Privacy Policy
1. Information We Collect
Account Information
When you create an account, we collect your email address and password. Your password is hashed and never stored in plain text. If you sign in with Apple or Google, we receive your name and email from those services.
Profile Information
During onboarding, you may provide your name, role (server, bartender, host, etc.), experience level, and preferences. All profile fields are optional except email.
Shift Data
When you log shifts, we store the date, start and end times, shift type (e.g., Lunch Server, Dinner Bartender), credit card tips, cash tips, tip out amounts, total sales, hours worked, and any notes you add. If you attach a photo to a shift, the image is compressed and stored.
Guest Data
When you add guests to your GuestBook, we store names, phone numbers, drink and food preferences, allergies, special moments, birthdays (month and day only, no year), social media handles (Instagram and LinkedIn only), tags, and notes. When you log visits, we store the date, time, bill amount, tip amount, items ordered, notes, and any attached photo.
Usage Analytics
We use PostHog to collect anonymized usage events such as which features you use, how often you log shifts, and which screens you visit. We do not send your name, email, guest names, financial amounts, or any personally identifiable information to our analytics service.
Information We Do Not Collect
We do not collect your location, contacts, browsing history, advertising identifiers, or any data from other apps on your device.
2. How We Use Your Information
We use your information solely to provide and improve the TableMind service. Specifically:
- To calculate your earnings, take home pay, hourly rate, tax reserve, and projections
- To display your guest profiles, preferences, and visit history
- To track progress toward your monthly goals
- To generate insights, charts, and weekly reports about your earnings
- To send birthday and visit reminders within the app
- To improve the app based on anonymized usage patterns
We never sell, rent, or share your personal data with third parties for marketing or advertising purposes. We do not display ads in the app.
3. Where Your Data Is Stored
Cloud Storage
Your data is stored in a Supabase database hosted on Amazon Web Services (AWS) in the us-west-2 (Oregon) region. All data is associated with your authenticated account and protected by Row Level Security, which ensures only you can access your own data.
Local Storage
The app caches your data on your device using browser localStorage for offline functionality and faster loading. This local cache is automatically cleared when you sign out.
Photos
Photos attached to shifts and visits are compressed on your device (maximum 800px, JPEG quality 0.7) before being stored. Photos are saved as part of your shift and visit data in our database. They are not shared externally or stored in any separate image hosting service.
4. Data Security
We take the security of your data seriously and implement multiple layers of protection:
- All data is transmitted over HTTPS with TLS encryption
- Passwords are hashed using bcrypt and never stored in plain text
- Row Level Security (RLS) policies on every database table ensure users can only read and write their own data
- Server side triggers prevent privilege escalation (users cannot grant themselves Pro access)
- Server side constraints validate all input data (no negative values, enforced character limits, photo size limits)
- All user supplied content is sanitized before display to prevent cross site scripting
- Leaked password protection checks new passwords against known data breaches
While we implement strong security measures, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please contact us immediately at info@tablemind.app.
5. Third Party Services
TableMind uses the following third party services to operate:
- Supabase provides our database, authentication, and real time sync infrastructure. Your account and app data are stored in Supabase. Supabase Privacy Policy
- PostHog provides anonymized usage analytics. No personally identifiable information is sent to PostHog. PostHog Privacy Policy
- RevenueCat manages subscription billing when you upgrade to Pro. RevenueCat processes your subscription through Apple's App Store. RevenueCat Privacy Policy
- Apple processes payments for Pro subscriptions through the App Store. Apple Privacy Policy
- Netlify hosts our website at tablemind.app. Netlify Privacy Policy
We do not use any advertising networks, data brokers, or social media tracking pixels.
6. Data Export and Deletion
Exporting Your Data
You can export all of your data at any time from the BOH (Settings) tab in the app. Exports are available in CSV format (for shifts, guests, and visits separately) and as a complete JSON backup that includes all your data. Your data belongs to you.
Deleting Your Account
You can delete your account and all associated data from within the app by going to BOH (Settings) and tapping "Delete My Account." This permanently removes all your shifts, guests, visits, goals, preferences, tags, and profile data from our servers. Account deletion requires a three step confirmation to prevent accidental data loss.
After deletion, authentication records are purged within 30 days. If you need assistance with account deletion, contact us at info@tablemind.app.
What Happens If You Cancel Pro
If you cancel your Pro subscription, your account reverts to the free tier. You retain full read only access to all your existing data, including data that was created while on Pro. You can continue to view and export everything. You can resubscribe at any time to regain full editing access.
7. Children's Privacy
TableMind is designed for use by adults aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at info@tablemind.app and we will delete the information promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the "Effective" date at the top of this page. We encourage you to review this page periodically. Your continued use of TableMind after changes are posted constitutes your acceptance of the updated policy.
9. Contact Us
If you have any questions about this Privacy Policy, your data, or your privacy rights, contact us at:
TableMind LLC
Email: info@tablemind.app
Massachusetts, United States