tastify/ privacy policy
← home
privacy policy

Privacy Policy

last updated · 2026-04-01·version 2.3·
On this page
01Introduction02Information we collect03How we use your data04Tenant isolation05Storage & security06Sharing & sub-processors07Cookies08Data retention09Your rights10Children's privacy11Changes to this policy12Contact
→ Privacy Policy→ Terms of Service→ DPA→ legal@tastify.co
01

Introduction

#
tl;drWe run Tastify on your behalf. We handle personal data carefully, store it in isolated tenant schemas, and never sell it.

This policy explains what we collect when you use Tastify, how we use it, who we share it with, and the rights you have over your data.

02

Information we collect

#

Account data

Name, email, role, tenant slug, and hashed credentials for operators and staff.

Usage data

Device, browser, IP, and product-analytics events — used to debug and improve the platform.

Business data

Menus, modifiers, tables, orders, reservations, sessions, and reports you create inside your tenant.

Customer data

Guest phone, loyalty points, and reservation details your restaurants capture on your behalf.

03

How we use your data

#
  • —To operate and secure your tenant console.
  • —To send transactional messages (receipts, password resets, reservation confirmations).
  • —To provide support when you ask.
  • —To investigate abuse and enforce our terms.
  • —To improve Tastify in aggregated, non-identifying ways.
04

Tenant isolation

#
tl;drEvery restaurant lives in its own PostgreSQL schema. One tenant never sees another tenant's data.

Queries run under a per-request tenant context enforced by middleware. Cross-tenant access is only possible for your own backoffice administrators.

05

Storage & security

#
  • —Encrypted in transit (TLS 1.2+).
  • —Credentials hashed with Argon2id.
  • —Refresh-token rotation on every sign-in.
  • —Daily encrypted backups; 30-day retention.
  • —Infrastructure in region of your choice (HK · SG · EU).
06

Sharing & sub-processors

#

We share data only with sub-processors required to run the platform:

  • —Supabase — object storage (menu images, receipts).
  • —Stripe · PayMe · FPS — payment processing.
  • —FoodPanda · Keeta — delivery order injection (when enabled).
  • —Resend — transactional email.
  • —Twilio — SMS and WhatsApp notifications.

We never sell personal data. We do not use your business data to train third-party models.

07

Cookies

#

We use strictly-necessary cookies for session state and a small set of first-party analytics cookies. You can clear them at any time.

08

Data retention

#

Business data is retained while your subscription is active plus 90 days. You can export a full tenant snapshot at any time from the backoffice. After termination, we purge data within 90 days unless legally required to retain.

09

Your rights

#

Depending on your jurisdiction, you may have the right to:

  • —Access the personal data we hold about you.
  • —Request correction or deletion.
  • —Request portability (machine-readable export).
  • —Object to or restrict certain processing.
  • —Lodge a complaint with your local data-protection authority.
10

Children's privacy

#

Tastify is not directed at children under 16. We do not knowingly collect personal data from children.

11

Changes to this policy

#

We'll post updates here and notify tenant owners by email for material changes. Continued use after the effective date constitutes acceptance.

12

Contact

#

Data-protection enquiries · legal@tastify.co · Tastify Ltd, Hong Kong.

questions? legal@tastify.co
© 2026 Tastify Ltd · Hong Kong
Privacy PolicyTerms of Service• all systems normal