Privacy Policy

Last updated: 13 April 2026

1. Introduction

booteek AI Limited ("Company", "we", "us", "our") operates the booteek platform ("Service"). This Privacy Policy explains how we collect, use, process, and protect your personal data when you use our Service.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Controller: booteek AI Limited

Registration: England and Wales, Company Number: 13426132

Address: 71-75 Shelton Street, London WC2H 9JQ

Contact: [email protected]

2. Legal Basis for Processing

We process personal data under the following legal bases:

  • Contract Performance: To provide our Service and fulfill our contractual obligations
  • Legitimate Interests: To improve our Service, prevent fraud, and ensure security
  • Legal Obligation: To comply with applicable laws and regulations
  • Consent: Where explicitly provided for specific processing activities

3. Data We Collect

3.1 Information You Provide Directly

  • Account Information: Name, email address, phone number, business name
  • Business Profile Data: Restaurant type, location, staff information (non-personal aggregated data only)
  • Payment Information: Processed by Stripe (we do not store full payment card details)
  • Communication Data: Support messages, feedback, and correspondence

3.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, click patterns
  • Device Information: IP address, browser type, operating system, device identifiers
  • Performance Data: Service performance metrics, error logs (anonymized)

3.3 Third-Party Platform Data

With your active use of the booteek Chrome Extension on platforms where you manage your venue, we collect the following publicly available review data so that you can aggregate, analyse, and respond to reviews from all your platforms in one place:

  • Public reviews: Review text, star rating, relative publish date, and publicly-displayed reviewer name as shown on the platform (Google Business Profile, Google Maps, TripAdvisor, OpenTable, TheFork, Facebook, Instagram, SevenRooms, DesignMyNight). We only ingest reviews for venues you have linked in the extension.
  • Owner responses: Your own published responses to reviews, so that the AI can learn your voice.
  • Venue metadata: Business name, address, category, aggregate rating and review count, opening hours, photos, menu — sourced from Google Places API, Serper Maps, and SerpAPI.
  • Google Business Profile data (optional): If you connect your GBP via OAuth, we access business information, listings, and review data with your explicit authorization.
  • Analytics data: Website and extension usage statistics (anonymized where possible).

A note on public reviewer names

Reviews on platforms like Google Maps are published publicly by reviewers under names of their own choosing. We store the reviewer name exactly as it appears on the source platform so you can read, understand, and respond to the review in context.

We do not re-publish, enrich, profile, sell, or share reviewer data, and we do not attempt to de-anonymise pseudonymous reviewers. Reviewers retain the right to erasure — if a reviewer contacts us at [email protected] we will delete their review data on request.

3.4 Data We Do NOT Collect

  • Private customer data: We do not access, collect, or store customer data from reservation systems, point-of-sale systems, or any non-public sources.
  • Sensitive personal data: We do not intentionally collect special-category data (health, ethnicity, religion, political opinions, sexuality, trade union membership, biometrics, genetics).
  • Employee personal data: We collect only aggregated, non-personal team metrics for the Life Skills & Talents dashboard. Individual employee names, contact details, or performance records are never collected.
  • Payment card numbers: All payment processing is handled by Stripe. We never see or store your full card details.

4. How We Use Your Data

4.1 Service Provision

  • Provide and maintain the booteek platform
  • Process your requests and transactions
  • Generate AI-powered insights and recommendations
  • Integrate with your Google Business Profile and other authorized platforms

4.2 Service Improvement

  • Analyze usage patterns to improve features
  • Develop new functionalities and services
  • Conduct research and analytics (using anonymized data)
  • Train and improve our AI models (using non-personal data only)

5. Chrome Extension Data Processing

The booteek Chrome Extension is installed on your own device and is designed to help you manage reviews across multiple platforms. Different categories of data are handled differently, and this section is authoritative for what the extension does and does not do.

5.1 Data stored on your device only

The following data never leaves your computer and is stored in Chrome's local extension storage:

  • Your UI preferences (selected platforms, theme, dismissed notices)
  • Your linked venue details after you confirm them (Place ID, business name, address, type, rating, review count)
  • A list of review IDs the extension has already sent to our server, used only to avoid sending duplicates
  • Response usage counter (how many AI responses you've used this month)

5.2 Data sent to booteek.ai servers

The following data is transmitted over HTTPS to our servers and stored in our database (hosted by Neon PostgreSQL in the EU) for the purposes described below:

  • Venue search queries: When you search for your venue during onboarding, your query string and the resulting venue list are sent to our search endpoint. Country is inferred from your IP via Cloudflare's CF-IPCountry header to scope results to your country.
  • Public reviews you view: When you visit a Google Maps page for your own linked venue, the extension reads the publicly-displayed review cards (reviewer name, rating, text, date, any published owner response) and sends them to our ingestion endpoint. We only ingest reviews for venues you have explicitly linked — we do not scrape other businesses you happen to browse.
  • AI response generation requests: The text of a review you want to respond to, your venue ID, and any optional reviewer name or tone preferences you specify.
  • Anonymous error telemetry: Generic error types and HTTP status codes (no personal data) if the extension encounters a bug.

