Tabi is a QR ordering service for restaurants and cafes. This policy explains what we collect, why, and who else touches it. Questions or requests: hello@tabi.menu
Two different people use Tabi
A venue — the owner and staff of a restaurant — has an account with us. A guest scans a QR code at a table and never creates one. We hold different data about each, and we hold it on a different footing.
For a guest's orders, the venue decides what happens and we act on the venue's instructions. In data-protection terms the venue is the controller and Tabi is its processor. For the venue's own account we are the controller.
If you have an account (venue owners and staff)
- Name, email address and phone number, as you enter them.
- If you sign in with Google or Facebook: the name and email those services return.
- A password, stored only as a hash. We cannot read it.
- Your venue's content: menu, photos, table names, opening hours, contact details.
- Billing state — which plan you are on and whether it is active. Card details go straight to Polar and never reach our servers.
- Emails we send you (verification, invitations) and any support message you write us.
If you are a guest scanning a QR code
You are not asked to register, and we do not ask for your name. We do record:
- Your IP address, browser user-agent and language preference, plus the country and city your connection resolves to.
- Which venue and table you scanned, and when.
- What you ordered, and any note you attached to the order.
- A
tabi_session cookie holding a random session id — this is what keeps your order attached to your table.
The technical details are there to keep a table session honest: without them anyone could replay a QR link and order to a stranger's table. A guest session goes idle after 45 minutes and expires for good after 3 hours.
Why we are allowed to hold it
- To perform the contract — running the account you signed up for, taking the order you placed.
- Legitimate interest — keeping sessions and orders attributable to the right table, and preventing abuse of a public URL.
- Legal obligation — keeping billing records for as long as tax rules require.
Who else processes it
We do not sell data and we do not use it for advertising. These providers hold parts of it:
- Vercel — application hosting, and Speed Insights, which measures page speed without cookies and without identifying anyone.
- Neon — the database. Data lives in Singapore (ap-southeast-1).
- Ably — realtime delivery of orders to the kitchen screen.
- Cloudinary — menu and venue photos.
- Resend — transactional email (verification, invitations).
- Polar — subscription billing. Polar is the merchant of record and handles card data itself.
- Google — a venue homepage may embed a Google map. Loading it contacts Google directly; see our Cookie Policy.
How long we keep it
- Guest sessions: 3 hours, then they expire.
- Orders: kept for the venue, as the venue's own trading record.
- Account and venue data: while the account is active.
- A deleted venue is purged 14 days after deletion.
- Billing records: as long as tax law requires.
Your rights
You can ask us for a copy of your data, for a correction, or for deletion, and you can object to processing based on legitimate interest. Write to hello@tabi.menu and we will answer within 30 days.
If you are a guest asking about an order you placed at a restaurant, ask the restaurant first — the order is theirs, and they can act on it immediately. If they need us, we will help them.
Children
Tabi is not directed at children, and we do not knowingly collect their data.
Changes
If we change this policy we will change the date at the top. Material changes are announced to account holders by email.