Privacy Policy
Last updated
This policy explains how Tahlib Private Limited ("Tahlib", "we") handles personal data. We are a company incorporated in India and serve restaurants in India, the UAE and the wider GCC, and elsewhere.
We play two roles. For the restaurant businesses that use Tahlib and the people who use their accounts, we decide how data is used: we are the controller (the "data fiduciary" under Indian law). For the data restaurants keep in Tahlib about their own guests, employees and riders, the restaurant is the controller and we process it on the restaurant’s behalf as a processor. Section 3 explains what that means if you are a guest.
On this page
1. Data we collect as controller
- Account data: name, email address, password (stored only as a one-way hash), and, if you sign in with Google, your Google account identifier, name and profile picture.
- Business data: your business name, brands and locations, addresses, country, tax registration numbers, and the role of each person on the account.
- Billing data: the products and locations you subscribe to, invoices, payment status and billing contact. If you pay by card, the card is handled by the payment provider; we do not receive or store full card numbers.
- Usage and security data: IP address, browser and device information, sign-in times, active sessions, and an audit log recording which user made which change in the dashboard and from which IP address.
- Communications: messages you send us by email, WhatsApp or support chat, and the emails we send you about your account.
Our marketing website does not use analytics or advertising trackers and sets no cookies. See the Cookie Policy.
2. Data we process for restaurants
When a restaurant uses Tahlib, it may store the following in its account. We process it only on the restaurant’s instructions, under our Data Processing Addendum, and never sell it or use it for our own marketing.
- Guests: phone number, name, email, language, delivery addresses, orders and payments, loyalty points and rewards, feedback and reviews, and — where the restaurant or guest provides them — date of birth, gender, allergens and dietary needs, marketing consent and notes.
- Employees: name, contact details, role, wage, schedules, time clock records and, where the restaurant uses face attendance, a numerical face template, an enrolment photo, clock-in and clock-out photos and, if enabled, the device location at clock-in.
- Riders: name, phone, email, vehicle details, optional bank details for payouts, delivery records and proof-of-delivery photos.
If you are a guest ordering from, booking with or paying a restaurant through Tahlib, that restaurant is responsible for your data and its own privacy notice applies. Please send requests about your data to the restaurant. If you contact us instead, we will pass your request to the restaurant and help it respond.
Payments you make to a restaurant online are processed by the restaurant’s own payment provider, under that provider’s privacy policy. Tahlib does not receive your card details.
3. How we use data and our legal grounds
| Purpose | Legal ground |
|---|---|
| Creating and running your account and providing the Services | Performance of our contract with you |
| Billing, invoicing, collecting payments and keeping tax records | Contract; legal obligation |
| Signing you in, keeping the Services secure, preventing fraud and abuse, keeping audit logs | Legitimate interests; legal obligation |
| Sending service messages: verification, security alerts, trial and billing reminders | Contract |
| Answering support requests | Contract; legitimate interests |
| Improving the Services using aggregated, de-identified statistics | Legitimate interests |
| Sending product news and offers to account owners | Consent or legitimate interests, depending on your country; you can opt out at any time |
| Complying with law, and establishing or defending legal claims | Legal obligation; legitimate interests |
Where Indian law applies, we process personal data on the basis of your consent given at sign-up or for the legitimate uses the Digital Personal Data Protection Act, 2023 permits, such as providing a service you asked for and complying with law. You may withdraw consent at any time, though we may then be unable to continue the Services.
We do not make decisions that have legal or similarly significant effects about you based solely on automated processing.
4. AI features
Ask Tahlib, the AI analyst in Tahlib Intelligence, is off unless enabled. When a restaurant uses it, the question asked, a few previous turns of the conversation, and aggregated business figures (such as revenue, costs, labour totals, and menu item and ingredient names) are sent to a third-party AI model provider to produce an answer. We do not send guest identities, staff names or restaurant identifiers, and we do not use your data to train AI models. Conversations are visible only to the user who had them.
6. Where data is stored and international transfers
Tahlib is operated from India and our customers are in many countries, so personal data is transferred across borders. Our production servers are hosted in the European Union, and some of our service providers process data in other countries, including the United States, as listed on the Sub-processors page.
We transfer data only where the law that applies permits it and with appropriate safeguards, such as contracts with our providers requiring them to protect it, including the European Commission’s standard contractual clauses where EU or UK law applies. We will follow any restriction on transfers to particular countries notified under Indian law, and the cross-border transfer rules of the GCC data protection laws that apply to a customer’s data, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and the Saudi Personal Data Protection Law.
If your business needs data kept in a particular region, contact us before you sign up.
7. How long we keep data
- Account data: for as long as your account is open, then deleted or anonymised within 90 days of closure, unless we must keep it longer.
- Invoices, payments and tax records: for as long as company and tax law requires, generally up to 8 years.
- Security logs and audit logs: for as long as needed to secure the Services, investigate incidents and meet legal obligations.
- Sign-in codes: guest sign-in codes are stored only in hashed form and expire after 5 minutes.
- Customer Data: as instructed by the restaurant, and deleted within 90 days after its account closes, as set out in the Data Processing Addendum.
8. Security
We protect data with measures including encryption in transit (TLS), one-way hashing of passwords and sign-in codes, encryption of stored payment provider credentials, role-based access controls within each account, separation of each customer’s data, and audit logs of changes. No system is completely secure. If a personal data breach affects you, we will notify you and the relevant authorities as the law requires.
9. Your rights
Depending on where you live, you may have the right to:
- get a summary of, or access to, the personal data we hold about you and how it is used;
- correct, complete or update it;
- have it erased;
- withdraw consent, and object to or restrict some processing, including direct marketing;
- receive it in a portable format;
- nominate another person to exercise your rights if you die or become incapable (India);
- complain to us, and then to a data protection authority.
To exercise a right, email hello@tahlib.app from the address on your account, or tell us how we can verify it is you. We respond within 30 days, or sooner where the law requires. If your request concerns data a restaurant holds about you as a guest or employee, we will refer it to that restaurant.
If you are not satisfied with our response, you may complain to the Data Protection Board of India once it is able to receive complaints, or to the data protection authority where you live or work — for example the UAE Data Office, the Saudi Data & AI Authority (SDAIA), or an EU or UK supervisory authority.
10. Children
Tahlib accounts are for businesses and their staff aged 18 or over. We do not knowingly collect children’s data as controller. A restaurant that knowingly serves guests under 18 through Tahlib is responsible for any parental consent the law requires.
11. Emails from us
We send account owners service emails that are part of the Services, such as trial, billing and security notices; these cannot be switched off while the account is open. Product news and offers can be stopped at any time with the unsubscribe link or by writing to us.
12. Contact and Grievance Officer
For any question or complaint about this policy or your personal data, contact our Grievance Officer at hello@tahlib.app. We acknowledge complaints within 24 hours and aim to resolve them within 15 days.
13. Changes to this policy
We will post any change on this page with a new date. If a change is significant, we will also tell account owners by email or in the dashboard before it takes effect.