Legal
Privacy Policy
Last updated: 27 July 2026 · GotRegulars Ltd · Company no. 17344661
GotRegulars is the digital front-of-house for independent restaurants and bars ("venues"): a website built to rank on Google, an AI receptionist that answers the venue's phone 24/7, a live QR menu with dish photos and reels, quiet-night marketing, a loyalty programme, first-party review growth and a monthly numbers report. This policy explains, in plain English, what data we handle to deliver all of that, why we handle it, and your rights. Depending on the situation there are two data controllers: GotRegulars Ltd (the platform) and the venue whose menu, website or phone line you are using.
What we collect
- Guest profile — a device identifier stored in your browser, and (only if you choose to provide it) your name, phone number and email.
- Activity on a venue's menu — dishes you like ("pops"), reviews you submit, bookings you make and loyalty points you earn.
- Content you upload — photos and videos ("Guest Moments") you choose to share.
- AI conversations — what you type to the assistant, and what you say to the on-site voice concierge or the venue's AI phone receptionist. These conversations are transcribed and stored (see "AI assistant & voice calls" below).
- Venue owner data — if you run a venue on GotRegulars: your contact details, business details and billing information. Card payments are handled by Stripe; we never see your full card number.
- Enquiry data — if you ask us for a visibility audit or book a call: your restaurant's website and name, your name, mobile and email, and your answers to the short application — how your Tuesdays look, how you take bookings, what till you run, what you have already tried, why now, and who makes the decision — plus anything you add in the notes. This is separate from guest data on a venue's menu.
- Outreach data — publicly available business details we use to contact venues we think we can help (see "If we contacted your venue" below).
- Technical — basic device and browser information needed to run the service.
Why we use it (lawful bases)
- To provide the service — showing the menu, answering the phone, taking a booking, awarding loyalty points, publishing reviews (performance of a contract and legitimate interests).
- To improve quality — reviewing stored conversation transcripts so the assistant and the receptionist give better answers (legitimate interests).
- To run your visibility audit and your call — if you enquire or book, we check your restaurant's public website and how it shows up in Google and to AI assistants, store the resulting report, and email it to you before we speak; we may also build a private preview of what your GotRegulars site could look like. We hold the slot, put the call in the calendar and contact you about it by email and SMS. Rhys reviews every booking by hand before any of that work starts, so a real person sees your details first. (Steps taken at your request before entering a contract, and legitimate interests.)
- Marketing SMS and email from a venue — only with your separate, explicit opt-in, which you can withdraw at any time; every message tells you how.
- Billing and legal obligations — invoicing venues, keeping accounting records and meeting our legal duties.
AI assistant & voice calls
Venues on GotRegulars use AI in three places: a text assistant on the menu, an on-site voice concierge, and an AI receptionist that answers the venue's phone 24/7. The assistant always identifies itself as an AI. Live speech in voice and phone conversations is processed in real time by Retell AI, and text generation is routed via OpenRouter to models from providers including OpenAI and Anthropic. Calls and conversations are transcribed and stored so we can deliver the service — for example, passing your booking to the venue — and improve answer quality. Please do not share sensitive personal data with the assistant, and always confirm allergen and dietary information directly with venue staff — the assistant helps, but the kitchen has the final word.
Reviews & guest content
Reviews you submit are first-party reviews shown on the venue's menu. Genuine reviews are published — a venue may only remove reviews that are spam, abusive, fake or unlawful, with a logged reason. Venues cannot hide a review simply for being negative. If you upload a Guest Moment, you grant the venue and GotRegulars a licence to display it on the menu, and — only if you separately opt in — to re-share it on the venue's social channels. You must own the content and have the consent of anyone identifiable in it. You can ask for your content or review to be removed at any time.
Who we share with
We share data only with the service providers who help us run the platform, each engaged under appropriate data-protection terms:
- Vercel — website hosting.
- Supabase — database and file storage.
- Twilio — phone calls and SMS.
- Retell AI — live voice conversations: real-time speech processing and transcripts.
- OpenRouter — AI text generation, using models from providers including OpenAI and Anthropic.
- Stripe — billing and card payments, where enabled.
- Resend — transactional email.
- Google (Calendar & Meet) — booking your call. Your name and email are added to the calendar invite, Google emails you that invite and creates the Google Meet link for the call. Google also hosts the mailbox our own email replies arrive in.
- Google (PageSpeed Insights & Fonts) — measuring how fast your website loads during an audit, and the typefaces on our pages.
- DataForSEO — local search-volume and ranking data used to build an audit. Your website address and the search terms for your town only, never personal details.
We never sell your data.
International transfers
Some of these providers are based in the United States. Where personal data leaves the UK, the transfer is protected by the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses, alongside each provider's own safeguards.
Cookies & local storage
We keep this minimal. A device identifier in your browser's local storage keeps your session working — your pops, your loyalty points, your place. We do not use advertising cookies or cross-site tracking.
Your rights
Under UK GDPR you can access, correct, delete or export your data, object to or restrict processing, and withdraw consent at any time. Email hello@gotregulars.com and we will action it. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. Children under 16 should not submit content without a parent or guardian.
Retention & security
We keep data only as long as we need it to provide the service and meet our legal obligations, then delete or anonymise it. If you asked for an audit or booked a call and never became a client, we keep your enquiry, your report and our correspondence for up to 24 months — so we can pick the conversation back up and show where your details came from — then delete them. Ask us sooner and we will delete them sooner. Data is protected with row-level security and encryption in transit and at rest. If a venue leaves GotRegulars, its guest data and its phone number are always theirs to take — we provide an export as part of the wind-down.
If we contacted your venue
We contact venues we believe we can genuinely help. If you have heard from us, this is our transparency notice under Article 14 UK GDPR — where your details came from and what we do with them:
- We use publicly available business details only — Google Maps, your venue's own website and Companies House.
- Before we call, numbers are screened against the CTPS (Corporate Telephone Preference Service).
- Every outreach email includes a working unsubscribe.
- To be removed entirely, email hello@gotregulars.com and we will delete your details.
Contact
GotRegulars Ltd, company no. 17344661, registered in England & Wales at 66 Paul Street, London EC2A 4NA. Email hello@gotregulars.com or call +44 7751 314240. Your venue is a joint controller for its own menu and phone line — its contact details are shown on its page.
← Back to GotRegulars