Privacy policy
Last updated 2026-09-25
This policy explains how Tables Flow (operator legal name TBD) ("Tables Flow", "we") handles personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, and, where they apply, the Alberta and British Columbia Personal Information Protection Acts.
1. Person in charge of personal information
Person in charge of the protection of personal information (Privacy Officer): [Name to be designated]. Contact: privacy@tablesflow.example, [Mailing address TBD], Canada.
2. What we collect and why (purposes)
- Diners (no account): the items you order, the table or pickup lane, requested time, service choice (Be served / Self-serve), tip amount, and any order notes you type. Purpose: to send your order to the restaurant and have it prepared and delivered. We do not ask for your name, phone or email, and we do not record IP addresses or device identifiers in our database. We do not collect any payment information from diners: you pay the restaurant directly at its own terminal or counter, and TablesFlow never sees, processes or stores card details. Your order page is reached through a random link that only your phone has; your browser keeps that link (and any order waiting for a connection) in its local storage so a refresh doesn't lose it.
- Merchants: business name and address, contact name and email, licence number, year and province, a copy of the food-premises / business licence, and the time you gave privacy consent. Purpose: to verify that the restaurant is a licensed food operator before it can take orders, and to contact you about your account.
- Merchant subscription billing: billing email, billing address, subscription status, invoices and payment status. Card or bank details for the subscription are entered on Stripe's hosted pages and held by Stripe; we store only Stripe identifiers, the subscription status and the paid-through date. Purpose: billing the TablesFlow subscription and deciding whether service is active.
- Restaurant staff: name, email and role. Purpose: operating the kitchen and merchant tools.
- Platform operators: email address and Google account identifier used to sign in to the operator dashboard (no name or photo is stored).
We collect only what is necessary for these purposes. We do not sell personal information, and we do not use third-party analytics, advertising or tracking scripts.
3. Consent
Merchants give express consent at signup. Diners are shown a privacy notice at checkout; placing an order means the order details are used for the purposes above. We send only transactional messages. We will not send marketing email or SMS without separate, opt-in consent, and any commercial message will identify us and include an unsubscribe mechanism (CASL).
4. Retention
- Diner order notes on completed or cancelled orders are deleted after 30 days. Order amounts and item quantities are kept, without notes, for accounting.
- Technical retry keys are deleted after 7 days.
- Licence documents of rejected applications are deleted 30 days after the decision. Licence documents of active merchants are kept while the account is active and deleted when the account is closed.
- Operational alerts are deleted after 90 days once resolved; security audit logs after 365 days.
5. Where your information is stored (cross-border transfer)
Our application is hosted by Vercel Inc., our database by Neon (Databricks), and restaurant subscription payments are processed by Stripe, whose servers may be located outside Canada, including in the United States. Information stored there may be accessible to foreign courts, law-enforcement and national-security authorities under the laws of those countries. Before transferring personal information of Quebec residents outside Quebec we assess whether it will receive adequate protection, as required by Law 25.
6. Safeguards
Access to merchant licence documents is restricted to authenticated platform administrators; documents are never publicly accessible. We use encrypted connections (HTTPS), security headers, and limit staff access to what their role requires.
7. Your rights
You may request access to the personal information we hold about you, ask us to correct it, withdraw consent, or ask us to delete it. Quebec residents may also request de-indexation and information about automated decisions (we make none) and data portability where applicable. See how to make a request. We respond within 30 days. You may also complain to the Office of the Privacy Commissioner of Canada (OPC), the Commission d'accès à l'information du Québec, or the Alberta / BC commissioner.
8. Breach notification
If a breach of security safeguards creates a real risk of significant harm (or, in Quebec, a risk of serious injury), we will notify the Office of the Privacy Commissioner of Canada and, where applicable, the Commission d'accès à l'information, notify affected individuals as soon as feasible, and keep a record of every breach.
9. Restaurants
Each restaurant is the food operator and is responsible for the personal information it receives through its own orders (for example, notes you leave for the kitchen).
10. Changes and language
We will post changes here with a new date. A French version will be provided (Charter of the French Language). En cas de divergence, la version française prévaudra pour les résidents du Québec.