Privacy policy
Last updated 2026-05-22
This policy summarises how Deskbell handles personal data. For the full text of our security controls see /security.
What we collect
- Restaurant owner account data (name, email, phone) — to bill and contact you
- Restaurant configuration (menu, hours, capacity) — to operate the agent
- Caller data when a customer phones the AI — phone number, transcribed speech, optionally audio recording (only when you turn it on)
- Payment metadata via Stripe — we hold token references only, never card numbers
What we don't collect
- Card numbers, CVCs, expiration dates
- Government-issued ID or biometric data
- Location beyond what callers volunteer in conversation
- Children's data (under 13 — we are not a children's service)
Text messaging (SMS)
When a customer places an order or reservation by phone with a restaurant that uses Deskbell, Deskbell sends that customer transactional confirmation text messages on the restaurant's behalf — the order/reservation total, a confirmation link and code, and related status updates. This is a strictly transactional messaging program; we do not send marketing or promotional texts.
- Consent (opt-in): the customer provides their mobile number and agrees to receive a confirmation text during the phone call with the restaurant.
- Message frequency depends on how often the customer orders — typically one confirmation text per order or reservation.
- Opt-out: reply STOP to any message to unsubscribe; texting to that number stops immediately. Reply HELP for help. Message and data rates may apply.
- We do not sell or share mobile phone numbers or SMS opt-in data with third parties or affiliates for their own marketing or promotional purposes. Numbers are used only to deliver the confirmation texts described above, sent through our messaging provider (e.g. Twilio).
Your rights (GDPR / CCPA / state laws)
Restaurant owners can export and delete their data at any time from Settings → Danger Zone. For customer-side requests (a diner asking for their data), email privacy@deskbell.ai — we'll respond within 30 days per GDPR Art. 12.
Retention
Confirmed orders are anonymised after 7 years (tax records). Call recordings (when you enable them) are dropped after 12 months. SMS opt-outs are kept 5 years per TCPA. Detailed schedule in our compliance doc.
Questions? Email privacy@deskbell.ai.