chat2guest Privacy Policy
Effective date: 28 May 2026
Last updated: 28 May 2026
The canonical, publicly accessible version of this Privacy Policy is published at https://chat2guest.com/legal/privacy-policy. Read together with our Terms of Service.
1. Who We Are
This Privacy Policy explains how chat2guest ("chat2guest", "we", "us", or "our") processes personal data in connection with the chat2guest platform.
chat2guest is an AI-assisted restaurant communications and reservation platform that may include:
- a restaurant admin dashboard;
- public booking, waitlist, and private-room booking flows;
- a website chat widget;
- integrations with WhatsApp (including the official WhatsApp Business Cloud API and, where configured, a QR-code-based connector), Facebook Messenger, Instagram, and Google Business Profile reviews;
- AI-assisted drafting and response features;
- a restaurant-scoped knowledge and answer-reuse layer;
- payment and deposit collection features; and
- related notification, support, security, and account-management tools.
Controller details
- Legal entity: alpstudios GmbH, trading as chat2guest
- Country of establishment: Switzerland
- Registered address: Maschinengasse 10, 6330 Cham, Switzerland
- Email: [email protected]
- Privacy contact: [email protected]
- Telephone: +41 76 489 10 16
chat2guest is currently focused on the Swiss market. A second base of operations in the Netherlands is in preparation; when that Dutch establishment is operational and routinely takes decisions on the purposes and means of EU-related processing within the meaning of Article 4(16) GDPR, this Privacy Policy will be updated to reflect chat2guest's main establishment in the European Union.
Representatives under applicable law:
- EU representative (Article 27 GDPR): chat2guest does not currently target individuals in the European Union within the meaning of Article 3(2) GDPR and has therefore not designated a representative under Article 27 GDPR. Before chat2guest begins offering the Service to persons in the European Union, it will either designate an Article 27 representative or operate through a Dutch establishment that satisfies the same purpose. Until then, individuals located in the EU/EEA may contact chat2guest directly at [email protected].
- Swiss representative (Article 14 revFADP): Not applicable. chat2guest is established in Switzerland and is therefore not required to designate a representative under Article 14 revFADP.
2. Scope of This Policy
This Privacy Policy applies to personal data processed:
- when restaurant staff, owners, managers, or other business users use the
chat2guestplatform; - when prospective customers, partners, or vendors contact us;
- when a restaurant uses
chat2guestto communicate with its guests or process reservations, waitlists, private-room requests, or review replies; - when individuals interact with a
chat2guest-powered booking page, widget, or messaging flow; and - when we process data for security, authentication, logging, fraud prevention, legal compliance, or service support.
This Privacy Policy does not override:
- the privacy policies of restaurants using
chat2guest; - the privacy policies of Meta, WhatsApp, Facebook, Instagram, Google, Stripe, Apple, or other third-party platforms; or
- any data processing agreement ("DPA") or enterprise agreement between chat2guest and a restaurant customer.
3. Our Data Protection Roles
Depending on the context, chat2guest may act as either a controller or a processor / service provider.
3.1 When chat2guest acts as controller
chat2guest generally acts as a controller for personal data relating to:
- restaurant staff and admin users;
- account creation, login, authentication, and user management;
- platform administration, billing, contracting, and customer success;
- security, fraud prevention, audit logging, and abuse monitoring;
- support requests and product communications;
- our own business records; and
- limited operational metadata we need to operate and secure the platform.
3.2 When chat2guest acts as processor on behalf of a restaurant
For most restaurant guest / diner / end-customer data, chat2guest generally acts as a processor (or equivalent service provider) on behalf of the restaurant using the service. This typically includes:
- reservation and waitlist data;
- private-room enquiries and booking requests;
- chat, messaging, and review interactions handled for the restaurant;
- guest profile and communication history;
- AI-generated drafts and replies created in the restaurant's configured voice;
- restaurant-scoped knowledge entries, semantic recall, and answer-revalidation workflows derived from prior escalations or approved owner answers; and
- owner-approval, escalation, and manual-override workflows.
In those situations:
- the restaurant is usually the primary controller for the guest's personal data;
- the restaurant determines the relevant legal basis for the processing;
- chat2guest processes the data under the restaurant's instructions and contract, subject to applicable law; and
- guests should also review the relevant restaurant's own privacy notice.
