Privacy Policy
Version 1.0 · Effective 6 October 2026
This Privacy Policy explains how TablixAI ("TablixAI", "we", "us") collects, uses and protects personal data when you visit the Sofra website or use the Sofra restaurant management platform ("Sofra", the "Service").
1. Who we are and our role
Sofra is a restaurant management platform built and operated by TablixAI. For personal data about people who create and manage a Sofra account (for example restaurant owners, managers and staff users), TablixAI is the data controller.
Restaurants that use Sofra decide what information about their own guests, customers and employees is entered into the platform. For that data, the restaurant is the controller and TablixAI acts as a processor on the restaurant’s behalf and processes it only to provide the Service and on the restaurant’s documented instructions.
2. Information we collect
Depending on how you use Sofra, we may collect:
- Account and contact data: name, email address, phone number, company and country, job role, and the credentials you use to sign in.
- Workspace data you enter: restaurant and branch details, menus, prices, tables, orders, inventory, suppliers, staff records, schedules, reservations and reports.
- Customer data entered by restaurants: guest names, contact details, order history, preferences, reservations, feedback and loyalty information.
- Billing data: your plan, billing cycle, and invoice and transaction references. Card and payment details are collected and processed by our payment provider, not by us (see below).
- Usage and device data: pages and features used, log data, IP address, browser type and approximate location, collected to run, secure and improve the Service.
- Communications: messages you send us, support requests, and your marketing preferences.
3. How we use information
- To provide, operate, secure and support the Service, including authentication, order and inventory processing, reporting and notifications.
- To provide AI features, such as answering questions about your own business data, forecasting and anomaly alerts.
- To process subscriptions, send invoices and receipts, and manage plan changes.
- To communicate with you about your account, security, changes to our terms, and product updates.
- To send marketing communications where you have opted in or where permitted by law. You can opt out at any time.
- To prevent fraud and abuse, enforce our terms, and comply with legal obligations.
- To analyse and improve the Service using aggregated or de-identified information.
4. Legal bases (where GDPR or similar laws apply)
We rely on: performance of a contract (providing the Service you signed up for); legitimate interests (securing and improving the Service, preventing abuse); consent (marketing and optional cookies, which you can withdraw); and legal obligation (tax, accounting and regulatory requirements).
7. Security
We use technical and organizational measures designed to protect personal data, including tenant isolation so that each organization’s data is kept separate, role-based access controls, encrypted connections, and audit logs. No system is completely secure, so please protect your credentials and tell us promptly if you suspect unauthorized access.
8. Data retention
We keep personal data for as long as your account is active and as needed to provide the Service. Downgrading or moving to the Free plan does not delete your data.
After an account is closed we keep workspace data for 90 days, then delete it on request or automatically, unless we must keep certain records for legal, tax or security reasons (for example billing records).
9. International transfers
Sofra is used by restaurants in many countries and our providers may process data in countries other than your own. Where required, we use appropriate safeguards, such as standard contractual clauses, for international transfers.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal data, to object to certain processing, to withdraw consent, and to lodge a complaint with your data protection authority.
- Account holders can exercise most rights from within the app or by contacting us.
- If you are a guest or customer of a restaurant that uses Sofra, please contact that restaurant first, as it controls your data. We will assist the restaurant in responding to your request.
11. Children
Sofra is a business service and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new effective date and, for material changes, notify account owners by email or in the app.
13. Contact us
For privacy questions or to exercise your rights, contact TablixAI using the details below.
Web: tablixai.com
See also our Terms and Conditions.
