Privacy Policy
U.S.-first Privacy Policy revision 2026-07-19.us-v1 covering state rights, disclosures, retention, sensitive information, and privacy controls.
<!-- tbltap-policy revision=2026-07-19.us-v1 sha256=4d5654cd20e927d9b5bca1304cfbbb956d1ebc5f54c74e250c8d0ebaaccf293e normalization=lf-strip-marker-trim-final-newline-v1 -->
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
<title>tbltap Privacy Policy</title>
<style>
:root { color-scheme: light; } body { margin:0; padding:20px 18px 32px; font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Helvetica,Arial,sans-serif; font-size:14px; line-height:1.58; color:#111827; background:#F5F6FA; } main { max-width:900px; margin:0 auto; } h1 { font-size:21px; margin:0 0 4px; } h2 { font-size:16px; margin:22px 0 7px; } p,li { margin:8px 0; } ul { padding-left:21px; } a { color:#1d4ed8; } .meta,.footer { font-size:12px; color:#5f6877; } .footer { margin-top:26px; padding-top:14px; border-top:1px solid rgba(15,23,42,.12); } .table-wrap { overflow-x:auto; } table { width:100%; min-width:860px; border-collapse:collapse; font-size:12px; background:#fff; } th,td { text-align:left; vertical-align:top; padding:8px; border-bottom:1px solid #e5e7eb; } th { font-weight:650; }
</style>
</head>
<body><main>
<h1>tbltap Privacy Policy</h1>
<p class="meta"><strong>Revision 2026-07-19.us-v1</strong> | Effective upon publication</p>
<p>This Policy explains how <strong>Ngassa Holdings LLC, doing business as tbltap</strong> ("tbltap," "we," "us," or "our") collects, uses, discloses, and retains personal information. tbltap is currently offered in the United States. Privacy rights vary by state; this Policy does not limit rights that cannot lawfully be waived.</p>
<h2>1. Scope and roles</h2>
<p>This Policy applies to tbltap websites, apps, digital menus, ordering and payment-facing flows, table tags, business tools, support, and related services. A restaurant may independently determine how it uses guest, employee, menu, fulfillment, and transaction information, and its notice may also apply. tbltap may act as a service provider or processor for a restaurant and as an independent business or controller for account security, platform operation, billing, fraud prevention, support, and product analytics.</p>
<h2>2. Information we collect</h2>
<ul>
<li><strong>Identifiers and account data:</strong> name, email, phone, username, avatar, account IDs, authentication records, and profile preferences.</li>
<li><strong>Restaurant and workforce data:</strong> business details, membership and role records, staff invitations, representatives, tax and payout onboarding status, menus, hours, and operational settings.</li>
<li><strong>Orders and transactions:</strong> restaurant, table or service context, items, modifiers, timing, taxes, tips, service charges, receipts, refunds, disputes, and support history.</li>
<li><strong>Payment information:</strong> payment tokens and limited metadata such as brand, last four digits, status, and provider references. Payment providers, not tbltap, receive full card or bank credentials entered in their secure fields.</li>
<li><strong>Content:</strong> reviews, ratings, photos, messages, support submissions, waitlist details, and other content you provide.</li>
<li><strong>Device, network, and usage data:</strong> IP address, browser and device type, operating system, app version, language, cookie and storage identifiers, referring page, feature interactions, diagnostics, crash and security events, and approximate location inferred from IP.</li>
<li><strong>Location:</strong> precise geolocation only when a feature requests it and you grant device or browser permission; otherwise city or region may be inferred from IP or a restaurant you select.</li>
<li><strong>Inferences and personalization:</strong> preferences or recommendations inferred from interactions, orders, saved items, dietary choices, and reviews when personalization is enabled.</li>
<li><strong>Information from others:</strong> restaurants, staff, identity providers, payment processors, app stores, service providers, public sources, and people who invite or transact with you.</li>
</ul>
<h2>3. Sources and purposes</h2>
<p>We collect information directly from you; automatically from your device and use of tbltap; from restaurants and their staff; from payment, identity, hosting, communications, security, and support providers; from people who interact with or invite you; and from lawful public sources.</p>
<ul>
<li>provide accounts, menus, orders, checkout, receipts, restaurant tools, support, and requested features;</li>
<li>authenticate users, prevent fraud and abuse, secure systems, debug failures, and enforce terms;</li>
<li>process restaurant subscriptions, payment status, refunds, disputes, payouts, and accounting records;</li>
<li>remember settings and, subject to the Cookie Policy controls, measure use and personalize recommendations;</li>
<li>communicate service, security, transactional, and legally permitted marketing messages;</li>
<li>comply with law, respond to lawful process, protect rights and safety, and establish or defend claims; and</li>
<li>create aggregated or deidentified information that we do not reasonably attempt to reidentify.</li>
</ul>
<h2>4. Disclosures and recipients</h2>
<ul>
<li><strong>Restaurants and authorized staff</strong> receive information needed to fulfill orders, manage service, address refunds or disputes, and operate their account. We do not provide restaurants a raw cross-restaurant diner history.</li>
<li><strong>Processors, service providers, and contractors</strong> support hosting, databases, content delivery, security, communications, customer support, analytics, maps, identity, payments, and professional services. Core providers include Stripe, Supabase, Google Cloud, and Cloudflare.</li>
<li><strong>Payment and identity providers</strong> may use information under their own notices where they act independently.</li>
