Legal

Privacy Policy

This privacy notice explains how Thynkr Systems Ltd, operating as TableSyncAI, processes personal data in the TableSync apps for Android — TableSync POS (package com.tablesyncai.pos), TableSync Staff (package com.tablesyncai.staff) and TableSync Kitchen (package com.tablesyncai.kitchen) — the TableSyncAI platform services the apps connect to, Windows POS, and this website.

Last updated: 8 September 2026. Applies to TableSync POS release 0.5.0 and later, TableSync Staff release 0.1.0 and later and TableSync Kitchen release 0.1.0 and later, unless a newer notice replaces it.

Data deletion requests

Restaurants, staff and customers can ask us to delete personal data without reinstalling or opening the app. Email info@tablesyncai.com or read the data deletion section of this notice for what we need and what happens next.

Who we are

TableSync POS, TableSync Staff, TableSync Kitchen and the TableSyncAI platform are developed and operated by Thynkr Systems Ltd (trading as TableSyncAI), company number 15306717, registered in England and Wales. Registered office: Office 2, 1st Floor, 73 Station Passage, London E18 1JL. Telephone +44 (0)333 011 8207. Website: https://tablesyncai.com.

For anything about personal data or this notice, contact info@tablesyncai.com.

Scope of this notice

This notice covers:

  • TableSync POS, the point-of-sale app, with Android package com.tablesyncai.pos, used by restaurant staff on restaurant-owned devices;
  • TableSync Staff, the Android staff app, with package com.tablesyncai.staff, used by restaurant staff on restaurant-owned devices to sign in, record shifts and breaks, serve tables and send orders;
  • TableSync Kitchen, the Android kitchen display app, with package com.tablesyncai.kitchen, used on restaurant-owned devices to show and progress preparation tickets;
  • the TableSyncAI platform services the app connects to, including the restaurant dashboard and the TableSync API at api.tablesyncai.com; and
  • this website, tablesyncai.com, including its demo, partnership interest, integrations, support and general contact enquiry forms.

TableSync POS is a business tool. It is installed by a restaurant and used by that restaurant's staff to take and manage orders. People whose data it may process are restaurant staff (operators), restaurant customers whose orders are recorded, and the restaurant owners and managers who administer the account.

Where a restaurant also offers online or QR ordering through TableSyncAI, the customer and order details entered there are processed by the same platform services and this notice applies to them in the same way.

Data the TableSync apps may process

Staff processes the staff identity, authentication, order and table-service, customer name and phone (where the restaurant enables lookup), device identifier and operational categories below; it does not process customer addresses, cash, tender or settlement facts. Kitchen processes only order and table-service data needed for preparation, device identifiers and operational information; it does not process staff identity, customer details or settlement facts.

Depending on how a restaurant uses the app, the current release may process the following categories of data. The app does not process any category that is not listed here.

  • Restaurant staff identity: staff names, staff identifiers, roles and permissions, sign-in and sign-out times, till, break and clock-in activity, and which staff member handled an order or cash movement.
  • Authentication details: a staff PIN, used transiently to sign in. The app never stores a plain-text PIN. For approved offline sign-in it stores a device-bound, one-way verifier in the device's secure storage.
  • Customer name and phone number: where an order needs a customer record, for example collection, telephone or delivery orders and customer lookup.
  • Customer address: only where an order requires it, such as a delivery order.
  • Order and table-service data: menu items, options, notes, table, guest and round details, order source, promotions and order status.
  • Cash, tender and settlement facts: how an order was settled, split allocations, till and cash-drawer movements, and receipt records. The app does not process card numbers, bank account details or card tokens.
  • Device identifiers issued by TableSync: a device identity and a revocable device credential created when a restaurant enrols a device. TableSync issues these identifiers; the app does not read the Android advertising ID or any hardware identifier.
  • Operational and diagnostic information: local error codes, connectivity and sync state, and the app release version, used to keep the device working and to reconcile orders. No diagnostic, analytics or crash-reporting service receives this information.

