Privacy Policy
Last updated: August 2, 2026
OwnTable is a service operated by Brands Downtown (“OwnTable,” “Brands Downtown,” “we,” “us”) — a business registered in the United States. We provide ordering, AI order-taking, and customer-retention software to restaurants (“Restaurants”). This policy explains what personal data we handle, why, and the rights you have over it.
We act in two roles. For data about our Restaurant customers and their staff (account, billing, usage) we are a data controller. For data about a Restaurant’s own diners that flows through our platform (orders, phone numbers, delivery addresses) we are a data processor acting on that Restaurant’s instructions — see our Data Processing Addendum.
1. Data we collect
From Restaurants & their staff (as controller)
- Account: name, work email, role, hashed password, MFA enrollment.
- Restaurant profile: business name, address, phone, timezone, hours, tax rate, branding.
- Billing: plan, subscription status, and payment metadata held by our processor (Stripe). We never store full card numbers.
- Usage & telemetry: feature usage, AI tokens / voice minutes / messages consumed, error diagnostics.
From diners (as processor, on the Restaurant’s behalf)
- Name, phone number, and — for delivery — address.
- Order contents, totals, order history, and channel (web, voice, WhatsApp, SMS).
- Review text and ratings; support/chat conversation transcripts.
2. How we use data
- To operate the ordering, AI, delivery-dispatch, and retention features you use.
- To authenticate you, secure accounts, and prevent abuse/fraud (including rate-limiting).
- To bill accurately and meter cost-to-serve.
- To provide support and to diagnose and fix errors.
- To send transactional messages (order status, reviews, account notices). Marketing/reactivation messages to diners are sent on the Restaurant’s instruction and consent obligations rest with the Restaurant.
3. Legal bases (GDPR/UK GDPR)
- Contract — to deliver the service you signed up for.
- Legitimate interests — security, fraud prevention, product improvement, and analytics (balanced against your rights).
- Consent — non-essential cookies/analytics (see our Cookie Policy) and, where required, diner marketing.
- Legal obligation — tax, accounting, and lawful requests.
4. Sharing & subprocessors
We do not sell personal data. We share it only with vendors that process it on our behalf under contract:
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, hosting of application data | United States (us-east-2, Ohio) |
| Vercel | Application hosting & delivery | United States (iad1, Virginia) |
| Stripe / PayPal | Subscription billing | US / global |
| Resend | Transactional email | US |
| Twilio | SMS & delivery status messaging | US |
| Meta (WhatsApp) | WhatsApp messaging | Global |
| VAPI / ElevenLabs / Deepgram | Voice AI order-taking & transcription | US |
| Anthropic / OpenAI | AI order & support responses | US |
| Sentry | Error monitoring (personal data stripped) | US |
The full list — including which vendors a Restaurant connects itself, and which processing stays inside Saudi Arabia — is published at Subprocessors. Changes are notified there and via the DPA.
5. International transfers
Our infrastructure is located in the United States. Where data leaves the UK/EEA, or leaves the Kingdom of Saudi Arabia, we rely on Standard Contractual Clauses or an equivalent approved transfer mechanism with each subprocessor, supported by a documented transfer risk assessment. Card payments and tax e-invoicing for Saudi Restaurants are handled by providers inside the Kingdom and are not transferred abroad.
6. Retention
- Account & restaurant data: for the life of the account, then deleted or anonymized within 90 days of closure.
- Order & diner data: retained per the Restaurant’s instruction; deleted on their request or account closure.
- Billing records: retained as required by tax/accounting law (typically up to 7 years).
- Diagnostic logs: rolling ~90 days.
7. Your rights
Depending on where you live (GDPR/UK GDPR, CCPA/CPRA, and similar), you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. Restaurant owners can export or delete account data directly from Settings → Privacy & data. Diners should contact the Restaurant they ordered from; we will assist that Restaurant in fulfilling the request.
To exercise a right against OwnTable as controller, email sales@owntable.io. We respond within 30 days. You may also complain to your local supervisory authority (e.g. the UK ICO).
8. Saudi Arabia (PDPL)
For diners and Restaurants in the Kingdom of Saudi Arabia, we process personal data in line with the Personal Data Protection Law (PDPL), regulated by SDAIA. The Restaurant is the data controller of its diners’ data; OwnTable is its processor.
- Marketing consent: in the Kingdom, diner marketing (reactivation, campaigns) is sent only to diners who have opted in. Consent is captured at checkout, logged, and can be withdrawn at any time. Transactional messages (order status, receipts) are not marketing.
- Cross-border transfer: our database and application hosting are in the United States, so diner data is transferred outside the Kingdom. Because SDAIA has not issued an adequacy decision, we rely on Standard Contractual Clauses together with a documented transfer risk assessment, and we minimise what leaves the Kingdom. Payment authorisation (Tap, Moyasar) and ZATCA e-invoicing stay inside the Kingdom; card numbers never enter our systems. Restaurants can request the assessment summary and applicable clauses, and see the full vendor list at Subprocessors.
- Data-subject rights: diners may request access to, correction of, or erasure of their data via the Restaurant they ordered from; Restaurants can fulfil this directly (export or erase a diner) from the Customers screen.
- Breach notification: we notify affected Restaurants without undue delay and support notification to SDAIA and affected individuals within the required timeframe.
9. Security
Data is encrypted in transit (TLS) and at rest. Access is scoped per-tenant with row-level security; third-party credentials are stored in an encrypted vault and never shown back. Optional two-factor authentication is available on every account. See our Terms for the shared-responsibility model.
10. Children
The service is for businesses and is not directed at children under 16.
11. Changes
We’ll post material changes here and, where required, notify account owners by email. The “last updated” date above always reflects the current version.
12. Contact
Brands Downtown (operating OwnTable) — sales@owntable.io.
7901 4th St N, Ste 7115, St. Petersburg, FL 33702, United States.