Your information, handled with care and clarity.
This notice describes the information Tavolio handles, why we handle it, and the choices available to you.
Scope and responsibility
This Privacy Notice explains how Tavolio processes information when you visit the public website, create or use a workspace account, use the web workspace, use the Tavolio mobile app, contact support, or otherwise interact with the service.
Tavolio is a business operations platform. A restaurant or organization using the service may act as the controller of information it enters into its workspace. In those cases, Tavolio processes that information to provide the service on the organization’s instructions. The organization remains responsible for its own notices, lawful basis, and decisions about data entered into the workspace.
Information we collect
Account and identity information may include your name, email address, password credentials, optional staff PIN, role, invitation details, and authentication provider information.
Workspace information may include venue configuration, tables, menu items, categories, modifiers, staff records, roles, permissions, orders, payments, discounts, refunds, kitchen statuses, accounting exports, printer configuration, fiscalization configuration, and related operational records that your organization chooses to enter.
Technical and usage information may include IP address, device and browser information, operating system, app version, timestamps, authentication events, error logs, and product interaction events needed for security, reliability, diagnostics, and service improvement.
If you contact support, we process the category, subject, message, account context, request identifier, and any other information you choose to provide.
How we use information
- Provide, operate, maintain, and secure the Tavolio service.
- Authenticate users, manage sessions, invitations, roles, and permissions.
- Process orders and related restaurant workflows at your organization’s direction.
- Synchronize data across supported web, mobile, realtime, notification, and printing experiences.
- Provide support, troubleshoot incidents, and communicate service-related information.
- Monitor performance, prevent abuse, investigate suspicious activity, and protect users and the service.
- Understand aggregate product usage and improve features, reliability, and documentation.
- Meet legal obligations, enforce agreements, and establish or defend legal claims.
We do not sell personal information. We do not use restaurant order data to build advertising profiles.
When information is shared
We share information only as needed to operate the service, at your organization’s direction, or where legally required. This may include service providers that host infrastructure, deliver email or notifications, provide authentication, support databases and analytics, process payments or fiscalization where configured by the organization, or help us secure and maintain the platform.
Providers are expected to process information under appropriate contractual and security controls. We may also disclose information to professional advisers, authorities, or another entity involved in a merger, acquisition, financing, or reorganization when permitted by law and subject to appropriate safeguards.
Retention and deletion
We retain information for as long as needed to provide the service, maintain business and security records, resolve disputes, enforce agreements, and meet legal or accounting obligations. Retention periods vary by the type of information and the organization’s configuration.
Workspace administrators control many account and operational records. If you want information removed, start with your organization administrator or contact support. We may retain limited information where necessary for security, fraud prevention, legal compliance, or to document a transaction.
Security
We use technical and organizational measures designed to protect information, including authenticated access, role-based permissions, encryption in transit, logging, rate limiting, and operational controls around infrastructure and backups. No internet service can guarantee absolute security, and you are responsible for protecting credentials, devices, and access granted to staff.
Report suspected unauthorized access promptly through the support channel so we can investigate and respond.
Your choices and rights
Depending on where you live and the role your organization plays, you may have rights to request access, correction, deletion, restriction, portability, or objection to certain processing. You may also withdraw consent where processing relies on consent. These rights may be limited by legal requirements or by the organization’s role as controller.
To make a request, contact your workspace administrator or use the support page. We may need to verify your identity and coordinate with the organization that controls the relevant workspace data.
Children’s privacy
The service is intended for business users and is not directed to children. We do not knowingly collect personal information from children for independent use of the service. Contact support if you believe a child’s information was submitted.
Changes and contact
We may update this Notice when the service, laws, or our processing practices change. The current version will be published on this page with its effective date. Material changes may also be communicated through the service or by email where appropriate.
For privacy questions or requests, contact your organization administrator or use Customer support.
This notice is general product information, not legal advice. Your organization may need additional policies for its own customer, employee, payment, or regulatory data.