Privacy policy
Last updated: 17 September 2026
This document explains what is kept when you use Qder.ai — as a diner, as someone booking a table, or as a business — who sees it, where it is sent, how long it stays and what you can do with it. We wrote it to be understood without a lawyer, and every line in it was checked against what the code actually does.
This English text is provided for convenience. The Hebrew version of this document is the one that governs: מדיניות פרטיות.
1. Who is responsible for the information
Qder.ai is operated by Qder (an exempt dealer; the dealer number is given to businesses in the agreement and on the receipt) ("we"). We operate the platform; the restaurant you are sitting in is an independent business, and it owns the information about your order, your visit and your booking.
In the language of the Israeli Protection of Privacy Law, 5741-1981 (as amended by Amendment 13): for orders, visits and bookings the restaurant is the controller of the information and we hold and process it on its behalf; for personal accounts, business accounts, applications to join and security records, we are the controller. In the language of the GDPR, to the extent it applies: the restaurant is the controller and we are the processor for the order, and we are the controller for the account.
2. Diners: what is kept
The default is that you are anonymous. You can scan a code, ask, order and pay without giving a name, a phone number or an email address. What is kept in every case:
| What | Why | How long |
|---|---|---|
| The table session — the branch, the table number, when it opened, and the last time the phone spoke to the server | To know which table an order belongs to, and to flag in the panel a table whose phone has been silent for three quarters of an hour with no open bill | 4 hours, then deleted |
| The order — dishes, quantities, prices, when it was sent and when it was served | To pass it to the kitchen, produce a bill, and measure for the restaurant how long serving takes | Kept by the restaurant as a sales record, see keeping data |
| An allergy note or a request to the kitchen, if you wrote one | To pass it to the kitchen word for word | With the order |
| How you asked for each dish to be prepared — how well done, how spicy, extras, and a free request for a dish ("no onion") if you wrote one | To pass it to the kitchen with the dish, and to price a paid extra if you chose one | With the order, as part of the dish line |
| The most recent messages in the conversation with the digital waiter, tied to the table session (not to you) | So the digital waiter remembers what was said a moment ago, and so that words cannot be put in its mouth from the browser | 24 hours, then deleted from the server |
| The conversation log — what was asked and what was answered, after email addresses, phone numbers and long numbers (identity, card) have been replaced with a generic marker; with no name and no link to an account | To improve the digital waiter: to see which questions it answers badly, and to let a manager correct it. Repeated failure patterns are also examined across restaurants, but only after the name, the restaurant, the chain and the dish names have been replaced with a generic marker — what is kept from that examination is the pattern, not the conversation and not the restaurant. The conversation itself is never given to another restaurant, and is not used to train models | 90 days, then deleted. The log itself carries no account identifier; while the table session you opened as a signed-in diner exists (up to 4 hours) the rows can be tied to it, so they are included in your data export and deleted with your account. Anyone with an account can switch this off on the account page |
| Your chat history — the concierge conversations and the tables as shown in the app and on the site, tied to your account | So you see the same conversations on every device and can continue one that stopped. It is yours alone: no restaurant sees them, and they are not used to improve the waiter or to train models | 12 months from the last message, then deleted. Kept only for signed-in diners, and only while the "keep my chats" switch in settings is on (the default); switching it off deletes what was kept. You can delete one chat or all of them from the menu; they are included in your data export and deleted with your account |
| An email address, if you entered one at payment to receive a confirmation | To send a payment confirmation, and to notify you if the restaurant issued a refund | 400 days with the visit detail, then removed from the payment record |
| A link to pay part of the bill, if you shared one | To let someone sitting with you pay their share | The link is signed and is not stored; it expires after 6 hours |
| IP address | Rate limiting only — to prevent guessing table codes, mass form submission and repeated sign-in attempts | Until the end of the limiting window (up to a quarter of an hour); it is not written to a log and not kept with the order |
If you opened a personal account
An account is a choice, not a condition. If you opened one, these are kept as well: email address, name, phone number (required, so the restaurant can reach you if something about the order goes wrong; it is given only to the restaurant you are sitting in), date of birth (used solely so that alcoholic drinks are not sold through the system to anyone under 18; it is not given to the restaurant and is not used for anything else), and whatever you wrote in the allergies and dietary preference fields. Your password is not kept by us at all — identity is managed at Supabase, where it is stored as a one-way hash. Your visits are linked to your account so you can see them on the account page.
