Skip to content
Table
Contents

Legal

Privacy Policy

Last updated: 10 October 2026

This policy explains what personal data Table collects, why, who else handles it, how long we keep it and what you can do about it. It describes what the product does today, in plain English.

The short version

  • We use personal data to run Table for shops and their customers. We don’t sell it, and we use no advertising or analytics trackers. Our website counts clicks on a few of its links, never who clicked.
  • For a shop’s customers, staff and suppliers, the shop decides what to collect, and we process that data for the shop.
  • Our hosting, database, WhatsApp and AI providers are outside Lebanon, so data is stored and processed abroad.
  • Apart from old nightly backups, nothing is deleted automatically after a set time. We may delete a shop’s data once its licence has been expired or cancelled for 12 months, and you can ask us to delete data sooner.
  • Our security has limits you should know about, such as PINs kept in readable form on devices; see Security.

1.Who we are

#

Table is a point-of-sale (POS) system for restaurants, cafés and shops, operated by Table (TABLELB), based in Beirut, Lebanon. In this policy, “Table”, “we” and “us” mean Table (TABLELB), and “shop” means any business that uses Table, including restaurants.

This policy covers:

  • our website, tablelb.com, including our own shop at tablelb.com/shop;
  • the Table apps: the till (the Windows app), the owner phone app, waiter tablets, the customer display and the price-check screen;
  • the QR menus, online ordering, online stores and quotation links we host for shops;
  • Table’s WhatsApp number, including our WhatsApp assistant for owners.

You can reach us on WhatsApp at +961 81 664 397 or by email at tableposlb@gmail.com about anything in this policy.

2.Who is responsible for which data

#

Where Table decides (Table is responsible). For shop owners’ accounts, billing and support, conversations with Table’s WhatsApp number, orders from our own shop, people who contact us about Table, and visitors to our website, Table decides how the data is used and is responsible for it.

Where the shop decides (the shop is responsible; Table processes the data for it). For a shop’s own customers, staff and suppliers, the shop decides what to collect and why, and is responsible for it. Table stores and processes that data on the shop’s behalf, to provide, secure and support the service as this policy describes. We don’t use it for our own marketing, sell it or use it for advertising.

If you are a shop’s customer or employee, your first contact about your data is that shop. You can also message us, and we will help the shop respond.

3.What we collect

#

Visitors to our website

  • No analytics service or tracking. We don’t use Google Analytics, advertising pixels or any analytics service, and we don’t count page views or menu scans.
  • Click counts: on our own pages (not on shops’ QR menus or online stores), we count clicks on the links that start a free trial, open WhatsApp, download the Windows app or open a demo, as a total for each page and month. Nothing about who clicked is stored: no cookie, no IP address and no device ID.
  • Standard request data: like any website, our hosting provider receives your IP address, browser details and the page you asked for. Some stock photos load directly from Unsplash (see Who we share it with).
  • Your browser’s storage: our marketing pages set no cookies. Some pages keep a few items in your browser, listed in Cookies and storage.

Shop owners

  • Account details: shop name, the mobile number registered to your account, business type or location, logo, plan, trial and renewal dates, languages and exchange-rate settings. If you signed up through WhatsApp, also the Whish number you gave.
  • How your registered mobile number is used: it identifies your account and, with your PIN, finds your shop at tablelb.com/login. We use it to reach you about your account and to send announcements from Table, on WhatsApp. It is in your QR menu’s public page data, and customers see it after they order with Whish, OMT or Neo, even if you set a separate order number. Until you set one, the menu’s call and WhatsApp buttons use it too.
  • Payment settings: the Whish, OMT and Neo numbers and the order phone number you show customers.
  • Business details (Management → My company): name, legal name, address, phone, email, website, tax and registration numbers, bank details, logo and receipt text. They are printed on receipts and invoices. If you trade under your own name, some of this is personal data.
  • Your name on the admin profile.
  • Your conversations with Table’s WhatsApp assistant: your messages, transcripts of your voice notes, the assistant’s replies, a short AI-written summary of the conversation that we keep and update, notes you ask it to remember, and a log of actions it took.
  • Photos: images you send to Table’s WhatsApp number and product photos you upload in the apps.
  • Billing records: payments you make to Table (amount, method, reference and notes), codes you redeem, and renewal requests you send on WhatsApp.
  • Support records: tickets you send from the app (title, description, contact details you add, app version, and any screenshots, screen recordings or voice notes you attach, plus the help-assistant conversation if you send it to us), whose text may also be forwarded to our team on WhatsApp; our notes about your account, such as your email, address, Instagram, previous system, how you heard about us or who referred you, other contact people at your business with their role and phone number, the hardware we installed with its model and serial number, and follow-ups; reminders we send you; a log of support actions such as PIN resets; and your AnyDesk ID if you give it to us.
  • Signing up and signing in: when you sign up, your shop name, mobile number, business type and your till’s web address may be sent to our team on WhatsApp. With your sign-up we also receive where that browser tab’s visit to our website began: the first page of ours it opened, the name of the website that linked to it (such as google.com) and any campaign tags (utm_…) in its address. We keep them with your account to learn which pages and campaigns bring new shops. We record the times of failed PIN attempts, and keep counters of recent attempts by IP address to limit abuse (see Apps and devices below).

