Privacy Policy
What we collect, who processes it, how long we keep it, and how to get it deleted.
Last updated: 24 August 2026
Cheddar is a digital menu and AI assistant used by restaurants. Two very different groups of people touch it: the restaurant operators who run an account, and the diners who scan a QR code at a table. We collect quite different things from each, so this policy deals with them separately.
We have tried to write this plainly and honestly, including the parts that are not flattering. In particular, section 4 explains that messages diners type to the AI are stored word for word, that some people type health information into them, and how long we currently keep that.
1.Who this policy is for
This policy is published by Himanshu Jeetendra Bundel, an individual trading as Cheddar Labs("Cheddar Labs", "we", "us"). Cheddar Labs is a trading name, not a company — the data controller is an individual, and you can reach that person directly at cheddarlabsteam@gmail.com. This policy covers the Cheddar website, the operator dashboard, and the guest menu that diners reach by scanning a QR code.
Under data protection law, the roles differ. For restaurant operators' own account data, we are the controller — we decide what to collect and why. For diner data captured in a restaurant's menu, the restaurant is the controller and we act as its processor, running the service on its behalf. If you are a diner with a question about a specific restaurant, you can contact either the restaurant or us.
2.What we collect from restaurant operators
When you create and run a Cheddar account, we hold:
- Account details — first and last name, email address, password (stored only as a secure hash by our authentication provider, never in readable form), profile photo if you sign in with Google, timezone, your role, and whether your account is active.
- Business details — restaurant or organisation name, locations, branding and settings, plus the names and email addresses of team members you invite.
- Your menu content — dishes, descriptions, prices, photos, ingredient and allergen records, and QR code configuration. This is business data rather than personal data, but it is yours and we treat it as confidential.
- Billing information — your subscription plan, status, renewal dates and invoice history. Card payments are handled by Stripe; we receive confirmation of payment and limited details such as the card brand and last four digits. We never receive or store your full card number.
- Security and support records — sign-in attempts, failed-login counters used for account lockout, invitations and access codes, and any messages or feedback you send us.
We use this to run your account, to provide the service, to take payment, to keep the platform secure, and to contact you about your account or important changes. Our legal bases are performance of our contract with you, our legitimate interest in keeping the service safe and working, and consent where we ask for it.
3.What we collect from diners
Diners do not create an account, and we do not ask them for their name, phone number, address or payment details. Browsing a menu is anonymous. What we do record is:
- An anonymous session. When a diner opens a menu, a random session identifier is created and kept in their browser. It lets the menu remember the conversation and shortlist while they are at the table. It is not linked to a name and is not used to track people across other websites.
- Table and menu context — which restaurant and which QR code or table label was scanned, and when.
- Interaction events — which dishes were shown, viewed, filtered, or added to a shortlist, and similar usage signals. These become the analytics a restaurant sees in its dashboard.
- Chat messages with the AI assistant — see the next section, which deserves its own explanation.
- Technical data — standard information a web server and our error monitoring receive, such as browser type, approximate location derived from network address, and error diagnostics.
A restaurant can see this data for its own menu only. One restaurant can never see another's guests, menus or analytics.
4.Guest chat messages, including health information
We store the messages diners type to the AI assistant word for word, exactly as typed. They are saved in two places: a conversation record that lets the assistant remember the thread and lets the restaurant's staff see the chat, and a technical log used to monitor quality, cost and safety.
This matters because of what people actually type. Cheddar's assistant answers questions about dishes, so diners write things like "I'm anaphylactic to peanuts", "I have coeliac disease", or "I'm pregnant, can I eat this?". In many countries that is health information, which is treated as a specially sensitive category. We are not going to pretend otherwise: if a diner types a medical detail into the chat, we store it.
The messages are not attached to a name, email address or account, because we do not collect those from diners. They are attached to an anonymous session together with the restaurant, the table label and the time — so they are not anonymous in the strictest sense, since a restaurant could in principle connect a table and a time to a person who was sitting there.
Who can read them:
- The restaurant. Staff with the right role can see the conversations that happened on their own menu, in the dashboard's chat and AI tools. If a diner raises an allergy, the message is deliberately surfaced to staff so a human can respond — that is a safety feature.
- Cheddar Labs platform administrators. A small number of our staff hold platform-administrator access, which today allows reading raw guest messages across all restaurants for support, cost monitoring and AI safety review.
- Our AI provider, for the moment it takes to generate an answer — see the next section.
How long we keep them, honestly: at present we do not delete guest chat messages or AI logs automatically. There is no scheduled purge, so they remain until they are removed manually, until the related restaurant account or session record is deleted, or until someone asks us to delete them. We consider this longer than it should be for data that can include health details, and shortening it with an automatic deletion window is on our roadmap. Until that ships, this section describes the real behaviour rather than an intention.
