Effective date: Not yet formally dated. This policy reflects the platform's practices as of its current early-stage (MVP) release; a specific effective date will be added once the platform reaches general availability.
1. Who this policy covers
This policy applies to personal data processed through the Jantar AI platform: the website chat widget, the standalone chat page, WhatsApp conversations (where a restaurant has WhatsApp enabled), table bookings, and booking confirmation emails (where a restaurant has email confirmation configured).
2. Who is responsible for your data
Jantar AI provides the technology platform used by restaurants to communicate with their customers and manage bookings. In general:
- The restaurant you are contacting or booking with is generally the data controller for the booking and conversation data you provide to it — it decides why that data is collected and how it is used to serve you.
- Jantar AI provides the underlying platform and, in that role, generally acts as a service provider/processor that handles data on the restaurant's behalf.
This description reflects how the platform is architected today (each restaurant's data is kept separate and managed by that restaurant's own administrators). It is not a final legal determination — the precise controller/processor relationship for any given restaurant may depend on that restaurant's own arrangements and should be confirmed with that restaurant if you need certainty.
3. Information we collect
3.1 Booking information
When you make a table booking (via chat, the website widget, WhatsApp, or a restaurant's admin team), we collect:
- Your name
- Your phone number
- Your email address
- The requested booking date, time, and party size
- Any optional notes you provide (e.g. dietary requirements, special requests)
3.2 Conversation data
When you chat with a restaurant's AI assistant — through the website widget, the standalone chat page, or WhatsApp — we store the messages you send and the assistant's replies, so the conversation can be continued and so the restaurant can review its own conversations with its customers.
3.3 WhatsApp
Where a restaurant has WhatsApp enabled, we receive and process your WhatsApp phone number and the content of the messages you send through that channel, in order to operate the WhatsApp conversation and, where relevant, process a booking request.
3.4 Booking confirmation emails
Where a restaurant has email confirmations configured, your email address and your booking details (date, time, party size, and booking reference) are used to send you a confirmation email.
4. How your information is used
- To create, manage, and confirm your table booking.
- To respond to your messages and questions via chat or WhatsApp.
- To allow a conversation to be resumed rather than restarted.
- To let the restaurant you're contacting review its own bookings and conversations.
5. Third parties we use
We use a small number of third-party services to operate the platform. The table below describes what each one is used for and what may be sent to it.
| Service | What it's used for | What may be sent to it |
|---|---|---|
| Google (Gemini API) | Generating AI chat replies and processing booking requests made through chat | Your current message, relevant conversation history, and booking details you provide through chat |
| Meta (WhatsApp Business Platform) | Sending and receiving WhatsApp messages, where a restaurant has WhatsApp enabled | Your WhatsApp phone number and message content |
| Resend | Sending booking confirmation emails, where a restaurant has this configured | Your email address and your booking details |
| Railway | Hosting the application and its database | All data described in this policy, as part of hosting the service |
| Sentry (optional) | Error monitoring, if and only if a particular deployment has this enabled | Technical error information, configured to avoid capturing personal message content; this is off by default and not necessarily active for any given deployment |
We do not currently use any analytics or advertising/tracking services on this platform.
International transfers
Some of the third parties above may process data outside the United Kingdom or European Economic Area. We have not finalised, and this policy does not claim, any specific international-transfer mechanism, data processing agreement, or data-residency commitment with these providers — this is [TO BE CONFIRMED] and will be updated here once resolved.
6. How long we keep your information
Booking and conversation data is currently retained indefinitely. We do not yet operate an automatic deletion schedule or retention period for this data. If you would like data about you deleted, see Section 7 below.
7. Your rights and how to contact us
Depending on where you are located, you may have rights to access, correct, or request deletion of your personal data. We do not currently offer an automated self-service tool to access, export, or delete your data. Instead:
- Contact us at rankoutreachhub@gmail.com with your request.
- Requests are handled manually. Fulfilling a request may require the restaurant or the platform operator to locate the relevant booking or conversation records, which may take some time.
- If your enquiry relates to a specific restaurant's handling of your booking, we may need to involve that restaurant directly, since it is generally the controller for that data (see Section 2).
8. Security
We use a number of measures to help protect your information, including:
- API-key based authentication for restaurant administrators.
- Restaurant-level access controls, so one restaurant's admins cannot see another restaurant's data.
- Cryptographic signature verification on incoming WhatsApp messages.
- A policy of not writing customer names, phone numbers, emails, or message content to application logs.
- Rate limiting to reduce abuse of chat and admin endpoints.
- HTTPS-only communication with our email-sending provider (Resend).
- Origin-based access control isolating each restaurant's website widget from others.
- Keeping the underlying web framework up to date, including a recent security upgrade addressing a publicly disclosed framework vulnerability.
We do not currently claim database encryption at rest, a web application firewall, DDoS protection, or independent penetration testing — these are not implemented or verified as part of the current platform.
9. Restaurant-specific responsibilities
Individual restaurants using this platform may have their own additional legal or privacy responsibilities toward their customers — for example, their own privacy notices, staff training, or record-keeping obligations. This policy describes the platform's own practices and does not replace any separate privacy notice a restaurant may provide you directly.
10. Changes to this policy
We may update this policy as the platform's practices change. We encourage you to review it periodically.
11. Contact
Questions about this policy or how your data is handled can be sent to: rankoutreachhub@gmail.com.
Registered business address: Not currently published. Jantar AI is an early-stage (MVP) platform and does not yet have a registered business address to disclose here. For any correspondence, please use the contact email above.