Privacy Policy
Tijaro is a business-management and point-of-sale ("POS") platform for restaurants, operated by Devozar ("Devozar", "we", "us"), a company registered in the United Kingdom. This policy explains what personal data we handle, why we handle it, and the rights you have over it. It covers both the data we hold as a business in our own right and the data we process on behalf of the restaurants that use Tijaro.
1. Who this policy covers
This policy applies to:
- Restaurant operators and their staff who hold a Tijaro account to run their business (the till, ordering site, bookings, payments and books).
- Customers who place an order, make a booking, or otherwise interact with a restaurant that uses Tijaro — whether through the restaurant's own Tijaro-powered site or in person at the till.
- Visitors to Tijaro's own marketing website (tijaro.app).
Where a restaurant uses Tijaro to run its business, that restaurant decides what customer data is collected and why. This policy explains our part; the restaurant may also have its own privacy notice.
2. Our role: controller and processor
Data-protection law distinguishes between a controller (who decides why and how data is used) and a processor (who acts on the controller's instructions). Devozar wears both hats depending on the data:
- We are the controller for the accounts of restaurant operators and their staff, for our own website visitors, and for our billing and support records.
- We are a processor for the customer and order data that restaurants collect through Tijaro. In that role the restaurant is the controller and we act on its instructions under our terms of service.
The controller entity is Devozar Ltd, a company registered in Scotland (company number SC873296). Our contact details are in section 13.
3. Data we collect
3.1 Platform account data
When a restaurant operator signs up, we collect the details needed to create and run the account: business name and address, the names, email addresses and phone numbers of authorised users, login credentials, staff PINs and roles, and configuration such as menus, prices, printers and opening hours.
3.2 Customer and order data
When a customer orders or books through a restaurant on Tijaro, we process (on the restaurant's behalf) the data needed to fulfil that order: name and contact details, delivery or collection address, order contents, booking details, and payment status. Card details are handled by our regulated payment providers — we do not store full card numbers.
3.3 Data received from delivery platforms (including Uber Eats)
When a restaurant connects its Tijaro account to a delivery platform, we receive order information from that platform through its API so the restaurant can accept, prepare and fulfil the order. From Uber Eats this may include:
- Order details — items, quantities, modifiers, special instructions, prices and fees;
- The customer's first name and a masked (platform-provided) phone number;
- Delivery or pickup information needed to fulfil the order;
- Store-level information and order status updates.
We use this data solely to provide the ordering and fulfilment service: displaying the order to the restaurant's POS and kitchen screens, tracking preparation and fulfilment, supporting refunds and customer service, and producing the restaurant's own sales reporting. We do not sell this data, use it for advertising or marketing, build profiles from it, or use it for any purpose unrelated to fulfilling the order and operating the service. Access is limited to the restaurant fulfilling the order and to Devozar personnel who need it to operate and support the platform.
3.4 Technical and usage data
We collect standard technical data when you use Tijaro or our website: IP address, device and browser type, and logs of actions taken in the app. This helps us keep the service secure, diagnose faults and improve reliability. See section 4 for how cookies fit in.
4. Cookies and similar technologies
Tijaro uses strictly-necessary cookies to operate the service — for example to keep you signed in, secure your session, and remember your cookie choices. These are always on because the service cannot function without them.
Where you consent, we also use optional analytics cookies to understand how the platform is used so we can improve it. You can withdraw consent at any time.
For the full list of cookies, their purposes and how to manage them, see our Cookie Policy.
5. Why we use personal data
We only use personal data where the law allows. The table below sets out each purpose and the lawful basis under the UK GDPR that we rely on.
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Providing the POS and business-management platform to a restaurant | Contract (Art. 6(1)(b)) — performance of our agreement with the restaurant |
| Processing customer orders, bookings, payments and deliveries on a restaurant's behalf | Contract, and legitimate interests (Art. 6(1)(f)) in operating the service |
| Sending order confirmations and service messages | Contract / legitimate interests (Art. 6(1)(f)) |
| Fraud prevention, security and platform integrity | Legitimate interests (Art. 6(1)(f)) |
| Meeting our legal, tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Optional analytics and product improvement | Consent (Art. 6(1)(a)) where required |
| Marketing to restaurant operators (never their customers) | Consent / legitimate interests (Art. 6(1)(f)) |
6. Who we share data with
We share personal data only where it is needed to run the service, and never to sell it. Recipients include:
- Payment providers who process card and online payments securely.
- Infrastructure and hosting providers who store and serve the platform under contract.
- Delivery and marketplace platforms a restaurant chooses to connect (e.g. Uber Eats), to pass and receive the order data needed for fulfilment.
- Professional advisers and authorities where we are legally required to disclose.
All of our processors are bound by contract to protect the data and use it only on our instructions. A current list of our sub-processors is available on request to support@devozar.co.uk.
7. Where data is stored
Tijaro data is hosted on infrastructure located in the United Kingdom. Where any processing or support involves a transfer outside the UK, we put appropriate safeguards in place — such as the UK International Data Transfer Agreement or an adequacy decision — so your data keeps an equivalent level of protection.
8. How long we keep data
We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires:
- Account data is kept for as long as the restaurant's account is active, and for a reasonable period afterwards to handle wind-down and disputes.
- Order, booking and transaction records are kept in line with tax and accounting rules (generally at least six years).
- Technical logs are kept for a short period for security and diagnostics, then deleted or anonymised.
When data is no longer needed, we securely delete or anonymise it.
9. Security
We protect personal data with a mix of technical and organisational measures: encryption in transit and at rest, role-based access controls, staff PINs, audited access, and regular review of our systems. No system is perfectly secure, but we work to reduce risk and to detect and respond to incidents quickly. If a breach affects your rights, we will notify you and the ICO where the law requires.
10. Your rights
Under UK data-protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to certain processing;
- data portability, where it applies;
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, contact us using the details in section 13. If we process your data on a restaurant's behalf, we may direct your request to that restaurant as the controller. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
11. Children
Tijaro is a business tool intended for restaurant operators and their customers. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child's data has reached us, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our service or the law. When we make material changes we will update the "last updated" date at the top and, where appropriate, let account holders know. Please check back periodically.
13. Contact
If you have any questions about this policy or want to exercise your rights, contact us:
- Devozar Ltd, a company registered in Scotland
- Company number: SC873296
- Email: support@devozar.co.uk