waiter24.ai
Sign in Start free trial →

Privacy Policy

How AI Waiter collects, uses and protects personal data.

Updated: 28.07.2026

1. Who we are and what this Policy covers

AI Waiter / waiter24.ai («we», «us») provides an AI chat-assistant platform for restaurants. This Policy explains how we process personal data of:

  • Customers — restaurant owners and staff who register and use the admin panel; for this data we act as the data controller;
  • Guests — visitors who chat with a restaurant's AI assistant on the restaurant's website, Telegram or WhatsApp; for this data the restaurant is the controller and we act as its processor. Guests should direct privacy requests to the restaurant first; we will assist the restaurant in fulfilling them.

2. Data we collect

Customer (restaurant) data

  • Account data: name, e-mail, password (stored as a hash), restaurant name and settings.
  • Billing data: processed by our payment partners — Paddle (merchant of record, international cards) or LiqPay (card payments in UAH for customers in Ukraine). We do not store card numbers; we keep transaction metadata (plan, amount, status, dates).
  • Content: menu items and photos, prompts, knowledge-base texts, widget settings.
  • Technical data: IP address, browser type, log records.

Guest data (processed on behalf of the restaurant)

  • Conversation data: chat messages, selected language, session identifiers, timestamps.
  • Order and service data the guest chooses to provide in chat: name, phone number, delivery address, scheduled pickup/delivery time, table number, reservation details, callback requests.
  • Loyalty data: points balance and transactions keyed to the guest's phone number (where the restaurant enables the loyalty programme).
  • Feedback: post-order ratings (0–10) and comments.
  • Images: photos a guest uploads in chat (where the restaurant enables image upload) — used only to generate the AI response and provide support.
  • Dietary recommendations (health data): where the restaurant enables the diet-plan feature, a guest may upload a doctor's or dietitian's recommendation (image or PDF) to receive suitable dish suggestions. This may contain health data, so it is processed only after the guest's explicit in-chat confirmation (GDPR Art. 9(2)(a)), sent to the AI provider solely to generate that one reply and never stored on our servers or in the chat log.
  • Voice input: where enabled, speech is converted to text by your browser's built-in speech-recognition service (operated by the browser vendor, e.g. Google for Chrome); we receive and process only the resulting text, never the audio.
  • Interaction events: widget open/close, message sent, order placed and similar product-analytics events.

Prospective customers

  • Business contact data: we may process publicly available business contact details (e-mail address, business name) of restaurants to send a one-off invitation to the platform, based on our legitimate interest in reaching relevant businesses. Every such e-mail identifies us, explains where we obtained the address on request, and contains an unsubscribe link; opt-outs are kept on a suppression list and honoured permanently. You may object at any time (see Section 7).

Visitors to waiter24.ai

  • Anonymous visit statistics: for every arrival at our website we record the referring website or campaign tag, the landing page and its language. These records contain no IP address and no device or browser identifier, cannot be linked to you, and are therefore statistics rather than personal data.
  • Referral source (consent only): if you accept analytics cookies, a first-party cookie (w24_attr, 180 days) remembers which channel first brought you to the site. Should you later register an account, that channel is stored with the account so we can measure which of our own marketing works. Declining leaves the field empty and changes nothing else. See the Cookie Policy.

3. Purposes and legal bases

  • Providing and improving the Service (performance of a contract).
  • Measuring how our own marketing performs — anonymous visit statistics (legitimate interest, no personal data) and, where you consented, the referral source of a sign-up (consent, withdrawable at any time).
  • Generating AI responses to guest messages (performance of the restaurant's contract with us; the restaurant's legitimate interest in serving its guests).
  • Billing and account management (performance of a contract; legal obligations).
  • Service e-mails — receipts, trial and quota notifications, security notices (performance of a contract); product news (legitimate interest / consent, with an unsubscribe link in every such e-mail).
  • Security, fraud prevention and abuse detection (legitimate interest).

4. AI processing and sub-processors

  • To generate responses, conversation content (guest messages, relevant menu and prompt context, and uploaded images where applicable) is sent to a large-language-model provider. The default platform provider is Anthropic (Claude models). A restaurant may instead connect its own API key for a supported provider (OpenAI, Google Gemini, DeepSeek, Groq, xAI, Perplexity, OpenRouter, Together, Mistral, or a self-hosted endpoint) — in that case data is sent to the provider chosen by the restaurant.
  • Under the API terms of these providers, data submitted via API is not used to train their models.
  • Other sub-processors: payment processing (Paddle, LiqPay), transactional e-mail delivery (Postmark, Brevo or Resend, depending on configuration), hosting and infrastructure providers, and messaging platforms (Telegram, Meta/WhatsApp) where the restaurant enables those channels.
  • On our own marketing website, analytics (Google Analytics 4) and marketing (Meta Pixel) tools run only with your cookie consent — see the Cookie Policy.

5. Retention

  • Account data is kept for the lifetime of the account and deleted or anonymised after termination, except where law requires longer retention (e.g. accounting records).
  • Chat logs are kept for the period configured by the restaurant (default 1 year) and are then automatically deleted. Restaurants may also disable chat-log storage entirely.
  • Usage counters and aggregated statistics that contain no personal data may be kept longer.

6. Storage, transfers and security

Data is stored on servers located in the EU or Ukraine. Where data is transferred to providers outside these jurisdictions (e.g. AI providers in the US), we rely on appropriate safeguards such as standard contractual clauses offered by those providers. Security measures are described on the Security page and include TLS encryption in transit, encryption of stored API keys, hashed passwords, tenant data isolation and access controls.

7. Your rights

Under the GDPR and the Law of Ukraine «On Personal Data Protection» you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected and, in certain cases, have data erased;
  • restrict or object to processing;
  • receive your data in a machine-readable format (portability);
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with your data-protection authority.

To exercise these rights, e-mail [email protected]. If you are a restaurant guest, please contact the restaurant first — it controls your data; we will support its response.

8. Children

The Service is a business tool and is not directed at children. We do not knowingly collect children's data. Restaurants selling age-restricted products must enable the age-verification feature.

9. Cookies and browser storage

See the Cookie Policy.

10. Changes to this Policy

We will notify registered customers of material changes by e-mail at least 14 days before they take effect.

11. Controller identity and contact

The service is operated by: FOP (sole proprietor) Mykhailo Eduardovych Kulinich, tax ID (RNOKPP) 3264602177, registered address: 21 Nadii Kurchenko St., apt. 4, Kramatorsk, 84300, Donetsk region, Ukraine.

Privacy questions and requests: [email protected]

Last updated: 28 July 2026