Privacy Policy
Last updated: 7 July 2026
Click AI Agency ("we", "us", or "our") operates the Click Desk POS mobile application and the getclickdesk.com website (together, the "Service"). This policy also covers other services we provide from clickaiagency.com. This page explains what personal data we collect, why we collect it, and your rights over that data.
By using the Service, you agree to this Privacy Policy. If you disagree with anything below, please stop using the Service.
Who we are
Click Desk POS is a product of Click AI Agency, registered at [REGISTERED ADDRESS], [COMPANY NUMBER if applicable]. We are the data controller for personal data you provide directly (your account details) and a data processor for personal data you enter about your customers and staff (booking records, PINs, etc.) — you are the controller for that data.
Contact for privacy matters: privacy@clickaiagency.com
Data we collect
From operators (you)
- Account information: full name, email address, phone number, password (hashed), business name and address, timezone.
- Payment information: if you subscribe, we collect a Stripe customer ID. We do NOT store your card number — Stripe handles that.
- Usage data: which features you use, when you sign in, device information (iPad model, iOS version, app version, IP address).
- Support communications: emails and messages you send us.
About your customers (which YOU enter)
- Customer name, phone number, email address, booking history, allergens, notes/preferences.
- If your customer books via your Click Desk booking widget: their submitted details plus optional payment info (via Stripe).
About your staff (which you or they enter)
- Full name, email address, role, PIN (bcrypt-hashed), clock-in/out times, shift notes.
Automatically collected
- Device identifiers (for POS device pairing).
- IP address, browser/app version, session cookies.
- Error logs and performance telemetry (anonymised).
How we use your data
- Operate the Service and provide the features you use.
- Process payments through Stripe.
- Send booking confirmation SMS and emails on your behalf (via Twilio and Resend).
- Optionally, answer your restaurant's phone using ElevenLabs' AI voice service, if you enable that feature.
- Sync bookings to Google Calendar if you connect it.
- Send you product updates, security notices, and (with your consent) marketing.
- Investigate abuse, fraud, or violations of our Terms.
Legal basis (UK GDPR / EU GDPR)
We process your data under one of these bases:
- Contract — to provide the Service you signed up for.
- Legitimate interests — running our business, preventing fraud, improving the Service.
- Consent — where required (marketing emails, non-essential cookies).
- Legal obligation — where the law requires it (tax, law enforcement requests).
Who we share data with
We share data only with the sub-processors we need to run the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (Amazon Web Services) | Hosting, database, authentication | EU (Frankfurt / Dublin) |
| Vercel | App hosting | EU / global CDN |
| Stripe | Payments processing | US / EU |
| Twilio | SMS delivery | US / EU |
| Resend | Email delivery | US |
| ElevenLabs | AI voice agent (optional, only if enabled) | US |
| Calendar sync (optional) | US | |
| Apple | iOS platform services | US |
| Cloudflare | DNS, CDN | Global |
We do NOT sell personal data. We do NOT share personal data with advertising networks. We do NOT profile your customers for third-party marketing.
International transfers
Some sub-processors are outside the UK/EEA. Where personal data is transferred, we rely on the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses (SCCs), or equivalent safeguards.
Data retention
- While your account is active — we retain your data.
- When you cancel — customer data and staff data are deleted within 90 days (or exported to you first if you request).
- Financial records — retained 6 years to satisfy UK / EU tax and accounting requirements.
- Audit logs and security events — retained 1 year.
- Backup copies — purged from backups within 6 months.
Your rights
Under UK GDPR / EU GDPR (and equivalent laws elsewhere) you have the right to:
- Access — receive a copy of the personal data we hold about you.
- Rectify — correct inaccurate data.
- Erase — request deletion ("right to be forgotten").
- Restrict processing — pause or limit our use of your data.
- Data portability — receive your data in a structured, machine-readable format.
- Object — to processing based on legitimate interests or direct marketing.
- Withdraw consent at any time (where consent is the basis).
- Complain to your data protection authority — in the UK, the ICO (ico.org.uk).
To exercise any of these rights, email privacy@clickaiagency.com. We respond within 30 days.
Data security
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Passwords and PINs are hashed with bcrypt.
- Row-level access controls limit who inside our system can access which data.
- Regular security audits, dependency patching, and CSP / HSTS in place.
- We have a documented incident response plan.
Cookies
The Click Desk web dashboard uses essential cookies for authentication and session management. We do NOT use third-party analytics or advertising cookies without your consent.
Children
The Service is for business use by adults. We do not knowingly collect personal data from children under 13.
Changes to this policy
We may update this policy from time to time. If we make material changes, we'll email you and post a notice in the app. Continued use of the Service after changes means you accept the new policy.
Contact us
Data protection questions: privacy@clickaiagency.com
General questions: support@clickaiagency.com
Postal: [REGISTERED ADDRESS]
