Privacy

Last updated 31 August 2026

The short version. If you are a guest at a table, OnCue does not know who you are. It records that a table asked for something and when. There is no account, no cookie, no tracking, and nothing that identifies you. If you are a member of staff, we hold your name, your work email and — only if you switch alerts on — a notification address for your phone.

Who this is from

OnCue is operated by Novomed, trading as OnCue (“we”). Questions, corrections and deletion requests go to 1chaudhryibr@gmail.com.

Each restaurant controls its own data. We provide and host the software; the restaurant decides who its staff are and what happens to its records.

If you are a guest

You do not sign in, and we do not ask for your name, phone number, email or payment details. Nothing about you personally is collected.

When you tap a request, we store:

  • which table the tag belongs to
  • which request you chose, from the restaurant’s fixed list
  • the time it was sent, acknowledged and completed
  • which staff member handled it

That record describes a table, not a person. We cannot connect it to you, and neither can the restaurant.

No cookies. The guest page sets none. There are no analytics, advertising or tracking scripts anywhere in OnCue.

One thing on your device. If your request fails to send because the connection dropped, it is held in your browser’s local storage until it can be sent. It contains the table tag and which button you pressed. It never leaves your device except to send that request, and clearing your browser data removes it.

If you are staff or a manager

To give you an account and route requests to you, we hold:

  • your name, as entered by your manager or by you
  • your email address, used as your login
  • your password, stored only as a cryptographic hash by our authentication provider — we never see it and cannot recover it
  • your role, and whether your account is active
  • which sections you are covering and when your shifts start and end
  • a notification address for your device, if and only if you tap “Turn on table alerts”. You can revoke it at any time in your phone’s settings.

Your manager can see how quickly requests were acknowledged and completed. OnCue produces counts and durations only. It does not score, rank or grade you, and it draws no conclusions about your performance.

Session cookies are set when you sign in. They exist to keep you signed in and for nothing else.

Who else handles it

We do not sell data, and we do not share it for advertising. It is processed by the services that run the product:

  • Supabase — database and authentication
  • Vercel — application hosting
  • Apple, Google or Mozilla — only if alerts are switched on. Delivering a web notification requires passing it through the push service belonging to the browser maker. They receive the notification and the device address it is bound to.

These providers store data on servers in the United States. If you are in the UK, EU or elsewhere, your information is transferred there.

How long it is kept

Service records are kept as the restaurant’s own history until a manager deletes them, which they can do at any time from the app.

Removing a staff member deactivates their account rather than erasing it, because response-time history refers to it. Deactivation ends their shifts and deletes their notification address immediately. Complete erasure is available on request.

If a restaurant stops using OnCue, its data is deleted on request.

Your rights

Depending on where you live, you may have the right to see what we hold about you, correct it, have it deleted, object to how it is used, or receive a copy. Write to 1chaudhryibr@gmail.com and we will respond within one month.

Because guest requests are not linked to any person, we cannot locate or return “your” requests as a guest — there is nothing tying them to you. That is by design.

If you are in the UK or EU, our basis for holding staff data is performing our contract with the restaurant and our legitimate interest in running the service. Alerts rely on your consent, which you give by enabling them and withdraw by turning them off.

Security

Traffic is encrypted in transit. Restaurants are isolated at the database level: a signed-in account can only read rows belonging to its own restaurant, enforced by the database rather than by the application.

A table’s tag is a random identifier, not a guessable table number. Knowing it allows sending a request from that table and nothing else — no staff details, no other tables, no history.

No system is perfectly secure. If we discover a breach affecting personal data, we will notify affected restaurants and any regulator we are required to inform.

Children

OnCue is a tool for restaurant staff and is not directed at children. We do not knowingly collect data from anyone under 13.

Changes

If this policy changes materially we will update the date above and tell restaurant managers. Continuing to use OnCue after a change means accepting the revised policy.

This policy describes how the software behaves today and was written against the code itself. It is not legal advice and has not been reviewed by a lawyer. Before relying on it commercially, have a qualified adviser check it against the laws that apply to you.

Back to OnCue