Shop staff

The shop creates staff accounts and chooses which features to use. Depending on those choices, Table stores:

  • Staff profile: first and last name, optional email, PIN (with one-way hashes of it; see Security for when it is also kept in readable form), access level, role, wage type and rate, weekly shift schedule, overtime setting and card colour.
  • Time clock: clock-in and clock-out times, hours worked, amounts owed and notes. When payroll is switched on, cashiers are clocked in automatically when they sign in to the till. Changes to time-clock entries are logged with who made them; changes logged by earlier versions of Table hold the last two digits of the PIN used instead.
  • Excused absences: the date, whether it is paid, and a short reason. A reason could include health information, such as “called in sick”, so keep these notes short.
  • Activity: the staff member’s name on the sales, payments, shifts (including cash counted and any difference), voids, refunds, expenses and other records they make.
  • Delivery drivers: name, optional phone number and pay rates.
  • Biometric sign-in (passkeys): if someone sets up Face ID, fingerprint or Windows Hello, the face or fingerprint stays on the device. We store the passkey’s public key (which can check a sign-in but can’t be used to sign in by itself), a device label and the dates it was registered and last used. A successful biometric check signs the person in without their PIN. Older passkey records also hold a copy of the PIN; it is no longer used, and it is erased at the shop’s next sign-in with its main PIN or a passkey.
  • Failed sign-ins: the times of failed PIN attempts.

Shops’ customers

What we hold about you depends on how you order and which features the shop uses.

  • QR menu orders: your name and phone number, the items, add-ons and notes, the total, the payment method and whether it is delivery or pickup. For delivery we also keep your address, delivery zone, any coupon and, if you shared it, a Google Maps link to your location. The shop sees the order in its till and owner phone app, and we send these details to the shop on WhatsApp. For a cash order, the menu also opens WhatsApp on your phone with the order written out (the order reference, items, total, your name, address, location link if shared, zone, the amount you will pay with and your notes), and you send it yourself to the shop’s number.
  • Your location: collected only when you tap to share it at delivery checkout on the QR menu. There is no background tracking.
  • Online store orders: your name and phone number, the items, the payment method, your notes and, for delivery, your address. We send these to the shop on WhatsApp, and you may get updates about your order on WhatsApp from Table’s number. When you check an order’s status, the order reference and your phone number are sent in the web address of the request.
  • Coupons: when you use a coupon online, we record the code and your phone number so the shop’s per-customer limits work.
  • Reviews: after a QR menu order you can leave a 1–5 star rating and a comment. We don’t attach your name or phone number. Ratings of 5 stars, and of 1 or 2 stars, are sent to the shop owner on WhatsApp with the comment. When the owner asks the shop’s WhatsApp assistant for a report, one comment from that period, if there is one, is sent with the shop’s figures to our AI provider to write the report. If you tap the button to review the shop on Google, we record the tap and your rating, with nothing about you.
  • “Ask our AI Chef” chat: your last 10 messages in the chat (and the AI’s replies) are sent, with the menu, to our AI provider to get a reply. We don’t save the chat.
  • In the shop: if the shop creates a customer record for you, it can hold your name, phone, email, address, birthday, company, tax number, notes, total spent, number of visits, price tier, VIP level, loyalty points, credit limit and payment terms. Shops can also import customer lists from a file. Your name is saved on sales linked to you, and the sale notification sent to the owner on WhatsApp includes your name and the items. If you buy on credit, the shop keeps what you owe, and the owner’s app may alert them about your credit and your birthday.
  • Other records a shop may keep: reservations, open tabs and deliveries (name, phone, address, party size, times and notes); chalet self-orders (name, phone and notes, printed on the kitchen ticket); car rentals (the renter’s contact details, any additional driver, and vehicle inspection photos); session packages (your name, phone and the sessions booked and paid); phone top-ups and transfers (the recipient’s phone number); and warranties (the product’s serial number with your sale, which also appears in the owner’s WhatsApp notification).
  • Quotations: a shop can send you a quotation as a link. The page shows the quotation as it would print, including the customer details on it, to anyone who has the link. It is not listed in search engines.
  • Customer display: the screen facing you shows the items and totals of your sale and, on the shop’s own devices and on screens the shop has paired, your name and loyalty points if the sale is linked to you.

Customer sign-in (switched off)

The QR menu has no customer accounts or login. The web addresses of an older, switched-off customer sign-in still answer, though. If someone uses them directly, we store the phone number and a one-time code, which is sent by SMS if we have SMS set up, or on WhatsApp if that number messages our number asking for it. Completing the sign-in creates a customer account (phone number and name) and a session cookie, and keeps any delivery addresses saved through it (up to 10).

Buyers from our own shop

When you order hardware or a bundle through online checkout at tablelb.com/shop, we keep your name, phone number, business name, address, notes, the items and the payment status, plus the phone number that paid, as reported by Whish. When Whish confirms a payment, the order details are sent to our team on WhatsApp. If you order on WhatsApp instead, we receive what you send in your message. Either way, we contact you on WhatsApp to arrange delivery and installation.

Suppliers

If a shop records a supplier, including a farmer whose produce it sells on consignment, it can store the contact person’s name, phone, email, address, tax number, payment terms and notes.

People who contact us

If you message Table’s WhatsApp number or email us, we keep your messages (see WhatsApp messages). If you ask about Table, we may keep a short record of you as a possible customer: your name, phone, area, type of business, how you found us and notes about our conversations.