3.3 Independent third-party controllers
Some third parties may process personal data as independent controllers for their own purposes, including:
- Meta / WhatsApp / Facebook / Instagram;
- Google;
- Stripe; and
- browser or device platform providers involved in notifications.
4. Personal Data We Process
The categories of personal data depend on how chat2guest is used.
4.1 Business-user and account data
We may process:
- name, business email address, phone number, job title, and restaurant affiliation;
- username, password hash, login status, role, memberships, and account preferences;
- invitation, password-reset, session, and refresh-token data;
- login timestamps and authentication metadata;
- support and onboarding communications; and
- profile settings, language settings, and notification preferences.
4.2 Restaurant operational data
We may process restaurant-related business data, including:
- restaurant identity and contact details;
- supported languages, public booking settings, hours, closures, table and seating configuration;
- notification email addresses;
- connected channel and integration configuration;
- owner notification phone number;
- payment / payout configuration metadata;
- restaurant-defined AI persona or reply-style training materials; and
- owner-approved knowledge-base answers and related trust / reinforcement metadata.
4.3 Guest, diner, and end-customer data
When a restaurant uses chat2guest, the platform may process:
- guest name;
- email address;
- phone number;
- reservation details such as date, time, party size, duration, source, status, and booking reference;
- waitlist and slot-offer details;
- private-room request details;
- guest notes, special requests, and dietary or accessibility information;
- guest language preferences;
- guest history, visit count, and related restaurant-side notes or tags;
- messaging or conversation content;
- review content and owner replies;
- channel identifiers such as WhatsApp number, Messenger / Instagram identifiers, review identifiers, Chatwoot contact identifiers, or web-widget identifiers;
- consent records and related timestamps; and
- semantic-knowledge records derived from customer questions and owner-approved answers, including question text, answer text, trust status, reinforcement counts, related guest or conversation identifiers, and vector embeddings used for similarity matching.
4.4 Potentially sensitive data
Depending on what a guest or restaurant user provides, chat2guest may process information that could be considered sensitive or special-category data under applicable law, for example:
- allergy or dietary information;
- disability or accessibility-related requests;
- information that may reveal religious beliefs through dietary preferences; and
- complaint or incident details shared in free-text messages.
We ask restaurants to avoid collecting more sensitive data than is necessary. Where such data is processed on behalf of a restaurant, the restaurant is responsible for establishing an appropriate legal basis or condition for that processing.
4.5 Payment and financial data
If deposit or payment features are enabled, we may process:
- payment status;
- payment intent or transaction identifiers;
- amount, currency, refund status, and related payment metadata;
- payment-related consent records; and
- limited billing or payout metadata for connected restaurant accounts.
chat2guest is designed so that payment card details are processed primarily by Stripe, not stored in the chat2guest application database as raw card data.
4.6 Technical, device, and security data
We may process:
- IP-derived security information, including hashed or truncated IP information;
- user agent, browser, operating system, and device information;
- push-notification subscription endpoints or device tokens;
- audit logs, error logs, and webhook verification data;
- API and integration status information;
- cookie and session data; and
- real-time connection metadata needed to deliver updates and availability changes.
4.7 Data we receive from Meta platforms (WhatsApp, Messenger, Instagram, Facebook)
Where a restaurant connects its Facebook Page, Instagram Business or Creator account, or WhatsApp Business account to chat2guest, we receive and process data made available to us through the Meta Graph API, the WhatsApp Business Cloud API, the Messenger Platform, the Instagram Messaging API, and related Meta endpoints, including:
- Restaurant-side connection data: Facebook Page ID, Page name, Page Access Token, Page-Scoped User IDs (PSIDs), Instagram Business Account ID, Instagram username, WhatsApp Business Account ID (WABA ID), WhatsApp phone-number ID, WhatsApp display name, webhook subscription metadata, and granted permission scopes.
- Guest-side identifiers received from Meta: Page-Scoped User IDs (PSIDs) for Messenger, Instagram-Scoped IDs (IGSIDs) for Instagram messaging and comments, the guest's WhatsApp phone number, the guest's display name as provided by the platform, profile picture URL where supplied, and conversation, message, and comment identifiers.
- Conversation content: the text, media, attachments, stickers, reactions, quick-reply payloads, and timestamps of messages and comments exchanged between the guest and the restaurant, together with delivery and read receipts where provided by the platform.