What the current release does not do. The TableSync apps do not collect location data, do not use an advertising identifier, do not contain advertising SDKs, do not send crash reports or usage analytics to us, do not take card payments on the device, do not use NFC or tap-to-pay, and do not sell personal data. The optional enrolment QR scanner uses an on-device barcode-recognition library supplied by Google; when the scanner is used, that library may send device and app information, an installation identifier and technical diagnostic or usage metrics to Google over HTTPS under Google's own terms. Camera frames are never stored or uploaded.

How the data is used

We process the categories above only to:

  • provide the point-of-sale and kitchen display service: take, prepare, serve, settle and reconcile orders and table service;
  • authenticate staff and devices, attribute actions to the staff member who performed them, and allow approved offline operation when the network is unavailable;
  • keep accurate cash, tender, settlement and audit records for the restaurant;
  • secure the service, detect misuse and prevent fraud;
  • administer restaurant accounts and respond to support requests;
  • respond to enquiries submitted through this website; and
  • meet legal obligations, such as accounting and tax record-keeping.

Under UK data protection law, our legal bases are: performance of a contract (delivering the service the restaurant has signed up for), our legitimate interests in securing and operating the service and responding to enquiries, and compliance with legal obligations. We do not use personal data for profiling, behavioural advertising or automated decisions with legal effects.

Restaurants, TableSync and your data

Each restaurant that uses TableSync POS decides which staff to enrol, which customers to record and how long to keep its own operational records. For staff and customer data recorded in the app, the restaurant is the data controller and Thynkr Systems Ltd processes that data on the restaurant's instructions as its processor.

Thynkr Systems Ltd is the data controller for restaurant account and billing records, for security and audit records of the platform itself, and for enquiries submitted through this website.

If you are a customer or member of staff of a restaurant, you can raise a request with the restaurant or with us; we will work with the restaurant to resolve it.

Device and operational data

Enrolment and device identity. A restaurant enrols each device by scanning a short-lived enrolment QR code or entering the enrolment details manually. TableSync then issues the device a unique identity and a revocable credential so that the device can talk to the TableSync API. The restaurant can revoke a device at any time from the dashboard, and local removal of cached data depends on the application, as explained under Local storage below.

Android permissions. The apps request only these permissions:

  • Internet, to communicate with the TableSync API over HTTPS.
  • Camera (asked at run time), only to scan the enrolment QR code. Camera frames are decoded in memory and are never stored or uploaded. If you decline, the enrolment details can be typed instead.
  • Notifications (asked at run time), to show a persistent notice while pending orders need attention. Notification content stays on the device; no third-party push service is used.
  • Foreground service (media playback), to keep new-order alert sounds playing reliably while the app is in use.

TableSync Staff and TableSync Kitchen request only Internet and Camera (at run time, for the enrolment QR code; the details can be typed instead). They do not request notification or foreground-service permissions. Android adds a network-state permission through the scanner and transport libraries; it grants no access to personal data.

Local storage. To keep working during network interruptions the app keeps a local copy of the restaurant's menu, open orders, recent order and customer records and staff session state on the device. In the Android applications, this cache is protected by the Android application sandbox, is excluded from Android backup and device-to-device transfer, and is erased when the app data is cleared or the app is uninstalled. In TableSync POS and TableSync Kitchen the cache is also erased when the enrolment is removed on the device; TableSync Kitchen first checks for unsent preparation changes. TableSync Staff does not currently offer an on-device enrolment-removal control; its cache is erased when the restaurant clears the app data or uninstalls the app. Revoking a device from the dashboard withdraws its server access but does not itself erase work saved on that device, so a revoked device should have its app data cleared. Uninstalling an app does not delete records already stored in the restaurant's TableSync account. Device credentials and the offline sign-in verifier are held in Android secure storage.

Diagnostics. Operational state such as error codes and sync status is kept on the device to help the app recover. The apps report their release version and platform when a device is enrolled, and TableSync Kitchen periodically reports its version, unsent-action count and last synchronisation time so that the restaurant can see the display's health. Release builds do not send crash reports or usage analytics to us, and no third-party analytics or crash-reporting service is used. The barcode-recognition library described above may send its own technical metrics to Google. Google Play may provide Thynkr Systems Ltd with aggregated crash and performance statistics under Google's own terms.