Signing in with Google or Microsoft. If you chose to sign in through them, the provider verifies you and passes to us, through Supabase, the email address and the name registered with it. That is all that arrives: we have no access to your mailbox, your contacts or your files, and we publish nothing on your behalf. If you already had an account with that address, the sign-in reaches that same account.
Passkeys. If you added a passkey, your device holds the private key and Supabase keeps only the public key and a friendly name for the device. Your fingerprint or face never leaves the device and never reaches us.
Health information. What you write in the allergies field is information about your health, and under Israeli law that is information of special sensitivity. It is kept only in order to be told to the kitchen and to the digital waiter, it is sent to the restaurant you are sitting in and to no other restaurant, and you can delete it from your account at any moment.
If you booked a table
A booking requires a name and a phone number, so that whoever is at the door knows whose table it is and can call if something has changed. Kept: the name, the phone number, the number of diners, the time, a note if you wrote one, and the link to your account. The booking confirmation and any cancellation notice are sent to the account's email address. The name and phone number are deleted 90 days after the booking date; the fact that there was a booking, and whether you arrived, stays with the restaurant for a further year as an operational figure, without a name.
3. What is not kept
- Card details. Payment happens on the restaurant's payment page, at its own processor. A card number never passes through us and we never see it at any stage. All we keep is the transaction amount and the reference the processor returned.
- Location. We do not ask for access to GPS and we do not collect location. The code stuck to the table is what identifies where you are.
- Tracking or advertising cookies. There are none on this site. The only measurement is Cloudflare's page-view count, with no cookie and no device identifier, and you can switch it off in the settings panel in the cookie policy — switching it off genuinely removes it from the page rather than politely asking it to stop.
- A behavioural profile. We do not build a profile, we do not score you, and we make no automated decisions with legal significance about you.
4. Businesses: what is kept
- The application to join. The business name, company or dealer number, city, contact name, email, phone, and any document attached (for example a certificate of incorporation or a business licence). Documents are kept in a private folder at Supabase, with no public address, and are accessible only to our team for the purpose of reviewing the application. They are deleted 90 days after the decision; the application details themselves remain as the record of how the account came to exist.
- Staff accounts. Name, email, phone if given, role, the branch or chain, and whether two-factor authentication is enabled (the authentication secret is kept by us). The password is managed at Supabase.
- Payment processor details. The access keys for the processor account the business entered. They are kept in the database, used only by the server, and never returned to the browser — the panel shows only which fields were filled in.
- Operating data. Menu, prices, hours, tables, orders, visits, refunds issued (amount, reason, who issued it) and the branches' bookings, and the number of diners who spoke with the digital waiter (for billing, without the diner's identity).
- What is sent to the business assistant. Messages, images and files an employee sent to the assistant are passed to the model and are not kept by us after the reply; the proposals the assistant created are kept until they are approved or rejected.
- Subscription billing. Transaction accounts and receipts for the business are produced at iCount, our accounting provider, where the business name, company or dealer number, the billing contact's name and email, and the documents themselves are kept. Payment is by bank transfer only; the business's bank account details are not given to us. There is no card payment or standing order for the subscription fee, and we do not ask for card details.
5. Who the information reaches
The restaurant you are sitting in
The order, the allergy note and the table number reach that branch's kitchen screen. Another restaurant — even another branch of the same chain — does not see them. The chain manager sees the figures for all of their branches, without diners' names, except for a bill left unpaid (see the next paragraph). If you ordered while signed in to an account, the branch manager sees, on the screen for the table you are sitting at only: your name, your phone number if you gave one, and the allergies and preferences saved in your account. That serves one purpose — so that whoever comes to the table knows what not to bring. The information disappears from the screen when the table is cleared. An email address you entered at payment is kept in the restaurant's payment record, in order to send a confirmation and to notify you of a refund. For a booking, the restaurant sees the name and phone number you gave — and branch staff see in the panel only that day's bookings, not the whole booking diary.