5.3 What the extension does NOT do

  • We do not track which websites you visit outside of the platforms explicitly listed in the extension's permissions.
  • We do not read or transmit the content of any page other than review cards on your own linked venue's review platforms.
  • We do not access your browser history, cookies, passwords, or any data from other extensions.
  • We do not collect microphone, camera, or location data unless you actively opt in to voice recording for a specific feature.
  • We do not sell, rent, or share any data with advertising networks or third-party marketers.

5.4 Chrome Extension permissions explained

  • storage: Store your preferences and linked venue on your device.
  • sidePanel: Display the booteek interface in Chrome's side panel.
  • tabs: Open new tabs when you click links inside the extension.
  • alarms: Periodically refresh your AI usage counter.
  • offscreen: Required by Chrome for optional voice recording features.
  • Host permissions for business.google.com, google.com/maps, tripadvisor.com, opentable.com, thefork.com, designmynight.com, sevenrooms.com, facebook.com, and instagram.com: these are the review platforms the extension injects into when you visit them. The extension only activates on pages that match these hostnames.

6. Sub-processors

To operate the Service, we share certain data with trusted third-party processors. Each processor is bound by contractual data protection obligations (GDPR Article 28) and only processes data on our instructions for the specific purposes listed below.

ProcessorPurposeData categoriesLocation
Neon (PostgreSQL)Primary application databaseAccount data, venue data, scraped public reviews, usage metricsEU
RailwayApplication hostingAll application traffic and logsEU
CloudflareCDN, DDoS protection, WAFIP address, request headers, country (CF-IPCountry)Global (edge)
Google (Places API + Gemini)Venue search, business details lookup, and AI response generationSearch query strings, review text and venue context for AI responsesEU / global
Serper / SerpAPIVenue and review search (fallback)Search query stringsUS
StripePayment processingEmail, billing address, payment card (held by Stripe only)EU / US
ResendTransactional email deliveryEmail address, message contentEU
SentryError monitoringAnonymised stack traces and error contextEU

This list is kept current. We will update this Privacy Policy and notify affected users if we add or materially change a sub-processor that handles your personal data.

7. Data Security

7.1 Technical Measures

  • Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access with multi-factor authentication
  • Infrastructure Security: Industry-standard cloud security practices
  • Regular Updates: Security patches and system updates

7.2 Organizational Measures

  • Staff Training: Regular data protection and security training
  • Access Limitation: Access to personal data limited to authorized personnel only
  • Incident Response: Documented procedures for security incident response
  • Vendor Management: Due diligence on all data processors

8. Your Data Protection Rights

Under GDPR, you have the following rights:

Right of Access

Request confirmation of data processing and obtain a copy of your personal data

Right to Rectification

Correct inaccurate personal data and complete incomplete personal data

Right to Erasure

Request deletion of your personal data in certain circumstances

Right to Data Portability

Receive your data in a structured, commonly used format

Right to Object

Object to processing based on legitimate interests or direct marketing

Right to Restrict Processing

Limit how we process your data in certain situations

Exercising Your Rights

To exercise any of these rights:

  • Email us at [email protected]
  • Include your name, email address, and specific request
  • We will respond within one month (may be extended to three months for complex requests)

9. Data Retention

Retention Periods

  • Account Data: Retained while your account is active plus 3 years after closure
  • Usage Data: Retained for 2 years for service improvement purposes
  • Payment Data: Retained for 7 years for tax and accounting purposes
  • Marketing Data: Retained until consent is withdrawn
  • Scraped public reviews: Retained while the associated venue account is active. Deleted on request from the venue owner or the original reviewer (contact [email protected]).
  • Search query logs: 90 days for rate-limiting and abuse prevention, then deleted.
  • AI generation logs: 30 days for debugging, then deleted. Never used for model training.

10. International Data Transfers

When transferring data outside the UK/EEA, we ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries with adequate protection findings
  • Standard Contractual Clauses: EU-approved contract terms for data protection
  • Certification Schemes: Providers with recognized data protection certifications

11. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential: Required for Service functionality
  • Performance: Analytics to improve user experience
  • Functional: Remember your preferences and settings
  • Marketing: Deliver relevant advertisements (with consent)

12. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe we have violated data protection laws:

UK: Information Commissioner's Office (ICO)

Website: ico.org.uk

Phone: 0303 123 1113

13. Contact Information

For privacy-related questions or to exercise your rights:

Privacy Team

booteek AI Limited

Email: [email protected]

Address: 71-75 Shelton Street, London WC2H 9JQ

We will respond to all privacy inquiries within one month.

This Privacy Policy is effective as of 13 April 2026 and applies to the booteek platform, including the booteek.ai website, the booteek Chrome Extension, and the Breo AI companion, operated by booteek AI Limited.