Apps and devices

  • Abuse prevention: we keep counters of recent attempts, keyed by IP address, for sign-ups, Find my shop, the till’s PIN sign-in, the AI Chef chat, menu translation, online-store orders and order-status checks, orders from our shop, device pairing, redeeming renewal and licence codes, and our operator console’s sign-in. The switched-off customer sign-in counts attempts by phone number.
  • Error reports: if an app hits an error, it sends us the error message, technical details and browser or app details, which we store with the shop’s account so we can fix problems.
  • Device reports: the Windows app reports a random device ID, the shop, its version and its update channel when it starts. Our apps also report when a device loses or restores its pairing, and when a device lands on a missing page. After a connection problem, the Windows app reports how it recovered: the internet addresses it found for tablelb.com, whether a proxy was set up and whether our site answered.
  • Shop network: when a shop chooses a main till (Settings → General → Shop network), we keep the network’s key and where the main till is: its device ID, computer name, private addresses on the shop’s network and port, so the other tills can find it. Without internet, the Windows tills on the shop’s network then exchange open tables, kitchen rounds and their unsynced sale lines (item and quantity), and tills that share a register the amounts, payment methods and times of their unsynced sales, refunds and cash drawer entries (with each entry’s reason), directly with the main till, encrypted with a key unique to the shop.
  • Pairing code on the clipboard: on a Windows computer, Download and Copy code on our sign-up page copy the text “Table pairing code: ABC-XYZ” to your clipboard; on other devices Copy code copies just the code. The sign-up page never reads your clipboard. The Windows app reads it only on its pairing screen, while the app is not paired and nobody has typed there: when the screen opens and each time the app window comes back to the front, but not on the screen that “Unpair this device” in the till’s settings opens; and once right after the app pairs, to check whether the clipboard still holds the code it used. Only text that is exactly such a pairing code is used, and only that code is sent to us, to pair the app as a typed code would; anything else on the clipboard is left alone and sent nowhere. After pairing, the app clears that text from the clipboard if it still holds the code just used. What the app keeps about it is listed in Cookies and storage.
  • Menu translation: when a QR menu is shown in Arabic or French, untranslated menu text is sent for translation. Only menu text is sent; the counter above keeps your IP address.
  • Camera and microphone: the till and owner app can use the camera to scan barcodes; codes are read on the device and camera images are not sent to us. The microphone is used only when you choose to speak to the help assistant or record a voice note for a support ticket.

4.Why we use it

#
  • To provide Table: the till, QR menu, online ordering, online store, receipts, reports, time clock and the other features a shop uses.
  • To send notifications and messages: new orders, sales, reviews and alerts to owners, daily and weekly summaries, licence reminders and announcements from Table to owners, order updates to customers, and broadcasts a shop sends.
  • To run the WhatsApp assistant, the help assistant and the other AI features.
  • To manage accounts, licences, payments to Table and orders from our own shop.
  • To see how each account is used, such as order counts, sales over the last 30 days and the time since the last sale, so we can spot accounts that are broken, inactive or likely to stop using Table, and contact the owner; and to follow up with people who asked about Table or signed up.
  • To give support, fix errors, prevent abuse and keep Table secure and working, including automated daily checks and nightly backups.
  • To meet our legal obligations, such as answering a lawful request from a Lebanese authority or court.

We use data this way because it is needed to provide the service you or the shop signed up for, because the shop asked us to, because we need it to keep Table secure and working, or because the law requires it.

We do not sell personal data, we don’t use it for advertising, and we don’t run ad trackers.

5.Who we share it with

#
  • The shop and its staff. Staff see what their access level allows.
  • Table’s team. We can see every account’s data from our operator console, and we use it to run the service and give support. Some support actions, such as resetting a PIN, are logged.
  • The public. A shop’s QR menu and online store are public: items, prices, photos, logo and contact details. Some other shop details can be read by anyone who has the shop’s Table web address (see Security).
  • Service providers, listed below, who process data to run parts of Table.
  • Authorities, if Lebanese law or a court requires it.
  • A new owner of the service, if our business or the service is transferred to another company.

Supabase

Our database and file storage. The Table apps and our website reach the database only through our servers.

ReceivesAll the data described in this policy, including uploaded photos, support-ticket attachments and our nightly backups. Browsers load public files, such as product photos, directly from it.

Vercel

Hosts our website, the apps and our server code, and runs our scheduled jobs. Our API routes, the pages our servers build and our scheduled jobs run in Vercel’s Frankfurt, Germany region. Each request first reaches Vercel’s network at a Vercel location near you, which can answer with a stored copy of a page. A small part of our code runs there too: it adds security settings to each page and sends older browsers a simpler download page.

ReceivesEvery request made to Table, including the IP address, browser details and the data sent with it. Its server logs can contain phone numbers, voice-note transcripts, error details and PINs: the current apps send the PIN in a request header, but older copies of the apps still put it in the web address.

Meta (WhatsApp Business Platform)

Carries every message to and from Table’s WhatsApp number.

ReceivesPhone numbers and message contents: owners’ messages, voice notes and photos; order and sale notifications to owners (online orders include the customer’s name, phone, address, location link and notes; sales in the shop include the items, the cashier’s note, any warranty serial numbers and the name of a linked customer); messages to shops’ customers, such as order updates, ready times and broadcasts; sign-in codes that someone asks our number for; and messages to our own team, such as sign-up notices, the text of support tickets and paid orders from our shop.

Anthropic (Claude)

AI for the WhatsApp assistant and its conversation summaries, the in-app help assistant, the QR menu’s “Ask our AI Chef” chat, menu translation, item descriptions, calorie estimates, menu and Google Maps imports, daily and weekly sales summaries, the sales reports an owner asks the assistant for, and tools our team uses to review accounts.

ReceivesOwners’ messages and voice-note transcripts with recent conversation history and its summary (for numbers not yet linked to a shop, see WhatsApp messages below); menu photos sent for import; help-assistant questions with the rest of that chat and the shop’s current figures (such as sales totals, best sellers, low stock and the total owed on credit, without customer names); AI Chef messages with the menu; menu text and item names; the text of a Google Maps page an owner asks to import; order counts, revenue and top items for summaries, and, for a report an owner asks the assistant for, also expenses, the average review rating and one customer review comment; and, for our team’s tools, shop names, plans, licence status, sales totals, owners’ phone numbers and their payment history with Table.

OpenAI

Speech-to-text for voice notes and for voice questions to the help assistant, text-to-speech for the help assistant’s spoken replies, and AI-edited “studio” product photos.

ReceivesThe audio of voice notes and voice questions, the text of replies to be read aloud, and the photo and item name when an owner asks for a studio photo.

Whish Money

Hosted checkout for orders from our own shop at tablelb.com/shop, when online checkout is available there.

ReceivesThe amount and the order reference. You enter your payment details on Whish’s page, not ours. Whish tells us whether the payment succeeded and the phone number that paid, which we keep with the order.

