Privacy Policy
Last updated August 2026
This policy explains what data Serviate collects when you sign up and use the platform, why, and how it's handled. It applies to restaurant owners, their staff, and guests who order through a Serviate QR menu.
What we collect
When you create a Serviate account, we collect:
- Owner account: your name, email address, and password (stored as a one-way hash, so we never see or store your actual password).
- Restaurant details: business name, address, PAN/VAT number, phone, logo, and menu content you add.
- Staff accounts: name and, optionally, email or phone, set up by the restaurant owner. Staff sign in with a 4-digit PIN (also stored as a one-way hash), not a password.
- Operational data: orders, tables, sessions, and reports generated as you use the platform.
Guests ordering via a table QR code don't create an account. We don't collect guest names, emails, or phone numbers unless the restaurant's own staff records them separately.
Why we collect it
- To run your account and restaurant workspace. This is the core of the service; we can't provide it without this data.
- To send account-related emails: verifying your email, password resets, and staff invitations.
- To generate reports and analytics for your own restaurant (visible only to you and your staff).
We do not sell your data, and we do not use it for advertising.
Who we share it with
We use a small number of trusted service providers to run Serviate. Each only sees the data needed to do its job:
- Neon: hosts our Postgres database (where your account and restaurant data lives).
- Vercel: hosts the application itself.
- Resend: sends transactional emails (verification, password reset, staff invites). We never send marketing email through this.
- Cloudinary: hosts images you upload (logos, menu photos).
- Pusher: powers real-time updates, like new orders appearing on the kitchen display instantly.
We don't share your data with anyone else, except where required by law.
Cookies
We use a single session cookie to keep you signed in. We don't use advertising or third-party tracking cookies.
Data retention & deletion
We keep your data for as long as your account is active. If you want your account and restaurant data deleted, email us and we'll process the request.
Security
Passwords and staff PINs are never stored in plain text. Traffic to Serviate is encrypted (HTTPS). Restaurant data is isolated at the database level so one restaurant can never see another's data.
Children's privacy
Serviate is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 13.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page.
Contact
Questions about this policy or your data? Email support@serviate.com.