Privacy Policy
Last updated: March 21, 2026
GuestDesk Pro ("GuestDesk," "we," "our," or "us") takes the privacy of restaurants and their guests seriously. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have. If you have questions, contact us at privacy@guestdesk.pro.
By using GuestDesk, you agree to the practices described in this policy. If you do not agree, please discontinue use of the service.
1. Who This Policy Covers
This policy applies to two types of people:
- Restaurant customers (account holders): The restaurant owner or manager who signs up for GuestDesk and connects their Gmail account.
- End guests: The restaurant's own customers whose emails are processed through GuestDesk.
GuestDesk acts as a data processor on behalf of the restaurant (the data controller) with respect to end guest data. The restaurant is responsible for ensuring they have appropriate grounds to process guest communications.
2. Information We Collect
From restaurant account holders:
- Name and email address (used for your GuestDesk account)
- Restaurant name, location(s), and general profile information you provide during setup
- Gmail OAuth credentials (stored as tokens — we never see your password)
- Notification preferences and settings
- Billing information (processed by our payment processor; we do not store full card details)
- Usage logs and support correspondence
From guest email processing:
- Email content (subject line, body text) from incoming guest emails
- Guest name and email address as they appear in the email
- Email thread metadata (timestamps, message IDs) used for conversation tracking
- AI-generated reply drafts and the final approved replies your team sends
- Any notes or tags your staff add to a conversation
Automatically collected data:
- IP addresses and browser information when you access the GuestDesk web app
- Service interaction logs for debugging and performance monitoring
3. How We Use Your Information
- To operate the service: Receiving incoming emails via the Gmail API, generating AI reply drafts, delivering push notifications to your team, and storing conversation history.
- To improve reply quality: AI drafts improve as your team approves and edits responses. Approved replies are used solely to refine your restaurant's voice profile — this data is not used to train shared or public AI models.
- To provide support: We may access conversation logs if you contact us about a specific issue, with your permission.
- To send service communications: Account-related emails (receipts, security notices, product updates). We do not send marketing email to your guests.
- To comply with legal obligations: We may process data as required by applicable law.
4. Third-Party Services We Use
GuestDesk relies on a small number of trusted third-party providers to operate. Each receives only the data necessary to perform their specific function:
- Supabase: Encrypted database storage for conversation history, customer records, and account data. Hosted in the United States. Supabase Privacy Policy.
- Google Gmail API: Used to read incoming emails and send approved replies on your behalf via OAuth. We access only emails in the connected inbox. Google Privacy Policy.
- Google Gemini API: Email content is processed by Google's Gemini models to classify messages and generate reply drafts. This processing happens entirely within Google's own infrastructure — guest and email data is never sent to any non-Google AI provider. Content is processed transiently and is not used to train or improve AI models. Gemini API Terms.
- Web Push / GuestDesk App: Used to deliver notifications to your staff. Push notifications are handled via the GuestDesk web app and (coming soon) the native iOS app.
- Stripe: Payment processing. We do not store payment card data on our servers. Stripe Privacy Policy.
We do not sell your data or your guests' data to any third party, ever.
5. Data Retention
- Active accounts: Conversation history and guest records are retained for as long as your account is active.
- Cancelled accounts: We retain your data for 90 days after cancellation, during which you may export it. After 90 days, your data is permanently deleted from our systems.
- Billing records: Retained for 7 years as required by US tax law.
6. Data Security
We take reasonable technical and organisational measures to protect your data, including encryption at rest and in transit (TLS 1.2+), access controls limiting who within our team can access production data, and regular security reviews. No system is perfectly secure, and we cannot guarantee absolute security, but we take this seriously.
7. Your Rights
Depending on where you are located, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate data.
- Deletion: Request that we delete your personal data (subject to legal retention requirements).
- Portability: Receive your data in a structured, machine-readable format.
- Restriction / Objection: In certain circumstances, ask us to stop or limit how we process your data.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email privacy@guestdesk.pro. We will respond within 30 days.
8. Cookies
The GuestDesk web app uses session cookies to keep you logged in and functional cookies for performance monitoring. We do not use advertising or tracking cookies. You can disable cookies in your browser settings, though this may affect functionality.
9. Children's Privacy
GuestDesk is a B2B service intended for restaurant operators. We do not knowingly collect personal data from anyone under 16 years of age. If you believe a minor has provided data to us, please contact us immediately and we will delete it.
10. International Transfers
GuestDesk is operated from the United States. If you use the service from outside the US, your data will be transferred to and processed in the United States. By using the service, you acknowledge this. For users subject to GDPR, we rely on Standard Contractual Clauses (SCCs) where applicable.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice in the app at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For privacy-related questions or to exercise your rights: