Privacy Policy
Last updated: August 11, 2026
Waitor helps travelers choose and communicate food orders. This policy explains what we collect, why we collect it, and how to contact us about your data.
Information We Collect
- Account information, such as your email address, name, login method, and language preference.
- Restaurant inputs, such as place names, Google Maps links, restaurant links, and nearby-place selections.
- Menu inputs, including menu photos, text you enter, and information extracted from those photos or links.
- Food preferences, such as appetite, spice preference, dietary notes, allergies, budget, party size, and order notes.
- Order history and recommendation results, so you can return to recent plans.
- Approximate or precise location only when you allow it, used to suggest nearby restaurants.
- Technical information, such as platform, app version, build, workflow stage, performance timing, and privacy-filtered error diagnostics needed to operate and improve the app.
How We Use Information
- To create restaurant context, read menus, and generate practical order recommendations.
- To remember your preferences and recent order plans.
- To authenticate your account and keep your session secure.
- To troubleshoot, prevent abuse, and improve reliability.
- To respond when you contact support.
Sign-In Providers
If you sign in with Apple or Google, Waitor receives an identity token and basic profile information made available by that provider, such as your email address and name. We use this information only to create or access your Waitor account.
Service Providers
Waitor currently relies on the following service categories to provide the ordering workflow:
- Apple and Google for sign-in.
- Railway for application hosting and database infrastructure.
- Google Maps Platform for restaurant search, location context, place details, and restaurant imagery.
- SearchAPI and, when needed, Apify for public restaurant-review context.
- Brave Search for optional public web evidence about a restaurant selected by the user.
- OpenAI for menu-photo OCR and menu extraction.
- DeepSeek for optional AI recommendation and language assistance.
- Sentry for privacy-filtered crash and reliability diagnostics.
Information sent to a provider is limited to what is needed for that operation. For example, menu photos and menu text may be processed for OCR, while a recommendation can include restaurant context, parsed menu items, dietary preferences, allergies, and order instructions. These providers process information under their own terms and privacy commitments. Waitor does not sell personal information or use it for cross-app advertising or tracking.
Location and Photos
Location access is optional. Menu photo access is used only when you choose to upload or capture a menu. Location coordinates are sent only when needed to request nearby restaurants or directions. Waitor does not intentionally save the raw bytes of a user-captured menu photo in its database after OCR, although extracted menu text and structured menu items may be saved to your account. You can change app permissions through your device settings.
Web Evidence and Speech
Optional web evidence is requested only after you select a restaurant. Current public-release settings do not persist Brave Search evidence in the Waitor database; the app may keep a small result briefly in memory so the same screen can be reopened without another request. Staff-card speech uses the device text-to-speech service. Waitor does not record or upload your voice for this feature.
Data Retention
We keep account, preference, and order history information while your account is active or as needed to provide the service, comply with law, resolve disputes, and maintain security. You can delete your account from the Profile tab in Waitor. If you cannot access the app, follow our account and data deletion instructions.
Service providers may retain limited request or security records according to their contracts and policies. Privacy-filtered diagnostics contain release and failure information but are designed to exclude account, restaurant, menu, order, allergy, preference, prompt, URL, screenshot, and attachment content.
Children
Waitor is not intended for children under 13. We do not knowingly collect personal information from children under 13.
Security
We use reasonable technical and organizational safeguards to protect information. No internet service can guarantee perfect security.
Your Choices
You may contact us to request access, correction, export, or deletion of your information. Some requests may require identity verification. You can delete your account from inside Waitor or request deletion of specific data without deleting your account by following our account and data deletion instructions.
Contact
Questions or requests can be sent to support@waitorapp.com.
Changes
We may update this policy as Waitor changes. The latest version will be posted on this page with the updated date above.