Customer and order data

Customer details are recorded only where an order needs them and only to the extent the restaurant enters them: a name and phone number for collection, telephone and delivery orders and customer lookup, and an address for delivery orders. Order lines, table and round details and settlement facts are recorded for every order so that the restaurant can prepare, serve, settle and reconcile it.

This data is sent to the TableSync API over HTTPS and stored in the restaurant's account so that it is available across the restaurant's devices and dashboard. A copy may be cached on the enrolled device as described above. We do not use customer data for marketing and we do not share it with advertisers or data brokers.

Staff and operator data

Restaurant owners and managers create staff records and grant roles in the TableSync dashboard; there is no self-service account creation inside the app. Staff sign in with a PIN. The PIN is sent to the TableSync API for verification and is not stored in plain text on the device or the server.

The app records which staff member performed each action, including orders, cash movements, till operations, breaks and clock-in or clock-out events, so that the restaurant can operate and audit its service. These records belong to the restaurant's account and are visible to the restaurant's authorised managers.

In TableSync Staff, employees choose their name and sign in with a PIN. Locking the app or signing out ends the employee's session but does not clock the employee out; clocking in, clocking out and breaks are recorded separately from My shift. Where the restaurant has enabled approved offline access, an employee can continue taking orders during a connection outage using a device-bound verifier; saved work is sent when the connection returns and remains attributed to the employee who took it. Clocking, customer lookup and manager approval require a connection. Where the restaurant enables customer lookup on a Staff device, the lookup returns only the customer reference, display name and telephone number needed to attach the customer to an order; postal addresses, payment details and previous order totals are not sent to Staff devices. Those details remain available to TableSync POS for delivery and collection orders.

TableSync Kitchen has no employee sign-in. It shows preparation tickets, including table and round references, quantities, options and preparation notes written by colleagues, and sends preparation-state changes to the restaurant's account. It does not show customer names, contact details, addresses or payment information.

Signing out ends the employee's session. Removing the device enrolment or revoking the device withdraws the device's access; local data is erased as described under Local storage.

Website enquiries

When you submit a Book a Demo, Partnership Interest, integrations, support or general contact enquiry, we store the identity and contact details you provide, restaurant or company information, country or region, location or client-count range where requested, and enquiry content. We use these details to review and respond to your enquiry. Submissions are sent to and stored by the TableSync API as separate enquiry records. The API also records the submitting IP address and browser user-agent information for operational and security context. Authorised TableSync administrators can review the records; submitting a form does not create a restaurant or agency account or subscribe you to a marketing campaign.

The retention, service-provider, security and rights sections of this notice also apply to website enquiries. Contact us using the details below to request access, correction or deletion.

This website does not use advertising or analytics cookies and does not load third-party tracking scripts.

Service providers and processors

We use a small number of infrastructure providers that process data only on our behalf and on our instructions:

  • Server hosting. The TableSync API and its database run on a virtual server hosted in the United Kingdom.
  • Encrypted backups. Database backups are encrypted before they leave the server and are stored with a cloud object-storage provider.
  • Website and dashboard hosting. This website and the restaurant dashboard are served through a cloud hosting and content-delivery provider.
  • Transactional email. Account emails, such as setup links and invitations, are delivered through an email delivery provider.

These providers are processors and are not permitted to use the data for their own purposes. The current TableSync POS release does not send data to any payment provider, ordering marketplace, analytics vendor or advertising network. If a future release introduces a provider that receives personal data, we will update this notice before that provider goes live.

Data sharing

We do not sell personal data, and we do not share it with advertisers. We disclose personal data only:

  • to the restaurant whose account the data belongs to, and to the staff that restaurant has authorised;
  • to the service providers listed above, acting on our behalf;
  • where the law requires it, for example to a regulator, court or law-enforcement body, or to establish or defend legal claims; and
  • to a successor business if Thynkr Systems Ltd is sold or merged, in which case this notice will continue to apply to the data transferred.

Security

All traffic between the TableSync apps, the dashboard and the TableSync API uses HTTPS. The app refuses unencrypted connections and trusts only the Android system certificate authorities.

