ProjectApp Personal Data Processing Policy

Last updated: October 7, 2026.

This is a courtesy translation. The Spanish version is the official text and prevails in case of conflict. This policy applies to Waiter and its users. Use of the projectapp.co website and ProjectApp’s development services is also governed by the website privacy policy.

1. Who we are

ProjectApp is the trade name of SOFTPROJECTAPPCO, a business owned by GUSTAVO ADOLFO PEREZ PEREZ, identified with Colombian tax ID (NIT) 1021513348-7 (national ID 1021513348), domiciled at Calle 30A #79-42, Medellín, Colombia, phone +57 323 812 2373 and email team@projectapp.co (“ProjectApp”, “we”).

ProjectApp develops and operates Waiter, a cloud system for restaurants: point of sale, floor, kitchen, inventory, reservations, customers and points, QR digital menu, online payments, an AI assistant on the menu and on WhatsApp, invoicing and reports.

2. Our role regarding your data

  • When you are a customer of a restaurant that uses Waiter (diner, person making a reservation or writing on WhatsApp), the controller of the processing is that restaurant: it decides which data it asks for and why. ProjectApp acts as processor: it processes your data on the restaurant’s behalf, only to provide the Waiter service and according to its instructions. To exercise your rights you may contact the restaurant or us, and we will forward your request.
  • When you are an employee of a restaurant that uses Waiter, the controller is the restaurant, as your employer, and ProjectApp is the processor.
  • When you are the owner or representative of a restaurant that subscribes to Waiter, a member of the ProjectApp team or a visitor of projectapp.co, ProjectApp is the controller.

3. Data we process

3.1 Restaurant customers (diners)

  • If you use the digital menu without signing up: a random identifier stored in a cookie and, if you type it, your name or nickname.
  • If you create an account on a restaurant’s menu:
    • name, email and, if you provide it, mobile number;
    • password, stored hashed with a one-way algorithm;
    • allergies or foods you avoid, if you write them down;
    • whether you agree to receive news, which comes unchecked;
    • the record that you accepted this policy;
    • favorite dishes, rewards and prizes, and the reviews and ratings you leave.
  • If the restaurant registers you as a customer:
    • name, phone, email;
    • ID type and number;
    • address and city;
    • points, rewards and their transaction history.
  • Orders:
    • what you order;
    • kitchen notes and the allergies you indicate;
    • the table;
    • for deliveries, address and phone;
    • tip, payments and refunds.
  • Reservations:
    • name, phone and email;
    • party size, date and time, notes;
    • deposit and its status.
  • Online payments:
    • the amount, payment method, status and transaction reference;
    • for cards, only the card network (Visa, Mastercard or American Express).
  • Electronic invoicing: the buyer details you ask to include on the invoice:
    • name or company name;
    • ID type and number;
    • email, address and city.
  • Conversations with the assistant: the messages you write in the menu chat or on WhatsApp, the assistant’s replies and the dishes it suggested.
  • WhatsApp, when the restaurant connects its number to Waiter:
    • your WhatsApp number and profile name;
    • the content of the messages you send to the restaurant and those the restaurant or its assistant send you;
    • the date and time of each message and its status (sent, delivered, read).

3.2 Restaurant staff

  • Name, username, email, role and assigned locations.
  • Shift schedule and clock-in/clock-out records, to calculate hours worked.
  • Hourly rate, if the owner records it.
  • Sales and tips from the orders they register.
  • The actions they take in the system (change history).
  • Password hashed with a one-way algorithm.

We do not store your location or your IP address when you sign in.

3.3 Restaurant owners and the ProjectApp team

  • Company contact and billing details.
  • Users and hashed passwords.
  • Second authentication factor.
  • Access logs and records of support actions.

3.4 Visitors of projectapp.co

  • The data you send us through the form or by email.

4. Data we do NOT process

  • We do not receive or store your card number. You send it directly to the payment gateway (Wompi), which returns a token that cannot be used to charge you anywhere else.
  • We do not use analytics or advertising tools to track you on the menu or at the point of sale.
  • We do not sell or rent personal data.
  • We do not use WhatsApp messages or conversations with the assistant for advertising or to train artificial intelligence models.
  • Your location is not sent to our servers. If you allow it on the digital menu, it is used only on your phone to show the distance to the restaurant.

5. How we use the data

  • Providing the Waiter service to the restaurant:
    • taking, preparing, charging and delivering orders;
    • managing reservations, customers, points and rewards;
    • invoicing;
    • running the cash register and inventory;
    • generating reports.
  • Serving you on the digital menu and on WhatsApp with the assistant. The assistant answers questions about the menu, recommends dishes and builds orders that are sent to the kitchen only after you confirm them.
  • Processing online payments and reservation deposits.
  • Emailing you what you asked for: reservation confirmations, sales documents, password recovery codes.
  • Sending you the restaurant’s news and promotions, only if you agreed to it. You can withdraw your consent at any time.
  • Calculating staff hours, sales and tips as a basis for the restaurant’s payroll.
  • Security:
    • preventing unauthorized access and fraud;
    • limiting sign-in attempts;
    • keeping a record of who changed what.
  • Providing technical support to the restaurant. We only access the restaurant’s account with its express permission, for a limited time, and the access is logged.
  • Complying with legal, accounting and tax obligations.

6. Artificial intelligence

The Waiter assistant uses a language model from OpenAI to understand your message and propose a reply.

What we send to OpenAI:

  • the text you write;
  • the latest messages of the conversation;
  • the restaurant’s menu (dishes, descriptions, ingredients and prices).

