Privacy Policy
Last updated: 2 September 2026
1. Introduction
Adgili ("we", "us", "our") is a table reservation platform developed and operated by Adgili, a partnership registered in Georgia (the country), dedicated to helping users discover restaurants, cafes, and dining venues and reserve tables through our mobile and web application (the "App"). This Privacy Policy (the "Policy") explains what personal data we collect when you use our App, how we use and protect it, with whom we may share it, and what rights you have over it. By creating an account or using the App, you agree to this Policy. If you do not agree, please stop using the App. We may update this Policy from time to time; we will notify you of significant changes through the App. This App is not intended for children under the age of 13. We do not knowingly collect personal data from children. If you believe we have done so inadvertently, please contact us at the address in Section 15.
2. Who We Are — Data Controller
Adgili is the controller of the personal data you provide through the App. This means we are responsible for determining how and why your data is used. Contact: helloadgili@gmail.com Registered address: Batumi, Adjara, Georgia
3. What Personal Data We Collect
When you register and use the App, we may collect the following categories of personal data: 3.1 Account & Identity Data • Full name (first and last name) • Email address • Hashed password when you register with email and password (we never store your password in readable form) • Authentication method (email/password and/or a linked social sign-in provider: Apple, Google, Facebook, or Instagram) • Provider user ID — a stable identifier from a social sign-in provider when you use social sign-in (we do not store your social network password) 3.2 Contact Data • Mobile phone number (used so a restaurant may contact you about your reservation when necessary; collected at registration or when required to complete a booking) 3.3 Reservation & Usage Data • Restaurants searched, browsed, and followed • Reservation details: date, time, number of guests, and restaurant chosen • Visit history: record of confirmed reservations and visits • Dining preferences you provide in your profile and preferences inferred from your reservation history and browsing behaviour within the App 3.4 Location Data We collect location-related data in two ways: A) Location you choose manually — city or region selected in App filters (not precise GPS) B) Device location (optional, only with your permission) — if you grant "While Using the App" location permission, we may collect approximate coordinates to show nearby restaurants and distance labels. We request this permission only in connection with features that use location (for example, offers or distance labels). We do not collect location in the background. We do not track your location continuously. You may deny permission; the App remains usable with manual city/region selection. 3.5 Device Permissions & Media With your permission, and only when you use the relevant feature, the App may access: • Camera — to scan QR codes (check-in, digital menu) and take photos where offered (reviews, support, profile, or receipt photos for business users) • Photo library — to let you select images to attach. We access only the image(s) you choose through the system picker; we do not scan your entire photo library 3.6 Technical & Device Data • IP address • Device type, operating system, and App version • Session and diagnostic logs • Push notification token (Expo / Apple Push Notification service / Firebase Cloud Messaging on Android) when you enable push notifications on a registered account 3.7 Social Sign-In Data If you choose Sign in with Apple, Google, Facebook, or Instagram, we may receive (depending on your choices and the provider's policies): email (if shared), display name (if shared), and a stable provider user ID. We verify the provider token at sign-in; we do not store long-lived social network access tokens on our servers. 3.8 Data We Do NOT Collect We do not collect: • Payment or financial card data through the guest App at this stage (no in-app guest payments) • Special category data (health, religion, political opinions, sexual orientation, biometric templates for identification, etc.) • Your social network passwords • Persistent social network access tokens stored on our servers after sign-in is complete • Background or always-on location tracking • Contacts from your address book • App Tracking Transparency / cross-app advertising identifiers for third-party ad tracking • We do not sell your personal data
4. How We Collect Your Data
We collect your personal data through the following means: • Directly from you, when you register an account, make a reservation, browse venues, follow a restaurant profile, update your settings, or contact us • From social identity providers when you choose Sign in with Apple, Google, Facebook, or Instagram • Automatically, through your interactions with the App (searches performed, reservations created or cancelled, and similar usage events) • From your device, when you grant permission for location, camera, photo selection, or push notifications
5. How and Why We Use Your Data
We will only process your personal data where we have a lawful basis to do so. The purposes for which we use your data and the legal basis we rely on: • Creating and managing your account — Performance of a contract with you. • Authenticating you via email/password or social sign-in — Performance of a contract; legitimate interests (security and account integrity). • Processing and managing table reservations, including generating your QR entry code — Performance of a contract. • Sharing your reservation details with the relevant restaurant — Performance of a contract; legitimate interests (enabling the venue to prepare for your visit). • Sending push notifications about your reservations (confirmations, changes, reminders) — Performance of a contract; legitimate interests. • Sending push notifications about personalised offers and promotions — Your consent (you may opt out at any time in the App's notification settings). • Enabling restaurants to view activity data related to your reservations at their venue — Legitimate interests. • Showing nearby restaurants and distance labels when you grant optional location permission — Your consent (you may deny permission and select a city/region manually instead). • Processing photos you choose to upload (reviews, support, receipts for business users) — Performance of a contract; legitimate interests. • Improving the App and analysing aggregated usage — Legitimate interests (maintaining and improving our service). • Complying with legal obligations — Legal obligation.
