Data & GDPR
The guest's data is the guest's.
We collect the minimum personal data we need to operate the service. Card data lives entirely with Stripe and Viva Wallet, who are PCI-DSS Level 1. Data export and deletion are available by writing to privacy@tabbpay.com, and we respond within the GDPR-required 30 days.
—
What we hold, and how you control it.
Guest-side, we record the order content, the device that placed it, and the IP address for fraud prevention. Operator-side, we store the account details you give us at sign-up and the operational records (menu, staff, orders, tips, reviews) you generate while running the venue. Payment card details never touch our servers.
Operators are the data controller for their venue's data. TabbPay is the processor. You can export or delete your data at any time by writing to privacy@tabbpay.com. We will respond within 30 days as required by GDPR Article 12(3).
What this means in practice
Minimum data
We collect what the service needs to work, and nothing for re-marketing. No guest profiles across visits, no segmentation we did not need.
EU-region storage
Data lives in AWS Frankfurt (eu-central-1). Backups stay in the EU. Sub-processors operate under Standard Contractual Clauses.
No card data
Stripe and Viva Wallet handle every card number, CVC, and 3-D Secure step. We see an amount and a status.
Export and deletion
Email privacy@tabbpay.com to export your venue's data or request deletion. We respond within 30 days. Financial records required by Greek tax law are retained anonymised for 6 years.
Full transparency
The Privacy Policy lists every category of data, every sub-processor, and every retention period.