- Public review and engagement metadata received in connection with Facebook or Instagram surfaces that are made available to the restaurant.
We use this data only to operate the messaging, comment-management, booking, escalation, knowledge, and customer-support workflows described in this Privacy Policy and in the restaurant's instructions. We do not use this data for advertising, do not share it with data brokers, do not transfer it to ad networks, and do not use it to build cross-app profiles. We do not use Meta-platform data — including Business Solution Data — to create, develop, train, fine-tune, or improve any artificial intelligence or machine-learning models, except where that data is processed transiently to draft a reply within the conversation it relates to and is not retained for training purposes. Meta-platform data is processed in line with Meta's Platform Terms, Developer Policies, and the WhatsApp Business Solution Terms.
5. How We Collect Personal Data
We collect personal data:
- directly from you when you create an account, log in, contact us, or interact with a booking or chat flow;
- from the restaurant you interact with or work for;
- from messaging and review platforms configured by the restaurant, such as WhatsApp, Facebook Messenger, Instagram, or Google Business Profile;
- from payment providers such as Stripe;
- from email and notification services;
- automatically from browsers, devices, and application logs when the platform is used; and
- from AI-assisted workflows that generate drafts, infer booking context, link a guest identity across channels, or store approved answers for later restaurant-scoped recall.
6. Why We Process Personal Data and Our Legal Bases
Where chat2guest acts as controller, we rely on one or more of the following legal bases under the GDPR, as applicable:
- performance of a contract or steps at your request before entering into a contract;
- compliance with legal obligations;
- our legitimate interests, provided those interests are not overridden by your rights and interests; and
- your consent, where consent is required.
Where chat2guest acts as processor for a restaurant, the restaurant is primarily responsible for identifying the applicable legal basis for the processing of its guests' data.
6.1 Main processing purposes
| Purpose | Typical data involved | Typical legal basis |
|---|---|---|
| Provide and administer the platform | account, membership, restaurant configuration, session data | contract |
| Authenticate users and manage sessions | login credentials, refresh token data, security metadata | contract, legitimate interests |
| Operate reservations, waitlists, and private-room bookings | guest identity, booking details, notes, contact data | contract / pre-contract steps; restaurant-determined basis when chat2guest acts as processor |
| Run messaging, chat, and community inbox features | conversation content, channel identifiers, guest profile data | contract / legitimate interests; restaurant-determined basis where applicable |
| Draft AI replies, booking messages, and review responses | conversation content, booking context, review text, restaurant persona data | contract, legitimate interests, restaurant instructions |
| Build and maintain restaurant-scoped reusable knowledge entries | approved owner answers, prior escalations, customer questions, channel identifiers, embeddings, trust / reinforcement metadata | contract, legitimate interests, restaurant instructions |
| Escalate questions to restaurant owners and enable approval workflows | owner phone number, owner conversation content, customer conversation content | contract, legitimate interests, restaurant instructions |
| Send confirmation, reminder, waitlist, invitation, reset-password, and operational emails | contact data, booking data, account data | contract, legal obligation, legitimate interests, or consent depending on message type |
| Enable push notifications | push subscription data, device token, notification preferences | consent or legitimate interests, depending on the notification type and local law |
| Process deposits and payment events | payment metadata, booking identifiers, status and refund data | contract, legal obligations, fraud prevention, restaurant instructions |
| Maintain security, logs, rate limiting, and abuse prevention | token data, hashed IP data, user agent, audit trails | legitimate interests, legal obligations |
| Comply with legal requests and exercise or defend legal claims | any relevant data needed for the issue | legal obligation, legitimate interests |
| Improve and troubleshoot the service | operational metadata, logs, support records | legitimate interests |
6.2 Restaurant guest data handled on behalf of restaurants
When a restaurant uses chat2guest to interact with guests, common controller-side purposes may include:
- responding to customer enquiries;
- checking availability;
- creating, changing, confirming, or cancelling reservations;
- managing waitlists and slot offers;
- processing private-room requests;
- sending confirmations, reminders, or follow-up requests;
- handling complaints or escalations;
- responding to or drafting replies to public reviews; and
- reusing prior approved answers to similar guest questions within the same restaurant.
In those cases, the relevant restaurant usually determines whether the legal basis is, for example:
- performance of a contract;
- pre-contractual steps at the guest's request;
- legitimate interests;
- consent; or
- compliance with a legal obligation.
