App privacy disclosures
Scope of this notice
This notice covers:
- TableSync POS, the point-of-sale app, with Android package
com.tablesyncai.pos, used by restaurant staff on restaurant-owned devices; - TableSync Staff, the Android staff app, with package
com.tablesyncai.staff, used by restaurant staff on restaurant-owned devices to sign in, record shifts and breaks, serve tables and send orders; - TableSync Kitchen, the Android kitchen display app, with package
com.tablesyncai.kitchen, used on restaurant-owned devices to show and progress preparation tickets; - the TableSyncAI platform services the app connects to, including the restaurant dashboard and the TableSync API at api.tablesyncai.com; and
- this website, tablesyncai.com, including its demo, agency application, integrations, support and general contact enquiry forms.
TableSync POS is a business tool. It is installed by a restaurant and used by that restaurant's staff to take and manage orders. People whose data it may process are restaurant staff (operators), restaurant customers whose orders are recorded, and the restaurant owners and managers who administer the account.
Where a restaurant also offers online or QR ordering through TableSyncAI, the customer and order details entered there are processed by the same platform services and this notice applies to them in the same way.
Data the TableSync apps may process
Staff processes the staff identity, authentication, order and table-service, customer name and phone (where the restaurant enables lookup), device identifier and operational categories below; it does not process customer addresses, cash, tender or settlement facts. Kitchen processes only order and table-service data needed for preparation, device identifiers and operational information; it does not process staff identity, customer details or settlement facts.
Depending on how a restaurant uses the app, the current release may process the following categories of data. The app does not process any category that is not listed here.
- Restaurant staff identity: staff names, staff identifiers, roles and permissions, sign-in and sign-out times, till, break and clock-in activity, and which staff member handled an order or cash movement.
- Authentication details: a staff PIN, used transiently to sign in. The app never stores a plain-text PIN. For approved offline sign-in it stores a device-bound, one-way verifier in the device's secure storage.
- Customer name and phone number: where an order needs a customer record, for example collection, telephone or delivery orders and customer lookup.
- Customer address: only where an order requires it, such as a delivery order.
- Order and table-service data: menu items, options, notes, table, guest and round details, order source, promotions and order status.
- Cash, tender and settlement facts: how an order was settled, split allocations, till and cash-drawer movements, and receipt records. The app does not process card numbers, bank account details or card tokens.
- Device identifiers issued by TableSync: a device identity and a revocable device credential created when a restaurant enrols a device. TableSync issues these identifiers; the app does not read the Android advertising ID or any hardware identifier.
- Operational and diagnostic information: local error codes, connectivity and sync state, and the app release version, used to keep the device working and to reconcile orders. No diagnostic, analytics or crash-reporting service receives this information.
What the current release does not do. The TableSync apps do not collect location data, do not use an advertising identifier, do not contain advertising SDKs, do not send crash reports or usage analytics to us, do not take card payments on the device, do not use NFC or tap-to-pay, and do not sell personal data. The optional enrolment QR scanner uses an on-device barcode-recognition library supplied by Google; when the scanner is used, that library may send device and app information, an installation identifier and technical diagnostic or usage metrics to Google over HTTPS under Google's own terms. Camera frames are never stored or uploaded.
Device and operational data
Enrolment and device identity. A restaurant enrols each device by scanning a short-lived enrolment QR code or entering the enrolment details manually. TableSync then issues the device a unique identity and a revocable credential so that the device can talk to the TableSync API. The restaurant can revoke a device at any time from the dashboard, and local removal of cached data depends on the application, as explained under Local storage below.
Android permissions. The apps request only these permissions:
- Internet, to communicate with the TableSync API over HTTPS.
- Camera (asked at run time), only to scan the enrolment QR code. Camera frames are decoded in memory and are never stored or uploaded. If you decline, the enrolment details can be typed instead.
- Notifications (asked at run time), to show a persistent notice while pending orders need attention. Notification content stays on the device; no third-party push service is used.
- Foreground service (media playback), to keep new-order alert sounds playing reliably while the app is in use.
TableSync Staff and TableSync Kitchen request only Internet and Camera (at run time, for the enrolment QR code; the details can be typed instead). They do not request notification or foreground-service permissions. Android adds a network-state permission through the scanner and transport libraries; it grants no access to personal data.
Local storage. To keep working during network interruptions the app keeps a local copy of the restaurant's menu, open orders, recent order and customer records and staff session state on the device. In the Android applications, this cache is protected by the Android application sandbox, is excluded from Android backup and device-to-device transfer, and is erased when the app data is cleared or the app is uninstalled. In TableSync POS and TableSync Kitchen the cache is also erased when the enrolment is removed on the device; TableSync Kitchen first checks for unsent preparation changes. TableSync Staff does not currently offer an on-device enrolment-removal control; its cache is erased when the restaurant clears the app data or uninstalls the app. Revoking a device from the dashboard withdraws its server access but does not itself erase work saved on that device, so a revoked device should have its app data cleared. Uninstalling an app does not delete records already stored in the restaurant's TableSync account. Device credentials and the offline sign-in verifier are held in Android secure storage.
Diagnostics. Operational state such as error codes and sync status is kept on the device to help the app recover. The apps report their release version and platform when a device is enrolled, and TableSync Kitchen periodically reports its version, unsent-action count and last synchronisation time so that the restaurant can see the display's health. Release builds do not send crash reports or usage analytics to us, and no third-party analytics or crash-reporting service is used. The barcode-recognition library described above may send its own technical metrics to Google. Google Play may provide Thynkr Systems Ltd with aggregated crash and performance statistics under Google's own terms.
Website enquiries
When you submit a Book a Demo, agency application, integrations, support or general contact enquiry, we store the identity and contact details you provide, restaurant or company information, country or region, location or client-count information where requested, and enquiry content. An agency application may also include role, business identifier, countries served, client types, services, intended use and referral context. We use these details to review and respond to your enquiry. Submissions are sent to and stored by the TableSync API as separate enquiry records. The API also records the submitting IP address and browser user-agent information for operational and security context. Authorised TableSync administrators can review the records; submitting a form does not create a restaurant or agency account or subscribe you to a marketing campaign.
The retention, service-provider, security and rights sections of this notice also apply to website enquiries. Contact us using the details below to request access, correction or deletion.
This website does not use advertising or analytics cookies and does not load third-party tracking scripts.