Who is responsible
The TabChef operator is responsible for venue-account, platform and billing data. You can contact the operator at david@strics.at.
For a guest reservation, the restaurant shown on the booking page is responsible for the guest information. TabChef processes that information to provide the restaurant's booking service. Each live restaurant page must identify that restaurant and link to its own privacy notice.
The Demo Restaurant page is a product preview. It does not persist reservation submissions.
What TabChef processes
The venue account includes the owner's name, email address, sign-in and security information. Permitted-device records include registered-device information and access state.
Venue operations include restaurant settings, tables, menu items, immutable order commands, kitchen tickets, reservation state and audit events. Guest names, phone numbers and notes are kept in a separate contact record from the operational reservation. Kitchen roles cannot read that contact record.
Subscription records include the Firebase account identifier, selected plan, product, entitlement and billing status. Stripe handles web payments, the App Store handles native purchases, and RevenueCat coordinates subscription access. TabChef does not receive full payment-card details.
Providers may also process technical information such as IP address, browser or device information and request metadata to authenticate users, deliver the service and prevent abuse.
Why it is used
Account and venue data is used to provide the service requested by restaurant owners and staff. Reservation data is used to accept, manage and fulfil a booking for the restaurant. Security records are used to protect accounts, prevent abuse and keep an operational audit trail.
Billing information is used to provide the selected subscription, reconcile entitlement events and meet applicable accounting or legal duties. TabChef does not use reservation contact details for advertising, and the MVP contains no advertising SDKs.
Providers and processing locations
TabChef uses Google Firebase for authentication, database and trusted backend operations; Vercel for the website and server routes; RevenueCat for subscription entitlements; Stripe for web billing; and Apple for App Store billing.
The operational Firestore database is configured in the eur3 EU multi-region. Firebase Authentication and other provider services may process data outside the European Economic Area. Provider contracts and transfer safeguards apply where required.
How long data is kept
Account and venue information is kept while the account or venue is active and afterwards only as needed for export, security, disputes or legal duties. Billing and audit records may need to remain for longer where law requires it.
Live reservation contact records carry a deletion deadline 90 days after the reserved time. A restaurant may request earlier deletion when the information is no longer needed. Provider backups may take additional time to expire under their documented retention processes.
After account deletion, TabChef keeps only a domain-separated one-way hash of the former Firebase identifier, the completion time and policy markers. The tombstone contains no raw account identifier, email, device identifier, venue identifier or booking data. It is retained only while RevenueCat lifecycle events can still target that deleted identifier, solely to stop a delayed billing event from recreating account data. It is removed if that provider identifier is permanently erased or the integration can no longer send such events.
Your choices and rights
Depending on where you live, you may ask to access, correct, export, restrict or delete personal data, or object to certain processing. Account owners can write to david@strics.at. TabChef may need to verify the request before acting on it.
Reservation guests should contact the restaurant first because that restaurant controls the booking data. TabChef can help route a request when the restaurant cannot be reached. You may also complain to your local data-protection authority.
Security and changes
TabChef uses encrypted connections, managed provider encryption, venue-scoped access rules and protected management controls. No internet service can promise absolute security, so restaurant owners must protect account passwords and settings codes and remove access for lost devices or anyone who should no longer use the venue account.
This notice may change as TabChef adds providers or features. Material changes will be reflected here with a new update date.