6.3 Our legitimate interests
Where we rely on legitimate interests, those interests may include:
- securing the platform and preventing abuse, fraud, spam, and unauthorized access;
- maintaining reliable platform performance, diagnostics, and service continuity;
- supporting our restaurant customers and users;
- keeping internal records and maintaining corporate governance;
- exercising, defending, or enforcing legal claims; and
- improving the safety, quality, and resilience of the service.
6.4 When you must provide data
Some personal data is necessary for us or the relevant restaurant to provide the requested service.
Examples:
- if a restaurant staff user does not provide required login or account data, the account cannot be created or authenticated;
- if a guest does not provide required reservation details, a booking or waitlist request may not be possible;
- if deposit payment is required, the necessary payment and checkout data must be provided to complete the booking; and
- if you block strictly necessary cookies or session mechanisms, some secure parts of the platform may not function.
Where data is optional, we will try to indicate that in the relevant form or flow.
7. AI and Automated Processing
chat2guest uses AI-assisted functionality to help restaurants manage conversations and reservations. Depending on the feature configuration, the platform may:
- draft customer replies;
- answer common questions;
- suggest or create bookings based on restaurant-defined rules;
- draft Google review replies;
- generate semantic embeddings from restaurant questions and approved answers so the system can recall relevant prior answers within that same restaurant;
- convert approved owner answers into reusable knowledge entries;
- periodically ask the owner to re-confirm trusted knowledge entries so stale answers are not reused indefinitely;
- summarize or structure owner-defined tone and persona instructions; and
- route difficult cases for human review or manual override.
Important points:
- AI outputs are generated from the conversation, booking context, restaurant settings, and configured tools.
- Reusable knowledge recall is designed to be restaurant-scoped rather than shared across restaurants.
- Restaurants can configure approval, escalation, and manual-override workflows.
- Public comment or review surfaces may be restricted so the system redirects users to a private booking channel instead of taking a reservation publicly.
- Where the platform uses rules-based automation to confirm, hold, or reject a booking, the decision is typically based on operational constraints such as availability, party size, opening hours, closure rules, seating logic, deposit status, and restaurant-defined settings.
chat2guest does not intend to use solely automated decision-making that produces legal effects or similarly significant effects about individuals within the meaning of Article 22 GDPR or Article 21 revFADP without appropriate safeguards. If a restaurant enables highly automated customer handling, the restaurant remains responsible for ensuring any required disclosures, opt-outs, and safeguards are in place.
7.1 AI transparency (EU AI Act, Article 50)
Where chat2guest or a restaurant uses chat2guest to operate an AI-driven conversational system that interacts directly with a natural person — for example AI-drafted replies sent through WhatsApp, Messenger, Instagram, the web widget, or a Google review reply — chat2guest is committed to ensuring that, by default, those persons are informed in a clear and distinguishable manner that they are interacting with, or receiving content generated by, an AI system, in accordance with Article 50(1) of the EU AI Act. This disclosure is not required where the AI involvement is already obvious to a reasonably well-informed person from the context of the interaction.
For text that is intended for publication on a public channel (for example, replies to public Google reviews), chat2guest is configured so that the text is generated and, where technically appropriate, marked in a way that supports machine-readable identification of artificially generated or manipulated content in line with Article 50(2) of the EU AI Act.
Restaurants that enable AI-assisted or auto-reply features must keep these transparency settings in place in their own guest-facing communications and notices, and remain responsible for any further obligations that apply to them as deployers of an AI system under the EU AI Act, including obligations on human oversight, instructions for use, and record-keeping.
8. Cookies, Session Data, and Similar Technologies
chat2guest uses cookies and similar technologies primarily for authentication, user preferences, and security. Where the ePrivacy Directive (2002/58/EC) and equivalent Swiss rules (Article 45c of the Federal Telecommunications Act) apply, cookies and similar storage that are strictly necessary to deliver an information-society service expressly requested by the user are exempt from prior consent; non-essential cookies are not loaded by default and would require consent before use.
At the time of writing, the application is designed to use mainly the following categories:
8.1 Strictly necessary cookies
These are used to provide the service securely and cannot be switched off if you want to use the authenticated dashboard.
Examples may include:
refresh_token: httpOnly authentication cookie used to maintain a logged-in session;remember_session: stores the user's "keep me signed in" choice so session rotation works correctly;- security-related session or request state information.
8.2 Preference cookies
These remember user-selected settings such as:
- interface language (
locale); and - last selected restaurant context (
last_restaurant).
8.3 Push notifications and service workers
If you enable browser notifications, the application may:
- register a service worker;
- store a push subscription endpoint and cryptographic keys; and
- send notification payloads through browser push services or Apple push infrastructure.
8.4 No broad marketing analytics by default
Based on the current codebase, chat2guest does not appear to use broad third-party advertising analytics by default. If analytics, marketing cookies, or similar tracking technologies are added later, this Privacy Policy and any required consent mechanism should be updated before those tools are activated.
9. When We Share Personal Data
We may disclose personal data to the following categories of recipients, only where necessary:
- the relevant restaurant customer and its authorized staff;
- hosting, cloud, database, backup, and infrastructure providers;
- communications and inbox providers, including self-hosted or managed Chatwoot environments;
- AI model and AI-infrastructure providers;
- payment and payout providers, including Stripe;
- messaging and social platform providers such as Meta / WhatsApp / Facebook / Instagram;
- Google services, including Google Business Profile integrations;
- email delivery providers;
- browser, mobile, and device notification providers;
- professional advisers, auditors, insurers, or potential acquirers;
- regulators, law enforcement, courts, or other authorities where required; and
- other processors and subprocessors engaged to help us provide the service.
chat2guest does not sell personal data, does not share personal data for cross-context behavioural advertising, and does not engage in profiling for advertising purposes. The current codebase does not indicate broad third-party behavioural advertising tracking by default.
A current list of our sub-processors, together with a copy of our standard data processing agreement (Article 28 GDPR) where applicable, is available on request to [email protected].
9.1 Examples of service providers or platforms used by the product
Depending on how chat2guest is configured, these may include:
- OpenAI and/or Anthropic for AI features;
- Stripe for deposit collection and related payment workflows;
- Resend for email delivery;
- Meta services for WhatsApp, Facebook, and Instagram integrations;
- Google for Google Business Profile reviews and related OAuth flows;
- Apple Push Notification service (APNs) and browser push infrastructure; and
- hosting providers used for databases, queues, application hosting, and backups.
Some deployments may be self-hosted or customer-hosted, so the exact subprocessor stack may vary by environment and contract.
9.2 Google API Services User Data Policy (Limited Use)
Where chat2guest accesses data from the Google Business Profile APIs or other Google APIs on a restaurant's behalf, chat2guest's use and transfer of information received from those APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide or improve user-facing features that are prominent in chat2guest's user interface (for example, review syncing and owner-approved or AI-drafted review replies), is not transferred to third parties except as necessary to provide or improve those features, to comply with law, or as part of a merger, acquisition, or sale of assets with the relevant user's explicit consent, is not used to serve advertisements, and is not read, retained, or used for any other purpose by a human except (a) with the relevant user's affirmative agreement, (b) to comply with applicable law, (c) for security purposes, or (d) to perform internal operations where the data has been aggregated and anonymised.
A current list of sub-processors that may receive Google user data — together with the legal mechanism that governs any international transfers — is published at https://chat2guest.com/legal/subprocessors.
10. International Data Transfers
chat2guest may involve international transfers of personal data, including transfers outside the European Economic Area ("EEA") and outside Switzerland, for example where service providers, AI providers, messaging platforms, or payment providers operate internationally.
When we transfer personal data internationally, we aim to use appropriate safeguards, such as:
- an adequacy decision adopted by the European Commission (Article 45 GDPR) or recognised by the Swiss Federal Council (Article 16 revFADP), including, where applicable, the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework;
- the European Commission's Standard Contractual Clauses (Decision 2021/914), together with any necessary transfer impact assessment and supplementary measures following the Schrems II line of case-law;
- the Swiss Federal Data Protection and Information Commissioner's recognised version of the Standard Contractual Clauses; or
- another lawful transfer mechanism, including a derogation under Article 49 GDPR or Article 17 revFADP where strictly applicable.
Where required, you may request more information, including a copy of the relevant safeguards, by contacting us at [email protected].
11. How Long We Keep Personal Data
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
The exact period depends on the data type, the service configuration, the relevant restaurant's instructions, legal obligations, and the need to resolve disputes, maintain security, and enforce contracts.
11.1 Examples from the current product design
- Admin refresh-token cookies and server-side refresh-token records: typically up to 30 days unless revoked earlier.