Device credentials are stored hashed on the server and in Android secure storage on the device. Staff PINs are never stored in plain text. Offline sign-in uses a device-bound verifier that cannot be reused on another device. Data cached on the device is excluded from Android backup and transfer and is erased as described under Local storage.

Access to production systems is restricted to authorised personnel, database backups are encrypted, and platform actions are recorded in audit logs. No system is completely secure; if we become aware of a personal data breach that is likely to affect you we will notify the affected restaurant and, where required, the Information Commissioner's Office.

Retention

We keep personal data only for as long as it is needed for the purposes above:

  • Restaurant account, staff and customer records are kept for the life of the restaurant's TableSync account and are deleted or anonymised after the account is closed, subject to the exceptions below.
  • Order, settlement and cash records form part of the restaurant's business and accounting records and are retained for as long as UK accounting, tax and audit rules require.
  • Security and audit logs are kept for a limited period to detect and investigate misuse.
  • Data cached on an enrolled device stays on the device while it remains enrolled so that service can continue during network interruptions. It is erased when the app data is cleared or the app is uninstalled, and, in POS and Kitchen, when the enrolment is removed on the device. Revocation withdraws access but does not erase the device's saved work.
  • Website enquiries are kept for as long as needed to respond and follow up.

Data deletion requests

You can ask us to delete personal data without reinstalling or opening the app. This applies to restaurant owners who want their restaurant account and its data removed, to staff members whose details are held in a restaurant's account, and to customers whose details were recorded with an order.

How to request deletion. Email info@tablesyncai.com with the subject line Data deletion request. Tell us:

  • who you are and whether you are a restaurant owner or manager, a staff member, or a customer;
  • the restaurant the data relates to; and
  • what you would like deleted (for example your whole restaurant account, your staff record, or your customer details).

You can also write to us at the registered office address above. The permanent address of this section is https://tablesyncai.com/privacy#data-deletion.

Verification. Before we delete anything we may need to verify your identity, and your authority to act for a restaurant, so that we do not delete data at the request of someone who is not entitled to ask. Where the data belongs to a restaurant's account we will confirm the request with the restaurant's authorised owner or manager.

What we delete. Eligible account and personal data will be deleted or, where a record must be kept in a non-identifying form, anonymised. Restaurant owners can revoke a device from the Control Centre to withdraw its access. Revocation does not remotely erase cached data. The restaurant must arrange local removal of that data as described under Local storage.

What we may keep. Some records may be retained where necessary for legitimate legal, security, fraud-prevention, accounting or contractual obligations. In particular, order, settlement and cash records that form part of a restaurant's accounting records, and security or audit logs, may be kept for the period the law requires even after a deletion request. We will tell you if any part of your request cannot be fulfilled and why.

We normally respond to valid deletion requests within one month, subject to any lawful extension or retention obligation.

International processing and transfers

Thynkr Systems Ltd is based in the United Kingdom and the TableSync API and database are hosted in the United Kingdom. Our website and dashboard hosting, encrypted backup storage and email delivery providers may process data in other countries, including the United States, through their global infrastructure. Where required, we use appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

Your rights

Under UK data protection law you have the right to ask for access to the personal data we hold about you, to have inaccurate data corrected, to have data deleted, to restrict or object to certain processing, and to receive a copy of data you provided in a portable format. Where we act as a processor for a restaurant we will pass your request to the restaurant and help it respond.

Restaurants using the TableSync apps can manage staff records, revoke devices and view their operational data in the TableSync dashboard, and can contact us for anything the dashboard does not yet allow.

To exercise any right, email info@tablesyncai.com. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.

Children

The TableSync apps are business applications intended for restaurant staff and are not directed at children. We do not knowingly collect personal data from children; if you believe a child's data has been recorded through the service, contact info@tablesyncai.com and we will remove it.

Changes to this notice

We will update this notice when the app or the platform changes in a way that affects personal data, for example before any payment, marketplace or analytics integration goes live. The date at the top of the page shows when it was last changed. Material changes will also be communicated to restaurant account holders.

Contact

Thynkr Systems Ltd (TableSyncAI)
Office 2, 1st Floor, 73 Station Passage, London E18 1JL
Telephone +44 (0)333 011 8207
Email info@tablesyncai.com