Privacy Policy
Last updated: August 20, 2026
Ospee is a QR ordering and table-service platform for cafés and restaurants. This policy explains what information we handle across the Ospee website (ospee.com) and the Ospee apps — the guest menu opened by scanning a table QR code, and the staff apps used by waiters, the kitchen, and managers.
We built Ospee to need as little personal data as possible. Guests order without an account, and payments always happen at the venue — never inside Ospee.
Who this covers
- Guests — people who scan a table QR code and order from the digital menu.
- Staff — waiters, kitchen and managers who sign in to the staff apps with a login provided by their venue.
- Venues — the cafés and restaurants that subscribe to Ospee and manage their menu and service.
Information we handle
- Guests (anonymous): when you join a table you are given a random device token stored in your browser and an auto-generated nickname, used only to group your orders during that table session. We do not ask for or store your name, email, phone number, or payment details. The link between your device and your orders is pruned after the table session closes.
- Staff: a login name, a hashed password, a role, clock-in/out (shift) times, and — if you enable notifications — a push token so we can alert you to new orders and calls. These are provided and managed by your venue.
- Venues: business and contact details, menu content, orders, and the operational analytics shown to the venue.
How we use it
- To run the service — show the menu, route confirmed orders to the kitchen, track order status, answer table calls, and let staff manage the floor and stock.
- To send operational push notifications to staff (new orders, table calls) when enabled.
- To keep the platform secure, prevent abuse, and fix problems.
- To show each venue its own sales and service analytics.
What we do not do
- No advertising and no selling of personal data.
- No cross-device tracking or lasting profiles of individual guests.
- No handling of card or payment data — payment is taken by the venue, outside Ospee.
Service providers
We use a small number of processors to run Ospee: cloud hosting for our servers and database, Google Firebase Cloud Messaging to deliver staff push notifications, Google Cloud Storage for menu images, Google Fonts for typography, and Sentry for error monitoring. They process data only to provide these functions.
Data retention
- The device-to-order link for a guest session is pruned after the session closes or expires.
- Orders and sales records are retained for the venue’s operational and accounting needs.
- Staff accounts and shift records are kept while the account is active and removed at the venue’s request.
Security
Traffic is encrypted in transit (HTTPS). Passwords are stored hashed. Each venue’s data is isolated so one venue can never access another’s.
Your choices and rights
- Staff can turn push notifications off in the app; signing out removes the device’s push token.
- Depending on where you live, you may have rights to access, correct, or delete personal data. Because guest data is anonymous and short-lived, there is usually nothing tied to you personally. For staff or venue data, contact us or your venue.
- To make a request or ask a question, email contact@ospee.com.
Children
Ospee is a tool for hospitality businesses and is not directed at children.
Changes
We may update this policy; the date above shows the latest version. Material changes will be reflected here.
Contact
Questions about this policy: contact@ospee.com.