Privacy Policy

Last updated: 2026-08-14

This Privacy Policy explains how aimaitred (“we”, “us”) collects, uses and protects personal data when a venue uses our hospitality platform and when a guest scans a QR code to view a menu or place an order. The companies responsible for the service are listed at the bottom of this page.

1. Who we are

aimaitred is an AI-powered restaurant menu and hospitality platform operated by the companies listed under “Companies & registered offices” below. Depending on your region, the relevant company acts as the data controller (for guest data, the venue is usually the controller and we act as processor).

Which company that is depends on where the venue is: for venues in the United States it is einsOne LLC, and for venues everywhere else it is Salfi Ltd. Where this policy says “we”, it means whichever of those two is responsible for your venue.

2. Data we collect

Venue accounts: name, email, password (hashed), venue details, billing information and the menu/operational content you upload.

Guests: we deliberately require no guest accounts. We ask for no name, email address or phone number to view a menu or order. We store a randomly generated device session identifier, your chosen language, and the dietary and allergen preferences you select, so the menu can be personalised. If you place an order, we store the items, quantities and table reference. Your dietary and allergen choices are held against that device session identifier only and are never linked to your name.

Reservations and the venue's guest book: if you book a table, or a venue records you as a guest, we hold on that venue's behalf the name, email address and phone number you give, the booking itself, and any notes the venue's own staff write about the visit. Bookings that share a phone number or email address are grouped into one guest record so the venue recognises a returning diner. The venue decides what goes into that record and is the controller of it; we store and process it as its processor and do not use it for our own purposes.

Technical data: IP address, device and browser type, and basic usage analytics needed to run and secure the service.

We do not process card or bank details for guests: payment is settled in person at the venue.

3. How we use data

To provide the menu, ordering, bill-splitting, AI waiter and venue-management features.

To personalise the menu to your language, diet and allergen choices.

To operate, secure, debug and improve the service.

To send transactional emails (e.g. receipts, reservation reminders) and, to venues, service notices.

To comply with legal obligations.

4. Legal bases (GDPR)

Where the GDPR applies we rely on: performance of a contract (providing the service), legitimate interests (security, improvement, fraud prevention), consent (where required, e.g. non-essential analytics), and legal obligation.

Allergen and dietary preferences say something about your health, so the UK GDPR treats them as a special category of data. We process them only on your explicit consent under Article 9(2)(a), given when you choose them in the guest menu. You do not have to provide them: the menu works without them and you can skip the step. You can reopen your preferences from the menu at any time to change or remove them, which withdraws that consent for the future.

5. Sub-processors & sharing

We share data only with vetted providers acting on our instructions: cloud hosting and database (Supabase, Vercel), AI processing (OpenAI), transactional email (Resend), error and performance monitoring (Sentry), cookieless usage analytics (Vercel Analytics and Speed Insights), and venue subscription billing (PayPal). PayPal is used only to collect a venue's subscription fee; guests never pay through it. We do not sell personal data. We may disclose data where required by law.

This list is the complete set of sub-processors we use. We will update it here before adding a new one, and venues may object to a new sub-processor as set out in the Service Agreement.

6. Cookies & local storage

We use strictly necessary local storage to remember your device session, language and theme. We do not use third-party advertising cookies.

7. Data retention

Guest order data is retained only as long as needed to operate the venue’s service and meet legal/accounting duties, then deleted or anonymised. Venue account data is kept for the life of the account and a limited period afterwards.

An automated job runs every day and enforces this: a guest device session and the dietary and allergen preferences attached to it are deleted a month after that guest's last visit, and order records are stripped of the device session that placed them after 24 months, leaving anonymous sales history for the venue’s accounts. Reservation names, emails and phone numbers are cleared on the same 24-month basis.

8. International transfers

Data may be processed in the UK, EU and the United States. Where data leaves your region we rely on appropriate safeguards such as Standard Contractual Clauses.

9. Your rights

Subject to your local law (including the EU/UK GDPR and, in Colombia, Law 1581 of 2012 on Habeas Data), you may request access, correction, deletion, restriction, portability, and object to certain processing. You may also lodge a complaint with your supervisory authority.

To exercise any right, contact us at office@aimaitred.com.

10. United States: state privacy rights

This section applies if you are a resident of California or another US state with a comprehensive privacy law. It sits alongside the rest of this policy rather than replacing it.

Categories we collect, as those laws name them: identifiers (a device session identifier, and for a reservation the name, email address and phone number you give); commercial information (orders and bookings); internet activity (basic usage analytics); and, where you choose to give them, allergen and dietary preferences, which California treats as sensitive personal information because they concern health.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months. We run no advertising cookies and no advertising pixels, so there is nothing to opt out of, and we therefore publish no “Do Not Sell or Share My Personal Information” link.

We use sensitive personal information only to provide the feature you asked for, which is filtering a menu to your allergens. We do not use or disclose it to infer characteristics about you, so the right to limit its use has nothing to restrict.

Your rights: to know what we hold and how it is used, to receive a copy, to correct it, to delete it, and not to be treated worse for exercising any of them. Ask at office@aimaitred.com; an authorised agent may ask on your behalf. We will verify a request against the data we hold, which for a QR-menu guest usually means the device session in question, and respond within the period the law allows.

Where a venue records you in its own guest book, that venue is the business making the decisions and we act as its service provider: we will pass your request to the venue and act on its instruction.

11. Children

The service is intended for use by adults and venue staff. It is not directed at children, and we do not knowingly collect data from children.

12. Security

We use encryption in transit, access controls and row-level security. No system is perfectly secure, but we work to protect your data and to notify the relevant parties of any breach as required by law.

13. Changes

We may update this policy. Material changes will be reflected by the “Last updated” date above and, where appropriate, notified to venues.

Contact

For any question about this document or your data, write to us at office@aimaitred.com.

Companies & registered offices

Client office

ABC Austrian Business Company Limited

99a High Road, Beeston

Nottingham, NG9 2LH

United Kingdom

Registered office

Salfi Ltd · Co. No. 17208471

66 Paul Street

London, EC2A 4NA

United Kingdom

US entity

einsOne LLC

16192 Coastal Highway

Lewes, Delaware 19958

United States

Latin America entity

BRUECKE S.A.S. · NIT 900.819.271-0

Calle 29C No. 5-21, Barrio el Cortijo

Sincelejo, Sucre

Colombia

This document is published in several languages for convenience. If there is any conflict, the English version prevails.