Privacy Policy
How Tavolio collects, uses, shares, protects and retains personal data across its website, web workspace, mobile application, support and connected services.
Effective date: 7 September 2026
Service provider and data controller
- Legal name
- Tavolio
- NUIS / NIPT
- TBD
- Registered office
- TBD
- Legal and privacy contact
- legal@tavolio.al
This Privacy Policy is provided under Albanian Law No. 124/2024 “On Personal Data Protection”. It applies to Tavolio’s public website, accounts, hosted restaurant workspace, mobile application, support, billing and integrations. It does not replace the privacy notice that each restaurant may need to provide to its staff, customers, suppliers and other individuals.
“Personal data” means information relating to an identified or identifiable individual. “Processing” includes collecting, using, storing, disclosing and deleting that information.
1. Who controls the data
The entity identified above is the controller for account administration, subscriptions and billing records, direct support, website operation, Service security, fraud prevention and Tavolio’s own legal obligations.
For personal data that a Customer enters or generates in its restaurant workspace—such as staff assignments, order notes or customer-related transaction records—the Customer is ordinarily the controller and Tavolio processes the data on its documented instructions as a processor. The Customer decides why that data is used and must provide lawful instructions and notices. Tavolio may separately process limited service metadata as controller where necessary for security, billing, compliance and reliable operation.
2. Where data comes from
We obtain data directly from account holders and invited users; from a Customer’s administrators and restaurant operations; automatically from browsers, apps, devices and the Service; from Google, Apple, Stripe and other integrations a user chooses; from support communications; and from public or authorised address, business-profile and fiscalization services.
3. Personal data we process
- Account and identity data: name, email address, password hash, optional hashed staff PIN, role, permissions, account status, fiscal operator code, authentication provider identifiers and multifactor-authentication state.
- Venue and team data: venue name and identifiers, address and coordinates, currency, time zone, staff invitations, roles, tables, menus and configuration.
- Restaurant operations: orders, line items, notes and modifiers, tables, staff actions, voids, discounts, refunds, payment method and amount, tips, cash drawer activity, print jobs and operational timestamps.
- Fiscal and accounting data: seller name and NUIS, business-unit, TCR, software and operator codes, VAT and invoice data, immutable invoice snapshots, fiscal identifiers and status, provider requests and responses, ledger records and generated exports.
- Subscription data: plan, price and entitlement history, trial and renewal dates, billing contact, Stripe customer and subscription identifiers, transaction status and limited payment-method details supplied by Stripe. Tavolio does not receive the complete card number or security code.
- Integration data: Google or Apple account identifier and permitted profile details; encrypted Google Business Profile access and refresh tokens, account and location identifiers and synchronisation status; push-notification token; fiscal-provider references; and enabled integration settings.
- Uploaded and generated data: menu images and extracted draft menu content, natural-language analytics questions and generated answers. Raw menu-import images are processed in memory for the request and are not intentionally stored by Tavolio after the request completes; the resulting draft is saved only when the user confirms the import.
- Support and communications: subject, message, account, venue, role, current page, correspondence and resolution details submitted to support.
- Technical and device data: IP address, request and security logs, browser or app type, operating system, locale, device or installation identifiers, printer-agent version, printer names and network addresses, discovered printers, job status, error details and cookie or local-storage values.
4. Subscription payments and Stripe
When a Customer enters a payment method, the complete card or payment-account credentials are submitted directly to Stripe and are not made available to Tavolio. Stripe may collect the cardholder or payer name, billing address, email, payment credentials, bank or card-network response, authentication result, IP address, device and fraud-prevention signals, and transaction details such as amount, currency, merchant and time.
Tavolio receives and stores the information needed to administer the subscription and its records: billing identity and contact details, tax information where supplied, Stripe customer, subscription, payment, invoice and payment-method identifiers, card brand and final digits where supplied, amounts and currency, trial and billing-period dates, payment and authentication status, retry or failure information, and invoice or receipt references. Tavolio uses this information to enter and perform the subscription contract, collect recurring charges, manage plan changes and access, provide billing support, prevent fraud, recover debts, resolve disputes and meet tax, accounting and other legal obligations.
Stripe processes some payment data on Tavolio’s instructions and also acts independently for purposes such as payment-network operation, authentication, fraud prevention, security and regulatory compliance. Stripe may disclose data to banks, card networks, authentication providers and authorities as described in its own notices. Its entity, processing location and retention period depend on the payment service and country. Restaurant-customer payment records entered into Tavolio’s POS are operational data controlled by the Customer and are not the payment credentials used to buy a Tavolio subscription.
5. Purposes and legal bases
Where data is required to create an account, enter a subscription, issue a fiscal document or secure the Service, failure to provide it may prevent the relevant function. Optional fields and integrations are identified by their context.
- Contract and pre-contract steps: create and authenticate accounts; provide workspaces, POS functions, printing, analytics, support, integrations and subscriptions; process Customer instructions; and communicate operational notices.
- Legal obligation: retain and produce accounting, tax, fiscal, billing and security records; respond to lawful authorities and data-subject requests; and comply with Albanian and other applicable law.
- Legitimate interests: secure and monitor the Service, prevent fraud and abuse, diagnose errors, maintain availability, recover debts, keep proportionate audit records, understand aggregate feature performance and defend legal claims. We balance these interests against individuals’ rights and reasonable expectations.
- Consent: activate optional device permissions, marketing communications or integrations where consent is the appropriate basis. Consent may be withdrawn at any time without affecting earlier lawful processing.
- Customer instructions: process restaurant-workspace data on behalf of the Customer under the Customer’s legal basis and data-processing instructions.