Google (Gmail)

Our support email inbox.

ReceivesEmails you send us, with your email address.

Browser push services

If an owner turns on notifications in the owner phone app, alerts go through the push service of that phone’s browser (for example Google’s or Apple’s).

ReceivesThe alert, encrypted under the Web Push standard. Alerts can mention customers’ names, for example for credit limits or birthdays.

Cloudflare and Google (DNS)

The Windows app looks up internet addresses through their secure DNS services, and can fall back to the network’s normal DNS.

ReceivesThe names of the sites the app looks up, and the computer’s IP address.

Twilio

Text messages (SMS) for a customer sign-in that is switched off, only if we have SMS set up.

ReceivesA phone number and a one-time code, only if someone uses that switched-off sign-in directly.

AnyDesk

Remote-desktop support, only if you give us your AnyDesk ID.

ReceivesWhat is on your computer’s screen during a support session, under AnyDesk’s own terms.

These services get nothing about you beyond an ordinary web request:

  • Whish, OMT and Neo for a shop’s own payments. Table only shows you the shop’s number, the amount and the order reference; what you then do in their apps is covered by their own terms.
  • api.qrserver.com draws QR codes of public menu and app links.
  • lirarate.org Our server reads the USD/LBP exchange rate from it.
  • GitHub hosts installer files for the Table Windows app. When a download from tablelb.com/download or an automatic update fetches one of them, GitHub (github.com and githubusercontent.com) sees the computer’s IP address.
  • Unsplash supplies stock photos on our website. Your browser loads some of them directly from Unsplash, which sees your IP address and browser details.
  • Product photo search (SerpAPI for Google Images, Unsplash or Pixabay, if switched on): when staff search for a product photo, our server sends the search words. The results load straight from those image sites, which see the device’s IP address.
  • Photos from other websites. A shop can use a product photo or logo hosted elsewhere. Your browser then loads it from that site, which sees your IP address and browser details.

6.Data outside Lebanon

#

Our database and file storage (Supabase) are outside Lebanon. Our API routes, the pages our servers build and our scheduled jobs run in Vercel’s Frankfurt, Germany region, and each request first passes through Vercel’s network at a location near you. Meta, Anthropic and OpenAI are based in the United States, and most of the other providers above are also based outside Lebanon. So the personal data described in this policy, including data about shops’ customers and staff, is stored and processed outside Lebanon, where data-protection laws may differ from Lebanon’s. Each provider handles data under its own terms and security measures.

7.AI processing

#

Table uses AI from Anthropic (Claude) and OpenAI. The provider list above says what each receives.

  • Voice notes: the audio is sent to OpenAI to be transcribed. We don’t save the audio file of a WhatsApp voice note. We keep the transcript with your conversation, and it also appears in our server logs.
  • Conversation memory: the WhatsApp assistant is sent your latest messages and a short summary of earlier ones, and the summary is refreshed by AI as the conversation grows.
  • Help assistant: your questions, the rest of that chat and your shop’s current figures are sent to Anthropic. The chat history is saved only on the device you used. Spoken replies are made by OpenAI.
  • Automatic summaries: the daily and weekly AI summaries are based on order counts, revenue and, for the weekly one, top items. They include no customer names or phone numbers.
  • Output that reaches customers unchecked: menu translations, AI Chef answers, items imported from a menu photo, and the descriptions, add-ons and removable ingredients the assistant writes when an owner adds an item without a description or asks it to fill in details are not reviewed by a person first. Calorie estimates are published only after the owner replies YES.

AI can be wrong. Customers should confirm ingredients and allergens with the shop.

8.WhatsApp messages

#

Table runs one WhatsApp Business number through Meta’s WhatsApp platform. This section covers the messages it sends and receives. WhatsApp’s own terms and privacy policy also apply when you use WhatsApp. Automatic WhatsApp messages from Table's number (sale alerts, order alerts, daily summaries and the owner's WhatsApp assistant) are not offered as a dependable feature yet. They are sent as plain messages, which WhatsApp delivers only within 24 hours of the recipient's last message to Table's number.

If you own a shop

  • We receive your messages, voice notes and photos, and we store your messages, the transcripts and the assistant’s replies.
  • We may send you new-order and sale notifications, reviews, daily and weekly summaries, licence and billing reminders, service alerts, and announcements from Table to all owners.

If you are a shop’s customer

  • When you order online, the shop’s WhatsApp notification includes your name, phone number and notes and, for delivery, your address and your location link if you shared it.
  • When a sale in the shop is linked to your customer record, the owner’s WhatsApp sale notification includes your name and the items.
  • From Table’s number you may receive updates about an online-store order, a “ready around” time when the shop sets one, and promotional messages (broadcasts) that the shop sends. A broadcast from the shop’s WhatsApp assistant goes to phone numbers on the shop’s online orders and deliveries from the last 90 days; a shop can also pick customers from its customer list.
  • Broadcasts from a shop’s WhatsApp assistant end with “Reply STOP to opt out”. If you reply with just STOP or UNSUBSCRIBE (or the same in French or Arabic, such as “وقف”), we put your number and the date on one opt-out list for all of Table and reply to confirm. From then on, promotional messages that any shop sends through Table’s number, from its WhatsApp assistant or by picking customers in the app, skip your number, including shops you only order from later. Messages about your own orders still arrive. This also works from a number that is a shop’s registered mobile number on Table; that shop’s own alerts and WhatsApp assistant carry on as before.
  • If you message our number asking about your order, we look up the latest order placed with your phone number, at any shop on Table, and reply with its status.

