booteek AI Limited ("Company", "we", "us", "our") operates the booteek platform ("Service"). This Privacy Policy explains how we collect, use, process, and protect your personal data when you use our Service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller: booteek AI Limited
Registration: England and Wales, Company Number: 13426132
We process personal data under the following legal bases:
Contract Performance: To provide our Service and fulfill our contractual obligations
Legitimate Interests: To improve our Service, prevent fraud, and ensure security
Legal Obligation: To comply with applicable laws and regulations
Consent: Where explicitly provided for specific processing activities
3. Data We Collect
3.1 Information You Provide Directly
Account Information: Name, email address, phone number, business name
Business Profile Data: Restaurant type, location, staff information (non-personal aggregated data only)
Payment Information: Processed by Stripe (we do not store full payment card details)
Communication Data: Support messages, feedback, and correspondence
3.2 Information Collected Automatically
Usage Data: Pages visited, features used, time spent, click patterns
Device Information: IP address, browser type, operating system, device identifiers
Performance Data: Service performance metrics, error logs (anonymized)
3.3 Third-Party Platform Data
With your active use of the booteek Chrome Extension on platforms where you manage your venue, we collect the following publicly available review data so that you can aggregate, analyse, and respond to reviews from all your platforms in one place:
Public reviews: Review text, star rating, relative publish date, and publicly-displayed reviewer name as shown on the platform (Google Business Profile, Google Maps, TripAdvisor, OpenTable, TheFork, Facebook, Instagram, SevenRooms, DesignMyNight). We only ingest reviews for venues you have linked in the extension.
Owner responses: Your own published responses to reviews, so that the AI can learn your voice.
Venue metadata: Business name, address, category, aggregate rating and review count, opening hours, photos, menu — sourced from Google Places API, Serper Maps, and SerpAPI.
Google Business Profile data (optional): If you connect your GBP via OAuth, we access business information, listings, and review data with your explicit authorization.
Analytics data: Website and extension usage statistics (anonymized where possible).
A note on public reviewer names
Reviews on platforms like Google Maps are published publicly by reviewers under names of their own choosing. We store the reviewer name exactly as it appears on the source platform so you can read, understand, and respond to the review in context.
We do not re-publish, enrich, profile, sell, or share reviewer data, and we do not attempt to de-anonymise pseudonymous reviewers. Reviewers retain the right to erasure — if a reviewer contacts us at [email protected] we will delete their review data on request.
3.4 Data We Do NOT Collect
Private customer data: We do not access, collect, or store customer data from reservation systems, point-of-sale systems, or any non-public sources.
Sensitive personal data: We do not intentionally collect special-category data (health, ethnicity, religion, political opinions, sexuality, trade union membership, biometrics, genetics).
Employee personal data: We collect only aggregated, non-personal team metrics for the Life Skills & Talents dashboard. Individual employee names, contact details, or performance records are never collected.
Payment card numbers: All payment processing is handled by Stripe. We never see or store your full card details.
4. How We Use Your Data
4.1 Service Provision
Provide and maintain the booteek platform
Process your requests and transactions
Generate AI-powered insights and recommendations
Integrate with your Google Business Profile and other authorized platforms
4.2 Service Improvement
Analyze usage patterns to improve features
Develop new functionalities and services
Conduct research and analytics (using anonymized data)
Train and improve our AI models (using non-personal data only)
5. Chrome Extension Data Processing
The booteek Chrome Extension is installed on your own device and is designed to help you manage reviews across multiple platforms. Different categories of data are handled differently, and this section is authoritative for what the extension does and does not do.
5.1 Data stored on your device only
The following data never leaves your computer and is stored in Chrome's local extension storage:
Your UI preferences (selected platforms, theme, dismissed notices)
Your linked venue details after you confirm them (Place ID, business name, address, type, rating, review count)
A list of review IDs the extension has already sent to our server, used only to avoid sending duplicates
Response usage counter (how many AI responses you've used this month)
5.2 Data sent to booteek.ai servers
The following data is transmitted over HTTPS to our servers and stored in our database (hosted by Neon PostgreSQL in the EU) for the purposes described below:
Venue search queries: When you search for your venue during onboarding, your query string and the resulting venue list are sent to our search endpoint. Country is inferred from your IP via Cloudflare's CF-IPCountry header to scope results to your country.