- Access tokens: short-lived and designed to be held in memory for the active session rather than persistently stored in readable browser storage.
- Guest profile PII: may be subject to a restaurant-configured retention period; the current codebase uses a default guest-profile retention setting of 730 days and can automatically anonymize eligible guest profile data after the configured period if no newer reservation exists.
- Stripe webhook event payloads: designed to be retained for about 90 days after processing for debugging and replay, then deleted.
- Push subscriptions and device tokens: retained until unsubscribed, deleted, invalidated, or no longer needed.
- Google review cache and owner-reply history: retained while the review-management feature is active and for operational history, unless deleted or de-scoped according to system logic or contract.
- Restaurant knowledge entries, vector embeddings, and reinforcement history: retained while the knowledge feature is active and until archived, deleted, or otherwise removed under the applicable contract, tenant lifecycle, or internal retention rules. Owner-revalidation prompts are designed to encourage periodic review (current default: re-confirmation cadence of approximately 180 days) so that stale answers are not reused indefinitely.
- Audit logs and security logs: retained as necessary for accountability, security, legal compliance, fraud prevention, and incident response. Audit records are deliberately written to avoid raw personal data and to store IP information only in truncated or hashed form.
Some data may remain in backups, archived logs, or immutable audit records for a limited additional period as part of normal disaster recovery, security, or legal-hold processes.
12. Security Measures
We use technical and organizational measures designed to protect personal data, including measures such as:
- role-based access controls and a least-privilege role model (Owner, Manager, Host, Viewer, Platform Admin);
- authentication using short-lived access tokens (approximately 15 minutes) and rotated refresh tokens (up to 30 days), bound to httpOnly cookies;
- password hashing using bcrypt;
- hashing or truncation of IP-derived security data, so that raw IP addresses are not stored;
- encryption at rest of selected sensitive fields, including Meta Page Access Tokens, Meta long-lived user tokens, Instagram tokens, Google OAuth access and refresh tokens, and Stripe Connect account identifiers;
- HMAC-based webhook verification (including for Meta and Stripe webhooks) and request validation;
- append-only audit logging for sensitive actions, including platform-administrator impersonation start- and stop-events;
- rate limiting and abuse controls on public endpoints, sign-in flows, and booking submissions;
- environment-based secret management; and
- data minimization in logs and operational workflows.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12.1 Personal data breaches
If we become aware of a personal data breach affecting personal data for which chat2guest is controller, we will notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it, in line with Article 33 GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will also communicate the breach to those individuals without undue delay, in line with Article 34 GDPR.
Where the revised Swiss Federal Act on Data Protection applies, we will notify the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible in accordance with Article 24 revFADP.
Where chat2guest processes personal data on behalf of a restaurant, we will notify the restaurant of any relevant personal data breach without undue delay so that the restaurant, as controller, can meet its own notification obligations.
13. Your Rights
Your rights depend on the role we have in the processing and the law that applies to you.
13.1 If chat2guest is the controller
Subject to applicable law and any exceptions, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing;
- receive your data in a portable format where applicable;
- withdraw consent at any time where processing is based on consent;
- ask for human review where automated decision rules materially affect you and the law gives you that right; and
- lodge a complaint with a supervisory authority.
13.2 If chat2guest is processing data for a restaurant
If your personal data is being processed by chat2guest on behalf of a restaurant, you should normally direct your request first to that restaurant as the primary controller.
Where appropriate, chat2guest may assist the restaurant in responding to:
- access requests;
- correction requests;
- deletion or anonymization requests;
- portability requests;
- objection or restriction requests; and
- requests relating to AI-assisted or automated processing.
13.3 How and when we respond
Where chat2guest is controller, we will respond to a verified data-subject request without undue delay and, in any case, within one month of receipt, as required by Article 12(3) GDPR. That period may be extended by up to two further months where the request is complex or where we receive a high volume of requests, in which case we will inform you of the extension and the reasons for it within the first month. Comparable timeframes apply under the revised Swiss FADP.
We do not charge a fee for handling reasonable requests. Where a request is manifestly unfounded or excessive — in particular because of its repetitive character — we may charge a reasonable fee or refuse to act on the request, as permitted by Article 12(5) GDPR.
We may need to verify your identity before acting on a request in order to protect your personal data and the data of others.
