1. Who operates GuestSence
GuestSence provides restaurant guest-feedback and improvement software. Privacy questions and data requests can be sent to support@guestsence.com.
2. Information we collect
Guest feedback information. This may include the restaurant connected to the feedback, the guest's selected experience category and topics, written comments, language, submission time, feedback source and workflow status.
Optional follow-up information. When a guest asks the restaurant to follow up, GuestSence may process an email address or phone number, the chosen contact method and the guest's consent choice.
Restaurant and Merchant information. This may include restaurant identity and profile details, owner email or phone, account configuration, QR feedback sources, access status, password hashes, activity records, replies, follow-up records and improvement records.
Partner account information. For approved Partner accounts, this may include the Partner's name, email, Partner code, account status, activation and account timestamps, and authentication-related account records used to secure access.
Partner referral information. When a Partner registers a restaurant referral, GuestSence may process the restaurant name and city, contact name, business contact email or phone, registration and protection-expiry timestamps, and any later binding to a restaurant account. This information is used to record attribution, prevent duplicate or conflicting claims, maintain the 90-day referral protection period, connect eligible referrals to restaurant accounts and provide Partner tracking.
Limited referral status shown to Partners. An authenticated Partner may see limited account-status information needed to track the Partner's own referral, such as whether a trial has started, trial timing and end date, and relevant conversion or payment status. Partner access does not include guest feedback, guest identities or contact details, Merchant credentials, Merchant AI insights, Guest Care, private restaurant operations or another Partner's information.
Partner commission and payout records. GuestSence may process qualifying restaurant payment confirmations, commission amounts, the paid-referral sequence number, earned and payout timestamps, commission or payout status, payment method, transaction reference, and refund or chargeback review records where applicable. These are financial facts and references; GuestSence does not use this Partner system to store payment-card details or bank-account credentials.
Payment and subscription information. When a restaurant purchases GuestSence through Paddle, Paddle processes the checkout and payment as Merchant of Record. GuestSence may receive limited information needed to provision and administer the subscription, including the customer or billing email, Paddle customer, transaction and subscription identifiers, product and price identifiers, transaction amount and currency, subscription status, renewal or cancellation status, payment-status events, billing country, and refund or dispute status.
GuestSence does not receive or store the buyer's full payment-card number or card security code from Paddle.
Public review activity. Where a restaurant provides an external review link, GuestSence may record the first time a feedback submission uses that link for service reporting.
Technical and security information. GuestSence uses necessary session identifiers and may process request information such as an IP address for rate limiting and service protection. Rate-limit identifiers are derived using a one-way hash before they are stored. Hosting providers may also process ordinary server and request logs.
GuestSence does not currently use an advertising analytics SDK or an advertising cookie system in the application.
3. How we use information
- Provide the guest feedback and restaurant management service.
- Associate feedback with the correct restaurant and QR source.
- Authenticate Merchant and Admin access.
- Support guest follow-up and restaurant improvement workflows.
- Maintain, troubleshoot and protect the service.
- Respond to product, trial and support enquiries.
- Provide AI-assisted features when those features are enabled.
- Operate the Partner Program, including referral attribution, conflict prevention, trial tracking, commission and payout administration.
- Maintain referral, status-change and financial histories needed for accurate records, support questions and dispute review.
- When Paddle billing is used, administer paid subscriptions and confirm payment and subscription status.
- When Paddle billing is used, provision paid access and manage renewal or cancellation state.
- Respond to billing support and maintain refund or dispute records where needed.
4. Service providers and sharing
GuestSence uses service providers to operate the product. Current application services include Supabase for database and storage infrastructure, Vercel for application hosting and delivery, OpenAI for enabled AI-assisted features, and Resend for operational email delivery. When Paddle billing is used, Paddle provides checkout, payment processing, Merchant of Record services, subscription billing, applicable transaction-tax administration, order receipts, refunds and payment-related customer support.
These providers may process information as needed to perform their services. Information may also be disclosed when reasonably necessary to comply with law, protect users or the service, investigate misuse or enforce applicable agreements.
Restaurant pages may link to external services such as Google, Tripadvisor or Yelp. Visiting an external service is governed by that service's own terms and privacy practices.
5. AI-assisted processing
When a restaurant uses an enabled AI-assisted feature, information needed for that feature may be sent to OpenAI. Depending on the feature, this can include selected guest feedback, related restaurant context and instructions needed to prepare an experience brief or a reply draft.
AI-assisted processing is initiated through server-side GuestSence workflows with explicit input limits and output validation. Certain AI analysis workflows also remove common contact, payment-card and URL patterns from guest-written text before the relevant AI processing step.
AI output can be incomplete or inaccurate. Restaurant users remain responsible for reviewing it before using it. GuestSence does not make broader promises about a provider's handling of information beyond the service configuration actually in use.
6. Cookies and sessions
GuestSence uses necessary, first-party session cookies to keep Merchant, Partner and Admin users signed in and to validate access on the server. Partner access uses a session separate from Merchant access. These cookies are configured as HTTP-only and use secure transport settings in production. GuestSence does not currently use these cookies for advertising.
7. Retention
GuestSence retains information for as long as reasonably necessary to provide the service, maintain records, resolve disputes, meet legal obligations, protect the service or support other legitimate operational purposes. A single automatic retention period does not currently apply to every category of information.
8. Access, correction and deletion requests
Guests, restaurant users and Partners may contact support@guestsence.com to ask about account information or request access to, correction of or deletion of personal information connected with GuestSence. Requests are handled subject to applicable law, identity verification and legitimate record-retention requirements. Referral attribution, commission, payout and related audit history may need to be retained where those requirements apply.
Depending on where you live, applicable law may provide additional privacy rights.
9. International processing
GuestSence and its service providers may process information outside the country or region where a user is located. Data protection rules can differ between those locations.
10. Security
GuestSence uses access controls, restaurant-scoped authorization, protected server-side credentials, rate limiting and other technical and organizational safeguards appropriate to the service. More detail is available on the Security & Data page.
11. Changes to this policy
When this policy changes, GuestSence may update this page and, where appropriate, provide additional notice about material changes.
12. Contact
Privacy questions and requests can be sent to support@guestsence.com.