A bill that was not paid
If you left the table with the bill still open, your contact details — the name, phone number and email address on your account, and an email address you typed on a payment page that was not completed — are shown to the branch and to the chain's management, so that they can contact you and collect what is owed. That is the only purpose, and the legal basis is the restaurant's legitimate interest in collecting a debt. The details are not stored anywhere else: they are read from your account at that moment, shown only while the bill is open, and leave the screen as soon as it is settled or voided. Ordered without an account and without starting a payment? We have nothing to give, and we will give nothing. The business undertakes to us in the engagement agreement to use these details for collecting that bill alone, and not for marketing.
Our sub-processors
| Who | What they do | What reaches them | Where |
|---|---|---|---|
| Cloudflare | Hosts the site, the server and the database, counts page views (Web Analytics, with no cookies and no device identifier; can be switched off), and protects our internal operations console (Cloudflare Access; applies to Qder staff only, not to diners and not to restaurants) | Everything kept in the system; for the page count — the page address, where you arrived from, the browser type and load timings, with no identifier | The database is in western Europe; the network is global |
| Supabase | Identity management: passwords and their reset, signing in with Google and Microsoft, passkeys (WebAuthn); and storage of the documents attached to applications | Email and password for accounts; the public key of a passkey; business documents | Frankfurt, Germany |
| Google and Microsoft (only if you chose to sign in through them) | Verify your identity at sign-in | They see that you asked to sign in to Qder.ai; what reaches us is your name and email address, and nothing more | Per the provider's policy |
| OpenAI | Runs the language model behind the digital waiter and the business assistant | See use of artificial intelligence: the message, the menu, what has been ordered, and if you have an account: the allergies, the previous visit to that chain, and whether you are under 18 (not the date itself). Not a name, email, phone number or IP address | United States |
| Cloudflare (email service) and Resend (backup) | Send our email | The email address and the content of the message: booking confirmation, cancellation, application approval, a link to set a password, a payment confirmation and a refund notice to the address you entered | Cloudflare: global network; Resend: United States |
| The restaurant's payment processor (PayPlus, Hyp, Grow, Cardcom or Tranzila, depending on which the restaurant works with) | Takes the payment | What you type on its page, and — if you are signed in to an account, or entered an email at payment — your name and email address, so that the restaurant's payment page and receipt are in your name. Without an account only the table number is passed. Subject to its policy and the restaurant's, not ours | Israel |
| iCount (our accounting provider) | Produces and sends businesses the transaction accounts and receipts for the subscription fee | The business name, company or dealer number, the billing contact's name and email, the account lines and the documents. Nothing from diners and nothing from orders | Israel |
None of them is permitted to use the information for its own purposes. We do not sell information and we do not pass it to advertisers. We will give information to a competent authority only where the law requires us to.
6. Transfer of information outside Israel
Information is stored in Europe; conversations with the digital waiter are processed at OpenAI in the United States, and email is sent through Cloudflare, with Resend in the United States as a backup. The transfer is necessary in order to provide the service you asked for, and it is made to providers contractually bound to information security and to not using it for their own purposes, in accordance with the Protection of Privacy Regulations (Transfer of Information to Databases Abroad), 5761-2001.
7. Age
A personal account opens from the age of 14. Anyone younger can order without an account, and we do not knowingly collect identifying information from children under 14; if we learn that such an account was opened, we will close it. Alcoholic drinks are sold only to those who have turned 18: the system will not add them to an order for anyone whose account birth date says they are not yet 18, and it marks every order containing alcohol for the restaurant's staff to check identification. The actual check is the restaurant's, as the seller.
8. Your rights
You have the right to know what is kept about you, to receive a copy, to correct it and to delete it. A full copy downloads as a file in one click, for diners and businesses alike (a business receives all of the chain's or the branch's data, including an export to Excel). With us these are buttons on the account page, not forms. The full explanation, including who to contact if you do not have an account, is on the your rights page.
9. Changes to this document
If we change something material — what information is collected, who it reaches or how long it is kept — we will update the date at the top of the page and show it in the system. We do not change this document in order to widen the uses of information already collected.