PhoneTillPrivacy

UK · plain English

Data Processing Addendum (shops)

This short addendum sits alongside the PhoneTill Shop Agreement and Privacy notice. It describes roles under UK GDPR for takeaway shops using PhoneTill.

Who does what

What we process for you

Order and contact details needed to run the ordering line, send the kitchen WhatsApp ticket, text the customer (confirmation / pay link where used), and bill £1 per completed AI order. We do not sell this data.

Instructions

We only process that data to provide PhoneTill as described in the Shop Agreement — take the call, create the order record, notify kitchen and customer, and support billing / abuse controls. We do not use shop customer data for unrelated marketing.

Sub-processors

We use providers that make the product work — typically voice AI (call handling), Twilio (WhatsApp / SMS), hosting, and Stripe (payments). They process data only as needed for those services.

Security & incidents

We take reasonable technical and organisational measures appropriate to a small UK SaaS ordering line. If we become aware of a personal-data breach affecting your shop data, we will notify you without undue delay and help you meet any reporting duties.

Retention & deletion

We keep order and billing records while the shop is active and for a reasonable period afterwards (disputes, accounting, abuse prevention). You can ask us to delete a shop account; some records may need to stay for legal or financial reasons. See the Privacy notice for more.

International transfers

Some providers may process data outside the UK. Where that happens we rely on appropriate safeguards (such as the provider's UK/EU transfer mechanisms).

Questions

Email admin@phonetill.com. This one-pager is meant to be readable on a phone at the counter — not a substitute for legal advice if you need a longer DPA for a larger group.

Shop Agreement · Privacy · Status