13.4 Requesting deletion of data we received from Meta platforms
If you would like us to delete personal data that we received about you through Meta platforms (WhatsApp, Messenger, Instagram, or Facebook) — including the identifiers and conversation content listed in section 4.7 — you can request deletion at any time using either of the following methods:
- visit our data-deletion instructions page at https://chat2guest.com/legal/data-deletion and follow the steps described there; or
- email us at [email protected] with the subject line "Meta data deletion request" and, where you can, identify the restaurant Page, Instagram account, or WhatsApp number you interacted with so we can locate the relevant records.
Once we have verified your request, we will delete or irreversibly anonymise the relevant personal data within the timeframe set out in section 13.3, subject to any limited retention required by law, by Meta's platform terms, or for the establishment, exercise, or defence of legal claims. Some data may remain in backups for a limited additional period until those backups are rotated out in the normal course of business.
If your request concerns data primarily controlled by a restaurant using chat2guest (for example, conversation history that a restaurant continues to need to operate its service to you), we will forward your request to that restaurant and assist as described in section 13.2.
14. Additional Information for EU / EEA Data Subjects
If the GDPR applies, you also have the right to lodge a complaint with the supervisory authority in your habitual place of residence, place of work, or place of the alleged infringement.
chat2guest is established in Switzerland, which is not an EU or EEA member state, and does not currently have a main establishment in the European Union within the meaning of Article 4(16) GDPR. The one-stop-shop mechanism under Article 56 GDPR therefore does not currently apply, and the GDPR generally only applies to chat2guest's processing where chat2guest offers the Service to persons in the European Union or monitors their behaviour within the meaning of Article 3(2) GDPR (see Section 1).
If chat2guest establishes a Dutch operation that becomes its main establishment in the EU within the meaning of Article 4(16) GDPR, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) is expected to act as chat2guest's lead supervisory authority for cross-border processing under Article 56 GDPR. We will update this Privacy Policy when that change takes effect. The Autoriteit Persoonsgegevens may be reached at https://www.autoriteitpersoonsgegevens.nl/en.
15. Additional Information for Swiss Data Subjects
Because chat2guest is established in Switzerland, the revised Swiss Federal Act on Data Protection ("revFADP", in force since 1 September 2023) applies to its processing of personal data, and the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority. The FDPIC may be reached at https://www.edoeb.admin.ch/en.
Under the revFADP, you may have rights including, where applicable:
- the right to be informed about the collection of your personal data (Articles 19–21 revFADP);
- the right to access information about the processing of your personal data (Article 25 revFADP);
- the right to request correction of incorrect data (Article 32 revFADP);
- the right to request destruction or deletion where the legal conditions are met;
- the right to object to certain processing;
- the right to request restriction or blocking in appropriate cases;
- the right to data portability (Article 28 revFADP) where the legal conditions are met; and
- the right to obtain a human review of, and to express your point of view on, an automated individual decision that has a legal effect or significantly affects you (Article 21 revFADP), where applicable.
You may lodge a complaint with the FDPIC at https://www.edoeb.admin.ch/en.
16. Children
chat2guest is a business-focused service for restaurants and is not directed to children. We do not knowingly create direct end-user accounts for children.
Because restaurants may take reservations for family groups, children's information may still appear in booking notes or messages if voluntarily provided by an adult customer or entered by restaurant staff. We ask restaurants not to enter unnecessary data about minors.
17. Third-Party Platforms and Restaurant Notices
If you interact with a restaurant through WhatsApp, Facebook, Instagram, Google, Stripe, or another third-party platform, your data may also be processed under that platform's own privacy terms.
If you book or message a restaurant through a chat2guest-powered page, please also review:
- the relevant restaurant's privacy notice;
- the restaurant's terms and conditions; and
- any payment-provider terms presented during checkout.
The current product design allows restaurants to publish their own privacy-policy and terms links in public booking flows, and those restaurant-specific documents remain important for end-customer transparency.
17.1 WhatsApp connectors
WhatsApp connectivity can be configured either through Meta's official WhatsApp Business Cloud API or through a QR-code-based connector that uses a consumer WhatsApp account built on the open-source Baileys library. The official Cloud API is the recommended option for production use, and is the option we recommend for restaurants serving guests in the EU/EEA or Switzerland.
