Dummy Waiter ("we," "us," or "our") is operated by Luke, a Providence College student based in Providence, Rhode Island. This Privacy Policy explains what information we collect, how we use it, and how we protect it when you use the Dummy Waiter service.
1. What We Collect
We collect the following types of information when you use Dummy Waiter:
- Account information including your name, email address, and Google account details if you sign in with Google.
- Restaurant information including restaurant name, menu items, floor plan layout, and staff details.
- Audio recordings of order conversations, recorded when a server actively initiates a recording. These are processed for transcription and are not stored permanently after the order is confirmed, unless the restaurant opts in to quality improvement review.
- Order data including items ordered, modifications, allergy notes, and prices.
- Usage data such as pages visited and features used within the application.
- Bug reports and feedback submitted through the in-app reporting tool.
2. How We Use It
We use the information we collect to:
- Provide the core service: transcription, order parsing, and order management.
- Improve transcription accuracy and overall product quality.
- Communicate with you about the service, including updates and support.
What we do not do:
- We do not sell your data to third parties.
- We do not use restaurant data for advertising purposes.
3. Third-Party Services
We rely on the following third-party services to operate Dummy Waiter. Each has its own privacy policy governing how they handle data:
- Supabase for database hosting and authentication.
- Google for OAuth login.
- AI services for audio transcription and order parsing.
- Resend for transactional email delivery.
- Vercel for frontend hosting.
- Railway for backend hosting.
4. Audio Recording Disclosure
- Audio is recorded only when a server actively starts a recording. The device does not record passively or continuously.
- Recorded audio is sent to third-party AI services for transcription and order parsing.
- Audio is not stored long-term unless the restaurant opts in to quality review.
- It is the restaurant's responsibility to inform guests that AI-assisted order capture is in use, in compliance with applicable local laws.
5. Data Retention
- Account data is retained for as long as your account is active.
- Order data is retained for shift reporting and analytics purposes.
- Audio recordings are processed and discarded after transcription unless the restaurant has configured otherwise.
- You can request deletion of your data at any time by emailing luke@dummywaiter.com.
6. Security
- All data is encrypted in transit using HTTPS.
- Authentication is handled through Supabase with row-level security policies to isolate restaurant data.
- Staff PIN codes are stored as hashed values and are never kept in plain text.