1. Who we are
TableTop (usetable.top) is a restaurant management and online ordering platform owned and operated by DIGIDARK CORPORATION ("we", "us", "our"). This website is powered by the TableTop platform on behalf of the restaurant named on the home page (the "Restaurant"). For questions about this policy, contact us at support@usetable.top.
Where the Restaurant collects your details (for example when you place an order or make a reservation), the Restaurant is the primary controller of that data and DIGIDARK CORPORATION processes it on the Restaurant's behalf to provide the platform.
2. Information we collect
Visitors and customers
- Order details — items ordered, table number, order value, payment status, and any notes you add to an order.
- Contact details — name and phone number (and email, if provided) when you place an online order or are added to the Restaurant's customer records.
- Technical data — IP address, browser type, and device information collected automatically in standard server logs for security and troubleshooting.
Restaurant staff and account holders
- Account data — username, full name, role, and a securely hashed password (we never store passwords in plain text).
- Security data — login attempt records (by hashed IP address) used to block brute-force attacks, and two-factor authentication settings where enabled.
- Activity data — orders processed, cash drawer entries, and other actions taken inside the system, kept for the Restaurant's business records.
3. How we use your information
- To take, prepare, and deliver your orders and process payments.
- To operate the Restaurant's business: billing, reports, inventory, and staff management.
- To secure the platform: preventing fraud, abuse, and unauthorised access.
- To communicate order updates or service messages (for example via phone or WhatsApp, where you have provided a number for that purpose).
- To comply with legal obligations, including tax and accounting record-keeping.
We do not sell or rent personal data to third parties, and we do not use your data for third-party advertising.
4. Cookies
We use strictly necessary session cookies to keep you logged in and to protect forms against forgery (CSRF). We do not use advertising or cross-site tracking cookies. See our Cookie Policy for details.
5. Third-party services
Some features rely on third-party services, which may process limited data under their own privacy policies:
- Payment gateways — when you pay online, your payment details are handled directly by the payment provider; we never store your card or banking credentials.
- Google Maps — the location map on the home page is embedded from Google, which may set its own cookies when loaded.
- Telegram — the Restaurant may receive operational alerts (such as new-order notifications) through Telegram's messaging service.
- Content delivery networks — fonts, icons, and styling libraries may be loaded from CDNs, which receive your IP address as part of serving those files.
- Hosting providers — the platform and its database are hosted on secure third-party infrastructure.
6. Data retention
Order and billing records are retained as long as required for the Restaurant's business and statutory (tax/accounting) purposes. Login-attempt records are short-lived and automatically expire. Customer records are kept until the Restaurant deletes them or a valid deletion request is fulfilled.
7. Data security
We take reasonable security safeguards as required under applicable law, including hashed passwords, optional two-factor authentication, CSRF protection, login throttling, and role-based access control. No internet transmission is ever completely secure, but we work to protect your data using industry-standard practices.
8. Your rights
Under applicable data protection law, including India's Digital Personal Data Protection Act, 2023 (DPDP Act), you may request:
- Access to the personal data we hold about you;
- Correction of inaccurate or incomplete data;
- Deletion of your personal data, subject to legal retention requirements;
- Withdrawal of consent where processing is based on consent; and
- To nominate another individual to exercise these rights on your behalf, as provided by the DPDP Act.
To exercise any of these rights, email support@usetable.top or contact the Restaurant directly. We will respond within the timelines required by applicable law.
9. Grievance redressal
If you have a complaint about how your data is handled, contact our Grievance Officer at support@usetable.top with the subject line "Grievance — Privacy". We aim to acknowledge complaints promptly and resolve them within the period prescribed under applicable law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or other applicable authority.
10. Children's privacy
The platform is not directed at children. We do not knowingly collect personal data from children without verifiable parental consent as required by the DPDP Act. If you believe a child's data has been collected, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page shows when it was last revised. Continued use of the platform after changes take effect constitutes acceptance of the revised policy.