Privacy Policy — RTBS Staff App | Quick Book UK
Privacy Policy — RTBS Staff App
Last updated: 24 June 2026
This Privacy Policy explains how the RTBS Staff app (“the App”) handles information. The App is a staff-facing tool used by restaurants running the Restaurant Table Booking System (RTBS) WordPress plugin to manage their own bookings.
Who this policy is for
This policy is written for staff members who use the App on behalf of their employer (a restaurant or hospitality business). If you are a restaurant customer who has made a booking, your data is held by the individual restaurant you booked with, under their own privacy policy — please contact them directly with any questions about your personal data.
Who controls what data
The App is built and maintained by Quick Book UK (“we”, “us”). However:
- Each restaurant using the App is the data controller for its own customers’ booking data (names, phone numbers, email addresses, dietary requirements, allergen notes, and similar). That data lives on the restaurant’s own WordPress website, which the restaurant owns and operates.
- We act as a technology provider/processor: the App is the interface staff use to view and manage that data, and our infrastructure (described below) helps deliver push notifications, but we do not own, sell, or independently use restaurant customers’ booking data for our own purposes.
If you are a staff member with questions about how your employer handles customer data, please contact your employer directly. If your question is about the App itself (login, technical issues, push notifications), contact us using the details at the end of this policy.
Information the App collects
Account information
When you log in, the App sends your WordPress username and password directly to your employer’s own website to verify your identity — the same login your employer already uses for their WordPress site. We do not see, store, or have access to your password. Once logged in, the App stores a secure session token (not your password) in your device’s Keychain, which is Apple’s encrypted, on-device secure storage. This token is used to keep you logged in and is removed when you log out.
Site address
The website address you enter at login (e.g. yourrestaurant.co.uk) is stored locally on your device so you don’t need to re-enter it each time.
Booking information
While using the App, you can view bookings, including customers’ names, phone numbers, email addresses, dietary requirements, allergen information, and any notes added by staff. This data is requested live from your employer’s own website each time you use the App and is not permanently stored by us — it lives on your employer’s WordPress database, exactly as it does in their existing admin dashboard.
Push notification token
If you allow notifications, Apple assigns your device a push notification token. This token is sent to your employer’s website, which relays it (along with the message to be sent) through our central infrastructure to Apple’s push notification service, so that you receive alerts for new bookings, cancellations, and similar events. We do not use this token for anything other than delivering these notifications, and it is deleted when you log out.
What we don’t collect
The App does not use location services, does not access your camera or photo library, and does not include any third-party analytics or advertising software.
Who we share information with
- Apple Inc. — to deliver push notifications via Apple’s Push Notification service (APNs). Apple’s handling of this is governed by Apple’s own privacy policy.
- Your employer’s own website — all booking data originates from and is sent back to your employer’s WordPress installation; it is not shared with any other restaurant or third party by us.
We do not sell any data, to anyone, ever.
Data retention
- Your session token is stored until you log out or it expires (typically up to 30 days of inactivity).
- Your push notification token is stored until you log out.
- Booking data is not stored by the App beyond what’s needed to display it during use, and is governed by your employer’s own data retention practices on their WordPress site.
Your rights
Since each restaurant controls its own customers’ data, requests to access, correct, or delete customer booking data should be directed to the restaurant in question. If you are a staff member and want your own account information (e.g. your login’s associated session) removed, contact your employer’s site administrator, who can deactivate your account, or contact us directly and we’ll assist.
If you’re in the UK or EU, you have rights under UK GDPR/GDPR including access, correction, erasure, and objection to processing. These rights are exercised against the relevant data controller — your employer, for customer data, or us, for any account-level information we hold about App usage.
Security
- All communication between the App and your employer’s website, and between that website and our infrastructure, uses HTTPS encryption.
- Session tokens are stored in Apple’s Keychain, not in plain text.
- Access to booking data within the App is restricted by role (Manager, Supervisor, Staff, or Administrator) as configured by your employer.
Children’s privacy
The App is intended for use by adult staff members of hospitality businesses and is not directed at children. We do not knowingly collect information from children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected with an updated “Last updated” date above. Continued use of the App after changes are published constitutes acceptance of the revised policy.
Contact us
If you have questions about this policy or the App itself:
Quick Book UK