What we do NOT send: your name, email or phone. We ask OpenAI not to store the requests, and its terms for API customers state that it does not use this data to train its models.

That is why we ask you not to write sensitive data in the chat that is not needed for your order. Put allergies in the allergies field of your order or account: that way they reach the kitchen.

Assistant limits: it cannot charge, give discounts, change prices or confirm orders on its own. Prices and totals are calculated by the restaurant’s system.

7. WhatsApp

When a restaurant connects its WhatsApp Business number to Waiter, we use Meta’s official platform (WhatsApp Business Platform).

When you write to the restaurant, Meta provides us with:

  • your number;
  • your profile name;
  • your messages;
  • the delivery status of the messages.

We use them only to:

  • let the restaurant and its assistant reply to you;
  • record your orders and reservations;
  • send you updates about them, for example “your order is ready”.

What we do not do:

  • we do not send you promotional WhatsApp messages without your consent;
  • we do not share your number or messages with other restaurants.

You can write “humano” (human) or ask to talk to a person at any time. You can also block the restaurant’s number to stop receiving messages.

Meta processes the data under its own policies, available at whatsapp.com/legal.

8. Who we share data with

Only with those we need to provide the service, under contracts that require them to protect it:

WhoPurposeWhere
The restaurant you useIt is the controller of your data: it prepares your order, serves you and invoices youColombia
Meta Platforms (WhatsApp Business Platform)Sending and receiving the restaurant’s WhatsApp messagesUnited States and other countries
OpenAILanguage model for the assistant (see section 6)United States
Wompi (Bancolombia)Processing online payments and depositsColombia
Amazon Web Services (AWS)Hosting Waiter and its databasesUnited States
Google (Google Workspace)Sending service emailsUnited States
DIAN and the restaurant’s electronic invoicing providerValidating electronic invoices, when the restaurant invoicesColombia
GoogleScreen fonts and Google Maps “Directions” links (Google receives your IP address when loading them)United States
AuthoritiesWhen a law or court order requires itColombia

Some of these providers are outside Colombia. In those cases we make an international transmission to processors that must handle the data only according to our instructions and with equivalent security measures.

9. How long we keep data

DataPeriod
Diner accountUntil you ask us to delete it or after 24 months without use
Conversations with the assistant (menu and WhatsApp)90 days from the last message; you can delete the menu conversation at any time from the chat
Orders, payments, sales documents and reservationsThe period required by accounting and tax rules (up to 10 years); contact details not needed for that obligation are anonymized after 24 months
Customers registered by the restaurantWhile the restaurant is a Waiter customer and needs them, or until you request their deletion
Restaurant staffWhile the person works at the restaurant and up to 5 years afterwards, as payroll and hours records
Change history and security logs2 years
Session cookiesUp to 12 hours on the menu; until the end of the shift at the point of sale
When a restaurant leaves WaiterWe hand over its data if requested and delete it after 90 days, except what the law requires us to keep

10. Your rights

Under Colombian Law 1581 of 2012, you can:

  • access, update and correct your data;
  • request proof of the authorization you gave;
  • know how it has been used;
  • revoke the authorization and request deletion, when there is no legal or contractual duty to keep it;
  • access your data free of charge;
  • file complaints with the Superintendence of Industry and Commerce (SIC) after completing the process with us or with the restaurant.

How to exercise them: write to team@projectapp.co stating:

  • your name;
  • the restaurant;
  • the contact detail you used with Waiter (email or WhatsApp number);
  • what you are requesting.

If you are a restaurant customer, you can also ask the restaurant directly.

Response times:

  • inquiries: 10 business days, extendable by 5 more;
  • claims (correction, update, deletion or revocation): 15 business days, extendable by 8 more.

We will let you know if we need the extension.

Data deletion: the step-by-step guide is at projectapp.co/waiter/data-deletion.

11. Security

  • Encrypted communication (HTTPS).
  • Passwords stored with one-way algorithms, and codes and sessions stored as cryptographic hashes.
  • Encrypted payment gateway credentials.
  • Strict separation of each restaurant’s information.
  • Mandatory second factor for the ProjectApp team.
  • Support access only with the restaurant’s permission, time-limited and logged.

If an incident affects your data, we will inform the restaurant, the SIC and you when the law requires it.

12. Cookies and storage on your device

On the digital menu:

  • a session cookie (waiter_diner, up to 12 hours) that identifies you at the table;
  • a cookie that remembers you already saw the restaurant’s introduction (1 year);
  • in your browser, your menu preferences, which you can clear from the menu itself.

At the point of sale:

  • staff session cookies;
  • on the restaurant’s device, a temporary copy of working information, to keep operating without internet.

Waiter does not use advertising or analytics cookies.

13. Minors

Waiter is not directed at minors. If a minor uses a restaurant’s menu, they must do so with the authorization of their legal representative, and their data is processed respecting their best interests.

14. Changes to this policy

If we change it, we will publish the new version here with its date. If the change is significant, we will notify restaurants and, where appropriate, you.

15. Contact

team@projectapp.co · +57 323 812 2373 · Calle 30A #79-42, Medellín, Colombia.

ProjectApp · SOFTPROJECTAPPCO — GUSTAVO ADOLFO PEREZ PEREZ · NIT 1021513348-7 · Calle 30A #79-42, Medellín, Colombia · Phone +57 323 812 2373 · team@projectapp.co

© 2026 ProjectApp. Waiter is a ProjectApp product.

Chat with our website development team