Anyone who messages our number

  • Messages from numbers that are not linked to a shop are stored, and the sender’s number can be stored with them. Our AI assistant answers them and treats them as a possible new sign-up. When it replies, the assistant is sent only your own recent messages to us and its replies to you, not other people’s. Messages of this kind stored without a number are kept but never sent to the assistant again.
  • Any image sent to our number is saved in public storage, at a random web address. AI “studio” photos made from them are stored the same way, and when one becomes a product photo, its address appears on the shop’s public menu. Older images and studio photos are at addresses that include the sender’s phone number, and stay there.
  • If a number messages ours asking for a sign-in code (for example “TABLE CODE”), we reply with any unexpired code waiting for that number.

9.Cookies and storage on your device

#

We use no advertising, analytics or tracking cookies. Our marketing pages, QR menus and online stores set no cookies. These are the only cookies in Table:

Cookies
admin_authWhereTable’s operator console onlyWhat it doesKeeps Table’s own team signed in. Shops and their customers never get it. Page scripts can’t read it.Lasts30 days
webauthn_reg_challengewebauthn_auth_challengeWhereTill and owner appWhat it doesUsed during biometric sign-in (Face ID, fingerprint or Windows Hello). Page scripts can’t read them.Lasts60 seconds
pos_paired_slugWhereDevice set-up pageWhat it doesRemembers which shop a till belongs to. It holds the shop’s web name (the part after tablelb.com/pos/).LastsUp to 10 years
table_sessionWhereSwitched-off customer sign-inWhat it doesSet only if someone completes the switched-off customer sign-in by using its web address directly. Page scripts can’t read it.Lasts30 days

Table also keeps data in your browser’s storage and, for the Windows app, on the computer. None of it is used for advertising or tracking.

Our website

Our website
table_last_shopStored inLocal storageWhat it holdsThe name and web name of the last shop created or found on this browser, for the “last used here” card when you sign in.LastsUntil you clear it
table-shop-pending-paymentStored inLocal storageWhat it holdsThe order reference and Whish payment link while a payment for an order from our shop is open.LastsRemoved on the payment result page; otherwise until you clear it
__table_chunk_reload_atStored inSession storageWhat it holdsThe time of an automatic reload after part of a page failed to load.LastsUntil you close the tab
tl_srcStored inSession storageWhat it holdsThe first page of our website this tab opened, the name of the website that linked to it and any campaign tags in its address. Sent to us only with a sign-up from this tab.LastsUntil you close the tab

The offline helper

The Table apps, QR menus, online stores, quotation links and our sign-in and download pages install an offline helper (a “service worker”) so they can open without internet. Our other website pages, the sign-up page and our shop don’t.

The offline helper
table-pos-stabletable-pos-img-v1Stored inCache storageWhat it holdsCopies of pages, app files and up to 400 product images. It does not keep the answers our servers send to the apps.LastsUntil your browser clears them

QR menus and online stores

QR menus and online stores
QR menu languagereload timeStored inSession storageWhat it holdsYour language choice on the QR menu, and when it last reloaded itself.LastsUntil you close the tab
store_cart_<shop>store_wishlist_<shop>store_lang_<shop>Stored inLocal storageWhat it holdsYour cart, wishlist and language in a shop’s online store.LastsUntil you clear them
store_last_order_<shop>Stored inLocal storageWhat it holdsThe reference, phone number and time of your last order, to show its status.LastsShown for 48 hours; kept until you dismiss it or clear it

Table apps: the till, owner app, waiter tablet and price checker

On the till this storage belongs to the Windows app, and uninstalling the app does not remove it. In the owner app, waiter tablets and price checkers it is the browser’s storage.