<li><strong>Business-transfer recipients</strong> may receive information in diligence or a merger, financing, acquisition, reorganization, or sale, subject to confidentiality and applicable law.</li>
<li><strong>Government, legal, safety, and rights recipients</strong> may receive information when reasonably necessary to comply with valid process, protect users or the public, investigate abuse, or protect rights.</li>
<li><strong>Recipients you direct</strong> receive information when you ask, consent, or intentionally publish content.</li>
</ul>
<h2>5. California and preceding-12-month disclosures</h2>
<p>This section uses the categories in the California Consumer Privacy Act and applies to the extent tbltap is subject to that law. During the preceding 12 months, we collected the categories marked below from the sources in Section 3, used them for the purposes in Section 3, and disclosed them to the corresponding recipients for business purposes. We did not sell personal information or share it for cross-context behavioral advertising during the preceding 12 months. We do not have actual knowledge that we sold or shared personal information of consumers under 16.</p>
<div class="table-wrap"><table>
<thead><tr><th>California statutory category</th><th>Examples tbltap may collect</th><th>Business-purpose recipients</th><th>Retention period or criteria</th></tr></thead>
<tbody>
<tr><td>Identifiers</td><td>Name, email, phone, username, account, device, cookie, network, and provider identifiers</td><td>Restaurants for requested service; hosting, identity, communications, security, support, analytics, and payment providers</td><td>Account or service relationship plus the period needed for security, disputes, legal obligations, and backup expiration; shorter-lived session and security identifiers expire under the Cookie Policy</td></tr>
<tr><td>California Customer Records information</td><td>Contact, account, signature or acceptance evidence, and limited payment metadata</td><td>Restaurants, payment providers, support providers, professional advisers, and legal or safety recipients</td><td>Account relationship; transaction, tax, contract, and dispute records may be kept up to seven years or longer when legally required</td></tr>
<tr><td>Protected classification characteristics</td><td>Age range when legally needed; dietary or accessibility information only when provided and potentially revealing a protected trait</td><td>Restaurants and providers needed to deliver the requested feature</td><td>For the requested feature, account preference, or legal obligation; removed or deidentified when no longer needed</td></tr>
<tr><td>Commercial information</td><td>Orders, items, restaurant interactions, subscriptions, receipts, refunds, disputes, and purchasing tendencies</td><td>Restaurants, payment and accounting providers, support, hosting, fraud, and professional advisers</td><td>Transaction, tax, accounting, chargeback, and dispute records generally up to seven years or longer when legally required</td></tr>
<tr><td>Internet or other electronic network activity</td><td>Pages, clicks, feature interactions, referring pages, browser, app, diagnostics, and security events</td><td>Hosting, CDN, security, support, and optional analytics providers or systems</td><td>Short operational periods based on security, diagnostics, consent, and product need; retained longer only for an active incident, legal hold, or deidentified reporting</td></tr>
<tr><td>Geolocation data</td><td>Approximate location from IP or selected restaurant; precise location only with device permission</td><td>Restaurants and map, fraud, hosting, or feature providers needed for the requested service</td><td>Request/session duration unless saved for an account feature, fraud investigation, transaction record, or legal obligation</td></tr>
<tr><td>Audio, electronic, visual, or similar information</td><td>Photos, uploaded media, messages, support content, and records of electronic interactions</td><td>Restaurants, content hosting, support, moderation, security, and legal recipients as needed</td><td>Until content or account deletion, resolution of the support matter, or expiration of safety, dispute, and backup needs</td></tr>
<tr><td>Professional or employment-related information</td><td>Restaurant role, staff membership, authority, business contact, and operational permissions</td><td>The restaurant, identity, hosting, support, billing, and professional-service providers</td><td>Business relationship plus periods needed for access history, security, billing, disputes, and legal obligations</td></tr>
<tr><td>Education information</td><td>Not intentionally collected as a standard tbltap data category</td><td>Not routinely disclosed for a business purpose</td><td>If incidentally supplied to support, kept only for the support, safety, or legal need</td></tr>
<tr><td>Biometric information</td><td>tbltap does not intentionally derive biometric templates; device or identity providers may independently process biometric authentication without giving tbltap the biometric template</td><td>Independent device or identity provider under its notice</td><td>tbltap does not retain a biometric template for ordinary authentication</td></tr>
<tr><td>Inferences</td><td>Preference, taste, recommendation, fraud, and account-security signals</td><td>Restaurants only as needed for requested service; hosting, fraud, security, and optional personalization systems</td><td>While useful for the enabled feature, security purpose, or account relationship; deleted, reset, or deidentified when no longer needed</td></tr>
<tr><td>Sensitive personal information</td><td>Account credentials, precise geolocation when enabled, payment-account authentication handled by providers, and dietary data that may reveal health or religious traits</td><td>Restaurants and providers strictly needed for the requested feature, security, payments, or legal compliance</td><td>Only for the requested feature, security, transaction, or legal need; precise location is not retained beyond that need unless the user asks to save it</td></tr>
