booteek AI Limited ("Company", "we", "us", "our") operates the booteek platform ("Service"). This Privacy Policy explains how we collect, use, process, and protect your personal data when you use our Service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller: booteek AI Limited
Registration: England and Wales, Company Number: 13426132
Address: 71-75 Shelton Street, London WC2H 9JQ
Contact: privacy@booteek.ai
2. Legal Basis for Processing
We process personal data under the following legal bases:
Contract Performance: To provide our Service and fulfill our contractual obligations
Legitimate Interests: To improve our Service, prevent fraud, and ensure security
Legal Obligation: To comply with applicable laws and regulations
Consent: Where explicitly provided for specific processing activities
3. Data We Collect
3.1 Information You Provide Directly
Account Information: Name, email address, phone number, business name
Business Profile Data: Restaurant type, location, staff information (non-personal aggregated data only)
Payment Information: Processed by Stripe (we do not store full payment card details)
Communication Data: Support messages, feedback, and correspondence
3.2 Information Collected Automatically
Usage Data: Pages visited, features used, time spent, click patterns
Device Information: IP address, browser type, operating system, device identifiers
Performance Data: Service performance metrics, error logs (anonymized)
3.3 Third-Party Platform Data
With your active use of the booteek Chrome Extension on platforms where you manage your venue, we collect the following publicly available review data so that you can aggregate, analyse, and respond to reviews from all your platforms in one place:
Public reviews: Review text, star rating, relative publish date, and publicly-displayed reviewer name as shown on the platform (Google Business Profile, Google Maps, TripAdvisor, OpenTable, TheFork, Facebook, Instagram, SevenRooms, DesignMyNight). We only ingest reviews for venues you have linked in the extension.
Owner responses: Your own published responses to reviews, so that the AI can learn your voice.
Venue metadata: Business name, address, category, aggregate rating and review count, opening hours, photos, menu — sourced from Google Places API, Serper Maps, and SerpAPI.
Google Business Profile data (optional): If you connect your GBP via OAuth, we access business information, listings, and review data with your explicit authorization.
Analytics data: Website and extension usage statistics (anonymized where possible).
A note on public reviewer names
Reviews on platforms like Google Maps are published publicly by reviewers under names of their own choosing. We store the reviewer name exactly as it appears on the source platform so you can read, understand, and respond to the review in context.
We do not re-publish, enrich, profile, sell, or share reviewer data, and we do not attempt to de-anonymise pseudonymous reviewers. Reviewers retain the right to erasure — if a reviewer contacts us at privacy@booteek.ai we will delete their review data on request.
3.3.1 Vector embeddings and AI-powered search
To power AI features such as semantic review search and response generation, we create vector embeddings of review content. A vector embedding is a mathematical representation (a 1,536-dimensional numerical array) of a piece of text. It is used to find relevant context — it cannot be reverse-engineered to recover the source text.
Before any review content is stored or embedded, reviewer display names are reduced to initials (e.g. “Anthony Clarke” is stored as “A.C.”). Review text is then transmitted to the OpenAI API (model: text-embedding-3-small) to generate the embedding vector. OpenAI acts as a data processor under a Data Processing Agreement including Standard Contractual Clauses for UK/EEA-to-US transfers. OpenAI's API does not use submitted text to train its models. Once the embedding is generated, the raw review text is discarded from our AI knowledge base — only the embedding vector and aggregate metadata are retained.
This processing is carried out under our legitimate interests (UK GDPR Article 6(1)(f)) in providing contextually relevant AI responses to venue owners. Where you exercise the right to erasure of review data, associated embedding vectors are deleted at the same time.
3.4 How We Minimise and Handle Review Data
Our platform is designed to minimise the collection and retention of personal data. We do not collect, store, or process personal data about your end customers for any purpose other than the direct delivery of our services to you.
Where our platform processes review content from Google Business Profile (sourced via SerpAPI — see Section 3.3), we apply the following safeguards:
Reviewer display names are reduced to initials only (e.g. “A.C.”) before storage. Full names are never persisted.
Review text used for AI embedding is discarded after the embedding vector is generated. Only the vector and aggregate metadata (star rating, venue ID, approximate date) are retained in our AI knowledge base.