Table apps: the till, owner app, waiter tablet and price checker
pos_device_token_<shop>Stored inTillWhat it holdsA signed device token the till sends instead of the main admin PIN after a reload. It expires after 30 days unless the till renews it, and changing the PIN cancels it.LastsUntil it expires or is cancelled, or the app’s data is cleared
pos_pin_verifier_<shop>Stored inTillWhat it holdsA salted, scrambled (hashed) check of the main admin PIN, so the owner can sign in offline. It is not the PIN, but someone who copies it could work the PIN out by trying every possible PIN.LastsUntil the app’s data is cleared (a new PIN replaces it)
pos_pin_<shop>Stored inTillWhat it holdsThe main admin PIN in readable form: on a till that has not yet received a device token, and beside the token until our servers tell the till to delete it, so an older version of the app keeps working.LastsUntil the till deletes it or the app’s data is cleared
m_remembered_login_<shop>Stored inOwner appWhat it holdsIf you chose to stay signed in: a device token that signs you in again. It expires after 30 days unless the app renews it, and changing the PIN cancels it. An older version of the app kept the PIN itself here, in readable form, until the app next opens online.LastsUntil you sign out or clear the app’s data
tablet_login_cache_<shop>Stored inWaiter tabletWhat it holdsThe staff list and a salted, scrambled check of the PIN the tablet was signed in with (the shop PIN or a level-9 PIN), so the tablet can sign in offline. A copy saved by an older version holds that PIN in readable form until the tablet next opens Table.LastsUntil the browser’s data is cleared
pos_cdisplay_token_<shop>Stored inCustomer display on another deviceWhat it holdsThe screen’s pairing token, not the PIN.LastsUntil the shop unpairs its screens or the browser’s data is cleared
pos_print_company_cache_<shop>Stored inTillWhat it holdsThe last full company record from Management → My company, bank details included, so receipts print the same offline.LastsUntil the app’s data is cleared
pos_users_cache_<shop>pos_admin_cache_<shop>pos_security_cache_<shop>Stored inTillWhat it holdsThe staff list with scrambled (hashed) copies of staff PINs, the admin profile and access settings, for offline sign-in. A manager above the usual level keeps a scrambled copy of their PIN only on a till they have signed in to online.LastsUntil the app’s data is cleared
pos_queue_<shop>pos_actions_<shop>pos_customer_queue_<shop>pos_customers_cache_<shop>pos_pending_settle_<shop>pos_pending_split_<shop>pos_pending_voids_<shop>Stored inTillWhat it holdsSales and other changes waiting to sync, including changes sent but not yet answered, and new or cached customers, including names and phone numbers.LastsUntil they sync; the customer copy until the app’s data is cleared
pos_cash_cache_<shop>_<register>Stored inTillWhat it holdsThe register's last shift figures (opening, sales totals, pay-ins and pay-outs, counts and the names of the staff who opened and closed), so the cash drawer, the X report and closing the shift work without internet.LastsUntil the app’s data is cleared
pos_tabs_cache_<shop>pos_tables_cache_<shop>Stored inTillWhat it holdsThe table layout and the open tables with what was ordered on them (and the customer name when one was added), so dine-in tables still open, save, print to the kitchen and settle without internet.LastsUntil the app’s data is cleared
pos_active_cart_<shop>pos_saved_<shop>pos_cdisplay_cart_<shop>Stored inTillWhat it holdsThe current cart, parked sales and the customer-display cart.LastsUntil the app’s data is cleared
pos_print_settings_cache_<shop>Stored inTillWhat it holdsThe shop’s last saved till settings (printers, receipt layout, whether prices include tax, the main currency and other options), so the till totals and prints the same after a restart without internet.LastsUntil the app’s data is cleared
pos_loyalty_cache_<shop>pos_license_features_cache_<shop>pos_inventory_locations_cache_<shop>Stored inTillWhat it holdsThe shop’s loyalty rules, which paid add-ons it has and its stock locations with their quantities, so they still apply after a restart without internet.LastsUntil the app’s data is cleared
pos_coupons_cache_<shop>Stored inTillWhat it holdsThe shop’s coupons with each code scrambled (hashed), their percentages, limits and use counts, so a coupon can be checked without internet.LastsUntil the app’s data is cleared
recent-sales:<shop>Stored inTill (IndexedDB)What it holdsThe last 30 days of sales this till loaded (items, totals, payment method and customer name), so a sale can still be found and refunded, and sales history shown, without internet.LastsUntil the app’s data is cleared
pos_queue_dead_<shop>pos_actions_dead_<shop>Stored inTillWhat it holdsSales and other changes made without internet that our servers refused when they synced (with their items, amounts and the customer’s name when one was added), so staff can see them and redo them by hand.LastsUntil staff mark each one handled on the till’s Sync screen, or the app’s data is cleared
pos_ref_map_<shop>pos_refunded_lines_<shop>Stored inTillWhat it holdsFor sales made offline whose reference the server changed, the old and new reference, so an offline refund finds its sale; and which items of each sale this till has refunded, so the same items are not refunded twice offline.LastsUntil the app’s data is cleared; the refunded items for 30 days
pos_clock_entry_<shop>Stored inTillWhat it holdsFor each staff member clocked in on this till, the id and start time of their current clock-in, so a clock-out made without internet ends that one.LastsUntil they clock out, or the app’s data is cleared
product-meta:<shop>menu:<shop>storehouse:<shop>Stored inTill (IndexedDB)What it holdsThe menu (products, groups and prices) as our servers last confirmed it, the products’ barcodes, product and PLU codes, variations, add-ons, price tiers, packs, lira prices and stock counts, and the ingredients’ stock with the recipes, so the till can still find and sell them at their current prices, and warn when stock runs out, after a restart without internet.LastsUntil the app’s data is cleared
pos_assistant_chats_<shop>Stored inTill and owner appWhat it holdsHelp-assistant chats (up to 40). They are kept only on this device.LastsUntil the app’s data is cleared
pos_session_<shop>Stored inSession storageWhat it holdsA signed staff session.LastsUntil the tab or app closes; the session expires after 12 hours
table_device_idStored inTillWhat it holdsA random ID for this computer, sent with version reports and, on the shop network, to the main till.LastsUntil the app’s data is cleared
pos_lan_<shop>Stored inTillWhat it holdsThe shop network’s key, and where the main till is: its device ID, computer name, private addresses on the shop’s network and port.LastsUntil the app’s data is cleared
last-pos.jsonStored inWindows app (data folder)What it holdsThe address of the last till page the app opened, and when, so the app can open the till itself when its start page does not load.LastsUntil the app’s data folder is deleted
pos_handoff_triedStored inTillWhat it holdsA short fingerprint of the last pairing code tried or paired with on this computer, not the code itself, so that code is not sent again from the clipboard.LastsUntil the app’s data is cleared
table_signup_pairStored inSession storage (till)What it holdsWhen a shop is created on the sign-up page inside the Windows app: the new shop’s pairing code, admin PIN, name and web name, handed to the pairing screen.LastsRemoved when the pairing screen loads, ignored after 10 minutes, and gone when the app window closes
pos_paired_slugtablet_device_id_<shop>tablet_paired_slot_<shop>pricecheck_slugStored inAll devicesWhat it holdsWhich shop, and which tablet slot, the device is paired with.LastsUntil the data is cleared
tablet_tables_cache_<shop>tablet_pending_tabs_<shop>tablet_extras_<shop>Stored inWaiter tabletWhat it holdsThe table list and orders waiting to send.LastsUntil they send, or the data is cleared
PreferencesStored inAll devicesWhat it holdsLanguage, register, favourite reports, and printer, scale and display settings.LastsUntil the data is cleared

Files the Windows app keeps on the PC

Files the Windows app keeps on the PC
paired.jsonauto-launch.jsonsecure-dns.jsonnetwork-diagnostics.jsonupdate-hold.jsonStored inThe app’s folderWhat it holdsWhich shop the computer is paired with (in two places, so the pairing survives), whether the app starts with Windows, the DNS mode, the last network check and the update settings.LastsKept when the app is uninstalled
Print filesStored inA temporary folderWhat it holdsEach receipt or print job while it prints.LastsDeleted after printing

Protect these devices with a password, and clear the app’s data before you sell or give a device away. On a Windows till, uninstalling the app leaves its data on the computer.

