Privacy Policy
1. Overview
Tabble ("we", "us", or "our") operates a venue-based social ordering and community platform available via mobile application and web ("the Service"). This Privacy Policy explains what personal data we collect, how we use it, and what rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law.
By using Tabble, you agree to the collection and use of information described in this policy. If you do not agree, please do not use the Service.
2. What We Collect
2.1 Account Information
- Mobile number — used for authentication via OTP. We do not store passwords.
- Display name — chosen by you, shown in the community and to venue staff.
- Profile photo — optional, uploaded by you.
2.2 Order and Transaction Data
- Items ordered, quantities, special requests, and order timestamps.
- Total spend per order (used to calculate loyalty points).
- Payment confirmation status (we do not store full card or UPI details — payments are processed by our third-party payment provider).
2.3 Venue Visit History
- Which Tabble-enrolled venues you have visited, and when.
- Loyalty point balances earned and redeemed at each venue.
2.4 Community Activity
- Posts, photos, comments, and poll responses you create inside a venue's community feed.
- Reactions and interactions with other community members' content.
2.5 Spark Profile (Optional)
- If you opt in to Spark, we additionally collect: profile photo (can differ from main photo), interests or tags you choose, and your opt-in consent timestamp.
- We record which venues you have marked yourself as "present at" for Spark matching purposes.
2.6 Device and Technical Data
- Device type, OS version, app version, and crash reports — for debugging and service improvement.
- IP address — for fraud prevention and security logging.
- We do not use persistent advertising identifiers.
3. Why We Collect It
Every piece of data we collect has a specific purpose tied directly to delivering the Service:
- Mobile number — secure, passwordless authentication.
- Order history — to process your order, relay it to the venue, and calculate loyalty points accurately.
- Venue visit history — to display your loyalty balance and enable community membership at venues you actually visit.
- Community content — to display your posts within the venue community you posted them in.
- Spark data — to facilitate opt-in social discovery between verified venue visitors.
- Technical data — to keep the app stable, secure, and fast.
We do not use your data for targeted advertising. We do not build advertising profiles. We do not share data with marketing partners.
4. How We Store and Protect Your Data
Your data is stored on servers located in India or within jurisdictions that provide adequate data protection as recognised under Indian law. We apply the following controls:
- Encryption in transit (TLS 1.2+) and encryption at rest (AES-256).
- Access controls limiting who on our team can view personal data — only engineers with a specific operational need.
- Regular security reviews of our infrastructure and application code.
- Separation of payment processing — handled by a certified third-party provider; we never store raw financial credentials.
No method of electronic storage is 100% secure. If we become aware of a data breach that affects your rights, we will notify you and the relevant authority in accordance with the DPDP Act, 2023.
5. Data Sharing and Disclosure
We do not sell your data. We share data only in these limited, necessary circumstances:
5.1 With Venue Partners
When you place an order, the venue receives your display name, table number, and order details. Venues do not receive your mobile number, IP address, or Spark data.
5.2 With Service Providers
We work with carefully selected third-party providers for payment processing, cloud hosting, and error monitoring. These providers process data only on our instructions and are bound by data processing agreements.
5.3 Business Transfers
If Tabble is acquired, merged, or its assets are transferred, your data may be part of that transfer. We will notify you via in-app notice or email before any such transfer takes effect, and you will have the opportunity to delete your account.
6. Government and Law Enforcement
We review every such request for legal validity. We will resist requests that are overly broad, procedurally deficient, or not supported by proper legal authority.
7. Data Retention
- Active accounts — data is retained for as long as your account remains active.
- Deleted accounts — personal data is deleted or anonymised within 30 days of account deletion, except where retention is required by law (e.g., financial records for 7 years under Indian accounting law).
- Order data — retained for up to 3 years for dispute resolution and statutory compliance, then permanently deleted.
- Spark data — deleted immediately upon opting out of Spark, or upon account deletion.
- Crash logs and technical data — retained for 90 days then automatically purged.
8. Your Rights
Under the DPDP Act, 2023 and applicable Indian law, you have the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Erasure (Delete Account) — request deletion of your account and associated personal data. You can do this directly inside the app under Settings → Account → Delete Account. Deletion is processed within 30 days.
- Opt out of Spark — withdraw consent for Spark at any time via Settings → Spark → Disable. Your Spark data is deleted immediately.
- Grievance redressal — raise a complaint with our data officer (see Section 12 below). We will respond within 72 hours and resolve within 30 days.
- Nominate a representative — designate another person to exercise rights on your behalf in accordance with the DPDP Act.
To exercise any of these rights, contact us at tabblecustomers@gmail.com.
9. Spark Feature — Additional Notice
Spark is an opt-in social discovery feature. It enables users who are present at the same venue to indicate mutual interest and, if both parties consent, make a connection.
- Spark is available only to users who are 18 years of age or older.
- Participation requires an explicit opt-in; it is never enabled by default.
- Your Spark visibility is limited to other opted-in users at the same venue during overlapping visits.
- A connection is only established when both parties indicate interest — no one-sided reveals.
- You can block any user at any time. Blocked users cannot see you on Spark.
- You can opt out of Spark entirely at any time. All Spark data is deleted immediately on opt-out.
10. Children
Tabble is not directed at children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately at tabblecustomers@gmail.com and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification at least 14 days before the changes take effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
We will keep prior versions of this policy accessible so you can review what changed.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:
- Email: tabblecustomers@gmail.com
- Instagram: @tabble.in
- Location: India
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Information Technology (Amendment) Act, 2008.