Diners: you can ask us to delete the chat from your visit — see section 10. Please avoid typing more personal detail into the chat than you need to, and speak to a member of staff for anything genuinely health-critical. The assistant is not a medical service and can be wrong.
5.How AI processing works and who sees the messages
Cheddar's assistant does not run on our own servers. When a diner sends a message, we send that message, the recent conversation, and the relevant parts of the restaurant's menu to a third-party AI provider, which returns the answer.
- OpenAI is the default provider. It generates chat answers and also creates the mathematical "embeddings" used to search menu items.
- Google (Gemini) may be used as a fallback when an account exceeds its monthly AI allowance, or when a restaurant selects a Gemini model.
These providers process the message in order to produce a reply, under their own business terms. We use their standard business APIs, which do not use submitted content to train their public models by default. We do not sell guest messages, and we do not share them with advertisers.
Diners are told in the guest interface that they are chatting with an AI assistant and that it can be wrong. See our Beta Participation Agreement, section 5, for what the assistant does and does not claim about allergens.
8.Where your data is stored
Cheddar's database, hosting and AI providers are based in the United States, and data is processed there. If you are in the UK, the European Economic Area or another region with transfer restrictions, this means your information is transferred outside your region. Where required, those transfers rely on the standard contractual clauses or an equivalent approved safeguard offered by each provider.
The governing law for our operator agreement is set out in the Beta Participation Agreement, and is currently California.
9.How long we keep things
- Operator account and profile — for as long as the account is open, and for a reasonable wind-down period after it closes so the account can be restored or exported.
- Menu content — until you delete it, or until your account closes and the wind-down period ends.
- Billing and invoice records — kept for as long as tax and accounting law requires, typically several years, even after an account closes.
- Guest sessions and analytics events — kept while the restaurant's account is open. Deleting a menu or an account removes the linked guest sessions.
- Guest chat messages and AI logs — currently kept indefinitely, with no automatic deletion window in place. They are removed when the linked session, menu or account is deleted, or on request. See section 4, which explains why we are not comfortable with this and intend to shorten it.
- Error and monitoring data — kept according to each provider's default retention, typically weeks to months.
10.Your rights, including access and deletion
Depending on where you live — including under the UK and EU GDPR, and the California Consumer Privacy Act as amended by the CPRA — you have rights over your personal information:
- Access. Ask what we hold about you and get a copy.
- Correction. Ask us to fix anything inaccurate.
- Deletion. Ask us to delete your information, including guest chat messages from a visit, subject to what we must keep by law.
- Portability. Ask for your data in a machine-readable format.
- Objection and restriction. Object to processing based on our legitimate interests, or ask us to pause processing while a dispute is resolved.
- Withdraw consent at any time where processing relies on consent.
- No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of.
- No discrimination. Exercising these rights will never mean worse service or a different price.
To exercise any of these, email cheddarlabsteam@gmail.com. We aim to respond within 30 days, and will tell you if we need longer. We may need to verify who you are first. An authorised agent may act for you with written permission.
If you are a diner, tell us the restaurant, the table, and roughly the date and time of your visit — that is how we locate an anonymous session. Deleting it is usually straightforward, but if you cannot give us enough detail to find it, we may not be able to identify your data, and the law does not require us to collect more information just to make you identifiable.
If you think we have handled your information badly, please tell us first so we can fix it. You also have the right to complain to your local data protection authority.
11.How we protect information
Data is encrypted in transit. Passwords are stored only as secure hashes. Access between restaurants is separated at the database level so one account cannot read another's data, and administrative access to the platform is restricted to a small number of people. Sign-in attempts are rate-limited and repeated failures lock the account temporarily.
No system is perfectly secure, and we cannot guarantee that a breach will never happen. If one occurs that affects you, we will notify you and the relevant authorities where the law requires it.
12.Children
Cheddar is a business tool sold to restaurants and is not directed at children. Operator accounts are for adults. The guest menu is a public restaurant menu, and we do not knowingly collect personal information from children through it. If you believe a child has given us personal information, contact us and we will delete it.
13.Changes to this policy
We will update this policy as Cheddar changes — for example, when the automatic deletion window for guest chat messages described in section 4 is in place. The "last updated" date at the top always reflects the current version, and we will tell account holders by email about significant changes.
14.How to contact us
For any privacy question or request, email cheddarlabsteam@gmail.com. That inbox is read by Himanshu Jeetendra Bundel, who is the data controller. We do not publish a postal address; ask by email if you need one for a formal notice.