Privacy policy

Last updated: 2026-08-14

This page explains what Alnabil stores, why it stores it, and what it never touches. It describes what the system actually does rather than what a template says — where a section below says we do not do something, it is because there is no code in the product that does it. It is not legal advice.

1. Who we are, and what this covers

Alnabil is a digital menu and restaurant-management platform for restaurants and cafés. Owners use it to build a menu, publish it behind a QR code, and run what hangs off that menu: tables, service calls, staff accounts, reviews and ordering at the table. This policy covers the Alnabil dashboard and every public menu published through it. Using the platform means you accept it.

2. What we store about you, the owner

All of it is something you typed or uploaded yourself:

  • Your email address, and a password we never see — it reaches our sign-in provider hashed and is never held in readable form.
  • Your restaurant's name, type, address, phone and WhatsApp number, and any social links you choose to show.
  • Your menu: categories, items, prices, descriptions, option groups and add-ons, and the images you upload for any of them.
  • Your settings: logo, cover image, brand colour, splash screen, currency, opening hours and time zone.
  • Your subscription requests, and the photo of the bank transfer receipt you upload with them.

3. What we store about your staff

If you use staff accounts, we store what is needed to sign them in and route work to the right person:

  • Each employee's name, email, role, and the places or sections you assign them to.
  • Which employee acknowledged or resolved a service call — kept as a record even after they leave your team.
  • If you link a Telegram group for service alerts: the identifier of that group, and the first name Telegram reports for whoever claims a call from it.

4. What we store about your customers

Very little, and none of it identifies a person:

  • A daily count of how many times your menu was opened, and of how many distinct devices opened it. Both are plain numbers with nothing attached to them.
  • If a customer leaves a review: the rating, the comment text, and a name only if they chose to type one.
  • A random identifier kept in the customer's own browser, so one device is not counted twice and cannot review the same item twice. It is a random value tied to no account, no name and no IP address, and clearing browser data erases it.
  • If a customer presses the service button: which table it came from and when — not who pressed it.

5. What we never store

  • Orders. When you switch on ordering from the table, the cart lives entirely in the customer's browser, and is either shown to a waiter from their own screen or sent by the customer to your restaurant's WhatsApp if you switch that on — either way it goes from their device straight to you. It never reaches our servers, and there is no endpoint in the product that could receive one.
  • Card details of any kind. There is no online payment in the platform at all; subscriptions are activated by bank transfer.
  • Location. We do not ask for or collect the location of an owner, an employee or a customer.
  • Advertising and cross-site tracking data. There is no ad network, no advertising cookie and no tracking pixel anywhere in the platform.

6. Information collected automatically

Our hosting and database providers keep the ordinary technical logs any web service produces: the IP address a request came from, the browser and device type, the page requested, and the time. They exist to keep the service running and to investigate faults and abuse, they are retained by those providers for a limited period, and they are neither used to build a profile of anyone nor joined to your menu's visit counts.

7. Cookies and browser storage

We use cookies and browser storage to make the service work, never for advertising:

  • A sign-in cookie that keeps you signed in to the dashboard.
  • A cookie that remembers whether you are using Arabic or English.
  • Browser storage on a public menu, holding the anonymous device identifier described above and the customer's cart while they are building it.

8. How we use this information

  • To run the platform: sign you in, store your menu, and show it to your customers.
  • To provide the features you switch on — QR codes, service calls, staff accounts, reviews and analytics.
  • To process a subscription request and confirm a transfer.
  • To investigate faults, protect the service against abuse, and answer your support questions.

9. When information is shared

We do not sell, rent or trade your data or your customers' data to anyone, and we do not hand it to anyone to train an AI model on. It is shared only in these cases:

  • With the service providers who run the platform, strictly to perform that job.
  • With whoever you share it with yourself — a public menu is public by design, and a Telegram group you link receives the alerts you asked it to receive.
  • Where we are legally required to, under a valid order in the applicable jurisdiction.

10. How your data is protected

Everything travels over an encrypted HTTPS connection. Passwords are hashed by our sign-in provider and are never visible to us. Every query in the dashboard is scoped to the business that made it, so one restaurant's account cannot read another's data, and a staff account sees only what its role and assigned places allow. No system is perfectly secure, and we do not claim otherwise.

11. How long we keep data

Your account data is kept for as long as your account exists. If your subscription lapses nothing is deleted — your menu is hidden from customers and comes back exactly as you left it when you renew. When you ask us to delete your account, we remove it and its content from our live systems, and it falls out of routine backups as those age out. Aggregate visit counts, which identify nobody, may be kept as statistics.

12. Children's privacy

Alnabil is a tool for running a business and is not directed at children under 13, and we do not knowingly collect personal data from a child. A public menu can be opened by anyone with the link, but opening one requires nothing to be entered and collects nothing personal. If you believe a child has given us personal data, contact us and we will remove it.

13. Your rights

You can view, correct and delete almost everything yourself, at any time, from the dashboard — your menu, your images, your settings and your staff accounts. Beyond that, you can ask us to:

  • Give you a copy of the data held about you.
  • Correct anything inaccurate.
  • Delete your account and its content entirely.
  • Tell you what a particular service provider holds on our behalf.

14. Changes to this policy

When the product starts or stops touching a kind of data, this page changes with it, and the date at the top changes too. If a change materially affects your rights or your customers' data, we will tell account owners rather than rely on you re-reading the page.

15. Contact us

For any question about this policy, any request about your data, or anything you think this page gets wrong, reach us on WhatsApp or by email using the links below.