Security & Compliance
How Tabzy protects guest data, secures your restaurant's data, and where German fiscal compliance currently stands.
Privacy by design
Tabzy does not require guests to create accounts. We minimize personal data collection and automatically delete customer data when it is no longer required. Restaurants retain the billing information necessary for their operations and legal obligations.
No guest accounts
Guests never need to create an account to pay with Tabzy. We never collect guest names, email addresses, or phone numbers.
Data minimization
A table session is identified only by an anonymous, randomly generated device ID for the duration of the visit - never by personal data.
Customer-data deletion
Once a payment is completed, the table's device ID is automatically deleted - within 5 minutes of payment, or when the session times out. The table then resets for the next guest.
Retention periods
Guest data is never kept longer than needed to process the payment. Restaurants retain only the billing information required for their own operations and legal obligations.
Restaurant/customer data separation
A guest's short-lived session data is stored strictly separately from the restaurant's own long-term business records (e.g. accounting, revenue reports).
Encryption
All data is encrypted in transit (TLS) and at rest.
Access controls
Access to restaurant data is restricted to authorized, authenticated users and continuously monitored.
Role-based access control (RBAC)
Owners can assign their team graduated roles - such as owner, manager, or staff - so each person only sees and changes what their job requires.
Passkeys
Restaurant account login supports passkeys (WebAuthn) - a passwordless method that eliminates phishing and password-reuse risk.
Backups
Business data is backed up regularly and encrypted, to protect against data loss.
Incident response
In the event of a security incident, Tabzy follows a documented response process that notifies affected restaurants and handles the incident in line with statutory (GDPR) reporting obligations.
KassenSichV / TSE
German fiscal record-keeping law
Under Germany's Kassensicherungsverordnung (KassenSichV), electronic record-keeping systems must record transactions tamper-proof and cryptographically signed through a certified Technical Security Equipment (TSE).
Current status: Tabzy's TSE integration is currently in active development and has not yet completed certification. Once the integration is certified, we will publish the TSE provider, the certification reference, and a link to verify the certificate here.
TSE provider
To be published once certified
Certification
Pending
Verification
Link to follow once certified
Until TSE certification is complete, we encourage you to factor this into your decision. If you have questions about current status, reach us directly at any time.
Questions about security or compliance? Contact us directly.
Acquire Tabzy Software
Request a non-binding offer now - Start with a €0 monthly fee and no minimum contract term. Or email us directly at contact@tabzy.de.