Geographic availability of the official WhatsApp Business Cloud API. Under the WhatsApp Business Solution Terms as updated with effect from 15 January 2026, providers and developers of artificial intelligence or machine-learning technologies — including large language models, generative artificial intelligence platforms, and general-purpose AI assistants — are restricted from using the WhatsApp Business Solution for primary functionality, except where the recipient has registered a phone number with a country code from the European Economic Area or Brazil. chat2guest operates primarily as an AI-assisted restaurant communications platform and accordingly enables the WhatsApp Business Cloud API channel only for restaurants whose end-customers have registered EEA or Brazilian WhatsApp numbers. Restaurants serving guests in other regions can still use the QR-code-based connector (subject to the conditions in this section) or another supported channel until WhatsApp's policy changes, the relevant antitrust proceedings result in different rules, or chat2guest qualifies for a different category.
Where a restaurant nevertheless chooses to use the QR-code-based connector:
- the relevant guest messaging data is still handled under the protections described in this Privacy Policy and in the applicable contract;
- WhatsApp's own terms apply to the underlying account, and the QR-code-based connection method is not an officially supported integration and may contravene WhatsApp's terms of service;
- the underlying account may at any time be blocked, throttled, banned, or otherwise restricted by Meta, with no recourse from chat2guest, and continuity of the channel therefore cannot be guaranteed; and
- the restaurant assumes the operational and compliance risk of choosing this connector, including any obligations to inform guests about the channel they are using.
Restaurants are responsible for choosing which connector to use and for any guest disclosures they consider appropriate.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- the law;
- the platform's features;
- our security practices;
- our service providers; or
- our business operations.
When required, we will provide notice of material changes by updating this page, changing the "Last updated" date, or using another appropriate communication method.
19. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights where chat2guest is the controller, please contact:
chat2guest
Maschinengasse 10, 6330 Cham, Switzerland
Email (general): [email protected]
Email (privacy and data-deletion requests): [email protected]
Privacy / data-deletion instructions: https://chat2guest.com/legal/data-deletion
If your request concerns a reservation, waitlist entry, chat, review interaction, or other guest data processed for a restaurant, please contact the relevant restaurant first. If necessary, that restaurant can coordinate with chat2guest.
20. Optional Annex: Current Data Categories and Features Reflected in the Codebase
This annex is included so the public policy can be matched to the current product architecture.
20.1 Features currently reflected in the codebase
- multi-tenant restaurant admin accounts and role-based access (Owner, Manager, Host, Viewer);
- platform-administrator impersonation of restaurant accounts for authorized support purposes, with start- and stop-events recorded in the audit log;
- public booking pages and guest self-cancellation;
- waitlist and slot-offer flows, with auto-expiry of stale entries where configured;
- private-room public booking and request flows;
- AI-assisted messaging and booking workflows, including per-tenant agents that operate within tool restrictions enforced by surface (for example, certain booking tools are not made available on public comment or review surfaces);
- restaurant-scoped knowledge capture, semantic similarity search, trust scoring, and owner revalidation workflows, with optional deduplication of near-identical questions;
- owner escalation and approval flows over messaging channels;
- routing of restaurant messaging through a Chatwoot inbox that is provisioned per restaurant tenant;
- Google review syncing, AI-assisted drafting, and optional owner-approved or auto-posted replies;
- Stripe-connected deposit workflows using Stripe Connect Express accounts per restaurant;
- browser and device push notifications (Web Push and APNs);
- guest-profile enrichment across channels via channel-identity linkage; and
- data-subject-request workflows and automated guest-profile anonymisation after a restaurant-configured retention period.
20.2 Examples of data fields currently reflected in the codebase
Examples include:
- account name, email, phone, role, restaurant membership, and login history;
- guest first name, last name, email, phone, preferred language, dietary notes, internal notes, tags, and visit history;
- reservation reference, confirmation token, party size, reservation date, source, deposit status, and refund metadata;
- waitlist guest details, requested date, preferred time window, claim or cancellation token, and consent records;
- push subscription endpoints, device tokens, user agents, and notification preferences;
- Google review author name, profile link, review text, star rating, owner reply, and AI draft;
- social or messaging channel identifiers used to link a conversation to a guest profile; and
- knowledge-entry question text, answer text, trust state, reinforcement counts, linked guest or conversation identifiers, and embedding-derived similarity records;
- hashed refresh-token, invitation-token, reset-token, and IP-derived security data.