Legal
Privacy Policy
Effective 6 October 2026 · Sofra by TablixAI
This policy explains what personal data Sofra, provided by TablixAI (“we”, “us”), collects, why, who we share it with, and the choices you have. It covers our website, the Sofra portal and the Sofra restaurant platform.
1.Who is responsible for your data
- For your Sofra account (name, email, company, country, phone, billing relationship) we are the controller.
- For data a restaurant enters into Sofra about its guests, customers and staff (orders, reservations, contact details, staff records), the restaurant is the controller and we are its processor. We handle that data only on the restaurant's instructions. If you are a guest or staff member and want to exercise your rights, please contact the restaurant first.
2.What we collect
- Account details: name, email address, password, company name, country, phone number (with country code), and the date you accepted our terms. Passwords are stored only as salted hashes, never in plain text.
- Restaurant data: restaurant name, domains, plan and settings, and the operational data a restaurant enters: menus, tables, orders, inventory, customers, reservations, staff accounts and roles.
- Billing data: payments are processed by Paddle. We receive and store identifiers and status (customer and subscription IDs, plan, billing cycle, renewal date, payment status), not your card number.
- Usage and technical data: IP address, browser and device type, pages and actions, and error and security logs.
- Communications: messages you send to support.
3.How we use it
- To create your account, run the portal and operate your restaurants (contract).
- To take payments, send invoices and manage your subscription (contract and legal obligations).
- To keep Sofra secure, prevent abuse and fix problems (legitimate interests).
- To send service messages such as sign-in, billing and policy notices (contract and legitimate interests).
- To understand usage and improve the product, using aggregated or limited data (legitimate interests).
We do not sell your personal data and we do not use it for third-party advertising.
4.Who we share it with
- Paddle, our payment provider and merchant of record, to process payments, tax and invoices.
- Cloud hosting providers that run Sofra's servers and databases for us.
- Professional advisers and authorities where required by law or to protect our rights.
- A successor, if Sofra is part of a merger or sale, with notice to you.
These providers may only use data to provide their service to us. Data may be processed in countries other than your own. Where that happens we rely on appropriate safeguards, such as standard contractual clauses.
5.Cookies
We use cookies that are needed to keep you signed in and to protect your session. We do not use advertising cookies. Our payment provider may set its own cookies while its checkout is open. You can block cookies in your browser, but you will not be able to sign in without the essential ones.
6.How long we keep data
- Account and restaurant data is kept while your account is active.
- After an account is closed we keep its data for 90 days, then delete it on request or automatically.
- Billing and tax records are kept for as long as the law requires.
- Security and error logs are kept for a limited period.
7.Security
We protect data with encrypted connections (HTTPS), hashed passwords, separation between restaurants, and role-based access control. No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.
8.Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal data, to object to certain processing, and to withdraw consent. To exercise these rights over your account data, contact us using the details below. You can also complain to your local data protection authority.
9.Children
Sofra is for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children.
10.Changes to this policy
We may update this policy. For material changes we will notify you by email or in the app at least 30 days before they take effect. The effective date is at the top of this page.
11.Contact
Privacy questions and requests: the support contact shown in the Sofra app. See also our Terms of Service.
