provider services may process data outside the European Economic Area. Provider contracts and transfer safeguards apply where required.

05

How long data is kept

Account and venue information is kept while the account or venue is active and afterwards only as needed for export, security, disputes or legal duties. Billing and audit records may need to remain for longer where law requires it.

Live reservation contact records carry a deletion deadline 90 days after the reserved time. A restaurant may request earlier deletion when the information is no longer needed. Provider backups may take additional time to expire under their documented retention processes.

After account deletion, TabChef keeps only a domain-separated one-way hash of the former Firebase identifier, the completion time and policy markers. The tombstone contains no raw account identifier, email, device identifier, venue identifier or booking data. It is retained only while RevenueCat lifecycle events can still target that deleted identifier, solely to stop a delayed billing event from recreating account data. It is removed if that provider identifier is permanently erased or the integration can no longer send such events.

06

Your choices and rights

Depending on where you live, you may ask to access, correct, export, restrict or delete personal data, or object to certain processing. Account owners can write to david@strics.at. TabChef may need to verify the request before acting on it.

Reservation guests should contact the restaurant first because that restaurant controls the booking data. TabChef can help route a request when the restaurant cannot be reached. You may also complain to your local data-protection authority.

07

Security and changes

TabChef uses encrypted connections, managed provider encryption, venue-scoped access rules and protected management controls. No internet service can promise absolute security, so restaurant owners must protect account passwords and settings codes and remove access for lost devices or anyone who should no longer use the venue account.

This notice may change as TabChef adds providers or features. Material changes will be reflected here with a new update date.

TabChef

Tables, kitchen and guests. One simple app.

TermsPrivacySupport