- Last updated
- July 2026
- Data controller
- Labtechio Ltd.
- Contact
- Contact form
- Regulator
- UK Information Commissioner's Office (ICO)
Who we are
Labtechio provides a hosted and self-hosted restaurant point-of-sale platform for independent venues. When you visit this website or use our software as a staff member of a restaurant customer, we (or the restaurant that employs you) act as the data controller for the information described below.
What we collect
Website visitors
- Basic request metadata — IP address, browser, referrer, pages viewed — used only to keep the site available and secure.
- Contact form submissions — name, email, and the message you type. Used to reply to your enquiry.
- A session cookie required for CSRF protection and to remember whether you are signed in.
Restaurant staff and account holders
- Your name, email, hashed password, role, and store assignment — used to sign you in and enforce role-based access.
- Audit and activity logs (login, cash session open/close, sensitive changes) — used to keep your restaurant's own records intact.
- POS activity you generate on shift — orders, payments, tables, kitchen tickets, cash session totals.
Restaurant guests
- Order data placed via QR guest ordering (items, table, timestamp). Personal identifiers are only stored if the venue chooses to collect them (e.g. name for takeaway).
- Card payment data is never stored by Labtechio. Payments are handled by the venue's payment provider (for example, Stripe), and only a reference token is retained for reconciliation.
Why we hold it (legal bases)
- Contract — to provide the POS service to venues that subscribe to Labtechio.
- Legitimate interest — to keep the platform secure, prevent fraud, and improve the product.
- Legal obligation — to retain financial and tax records for as long as the law requires (typically 6 years in the UK).
- Consent — where you have opted in, such as marketing emails.
Who we share it with
We only share personal data with the sub-processors we need to run the service:
- Cloud hosting and backup providers within the UK or EEA.
- Transactional email providers (for password resets, receipts, notifications) — when SMTP is enabled.
- Payment processors chosen by each venue (for example, Stripe) to process card payments.
We do not sell personal data. We do not use it for third-party advertising.
Where your data lives
Primary processing takes place on servers within the UK or European Economic Area. If a sub-processor operates outside that region we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.
How long we keep it
- Contact form messages — up to 24 months, then deleted.
- Staff accounts — for as long as the venue subscription is active, plus 30 days.
- Order and financial data — as long as the venue's own retention policy or applicable tax law requires.
- Backups — rolling 30-day retention window.
Your rights
Under UK GDPR and EU GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Ask us to correct information that is wrong or incomplete.
- Ask us to erase your data, subject to legal retention rules.
- Object to or restrict processing based on legitimate interest.
- Withdraw consent for anything you previously opted into.
- Lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority.
To exercise any of these rights, please email us through the contact form. If you use Labtechio as a restaurant guest, please raise the request with the venue you ordered from — they are the data controller for that order.
Cookies
We only set the cookies we need to make the site work:
PHPSESSID— session cookie, required for security (CSRF) and for staying signed in.
We do not run third-party analytics, advertising, or tracking cookies on our public site.
Security
We hash all passwords, transport data over HTTPS, apply role-based access control on every endpoint, and keep encrypted rolling backups. If we ever suffered a personal data breach affecting your rights, we would notify the ICO within 72 hours and inform the venues affected without undue delay.
Changes to this policy
When we update this policy we will change the "Last updated" date above and, for material changes, notify signed-in account admins by email.
Contact us
Questions about privacy? Send us a message. We reply from the same inbox that supports live restaurants — no ticket queues.