7. AI-assisted menu import
When an authorised user selects menu import, Tavolio sends the uploaded menu image, extraction instructions and necessary request metadata to Google’s Gemini 3.5 Flash-Lite service. Google returns structured text used to prepare an editable draft. Tavolio does not use this feature to make a legal or similarly significant decision about a person.
Tavolio does not intentionally persist the raw image after the request completes. Google may process and temporarily retain prompts, files, responses and abuse-monitoring logs under the applicable Gemini API terms and the production account configuration. Users must not upload identity documents, payment-card data, health or allergy information linked to a person, or other unnecessary personal or confidential data. Every draft must be checked before saving or publishing.
8. International transfers
Some providers or their support personnel may process data outside Albania. Before transferring personal data to another country or international organisation, Tavolio uses a mechanism permitted by Chapter IV of Law No. 124/2024, such as a recognised adequacy decision, approved standard contractual clauses, binding corporate rules, or a specific statutory exception. Where required, we assess relevant risks and adopt supplementary technical or organisational measures.
A Customer that independently enables an integration or directs a transfer is responsible for ensuring that its own disclosure and instructions are lawful. Information about the relevant safeguard or a copy of it, subject to lawful redactions, may be requested using the privacy contact above.
9. Retention and deletion
We retain data only for as long as necessary for the stated purpose, the Customer’s documented instructions, and legal, tax, accounting, security and dispute requirements. Retention is determined by the type of record, the life of the account or contract, statutory limitation periods, integrity of linked transaction records and whether a dispute or lawful hold exists.
In particular, Albanian tax and accounting records are retained for at least five years from the end of the tax year to which they relate, and longer where another rule or proceeding requires it. Fiscal invoices, immutable snapshots, payment, refund, cash-drawer and accounting-ledger records may therefore remain after a user or workspace is deleted. Generated accounting-export files are normally removed after 7 days; processed analytics delivery events after 7 days; staff invitations after 7 days; password-reset links after 1 hour; and refresh-token records on expiry or revocation, ordinarily within 30 days. The locale cookie lasts up to one year.
When an account is deleted, Tavolio revokes active authentication credentials and removes or replaces direct profile identifiers. If the user is the sole venue member, the venue is marked deleted and its subscription is cancelled. Records that must be preserved are restricted and retained with de-identified or replacement account details where feasible. Backups and security logs expire on controlled schedules and are not restored for ordinary use after deletion.
10. Security
We use risk-appropriate technical and organisational measures, including access controls and roles, password and PIN hashing, encryption for stored Google credentials, transport security, token expiry and revocation, rate limiting, logging, backups and restricted administrative access. Measures are reviewed as the Service and risks evolve.
No system is perfectly secure. Users must use unique credentials, protect devices and PINs, apply updates, assign least-privilege roles, remove former staff promptly and report suspected compromise. If a personal-data breach creates a legally reportable risk, Tavolio will notify the Commissioner and affected individuals within the periods and with the information required by law; where Tavolio is processor, it will notify the relevant Customer without undue delay.
11. Cookies and local device storage
The web application uses a refresh-token cookie needed to maintain a secure session and a locale-preference cookie lasting up to one year. It also uses browser storage for access-session state, theme, user cache, printing-agent selection and operational preferences. The mobile application stores authentication credentials in the device secure store where supported and limited cached account or preference data in application storage.
These technologies are used to provide requested functions, security and preferences, not third-party behavioural advertising. Blocking required storage may prevent sign-in or other features. Signing out, clearing browser or app data, or uninstalling the app removes many local values; server records remain subject to the retention rules above.
12. Your data-protection rights
Subject to Law No. 124/2024, an individual may request information and access; correction of inaccurate data; completion of incomplete data; erasure; restriction; portability of data supplied to us; objection to processing based on legitimate interests or direct marketing; withdrawal of consent; and protection from a decision based solely on automated processing that produces legal or similarly significant effects. Rights may be limited where a lawful exception applies, including required tax records or the rights of others.
Send a request to the privacy contact above and describe the account, Customer and request. We may verify identity and authority and may refer workspace-data requests to the Customer that controls the data. We respond without undue delay and ordinarily within 30 days; where legally permitted for a complex or numerous request, we will explain any extension. Requests are normally free, but a manifestly unfounded or excessive request may be refused or charged as permitted by law.
You may complain to Albania’s Commissioner for the Right to Information and Protection of Personal Data, or to another competent supervisory authority. We encourage you to contact us first so we can investigate, but doing so does not limit the right to complain or seek a judicial remedy.
13. Automated decisions and analytics
Tavolio uses automation to authenticate requests, enforce plan and permission limits, detect abuse, route print and fiscalization jobs, calculate operational analytics and create drafts. Tavolio does not make decisions based solely on automated processing that produce legal or similarly significant effects about account users. Customers must not use Service output as the sole basis for such a decision about staff or customers without a lawful basis, appropriate safeguards and meaningful human review.
14. Children and special-category data
The Service is intended for authorised business users and is not directed to children. We do not knowingly invite children to create independent Tavolio accounts. Customers must not enter children’s data, health data, biometric data, political or religious beliefs, or other special-category data unless strictly necessary, lawful, transparently disclosed and protected by appropriate safeguards. Contact us if you believe such data was submitted improperly.
15. Changes and contact
We may update this Policy when processing, providers, security measures or law changes. The current version and effective date will remain on this page. We will give additional notice through the Service or by email where a change materially affects individuals or consent is required.
Questions, requests and complaints may be sent to the privacy contact shown above. Operational support may also be contacted through the Customer Support page. For workspace data controlled by a restaurant, contact that restaurant or its administrator as well.