Public reviews you view: When you visit a Google Maps page for your own linked venue, the extension reads the publicly-displayed review cards (reviewer name, rating, text, date, any published owner response) and sends them to our ingestion endpoint. We only ingest reviews for venues you have explicitly linked — we do not scrape other businesses you happen to browse.
AI response generation requests: The text of a review you want to respond to, your venue ID, and any optional reviewer name or tone preferences you specify.
Anonymous error telemetry: Generic error types and HTTP status codes (no personal data) if the extension encounters a bug.
5.3 What the extension does NOT do
We do not track which websites you visit outside of the platforms explicitly listed in the extension's permissions.
We do not read or transmit the content of any page other than review cards on your own linked venue's review platforms.
We do not access your browser history, cookies, passwords, or any data from other extensions.
We do not collect microphone, camera, or location data unless you actively opt in to voice recording for a specific feature.
We do not sell, rent, or share any data with advertising networks or third-party marketers.
5.4 Chrome Extension permissions explained
storage: Store your preferences and linked venue on your device.
sidePanel: Display the booteek interface in Chrome's side panel.
tabs: Open new tabs when you click links inside the extension.
alarms: Periodically refresh your AI usage counter.
offscreen: Required by Chrome for optional voice recording features.
Host permissions for business.google.com, google.com/maps, tripadvisor.com, opentable.com, thefork.com, designmynight.com, sevenrooms.com, facebook.com, and instagram.com: these are the review platforms the extension injects into when you visit them. The extension only activates on pages that match these hostnames.
6. Sub-processors
To operate the Service, we share certain data with trusted third-party processors. Each processor is bound by contractual data protection obligations (GDPR Article 28) and only processes data on our instructions for the specific purposes listed below.
Processor
Purpose
Data categories
Location
Neon (PostgreSQL)
Primary application database
Account data, venue data, scraped public reviews, usage metrics
EU
Railway
Application hosting
All application traffic and logs
EU
Cloudflare
CDN, DDoS protection, WAF
IP address, request headers, country (CF-IPCountry)
Global (edge)
Google (Places API + Gemini)
Venue search, business details lookup, and AI response generation
Search query strings, review text and venue context for AI responses
EU / global
Serper / SerpAPI
Venue and review search (fallback)
Search query strings
US
Stripe
Payment processing
Email, billing address, payment card (held by Stripe only)
EU / US
Resend
Transactional email delivery
Email address, message content
EU
Sentry
Error monitoring
Anonymised stack traces and error context
EU
This list is kept current. We will update this Privacy Policy and notify affected users if we add or materially change a sub-processor that handles your personal data.
7. Data Security
7.1 Technical Measures
Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
Access Controls: Role-based access with multi-factor authentication
Include your name, email address, and specific request
We will respond within one month (may be extended to three months for complex requests)
9. Data Retention
Retention Periods
Account Data: Retained while your account is active plus 3 years after closure
Usage Data: Retained for 2 years for service improvement purposes
Payment Data: Retained for 7 years for tax and accounting purposes
Marketing Data: Retained until consent is withdrawn
Scraped public reviews: Retained while the associated venue account is active. Deleted on request from the venue owner or the original reviewer (contact [email protected]).
Search query logs: 90 days for rate-limiting and abuse prevention, then deleted.
AI generation logs: 30 days for debugging, then deleted. Never used for model training.
10. International Data Transfers
When transferring data outside the UK/EEA, we ensure adequate protection through:
Adequacy Decisions: Transfers to countries with adequate protection findings
Standard Contractual Clauses: EU-approved contract terms for data protection
Certification Schemes: Providers with recognized data protection certifications
11. Cookies and Tracking
We use cookies and similar technologies for:
Essential: Required for Service functionality
Performance: Analytics to improve user experience
Functional: Remember your preferences and settings
We will respond to all privacy inquiries within one month.
This Privacy Policy is effective as of 13 April 2026 and applies to the booteek platform, including the booteek.ai website, the booteek Chrome Extension, and the Breo AI companion, operated by booteek AI Limited.