TBLE

Privacy Policy

Last updated: July 2026

1. Who we are

NobleTable is a multi-tenant hospitality operating system that helps restaurants run their business — a restaurant website builder, QR ordering, point of sale (POS), kitchen display, reservations, inventory, CRM, analytics, and an AI website builder called Noble AI. NobleTable is provided by Noxira for Software and Artificial Intelligence Solutions W.L.L(“Noxira”, “we”, “us”), a limited liability company registered in the State of Qatar under Commercial Registration No. 247351. This Privacy Policy explains what personal data we handle, why, and the choices and rights you have.

For questions about this policy or to exercise your rights, contact us at nobletable.org@gmail.com.

2. Controller and processor roles

NobleTable operates in two distinct roles depending on the data involved, and this distinction matters for who is responsible:

  • For restaurant owner and staff accounts (the people who sign up to use NobleTable), and for our own website and billing operations, NobleTable is the controller.
  • For the restaurants’ own guest data that flows through the platform — for example a diner’s reservation details or a QR order — NobleTable acts only as a processor. The restaurant using NobleTable is the controller of its guests’ data. We process that data on the restaurant’s instructions to provide the service, and guests should direct their privacy requests to the restaurant they interacted with.

3. What data we collect and why

We collect and process the following categories of data:

  • Account data — for restaurant owners and staff: name, email address, phone number and a hashed password. Used to create and secure accounts, authenticate users, and communicate about the service. We never store passwords in plain text.
  • Business content — menus, orders, reservations, inventory records, CRM entries and other content a restaurant creates in NobleTable. Used to operate the features the restaurant has enabled.
  • Guest data (as processor)— data belonging to a restaurant’s own guests that passes through the platform, such as reservation names, emails and phone numbers, and QR-order details. Processed on behalf of the restaurant to deliver reservations and ordering.
  • Payment data — handled by our payment processor. Full card numbers are never stored by NobleTable; we retain only limited billing metadata (such as a subscription status and the last four digits or a token supplied by the processor) needed to manage subscriptions.
  • Usage and device data — cookies and similar technologies required to keep you signed in and to remember essential preferences. See our Cookie Policy. Analytics are not yet enabled.
  • AI builder inputs — the descriptions, menu text and prompts you submit to Noble AI, used to generate a website and menu for you. See sub-processors below for how this data is processed.

4. Sub-processors

We rely on a small set of trusted service providers (sub-processors) to run NobleTable. Each processes data only as needed to provide their service to us:

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting and content delivery (CDN).
  • Resend — delivery of transactional email (for example account and notification emails).
  • Groq — the large language model provider that powers Noble AI. Data you submit to the AI builder may be processed by this provider to generate your site and menu. Avoid entering sensitive personal data into the AI builder.
  • Payment processor — a payment gateway (such as Stripe and/or regional gateways) once billing is live, to process subscription payments securely.

5. International transfers

NobleTable is operated from Qatar, and some of our sub-processors store or process data in other countries. Where personal data is transferred outside Qatar, we take reasonable steps to ensure it is protected in a manner consistent with Qatar’s Law No. (13) of 2016 (Personal Data Privacy Protection Law, or “PDPPL”) and, for international users, with GDPR-style safeguards such as reputable providers and appropriate contractual protections.

6. Data retention

We keep personal data only for as long as needed for the purposes described here. Account and business data are retained while your account is active and for a reasonable period afterwards to meet legal, accounting and dispute-resolution obligations, then deleted or anonymised. Guest data processed on behalf of a restaurant is retained per that restaurant’s instructions and deleted when no longer required or on the restaurant’s request.

7. How we protect your data

We apply technical and organisational measures appropriate to the risk, including:

  • Tenant isolation— strict per-restaurant data separation enforced at the database layer using row-level security (RLS), so one restaurant cannot access another’s data.
  • Encryption in transit — data is transmitted over encrypted connections (HTTPS/TLS).
  • Hashed credentials — passwords are stored as one-way hashes, never in plain text.
  • Least-privilege access — access to production data is limited to what is necessary to operate and support the service.

No method of transmission or storage is completely secure, but we work to protect your data and to promptly address any issues.

8. Your rights

Subject to applicable law, and honouring GDPR-style data-subject rights for international users, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data, subject to legal retention requirements.
  • Objection — object to or ask us to restrict certain processing.

To exercise any of these rights, email us at nobletable.org@gmail.com. We may need to verify your identity before acting on a request. If you are a guest of a restaurant using NobleTable, please contact that restaurant directly, as it is the controller of your data; we will support them in responding.

9. Children’s data

NobleTable is a business tool intended for restaurant operators and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of NobleTable after an update means you accept the revised policy.

11. Contact

Questions about privacy? Email nobletable.org@gmail.com or reach us at noble-table.com. See also our Company Information page.