</tbody>
</table></div>
<p>Business-purpose disclosures during the preceding 12 months may include identifiers, Customer Records information, commercial information, internet or network activity, geolocation, visual or electronic content, professional information, inferences, and sensitive personal information to the recipients described above. tbltap did not disclose education information or tbltap-derived biometric templates for a business purpose as an ordinary practice.</p>
<h2>6. Cookies, analytics, personalization, and Global Privacy Control</h2>
<p>Necessary cookies and storage support sign-in, security, fraud prevention, language, carts, table or guest continuity, and requested functions. Optional analytics or personalization storage and events are controlled through the cookie banner or privacy settings. See the <a href="/docs/cookies">Cookie Policy</a> for verified names, durations, and controls.</p>
<p>We treat a recognized Global Privacy Control signal as an opt-out of sale, sharing, and targeted advertising for that browser where required. Because tbltap does not currently conduct those activities, the signal confirms that status; it also disables optional analytics and personalization in tbltap's consent control. GPC does not disable storage necessary to provide a requested service.</p>
<h2>7. Retention</h2>
<p>The category-level periods and criteria in Section 5 govern our retention. We keep information only as long as reasonably necessary for the disclosed purpose, then delete, deidentify, or isolate it unless law requires longer retention. Criteria include account and restaurant instructions, transaction and tax duties, chargeback and dispute windows, fraud and security needs, consent status, legal holds, and backup cycles. Backups expire on scheduled cycles and may not be immediately editable.</p>
<h2>8. Security</h2>
<p>We use administrative, technical, and physical safeguards appropriate to the information and service, including access controls, transport encryption, credential protections, logging, and provider security controls. No system is perfectly secure. Do not send full card numbers, passwords, one-time codes, private keys, or other secrets through support messages.</p>
<h2>9. U.S. state privacy rights and requests</h2>
<p>Depending on your state and subject to legal exceptions, you may have rights to know or access personal information; confirm processing; correct inaccuracies; delete information; obtain a portable copy; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive information; withdraw consent; and receive equal service without unlawful discrimination.</p>
<p>You may submit a request through the privacy or account controls in Settings, or email <a href="mailto:[email protected]">[email protected]</a> with subject "Privacy Request." State your state of residence, requested right, and the account or transaction information needed to locate records. We will respond within the period required by applicable law.</p>
<p>We verify requests in a manner proportionate to risk. We may ask you to confirm control of the account email or phone, authenticate, identify a transaction, or provide a signed declaration. We use verification information only to process the request. An authorized agent may submit a request where law permits, but we may require proof of signed authority and direct identity confirmation unless a valid power of attorney applies. If we deny a request, residents of states providing an appeal right may appeal through Settings or by emailing <a href="mailto:[email protected]">[email protected]</a> with subject "Privacy Appeal." You may contact your state attorney general or other regulator where applicable after an appeal decision.</p>
<p>We do not discriminate against you for exercising a privacy right. Deleting information necessary for a requested service may make that service unavailable, and a legally permitted financial incentive would be described in separate terms before enrollment.</p>
<h2>10. Sensitive personal information</h2>
<p>Payment credentials are handled by payment providers. Precise location, authentication information, dietary information that may reveal health or religious traits, and account credentials may be sensitive under some state laws. We use and disclose sensitive personal information only for requested features, security, fraud prevention, service operation, legal compliance, and other purposes permitted without a separate right to limit, or with consent where required. We do not use sensitive personal information to infer characteristics for advertising. Where applicable law provides a limit or consent-withdrawal right beyond these practices, use Settings or contact support.</p>
<h2>11. Children</h2>
<p>tbltap is not directed to children under 13, and we do not knowingly collect their personal information. We do not knowingly sell or share personal information of users under 18 for targeted advertising. A parent or guardian who believes a child provided information may email <a href="mailto:[email protected]">[email protected]</a>.</p>
<h2>12. Communications</h2>
<p>You may opt out of promotional email using its unsubscribe link and adjust available notification settings. We may still send transactional, account, safety, legal, and service messages. Carrier and platform settings may separately control SMS or push notifications.</p>
<h2>13. Changes and contact</h2>
<p>We may update this Policy. We will change the revision and provide additional notice or request consent when law requires. Material changes are prospective unless law permits otherwise.</p>
<p>Privacy requests, appeals, and questions: <a href="mailto:[email protected]">[email protected]</a>.</p>
<p class="footer">Revision 2026-07-19.us-v1. This Policy should be read with the Terms of Service and Cookie Policy.</p>
</main></body>
</html>
Contact tbltap support and include the document title so we can route your question quickly.
Contact support