We process review data from Google only. TripAdvisor, OpenTable, TheFork, and other review platforms are deliberately excluded from our background data pipeline — a data minimisation decision under UK GDPR Article 5(1)(c).
We do not use review data for any purpose other than the delivery and improvement of our services to you.
The following data is never stored by us in any form:
Passwords or platform login credentials
Payment card details (handled exclusively by Stripe)
Sensitive personal data as defined in Article 9 UK GDPR (health, ethnicity, religion, political opinions, sexuality, biometrics, genetics)
Browsing history outside the specific review and business profile platforms relevant to your business
Private customer data from reservation systems, point-of-sale systems, or any non-public source
3.5 AI Knowledge Base (RAG System)
Our platform operates an AI knowledge base using Retrieval-Augmented Generation (RAG) technology, which enables our AI tools — including breo, the Review Response Generator, and the donde-onde-where.com venue discovery platform — to generate contextually relevant outputs.
The AI knowledge base stores anonymised and/or pseudonymised text passages derived from: (a) publicly available hospitality job postings from UK and EU job boards; (b) publicly available venue, city intelligence, and hospitality market data; and (c) review content processed in connection with our Clients' businesses, anonymised as described in Section 3.4 above.
Text passages are converted into vector embeddings using OpenAI's text embedding service (see Section 3.3.1). Embeddings are stored in our database and used to retrieve relevant context when generating AI outputs. Raw review text is discarded post-embedding — embeddings do not contain human-readable source text.
Legal basis:Legitimate interests (UK GDPR Article 6(1)(f)) — improving AI model quality for the benefit of our hospitality business clients, balanced against the rights of data subjects as assessed in our Legitimate Interests Assessment (available on request). Where review data is processed specifically for an identified Client's venue, Contract Performance (Article 6(1)(b)) may also apply as part of service delivery.
4. How We Use Your Data
4.1 Service Provision
Provide and maintain the booteek platform
Process your requests and transactions
Generate AI-powered insights and recommendations
Integrate with your Google Business Profile and other authorized platforms
4.2 Service Improvement
Analyze usage patterns to improve features
Develop new functionalities and services
Conduct research and analytics (using anonymized data)
Generate vector embeddings of review content to power semantic search and AI response generation (review text is transmitted to OpenAI's API for this purpose — see Section 3.3.1)
Analyse aggregated, anonymised usage patterns to improve platform features (we do not use individual customer data or review content to train external AI models)
5. Chrome Extension Data Processing
The booteek Chrome Extension is installed on your own device and is designed to help you manage reviews across multiple platforms. Different categories of data are handled differently, and this section is authoritative for what the extension does and does not do.
5.1 Data stored on your device only
The following data never leaves your computer and is stored in Chrome's local extension storage:
Your UI preferences (selected platforms, theme, dismissed notices)
Your linked venue details after you confirm them (Place ID, business name, address, type, rating, review count)
A list of review IDs the extension has already sent to our server, used only to avoid sending duplicates
Response usage counter (how many AI responses you've used this month)
5.2 Data sent to booteek.ai servers
The following data is transmitted over HTTPS to our servers and stored in our database (hosted by Neon PostgreSQL in the EU) for the purposes described below:
Venue search queries: When you search for your venue during onboarding, your query string and the resulting venue list are sent to our search endpoint. Country is inferred from your IP via Cloudflare's CF-IPCountry header to scope results to your country.
Public reviews you view: When you visit a Google Maps page for your own linked venue, the extension reads the publicly-displayed review cards (reviewer name, rating, text, date, any published owner response) and sends them to our ingestion endpoint. We only ingest reviews for venues you have explicitly linked — we do not scrape other businesses you happen to browse.
AI response generation requests: The text of a review you want to respond to, your venue ID, and any optional reviewer name or tone preferences you specify.
Anonymous error telemetry: Generic error types and HTTP status codes (no personal data) if the extension encounters a bug.
5.3 What the extension does NOT do
We do not track which websites you visit outside of the platforms explicitly listed in the extension's permissions.
We do not read or transmit the content of any page other than review cards on your own linked venue's review platforms.
We do not access your browser history, cookies, passwords, or any data from other extensions.
We do not collect microphone, camera, or location data unless you actively opt in to voice recording for a specific feature.
We do not sell, rent, or share any data with advertising networks or third-party marketers.
