Privacy Policy
What we collect, why we collect it, and the controls you have over your business's and your customers' data.
Last updated · August 24, 2026
1. Who we are
Servd ("Servd," "we," "us") is a food commerce platform — ordering, payments, kitchen operations and reporting for food businesses. This policy explains how we handle personal data for two groups: our customers (business owners and their staff) and their customers (people who place orders through a Servd-powered menu).
For diner order data, the venue is the seller and data controller and Servd is a processor acting on its instructions. For account, billing, security, and support data handled for our own purposes, Servd is the controller.
2. What we collect
From food businesses
- Account details — name, business name, email, phone, country.
- Menu, pricing, location and staff configuration you enter.
- Billing identifiers and invoices (card data is held by our payment providers, not by us).
- Usage and device logs to keep the service secure and reliable.
From your customers
- Order contents, table or location, and order timestamps.
- Contact details when provided for pickup or delivery (name, phone, address).
- Payment confirmation status — never full card numbers.
- For orders placed through an AI assistant, only the order, contact, and fulfillment fields the assistant sends to the Servd tool or API — we do not ask for the conversation transcript.
3. How we use it
We process data to:
- Operate the ordering, kitchen, payment and reporting features you use.
- Route orders to the correct location, station and rider.
- Process payments and produce daily settlement reports.
- Provide support, prevent fraud, and secure the platform.
- Improve the product in aggregate. We do not sell personal data.
4. Sharing
We share data only with processors that help us run Servd — cloud hosting, payment providers, messaging (WhatsApp Business API), and analytics — each bound by contract to use it solely on our instructions. We may disclose data when required by law.
5. Payments & card data
Card payments are handled by PCI-DSS Level 1 certified providers (such as Paymob, Fawry, PayTabs, Kashier, and Stripe). Servd never stores full card numbers or CVV codes; we receive only tokenized references and the result of each transaction.
6. Orders placed through AI assistants
An AI assistant or integration is another ordering channel. The following limits apply:
- Pickup requires the diner's name and phone. Email is optional. Delivery address fields are collected only for delivery.
- Servd receives the structured tool or API fields needed for the order, not the full assistant conversation. Create and status responses omit diner contact details, address, notes, and item-level customer data.
- A signed cart confirmation expires after 10 minutes and carries hashes of the confirmed cart and quote rather than the contact fields themselves. Retry records store a request hash and customer-safe response, not another copy of the request body.
- The venue remains the seller and controller for the order. The assistant provider separately handles the conversation under its own privacy policy and terms.
7. Data retention
We keep order and payment records on the venue's behalf for operations, accounting, fraud prevention, and applicable legal duties. We keep business account and transaction records while the business uses Servd and afterward where law requires. Deletion requests are assessed against those record-keeping duties; we do not keep a second copy of public agent request bodies in tool audit logs.
8. Your rights
Depending on your jurisdiction, you may request access, correction, deletion, or export of your personal data, and object to certain processing. People who placed an order should contact the business they ordered from; we will assist that business in responding.
9. Contact
Questions or requests? Email servdme@gmail.com. We aim to respond within 30 days.