Legal

Privacy policy.

Aplateful handles two kinds of data: restaurant operational data (menus, wine lists, reservations) and guest data (names, contact details, dietary preferences, past orders). This policy explains how each is treated.

1. Who this policy covers

This policy applies to restaurants and hospitality groups who use Aplateful, and to their guests whose reservation records and preferences are processed through the service.

2. What data restaurants provide

Restaurants provide their operational data: menus, wine and beverage lists, kitchen station configuration, reservation patterns, seating layouts, staff accounts, and any guest records they wish to import.

This data is used strictly to run the service engine for that restaurant. It is not pooled with other restaurants, and it is not used to train shared models across accounts.

3. What guest data is processed

Guest data typically includes: name, contact channel used to book, party size, reservation notes, dietary and allergy information, past orders, pairing choices and pacing notes.

Allergy and dietary information is treated as sensitive. It is stored encrypted at rest and surfaced only to staff on the floor for that guest's service.

4. Lawful basis

Restaurants act as the data controller for their own guest records. Aplateful acts as the data processor, operating strictly within instructions defined in the service agreement and in this policy.

5. Access controls

Guest records are scoped to the restaurant and, within a restaurant, to the staff assigned to that service. Access is logged per session, per staff account, and is available to the restaurant on request.

6. Retention

Reservation records and guest preferences are retained while the guest is active with the restaurant. When a guest becomes inactive under the retention window set by the restaurant, their record is purged. Purged records are not recoverable.

7. Guest rights

A guest may request a full copy of the record held about them, a correction to any field, or the erasure of their record. Erasure requests are actioned within one working week and are confirmed in writing to the requesting guest.

8. Sub-processors

Aplateful uses a small number of infrastructure sub-processors to run the service: cloud hosting, transactional email, and error monitoring. A current list of sub-processors is available on request from the contact page.

9. Security incidents

In the event of a confirmed security incident affecting guest data, restaurants are notified within one working day, with a summary of scope, impact and remediation.

10. Changes to this policy

Material changes to this policy are notified to active restaurants by email at least two weeks before they take effect.

11. How to reach us

For privacy questions, please write to us through the contact page.