10.How long we keep data

#

We do not delete personal data automatically after a set period, except for old nightly backups. Here is how it works today:

  • A shop’s data, including its account, sales, customers, staff records, WhatsApp conversations, reviews, support tickets and logs, is kept while the account exists, unless the shop deletes records or asks us to delete the account. An expired, cancelled or unpaid licence does not delete anything: we keep the data so the shop can renew and carry on.
  • Inactive shops. We may permanently delete the data of a shop whose licence has been expired or cancelled for 12 months. We don’t do this automatically. The owner can ask us to delete it sooner (see Your rights and choices).
  • Nightly backups: every night we back up each shop’s business data (menu, orders, customers, staff, credit balances and the time clock) to private storage. It holds the same data as the Settings → Database download, plus Table’s own notes about the account that the download leaves out. Like the download, it leaves out PINs and passkey records; copies made before that change still hold them (see Security). We keep the 30 most recent daily copies for each shop, plus a copy of the latest one; when a new backup of a shop succeeds, its daily copies beyond the 30 most recent are deleted. We don’t guarantee a backup of every account every night. Backups of an account that has been deleted are not removed automatically.
  • Photos, support-ticket attachments and images sent to our WhatsApp number stay in storage until they are removed by hand.
  • Sign-in codes and abuse-prevention counters are kept by phone number or IP address, not by shop. No scheduled job deletes them (a successful sign-in clears some counters), and deleting a shop’s account does not remove them.
  • Messages from numbers not linked to a shop are kept with no automatic deletion.
  • Broadcast opt-outs (the phone number and the date) are kept on one list for all of Table, apart from any shop’s data. Nothing removes a number from it, and resetting or deleting a shop does not touch it.
  • Some of our records are kept apart from each shop’s data: our log of actions our team and systems take on accounts (such as PIN resets, recorded payments and reminders, with the shop’s name and sometimes the owner’s phone number), reports from devices, the list of app versions each device runs, and our records of people who asked about Table. Some of these logs are capped in size, so older entries drop off; otherwise they are kept until we delete them, including after a shop’s account is deleted.
  • Trash: The Trash does not empty itself; archived items stay until someone purges them.
  • Deleting a customer record does not remove the name and phone number saved on that customer’s past orders.
  • Some internal logs are capped in size, so older entries drop off. For example, error reports are kept to the latest 500 per month for each account.
  • Vercel keeps its server logs, and our other providers keep data, under their own policies.
  • Data on a device, such as sales waiting to sync or help-assistant chats, stays there until it syncs or the device’s data is cleared.
  • Orders from our own shop are kept until we delete them.

11.Security

#

What we have in place

  • Secure connections (HTTPS) everywhere, and browsers are told to always use one for our site.
  • Browser protections that stop other websites from showing our pages inside theirs, and limit which scripts the apps, QR menus and online stores can run.
  • Our server code keeps each shop’s data separate. Through our apps and servers, most till data can only be read or changed with the shop’s PIN, and refunds, cash and other protected actions also need a signed staff session with the right access level. What the Management, Settings, Reports and Sales history screens load and save is also checked on our servers against the signed-in person’s access level (see the limits below).
  • The main admin PIN is kept on our servers as a one-way hash, staff PINs are moving to one-way hashes (see the limits below, for when a PIN is still kept in readable form and for the hash used for offline sign-in), and repeated wrong PINs slow down and then temporarily block further attempts.
  • For offline sign-in, the apps receive scrambled (hashed) copies of staff PINs, not the PINs themselves.
  • The current apps send the PIN, or the till’s device token, in a request header rather than in the web address, and after a reload a till sends its device token instead of the main admin PIN.
  • A customer display on another computer or tablet is paired once with the shop PIN; once a shop has paired a screen, unpaired screens receive nothing.
  • Versions of the Windows app after Standard 2.0.23 and Legacy 1.0.68 give silent printing, the cash drawer, shutting the computer down and their other device functions only to pages on Table’s own web addresses, and do not load other websites inside the app. A till keeps the older, looser check of the version it has until it installs one of those versions.
  • Biometric sign-in uses passkeys, so face and fingerprint data stay on the device.
  • When the payment numbers customers pay to are changed in the app, the change is logged and we send the owner a WhatsApp message.
  • Backups, both the one you download from the app and our nightly copy, leave out PINs and passkey records.
  • We check Meta’s signature on every incoming WhatsApp message before acting on it.
  • Sign-up, sign-in, online-store checkout, our shop’s checkout and code redemption limit repeated attempts.
  • Our operator console uses a signed session cookie and limits repeated sign-in attempts.
  • Nightly backups go to private storage.

