Last updated: 20 July 2026
Privacy Policy
This policy describes what information EatBot processes, why we process it, and the protections we currently apply. It reflects how the product is built today. This is operational information, not legal advice, and not a certification of compliance with any specific regulation.
1. Who this policy applies to
This policy covers two audiences:
- Restaurant account holders who sign up for EatBot to manage a Digital Menu and Restaurant Website.
- Visitors of the public restaurant pages that EatBot hosts on behalf of restaurants.
2. Information restaurant account holders provide
When you create and use an EatBot account, you may provide:
- Your name or display name, where applicable
- Your email address
- Restaurant information such as name, location, address, description, and cuisine
- Phone number and other contact information
- Menu content: categories, items, prices, descriptions, variants, add-ons, and images
- Website content and gallery images
- Social media links you choose to display
- Payment reference information and payment proof uploads (screenshots or receipts) when submitting a payment request
- Any messages you send to us when requesting help or support
3. Authentication
EatBot supports email/password authentication and Google sign-in. When you sign in with Google, Google confirms your identity to EatBot; EatBot does not receive your Google password. Some authentication information is handled by the authentication provider that hosts our identity service.
4. Public analytics on restaurant pages
EatBot processes privacy-conscious usage information about the public Digital Menu and Restaurant Website pages we host on behalf of restaurants. This currently includes:
- Digital Menu page views
- Restaurant Website page views
- A source classification (QR, direct, referral, or internal)
- Approximate anonymous visitor counts
- A device class such as mobile, desktop, tablet, bot, or unknown
- The referring hostname where available
- Categories of customer actions taken on public buttons, such as WhatsApp, Call, Directions, and supported social buttons
What EatBot does not intentionally store in analytics
- No raw visitor IP address is intentionally stored in EatBot analytics tables.
- No full raw browser user-agent string is intentionally stored in EatBot analytics tables.
- No phone number, WhatsApp destination, email address, social handle, full destination URL, map coordinates, or message text is stored as part of customer-action analytics. Only the category of action is recorded.
Privacy protections we apply today
- Anonymous visitor identifiers are hashed server-side before storage.
- Analytics hashing uses a rotating salt so identifiers are not comparable across long time windows.
- Approximate unique-visitor metrics are estimates and may not equal real people.
- Requests classified as bots are excluded from most reported metrics.
EatBot does not claim complete anonymity, zero data collection, perfect bot detection, or perfect security. Information sent by a browser (for example an IP address) is unavoidably visible to infrastructure providers while a request is in flight, even when EatBot itself does not store it.
5. Why we use this information
- To operate EatBot and provide the features you signed up for
- To authenticate your account and keep it secure
- To publish and host the restaurant content you configure
- To administer subscriptions, verify manual payments, and issue approval or rejection decisions
- To detect abuse, secure the service, and troubleshoot problems
- To produce aggregate analytics that help restaurants understand engagement on their public pages
- To improve EatBot as a product and prioritize new features
- To send in-product notifications relevant to your account (for example payment or subscription events)
6. Service providers
EatBot relies on third-party service providers to operate, including hosting, database, authentication, and email infrastructure. These providers process information on our behalf under their own terms. Public buttons on restaurant pages may open third-party destinations chosen by the restaurant, and those destinations are governed by their own privacy practices.
7. Public restaurant content
Restaurant content that a restaurant chooses to publish (Digital Menu content, Restaurant Website content, images, contact links, and QR-linked destinations) is intentionally publicly accessible on the internet after publication. Please do not upload confidential information you do not want to be publicly viewable.
8. Data retention
EatBot retains account, restaurant, menu, website, subscription, and payment records for as long as your account is active or as long as needed to provide the service and meet operational, administrative, and security needs. Analytics data may be kept for a reasonable period to support historical reporting.
Payment proof uploads are stored only for administrative verification of the corresponding payment request.
9. Data sharing
EatBot does not sell your personal information. We share information only with service providers who help us operate the service, where required by law, or with your permission (for example when you publish restaurant content).
10. Your requests and account deletion
You can ask EatBot to access, correct, or delete information associated with your account by contacting us at support@eatbot.app. You can also delete your account at any time from Dashboard → Settings → Danger zone. When you delete your account:
- Your public Digital Menu and Restaurant Website stop being available immediately.
- Menu content, restaurant profile, website content, QR configuration, gallery, and logo are removed.
- Any active subscription is cancelled.
- Payment requests, payment proofs, subscription events, and related audit records may be retained in anonymised form for legal, accounting, dispute-resolution, and fraud-prevention purposes. Retained records cannot be used to reactivate the deleted restaurant or make it publicly visible.
- Full removal of your sign-in record may be completed on a delayed basis; contact support if you want confirmation.
11. Security
EatBot uses reasonable technical and organisational measures to protect information, including access controls at the database level, restricted administrative access, and hashing of anonymous visitor identifiers. No online service can be guaranteed to be fully secure. Please keep your account credentials confidential and let us know if you believe your account has been compromised.
12. Children
EatBot is intended for restaurant operators and their teams. It is not directed to children, and we do not knowingly collect information from children.
13. International processing
Depending on where our service providers operate, information you provide may be processed in countries other than the one you live in. Applicable protections continue to apply where required by law.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page.
15. Contact
For privacy questions or requests, contact us at support@eatbot.app.