6. QR Codes and In-Venue Experience
The App uses two types of QR codes: 6.1 Entry QR Code When you complete a reservation, the App generates a unique QR code linked to your booking. When you arrive at the venue, the host scans this code to verify your reservation and assign you a table. The scan logs your arrival as part of your visit history in the App. 6.2 Digital Menu QR Code Once you are seated, a second QR code is available at your table which, when scanned, opens the restaurant's digital menu. Scanning this code does not generate or transmit any additional personal data about you beyond confirming that a user with an active reservation at that table accessed the menu.
7. Who We Share Your Data With
We do not sell your personal data. We share it only in the following circumstances: 7.1 With Restaurants When you make a reservation, we share with that restaurant only: your first and last name, email address, mobile phone number (when provided), reservation details (date, time, number of guests), and your visit history and dining preference data relevant specifically to that restaurant. Restaurants use this data to prepare for your arrival, manage table allocation, and — where you have opted in — send you personalised offers through the App. Restaurants may not use your contact details for independent direct marketing outside the App. 7.2 With Service Providers and Social Sign-In Partners We work with carefully selected third parties who process data on our behalf or provide authentication services. These include, depending on the features you use: • Cloud hosting and infrastructure providers — to run the App, API, and databases • Push notification delivery services (including Apple Push Notification service and, on Android, Google Firebase Cloud Messaging via Expo) — to deliver notifications you have enabled • Apple Inc. — when you use Sign in with Apple • Google LLC — when you use Google Sign-In • Meta Platforms, Inc. — when you use Facebook Login or Instagram sign-in, where enabled Each provider receives only the data necessary for its role. We require our service providers to protect personal data under contractual obligations that provide the same or equal protection of user data as stated in this Policy and as required by applicable law. We do not authorise these parties to use your data for their own independent marketing unrelated to providing services to Adgili. 7.3 Legal Requirements We may disclose your data to law enforcement or regulatory authorities where required by Georgian law or applicable EU law, or where necessary to protect the rights, safety, or property of Adgili, our users, or others. 7.4 Business Transfers If Adgili undergoes a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you beforehand where required by law.
8. International Data Transfers
Our App, API, and databases are hosted with established cloud infrastructure providers. Personal data may be processed in Georgia and in other countries where our hosting or subprocessors operate (for example, within the European Economic Area or the United States), depending on service configuration. If your personal data is transferred outside Georgia, we ensure appropriate safeguards — such as standard contractual clauses approved by the relevant supervisory authority, or equivalent measures — so that your data remains protected to at least the standard required under Georgian law and, where applicable, the GDPR. Details of primary processing locations may be updated from time to time; material changes will be reflected in this Policy.
