Privacy Policy

Last updated: June 19, 2026

This Privacy Policy explains how Plato (the “Company”, “we”) collects, uses, and protects personal data in connection with the Plato platform. For account data of restaurant staff, Plato acts as a data controller. For guest reservation data submitted by a restaurant, the restaurant is the controller and Plato acts as a processor on the restaurant’s behalf (see our Data Processing Addendum).

1. Data we collect

Account data: the name, email, phone number, and role of restaurant staff who create or are invited to an account, plus authentication and usage information.

Guest reservation data: data the restaurant records about its guests — names, contact details, reservation history, preferences, allergies/dietary notes, and messages — processed on behalf of the restaurant-controller to deliver the reservation and operations service.

2. How we use data

We process data to provide, secure, and improve the Service: to operate reservations and floor management; to send transactional and operational messages to guests on the restaurant’s instruction; to provide reporting; to prevent abuse; and to comply with legal obligations. We do not sell personal data.

3. Processors and subprocessors

We use the following service providers to operate the platform, each under contractual data protection obligations: Supabase (database and authentication hosting), Resend (transactional email delivery), Twilio (SMS and WhatsApp message delivery), Meta (WhatsApp Business messaging), Anthropic (AI assistance features), Google Places (location and address lookup), and Stripe (payment processing). The current subprocessor list also appears in our Data Processing Addendum.

4. Purposes and legal bases

We process account data to perform our contract with you and for our legitimate interest in operating and securing the Service. We process guest data on the documented instructions of the restaurant-controller. Where consent is required (for certain guest communications), the restaurant is responsible for obtaining it.

5. Retention

We retain account data for the life of the account and as required to meet legal, accounting, or reporting obligations. Guest data is retained for as long as the restaurant maintains it in the Service and is deleted or returned on the restaurant’s instruction or on termination, subject to legal retention requirements.

6. Guest rights

Guests may have rights to access, correct, delete, or restrict the processing of their personal data, and to object to certain processing. Because the restaurant is the controller of guest data, requests are directed to the restaurant; we assist the restaurant in responding as a processor.

7. International transfers

Our providers may process data outside your country, including in the United States and the European Union. Where data is transferred across borders, we rely on appropriate safeguards (such as the providers’ standard contractual clauses) as required by applicable law.

8. Contact

For privacy questions or requests, contact hi@plato.company.