Privacy Policy
This policy explains what data we collect across all TableOne services, how we use and share it, how we protect it, and your rights over your personal data.
01Introduction & Scope
This Privacy Policy explains how F&B POS (“we”) collects, uses, shares, and protects personal data in connection with your use of our services — including web apps, device apps (POS, Kiosk, KDS/ODS), reservations, and this site (the “Service”).
This policy applies to Merchants (business owners/managers who subscribe), Users (staff granted access), and End Customers (a Merchant's consumers who interact with the Service). By using the Service, you agree to the practices in this policy together with our Terms & Conditions and Cookie Policy.
02Our Role Regarding Data
- For Merchant and User account data and your interactions with our site, we act as the data controller.
- For End Customer data processed through the Service on a Merchant's instruction (e.g. orders, reservations, feedback, membership), the Merchant is the data controller and we act as the data processor.
If you are an End Customer with questions about your data, please first contact the Merchant (the business you transacted with) as its data controller.
03Data We Collect
a. Account & Business Profile Data
- name, email, and phone/WhatsApp number (including for OTP verification);
- business, brand, and outlet data (name, address, city, location coordinates, operating hours);
- business legal data if provided (e.g. legal entity type, NPWP, NIB, PKP status).
b. User/Staff Data
- employee and staff account data, roles/permissions, PINs/credentials, and attendance and schedule data.
c. Transaction & Operational Data
- orders, items, modifiers, payments, cashier shifts, inventory, recipes, promos, and reports.
d. End Customer Data
- QR/Kiosk ordering data, table reservation data, feedback form entries;
- membership/loyalty data (e.g. name, contact, points, history) if the Merchant enables it.
e. Payment Data
- payments are processed by third-party providers (e.g. Midtrans). We receive transaction status and references, but do not store your full card data.
f. Device, Technical & Usage Data
- device identifiers, IP address, device/browser type, and activity logs;
- offline sync data and timestamps for multi-device data consistency;
- cookies and similar technologies (see the Cookie section).
g. Communication & Support Data
- support ticket contents, attachments, and email/chat correspondence with us.
04How We Collect Data
- Directly from you — when you register, fill in forms, upload content, or contact us;
- Automatically — when you use the Service (logs, devices, cookies);
- From Merchants — if you are an End Customer, some data comes from the Merchant;
- From third parties — e.g. payment, OTP/messaging, or verification providers.
05How & On What Basis We Use Data
We use data to:
- provide, operate, maintain, and secure the Service;
- process transactions, subscriptions, and billing, and send related notifications;
- verify accounts (email/WhatsApp OTP) and prevent abuse/fraud;
- provide customer support and respond to your requests;
- analyze and improve the quality, performance, and features of the Service;
- send product or promotional information according to your preferences/consent;
- meet legal obligations and enforce our terms.
The basis for processing may be performance of an agreement with you, our reasonable legitimate interests, legal compliance, and/or your consent — in line with applicable regulations.
07Payment Data
Payments (e.g. QRIS, cards, e-wallets) are facilitated by third-party payment providers such as Midtrans. Processing of payment data is subject to those providers' privacy policies. We do not store your full card number or payment authentication data; we only receive the information needed to record transaction status.
08Sharing & Disclosure of Data
We do not sell your personal data. We may share data on a limited basis with:
- Service providers/sub-processors that help operate the Service — including but not limited to cloud infrastructure & storage providers (e.g. Cloudflare), payment gateways (e.g. Midtrans), email/OTP/messaging providers, bot protection (e.g. hCaptcha), and error/performance monitoring — bound to maintain confidentiality;
- The relevant Merchant — if you are an End Customer, your data is shared with the Merchant you transacted with;
- Competent authorities — where required by law or to protect rights, safety, and security;
- In corporate transactions — e.g. merger, acquisition, or asset transfer, with reasonable protections;
- With your consent — for other purposes you agree to.
09Merchant End Customer Data
End Customer data collected through ordering, reservations, feedback, or loyalty is processed on behalf of and on the instruction of the Merchant as data controller. The Merchant is responsible for the legal basis and consent for its collection, and for handling data-subject rights requests from its End Customers.
10Storage & Cross-Border Transfer
Data may be stored and processed on cloud infrastructure that may be located inside or outside Indonesia. Where a cross-border transfer occurs, we apply reasonable safeguards and comply with applicable regulations to protect your data.
11Data Security
We apply reasonable technical and organizational measures to protect data from unauthorized access, alteration, disclosure, or destruction, including:
- transport encryption (HTTPS/TLS) and role-based access control;
- account-security mechanisms such as single active sessions and audit trails for sensitive actions;
- regular backups and security monitoring.
Nevertheless, no method of transmission or storage is completely secure. You also play a role in keeping your credentials and devices confidential.
12Data Storage & Retention
We retain data while your Account is active and for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. After termination, we may retain data for a reasonable period so you can export it, then delete or anonymize data per our retention policy and applicable law. Copies in backups may persist for a limited period.
13Your Rights
Under applicable regulations, including Indonesia's Personal Data Protection Law, you may have the right to:
- access and obtain a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion of data under certain conditions;
- restrict or object to certain processing;
- withdraw consent you have given;
- obtain and move your data (portability).
To exercise your rights, contact us via the details below. If you are an End Customer, submit your request to the relevant Merchant. We may verify your identity before processing a request.
14Marketing & Communications
We may send service-related communications (e.g. transactions, security, important changes) that are essential and cannot always be turned off. For marketing communications, you can unsubscribe at any time via the opt-out link or by contacting us.
15Children's Privacy
The Service is intended for business use and is not directed at minors. We do not knowingly collect children's personal data. If you believe a child has provided data to us, please contact us so we can follow up.
16Third-Party Links & Services
The Service may contain links or integrations to third-party sites/services that have their own privacy policies. We are not responsible for those third parties' privacy practices; we recommend you read their policies.
17Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the Service, by email, or by posting the latest version on this page along with the update date. By continuing to use the Service, you are deemed to agree to the updated policy.
18Contact Us
For questions, data-rights requests, or privacy complaints, please contact us:
© 2024–2026 TableOne. All rights reserved. Effective version: June 19, 2026.