9. How Long We Keep Your Data
We keep your personal data only for as long as is necessary for the purposes described in this Policy, or as required by law. • Active account: we retain account and usage data for as long as your account remains open. • After account deletion: when you delete your account through the App (Profile → Edit profile → Delete account) or by contacting us, we delete or anonymise personal data connected to your account, except minimal identifiers we may retain to prevent re-registration abuse, resolve disputes, or comply with legal obligations. • Minimal retention after deletion: we may retain an anonymised internal user ID, a hashed email address, and/or a hashed password identifier solely to prevent abuse and satisfy record-keeping obligations. These identifiers are not used for marketing or profiling. • Legal obligation: where applicable law requires us to retain certain records, we will do so for the required period.
10. Security
We take the security of your data seriously. The measures we have in place include: • All passwords are stored exclusively in hashed (bcrypt) form — we never store or have access to your actual password • All data transmission between the App and our servers is encrypted using TLS • Access to personal data is restricted to personnel who have a legitimate operational need • We have procedures for detecting and responding to incidents involving personal data. No method of electronic storage or transmission is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
11. Push Notifications
We use push notifications for two purposes: 11.1 Reservation Notifications (Transactional) We may send push notifications relating to your reservations — such as confirmation, reminders, and changes or cancellations. These are necessary to fulfil your reservation contract. To receive them, you must enable push notifications on your device. You may disable push notifications entirely in your device settings at any time; some reservation updates may then be available only inside the App or by email where applicable. 11.2 Promotional Notifications (Marketing) With your consent in the App's notification settings, we and participating restaurants may send personalised push notifications about special offers, discounts, and promotions relevant to your dining preferences and visit history. You may withdraw this consent at any time in Profile → Notification settings by turning off marketing notifications, without affecting transactional reservation notifications (subject to your device-level push settings). 11.3 When We Ask for Permission We ask for device push permission when you choose to enable push notifications in the App (or when the App needs to register your device for notifications you have requested). We explain the purpose before triggering the system permission dialog where the App provides an in-app prompt.
12. Your Rights
Under Georgian data protection law and, to the extent applicable, the GDPR, you have the following rights with respect to your personal data: • Right of access — to request a copy of the personal data we hold about you. • Right to rectification — to ask us to correct inaccurate or incomplete data. • Right to erasure — to request deletion of your data, subject to legal retention obligations (see Section 9). • Right to restriction of processing — to ask us to pause processing of your data in certain circumstances. • Right to data portability — to receive your data in a structured, machine-readable format where processing is based on consent or contract. • Right to object — to object to processing based on legitimate interests. • Right to withdraw consent — where processing is based on your consent (for example, marketing push notifications or optional location), you may withdraw it at any time without affecting the lawfulness of prior processing. How to exercise your rights: • Account deletion: in the App, go to Profile → Edit profile → Delete account, confirm by typing DELETE, or email helloadgili@gmail.com • Marketing push: Profile → Notification settings → turn off marketing notifications • Location: deny or revoke location permission in your device settings; the App remains usable with manual city/region selection • Social sign-in: to disconnect a linked social provider or request account erasure, use Delete account in the App or contact helloadgili@gmail.com • Other requests: email helloadgili@gmail.com We will respond within 30 days. We may ask you to verify your identity before acting on your request. You also have the right to lodge a complaint with the Personal Data Protection Service of Georgia (www.pdp.ge), or with the supervisory authority of an EU member state if you are based in the EU.
13. Cookies
Our App uses session and persistent cookies and similar technologies to remember your preferences, maintain your login session, and understand how you use the App. You may control cookie behaviour through your browser or device settings; however, disabling certain cookies may affect App functionality.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our App, our data practices, or applicable law. When we make significant changes, we will notify you via a push notification or an in-App message where appropriate. The "Last updated" date reflects when it was last revised. Continued use of the App after a change constitutes acceptance of the updated Policy.
15. Contact Us
If you have any questions about this Policy, wish to exercise your rights, or want to raise a concern, please contact us: Adgili Email: helloadgili@gmail.com Address: Batumi, Adjara, Georgia We will do our best to address your concern promptly. If you are not satisfied with our response, you have the right to escalate to the Personal Data Protection Service of Georgia (www.pdp.ge). Adgili — Your spot, reserved.