Privacy Policy

Last updated: September 28, 2026

Who we are

TableFlow is a QR-code ordering system for restaurants, operated by IronClad Enterprises LLC, a veteran-owned business based in Jacksonville, Florida, United States. In this policy, “we”, “us” and “TableFlow” refer to IronClad Enterprises LLC.

For any privacy question or request, contact us at [email protected].

Who the data is about

TableFlow serves three different kinds of people, and we handle their data differently. This distinction matters, so we set it out plainly.

Restaurant owners

Owners create an account to manage a restaurant. We store the account email address, a securely hashed password (we never store passwords in readable form), and the restaurant details you enter — name, menu, categories, table layout, branding and pricing.

If you sign in with Google, we receive only your basic profile information and email address (the userinfo.profile and userinfo.email scopes). We do not receive your Google password, and we cannot read your Gmail, Drive, contacts or calendar.

Restaurant staff

Staff accounts are created by the restaurant owner, not by us. Staff records hold a name, a role, and an internal scoped identifier used to tie the account to one restaurant. Staff access is limited to the kitchen and reception screens for the restaurant they belong to.

Diners

Diners do not create an account and do not give us their name, email or phone number. When someone scans a QR code at a table, we process only what is needed to fulfil the order:

  • the table token encoded in the QR code, which identifies the table
  • the items ordered, quantities, and any note added to the order
  • the order status and timestamps, so the kitchen and the diner can follow it

Order records belong to the restaurant. We process them on the restaurant’s behalf so it can prepare and serve the order.

Payments

Card payments are handled entirely by our payment processors, Square and Stripe. Card numbers, CVC codes and expiry dates are entered directly into their systems and never reach TableFlow’s servers. We store only the result of a payment — whether it succeeded, the amount, and a processor reference used to reconcile the order.

Square and Stripe are independent controllers of the payment data they collect. Their handling of it is governed by their own privacy policies.

Where data is stored

TableFlow runs on our own server infrastructure in the United States, using a self-hosted PocketBase database. We do not sell your data, and we do not share it with advertising networks or data brokers. Data is shared only with the service providers we depend on to run the product: our payment processors (Square, Stripe), our hosting and network providers, and Google where you choose to sign in with Google.

Cookies and local storage

We keep this minimal. TableFlow does not use advertising or tracking cookies.

  • Authentication cookies (owner_auth, staff_auth) — set as HTTP-only, so they cannot be read by scripts in your browser. They keep you signed in, and are cleared when you log out.
  • Local storage — remembers small display preferences such as your light or dark theme. This never leaves your device.

Security logging

We keep an audit log of security-relevant events — sign-ins, permission changes and administrative actions — so that account owners can see what happened on their account and so we can investigate abuse. These logs are retained only as long as they are useful for that purpose.

How long we keep data

  • Account and restaurant data — kept while the account is active. If you delete your account from the dashboard, the account and its restaurant data are removed.
  • Order records — retained for the restaurant’s own operational and accounting needs, then deleted.
  • Payment records — retention is governed by Square and Stripe and by applicable tax and accounting law.

Your rights

You can ask us to give you a copy of your data, correct it, or delete it. Owners can delete their own account and associated restaurant data directly from the dashboard at any time.

Depending on where you live, you may have additional rights — for example under the California Consumer Privacy Act or, in the UK and EEA, the GDPR. We apply these rights to anyone who asks, regardless of location. To make a request, email [email protected]. We will respond within 30 days.

If a diner wants an order record removed, please contact the restaurant that took the order, since the record belongs to them. We will help the restaurant action it.

Children

TableFlow is a tool for restaurants and is not directed at children. We do not knowingly collect personal information from children under 13.

Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your data, we will tell account owners directly.

Contact

IronClad Enterprises LLC, Jacksonville, Florida, United States — [email protected]