1. Introduction
SmartServe AI Ltd ("SmartServe", "we", "us" or "our") respects your privacy and is committed to protecting personal information.
This policy explains how we handle personal information when you visit our website, contact us, use the SmartServe platform, make a booking through a SmartServe-powered booking page or receive communications sent using our services.
This policy applies to smartserveai.uk and SmartServe-operated subdomains and services. A restaurant or other venue may also provide its own privacy notice explaining how it uses your information.
2. Who we are
SmartServe AI Ltd is a private limited company registered in England and Wales.
- Legal name
- SmartServe AI Ltd
- Company number
- 16770812
- Registered office
- 2 Henry Street, Cockermouth, United Kingdom, CA13 0AT
- Privacy contact
- gdrimmie@smartserveai.uk
3. When we are a controller or processor
SmartServe is a data controller when we decide why and how personal information is used for our own purposes. This includes business enquiries, customer relationships, platform administration, billing, security and direct communications from SmartServe.
When a restaurant or venue uses SmartServe to manage bookings, venue staff or guest marketing, that venue will generally be the data controller. SmartServe acts as its data processor and handles information according to the venue's documented instructions.
Questions about how a particular venue uses your booking or marketing information should normally be directed to that venue. We will assist the venue in responding where required.
4. Information we collect
Depending on how you interact with SmartServe, we may collect the following information:
- Enquiry information: your name, business name, job role, email address, telephone number and the contents of your enquiry.
- Venue and staff information: names, work contact details, role, venue, account information, access permissions, support requests and account activity.
- Guest booking information: name, email address, telephone number, booking date and time, party size, booking status, booking history and information voluntarily entered into a booking request.
- Marketing information: name, email address, consent status, subscription preferences, delivery status and, where enabled, campaign opens and link clicks.
- Payment information: deposit amount, payment status, transaction reference and limited payment information returned by Stripe.
- Technical and security information: IP address, browser and device information, request timestamps, authentication events, audit records and security logs.
We do not receive or store full payment-card numbers, card security codes or complete card details. Card information is provided directly to Stripe and processed through Stripe's payment systems.
Please avoid including unnecessary sensitive information in free-text booking fields. Where a booking note contains allergy, accessibility or other health-related information, it is handled only as necessary to support the booking and according to the venue's instructions.
5. How we receive information
We may receive personal information:
- directly from you;
- from a restaurant or venue using SmartServe;
- when you make or manage a restaurant booking;
- when a venue creates a staff account for you;
- when you subscribe to or interact with an email campaign;
- from Stripe when it processes a deposit or payment; and
- automatically through essential platform, server and security logs.
6. How and why we use information
We use personal information only where we have a lawful reason to do so. Depending on the circumstances, we may use it to:
- provide, administer and support SmartServe services;
- create and secure venue and staff accounts;
- process, confirm, modify and cancel bookings;
- process deposits and maintain payment records;
- respond to enquiries and arrange product demonstrations;
- send transactional booking and account communications;
- send marketing communications where permitted;
- diagnose faults, prevent misuse and protect our systems;
- improve the reliability and operation of the platform; and
- meet legal obligations and establish, exercise or defend legal claims.
The lawful bases we rely on may include performance of a contract, taking steps before entering a contract, compliance with a legal obligation, consent and our legitimate interests in operating, securing and improving our business.
When SmartServe acts as a processor, the relevant venue determines the lawful basis for processing guest and staff information.
7. Marketing communications
SmartServe may send relevant business marketing to restaurant representatives where they have requested it or where the law otherwise permits us to do so. Every marketing email will provide a straightforward way to opt out.
Restaurants using SmartServe may send campaigns to guests who have chosen to receive their marketing. The restaurant is responsible for ensuring it has an appropriate lawful basis and that its contact list is used lawfully.
Marketing emails may record delivery, opens, link clicks, bounces and unsubscribe requests. This helps the sender understand campaign performance and maintain a healthy mailing list.
You may withdraw consent or unsubscribe at any time by using the unsubscribe link in an email or contacting the relevant sender. We may retain a minimal suppression record so that your opt-out continues to be respected.
10. International transfers
SmartServe's core PostgreSQL booking database is hosted in the United Kingdom.
Some providers we use, including Vercel, Stripe and Twilio SendGrid, operate internationally. Certain technical, payment or email information may therefore be processed or accessed outside the United Kingdom.
Where a restricted international transfer takes place, we use providers offering an appropriate legal transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another safeguard permitted by law.
You may contact us for further information about the safeguards relevant to your information.
11. How long we retain information
We retain personal information only for as long as it is reasonably needed for its purpose, subject to legal, contractual and dispute-related requirements.
- Our standard retention period for guest booking information is six months after the booking takes place.
- Booking information may be retained for longer where a dispute, chargeback, legal claim, safeguarding concern or legal obligation requires it.
- Venue and staff account information is retained while the relevant account or customer relationship remains active and then only for as long as reasonably required.
- Enquiry and support information is retained for as long as needed to respond, maintain appropriate business records and manage any resulting relationship.
- Financial and transaction records are retained for the period required by accounting, tax and other applicable laws.
- Marketing information is retained while the person remains subscribed or until it is no longer reasonably required. A minimal suppression record may be retained after an unsubscribe request.
- Security and technical logs are retained only for as long as necessary for security, troubleshooting and legal compliance.
When SmartServe acts as a processor, information may also be returned or deleted according to the relevant venue's lawful instructions and our agreement with that venue.
12. How we protect information
We use appropriate technical and organisational measures designed to protect personal information from unauthorised access, alteration, disclosure, loss or destruction.
These measures include access controls, authentication, role-based permissions, secure hosting, encryption in transit, logging, backups and limiting access to people and providers who require it.
No internet service can guarantee absolute security. You should protect account credentials and contact us promptly if you suspect unauthorised access.
13. Your data-protection rights
Depending on the circumstances, UK data protection law may give you the right to:
- request access to your information;
- ask us to correct inaccurate or incomplete information;
- request deletion of your information;
- ask us to restrict how information is used;
- object to certain processing;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent; and
- object at any time to the use of information for direct marketing.
These rights are not absolute and may depend on why the information is being processed.
To make a request, email gdrimmie@smartserveai.uk. We may need to confirm your identity before completing a request.
If your request concerns a particular restaurant, we may refer the request to that venue because it is the relevant data controller.
14. Complaints
Please contact us first if you have concerns about how your information has been handled so that we can try to resolve them.
You also have the right to complain to the Information Commissioner's Office, the United Kingdom's data-protection regulator.
Visit ico.org.uk/make-a-complaint.
15. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The latest version will be published on this page with an updated revision date.