Privacy Policy

Last updated: 18 June 2026

1. Who we are

TableServe is a QR-based table ordering platform for South African restaurants. TableServe is operated by Karthickraja Dhakshinamoorthy, based in Durban, KwaZulu-Natal, South Africa. For the purposes of the Protection of Personal Information Act, 2013 (POPIA), the operator is the responsible party for personal information processed through this platform.

You can contact us for any privacy matter at privacy@tableserve.co.za.

2. What this policy covers

This policy applies to personal information collected when you:

  • Visit the marketing site at tableserve.co.za
  • Submit a demo request via the lead form
  • Use a restaurant's customer ordering menu (by scanning a QR code at a table)
  • Sign in as a restaurant staff member (owner, waiter, or kitchen)

3. Information we collect

From restaurant prospects (lead form)

  • Restaurant name
  • Contact person's name
  • Phone number
  • Optional message
  • IP address and browser user agent (for spam prevention)

From restaurant customers (QR ordering)

  • Items ordered, quantities, and any notes you add to an order
  • The table you are seated at (via the QR code you scanned)
  • Requests for the bill or for waiter assistance
  • IP address (used only for rate limiting and abuse prevention, not retained beyond what is necessary for that purpose)

We do not require you to log in, create an account, or provide your name, email, or payment information to place an order. Payment is handled directly between you and the restaurant.

From restaurant staff

  • Name
  • Email address (used as sign-in identifier)
  • A securely hashed password (we never store passwords in plain text)
  • Role at the restaurant (owner, waiter, or kitchen)
  • Session cookies to keep you signed in

4. Why we collect it (lawful basis)

We process personal information for the following purposes, each of which has a lawful basis under POPIA:

  • To operate the ordering platform — orders, table sessions, alerts, and staff sign-in are core functions of the service (performance of contract, legitimate interest).
  • To respond to demo requests — when you submit the lead form, you are giving consent for us to contact you about TableServe.
  • To prevent abuse — IP addresses are used to rate-limit ordering and lead-form submissions. This is a legitimate interest in keeping the service available.
  • To monitor service health — we use error tracking (Sentry) and uptime monitoring (UptimeRobot) to detect and fix problems. These tools collect technical data only.

5. Who we share information with

We do not sell personal information. We share limited information with the service providers we use to run the platform (operators under POPIA):

  • Supabase (database hosting, EU — Ireland) — stores all order, staff, and lead data.
  • Vercel (application hosting, global edge) — serves the website and processes requests.
  • Cloudflare (DNS and email routing) — directs traffic and forwards privacy emails.
  • Sentry (error tracking, EU storage) — receives error reports if the platform crashes. Configured for errors only; no session recording or user tracking.
  • UptimeRobot (uptime monitoring) — checks whether the site is up.

Each of these providers has been chosen with consideration for their security and data-protection practices. Where personal information leaves South Africa, it is processed in jurisdictions with comparable data-protection laws (primarily the European Union).

6. How long we keep information

  • Customer order data— retained for as long as the restaurant remains a customer of TableServe, for the restaurant's own record-keeping and reporting. No customer personal information is stored alongside orders.
  • Demo leads — retained for up to 24 months from last contact, after which they are deleted if no business relationship has formed.
  • Staff accounts — retained for as long as the staff member is active. Deactivated accounts are retained for up to 12 months for audit purposes, then deleted.
  • Error and uptime logs— retained according to the provider's defaults (Sentry: 30 days on the free plan).

7. Your rights under POPIA

You have the right to:

  • Know what personal information we hold about you
  • Request a copy of that information
  • Request correction of inaccurate information
  • Request deletion of your information, where legally permitted
  • Object to processing for specific purposes
  • Withdraw consent (where consent is the basis of processing)
  • Lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za

To exercise any of these rights, email privacy@tableserve.co.za. We will respond within 30 days, as required by POPIA.

8. Security

We take reasonable technical and organisational measures to protect personal information: passwords are stored as one-way hashes, traffic is encrypted in transit over HTTPS, API endpoints require authentication, and database access is restricted. No system is perfectly secure, however, and we cannot guarantee absolute security.

9. Children

TableServe is intended for use by restaurant patrons and staff. We do not knowingly collect personal information from children under 18 except in the ordinary course of a child ordering food at a restaurant table, where no personal identifiers are collected.

10. Cookies

See our Cookie Notice for details on the cookies we use. In short: we use only essential cookies for signing in to staff portals. We do not use advertising cookies or third-party tracking.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the “last updated” date at the top of the page. Material changes will be communicated to active customers via email.

12. Contact

TableServe
Operated by Karthickraja Dhakshinamoorthy
Durban, KwaZulu-Natal, South Africa
privacy@tableserve.co.za