Limits you should know about

  • The main admin PIN is kept on our servers as a one-way hash; an older shop’s starting PIN stays in readable form until it is first used.
  • Staff PINs are moving to one-way hashes in two stages. Until we switch on the second stage, a staff PIN that is set or changed is still stored in readable form beside its hashes, so an older version of Table keeps working. From the second stage, a new staff PIN is kept only as hashes, and an older staff record keeps its readable PIN until the owner’s till next loads the staff list or that PIN is next used.
  • A passkey record (from biometric sign-in) made before we stopped copying PINs into them holds a copy of the PIN until someone next signs in to the shop with its main PIN or a passkey.
  • For offline sign-in, each staff record on our servers also holds a second, faster hash of the staff PIN, and tills and waiter tablets keep copies of it; someone who copies one could work out the PIN by trying every possible PIN.
  • Nightly backups made before we started leaving PINs out of them contain staff PINs and passkey records. They are deleted as newer backups replace them, except copies that no newer backup replaces, such as those of a deleted account.
  • Tills keep the main admin PIN in readable form beside their device token until our servers tell them to delete it, which they do from the second stage above. The owner app keeps a device token when you choose to stay signed in, and a waiter tablet keeps a scrambled check of its PIN; copies saved by older versions of those apps hold the PIN in readable form until the app next opens.
  • A till’s device token works like the main admin PIN for most actions: someone who copies it from the till can use it until it expires, at most 30 days after it was issued, or until the PIN is changed.
  • The current apps send the PIN in a request header. Older copies of the apps, until a device loads the new version, still put it in the web address, so PINs can appear in plain text in our hosting provider’s request logs.
  • Photos and support-ticket attachments (screenshots, recordings and voice notes) are stored at public links: anyone who has a link can open it. Images sent to our WhatsApp number, and AI studio photos made from them, now get a random address, but older ones are at addresses that include the sender’s phone number. A quotation link shows that quotation to anyone who has the link.
  • Opening the cash drawer outside a sale is checked by the till app only. The level checks on Management, Settings, Reports and Sales history apply to requests from the till's own screens; a request made directly with the shop's owner credential, such as the sign-in a till keeps, counts as the owner's. Data those screens share with the sale screen, such as products, customers, stock counts and tables, is not re-checked against the user's access level.
  • We don’t add our own encryption to stored data beyond what our providers offer.
  • Table’s team can access all account data, and our automated checks can use every shop’s PIN-protected functions.
  • Some shop details are public by design and can be read without a PIN by anyone who has the shop’s Table web address: the QR menu’s page data, including the account’s registered mobile number and the Whish, OMT and Neo numbers the shop set; the product list used by the price-check screen, including barcodes and SKU/PLU codes; the items and totals of the sale on the customer display, until the shop pairs its first customer-display screen (from then on only paired screens and the shop’s own devices receive it); what a receipt prints from Management → My company: the shop name, logo, website, address, phone, email, legal name, tax and registration numbers, receipt header and footer, and tax rates (the bank details need a PIN); the licence plan, whether it is active or paused, and how many days are left; which of these add-ons the licence includes: the QR menu, the online store, chalets, session packages and extra cash registers (and how many), how many waiter-tablet slots it has, and what those cost at list price (the itemised bill and any agreed price need a PIN). Only enter business details you are happy to make public.

No system is perfectly secure. If you think something is wrong, tell us on WhatsApp at +961 81 664 397 or by email at tableposlb@gmail.com.

12.Your rights and choices

#
  • See and export your data. Owners can download a backup of their business data (menu, sales, customers, stock, staff, shifts, time clock and settings) from Settings → Database with the shop’s PIN, reports and customers as CSV, and products as CSV or XML. The backup does not include your WhatsApp conversations with our assistant, reviews, your payments to Table, Table’s own notes about your account or the photo and media files, so ask us for a copy of those. While your licence is expired or your account is paused, the app blocks these screens, so ask us for a copy.
  • Correct your data. Edit it in the apps or through the WhatsApp assistant. To change the mobile number registered to your account, message us.
  • Delete records. Owners can delete individual customers, staff, sales and other records, or reset whole categories of data from Settings → Database. A reset needs the admin PIN and a typed confirmation, and downloads a safety backup first. A reset is not a full erasure: the account, PINs, staff accounts and some settings stay. Permanently deleting a customer from the Trash is refused while money is still open between them and the shop, such as unpaid credit or store credit.
  • Delete the whole account. Message us on WhatsApp from the account’s registered mobile number, or email us; if you email, we may ask you to confirm from that number. We can’t promise to restore an account once it is deleted. Deletion removes the shop’s records from our database, including the menu, sales, customers, WhatsApp conversations linked to the account, payments and settings. It does not automatically remove backup files, stored photos and media, messages sent to us before the account existed, our log of actions on the account (including the deletion) and of reminders we sent, device reports and the list of device versions, any record of you as someone who asked about Table, or technical records such as sign-in codes, abuse-prevention counters and server logs. If you want backups and photos removed too, say so in your request.
  • Shops’ customers and staff. Ask the shop, which controls your data. You can also message us, and we will pass your request on and help the shop respond.
  • Marketing messages. See WhatsApp messages above.

In Lebanon, Law No. 81 of 2018 on Electronic Transactions and Personal Data sets rules for processing personal data, and the law where you live may give you further rights. Whatever law applies to you, send any request about your data to us on WhatsApp at +961 81 664 397 or by email at tableposlb@gmail.com. We may ask you to confirm who you are, and we will reply as soon as we reasonably can.

13.If you run a shop on Table

#

If you run a shop on Table, you decide what personal data you collect about your customers, staff and suppliers, and you are responsible for it. In particular:

  • Have a lawful reason for what you collect, and collect only what you need.
  • Tell people how you use their data, for example at the counter, on your menu or in your staff contracts, and that it is stored with Table as described in this policy.
  • Only message people who agreed to hear from you. A STOP reply only stops promotional messages sent through Table’s number, so when someone asks you to stop in any other way, or on your own WhatsApp, stop sending them messages yourself and tell us.
  • Keep notes short and factual. Don’t put health or other sensitive details in customer notes, staff absence reasons or other free-text fields unless you must.
  • Handle requests from your customers and staff to see, correct or delete their data. You can edit and delete records in the apps; message us if you need help.
  • Protect access: change the default PIN, give staff their own PINs and the lowest access level they need, deactivate staff who leave, and secure the devices that run Table.
  • Mind what is public, such as your QR menu, your business details and quotation links (see Security).

14.Children

#

Table is a tool for businesses and is not aimed at children. We don’t knowingly collect children’s data for our own purposes. QR menus and online stores are public and don’t ask anyone’s age, so a shop’s customers may include minors; the shop is responsible for that data.

15.Changes to this policy

#

We will update this policy when Table changes how it handles data, and change the date at the top. For important changes we may also tell owners on WhatsApp.

16.Contact us

#

Questions, requests or complaints about privacy:

These are Table’s only contact channels, for privacy requests as well as accounts, licences and cancellations. If you see a different number for Table in an app or an old message, use these. Table (TABLELB) is based in Beirut, Lebanon.

See also our Terms of Service.