Skip to content

Privacy Policy

Last updated: September 16, 2026

This policy explains what Grubbitt collects, why, and what you can do about it. It covers three groups of people:

  • Restaurant users: owners, admins, and staff who sign in to run a restaurant.
  • Guests: diners who scan a table QR code to browse a menu, order, and rate their meal.
  • Visitors: anyone who reads this website or sends us a message through the contact form.

1. Information You Give Us

Account details. When you sign in, we store your name and email address. When you sign in with Google or GitHub, that provider sends us your name, email address, and profile picture. We never store a password for you: you sign in with a link we email you or with Google or GitHub. You can add a phone number to your profile.

Restaurant details. To set up a restaurant you give us its name, logo, address, business email and phone number, country, currency, and timezone. Depending on the country you may add tax identifiers such as a GSTIN, PAN, VAT number, or TRN. You also give us your menu: categories, items, descriptions, prices, photos, add-ons, tax rates, and the service charges and fees you add to orders.

Team details. When you invite someone to your restaurant, we store their email address and the role you chose, and we email them an invitation link.

Orders, invoices, and payments. Every order stores the items ordered, any charges added to it, the table, the guest name and phone number, an optional email address, and any special notes. Invoices add the customer details you confirm, including an optional tax number. Every payment or refund you record stores the method, the amount, an optional reference such as a transaction ID, notes, and the team member who recorded it.

Reviews and feedback. Guests can rate a completed order from 1 to 5 stars and add a comment. Restaurant users can send us a star rating and a message about the app.

Support and contact messages. Support tickets store the subject, priority, and every message in the thread. The contact form stores your name, email address, optional phone number, subject, and message.

AI inputs. When you import a menu from photos, we receive those photos. When you generate a menu theme, we receive the description you type. Section 4 explains how we process them.

2. Information We Collect Automatically

Sign-in sessions. Each time a restaurant user signs in, we record the IP address and browser used. This lets us detect unusual sign-ins and expire old sessions.

Request logs. We keep operational logs of requests to the platform. A log entry records what was requested, which account made the request, how long it took, and whether it succeeded. We use these logs to diagnose problems and investigate abuse.

Cookies. We set the cookies the platform needs to work and none for advertising or third-party analytics:

  • A sign-in cookie that keeps restaurant users signed in.
  • A guest cookie that lets a guest see their own orders and ratings on the menu. It is set when a guest places their first order and lasts up to 365 days.
  • A cart cookie that keeps a guest's cart for one table. It lasts 1 day.
  • Preference cookies and browser storage that remember your light or dark mode and sidebar layout.

3. How We Use Information

We use the information above to:

  • Sign you in and keep your account secure
  • Show menus to guests and deliver their orders to the restaurant
  • Create invoices, record payments and refunds, and build the dashboard and reports a restaurant sees
  • Send the emails described in section 6
  • Answer support tickets, feedback, and contact form messages
  • Apply the limits of the plan a restaurant is on
  • Diagnose faults, prevent abuse, and improve the platform
  • Meet legal obligations

We do not sell personal information and we do not show ads.

4. AI Features

Two features use an AI model run by Google. Menu import sends the menu photos you upload to the model and returns a list of items, prices, and categories for you to review. Theme generation sends the description you type and returns a color palette.

We send only the photos or the description you submit for that request. We do not send your account details, guest data, orders, or invoices. Both features have a daily cap per account or restaurant, and the app tells you when you reach it.

5. Who Can See Your Information

Your restaurant's team. Owners and admins of a restaurant see everything in it: menu, orders, invoices, payments, guest details, reviews, and restaurant support tickets. Staff see orders, tables, live sessions, and payments but not money totals on the dashboard. When you leave a restaurant, the records of what you did there stay with the restaurant.

Guests. Anyone with a restaurant's menu link can see its name, logo, menu, and menu photos. Guest names, phone numbers, and ratings are shown only to the restaurant's team, never to other guests.

Our support team. To answer a ticket, our team can view a restaurant's plan, settings, and records, and can open your account the way you see it. We do this only to resolve support requests, enforce our terms, or investigate abuse.

Service providers. We use providers to host the platform and its database, store uploaded files, deliver email, run the AI features, and offer sign-in with Google and GitHub. Each provider receives only what it needs for its task and may not use it for anything else.

Legal reasons. We disclose information when the law requires it, to protect the rights and safety of restaurants, guests, or the public, or as part of a merger or sale of the business. We notify you before your data becomes subject to a different privacy policy.

6. Emails We Send

We email restaurant users to:

  • Welcome you when your account is created
  • Deliver a sign-in link when you ask for one
  • Invite you to a restaurant on behalf of its owner or admin
  • Reply to contact form messages
  • Tell you about changes to your plan or these policies

We do not send marketing email, and we do not email guests. A guest's email address is kept only so the restaurant can put it on an invoice.

7. Guests and Restaurants

A restaurant decides what to do with the guest data it collects through Grubbitt, such as contacting a guest about an order. We store and process that data on the restaurant's behalf and under its instructions.

If you are a guest and want your details corrected or removed, ask the restaurant you ordered from. If you cannot reach the restaurant, contact us and we will pass on your request.

8. How Long We Keep Information

  • Restaurant records stay as long as the restaurant exists. When the owner deletes a restaurant, we delete its menu, tables, orders, invoices, payments, reviews, uploaded files, and settings.
  • Account details stay as long as your account exists. To delete your account, transfer or delete the restaurants you own and then contact us.
  • Invitations expire 7 days after they are sent.
  • Sign-in sessions expire on their own and end when you sign out.
  • Uploaded photos and logos are deleted when you replace them or delete the item or restaurant they belong to.
  • Support tickets, feedback, and contact messages stay so we can follow up and keep a record of what we agreed.

We keep information longer when the law requires it, for example tax records, or when we need it to resolve a dispute.

9. Security

Every connection to Grubbitt is encrypted. Access inside a restaurant follows the role each team member has. Sign-in links expire after one use and we store no passwords. Our team's access to customer data is limited to what support and operations need.

Keep your email account secure. Anyone who can read your email can request a sign-in link for your account. Remove team members from a restaurant as soon as they leave.

10. Where Your Information Is Stored

We store and process information on servers run by our hosting providers, which may be outside the country you or your restaurant are in. By using Grubbitt you agree to this transfer.

11. Your Rights

Depending on where you live, you may have the right to access, correct, export, delete, or restrict the use of your personal data, and to object to how we process it. You can update your name from your profile page and every restaurant detail from its settings page. For anything else, contact us and we will respond within 30 days.

12. Children

Grubbitt accounts are for people aged 18 or over who run or work at a restaurant. We do not knowingly collect account data from anyone under 18. Guest ordering collects only what the restaurant needs to serve the table.

13. Changes to This Policy

We may update this policy as the platform changes. We post every version on this page with its date. If a change reduces your rights, we email restaurant owners before it takes effect.

14. Contact Us

If you have a question about this policy or our data practices, contact us. You can also write to hello@grubbitt.com.