5.4 Chrome Extension permissions explained
storage: Store your preferences and linked venue on your device.
sidePanel: Display the booteek interface in Chrome's side panel.
tabs: Open new tabs when you click links inside the extension.
alarms: Periodically refresh your AI usage counter.
offscreen: Required by Chrome for optional voice recording features.
Host permissions for business.google.com, google.com/maps, tripadvisor.com, opentable.com, thefork.com, designmynight.com, sevenrooms.com, facebook.com, and instagram.com: these are the review platforms the extension injects into when you visit them. The extension only activates on pages that match these hostnames.
6. Sub-processors
To operate the Service, we share certain data with trusted third-party processors. Each processor is bound by contractual data protection obligations (GDPR Article 28) and only processes data on our instructions for the specific purposes listed below.
Processor
Purpose
Data categories
Location
Neon Inc. (PostgreSQL + pgvector)
Primary application database and AI knowledge base vector store (chunk_registry)
IP address, request headers, country (CF-IPCountry)
Global (edge)
Google (Places API + Gemini)
Venue search, business details lookup, and AI response generation
Search query strings, review text and venue context for AI responses
EU / global
OpenAI
Vector embedding generation for AI-powered search and response features (model: text-embedding-3-small)
Review text passages and venue descriptions submitted for embedding. OpenAI does not retain or train on submitted data under the API DPA.
US
Serper / SerpAPI
Venue and review search (fallback)
Search query strings
US
Stripe
Payment processing
Email, billing address, payment card (held by Stripe only)
EU / US
Resend
Transactional email delivery
Email address, message content
EU
Sentry
Error monitoring
Anonymised stack traces and error context
EU
This list is kept current. We will update this Privacy Policy and notify affected users if we add or materially change a sub-processor that handles your personal data.
7. Data Security
7.1 Technical Measures
Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
Access Controls: Role-based access with multi-factor authentication
Regular Updates: Security patches and system updates
7.2 Organizational Measures
Staff Training: Regular data protection and security training
Access Limitation: Access to personal data limited to authorized personnel only
Incident Response: Documented procedures for security incident response
Vendor Management: Due diligence on all data processors
8. Your Data Protection Rights
Under GDPR, you have the following rights:
Right of Access
Request confirmation of data processing and obtain a copy of your personal data
Right to Rectification
Correct inaccurate personal data and complete incomplete personal data
Right to Erasure
Request deletion of your personal data in certain circumstances
Right to Data Portability
Receive your data in a structured, commonly used format
Right to Object
Object to processing based on legitimate interests or direct marketing
Right to Restrict Processing
Limit how we process your data in certain situations
Exercising Your Rights
To exercise any of these rights:
Email us at privacy@booteek.ai
Include your name, email address, and specific request
We will respond within one month (may be extended to three months for complex requests)
9. Data Retention
Retention Periods
Account Data: Retained while your account is active plus 3 years after closure
Usage Data: Retained for 2 years for service improvement purposes
Payment Data: Retained for 7 years for tax and accounting purposes
Marketing Data: Retained until consent is withdrawn
Scraped public reviews: Retained while the associated venue account is active. Deleted on request from the venue owner or the original reviewer (contact privacy@booteek.ai).
Search query logs: 90 days for rate-limiting and abuse prevention, then deleted.
AI generation logs: 30 days for debugging, then deleted. Never used for model training.
Vector embeddings: Retained for as long as the underlying review data is retained. When review data is deleted (on account closure or erasure request), the corresponding embedding vectors are also deleted.
10. International Data Transfers
Certain sub-processors are located outside the UK/EEA. Transfers are protected by the following mechanisms:
Standard Contractual Clauses (SCCs): Used for transfers to US-based processors including OpenAI (vector embedding generation), Serper, SerpAPI, and Stripe. EU-approved SCCs provide a contractual guarantee of adequate data protection.
Adequacy decisions: Where transfers are to countries with an adequacy finding, no additional mechanism is required.
Certification schemes: Where relevant, providers hold recognized data protection certifications (e.g. ISO 27001) as a supplementary safeguard.
OpenAI specifically: Review text passages are transmitted to OpenAI's API (hosted in the US) for vector embedding generation. This transfer is covered by OpenAI's API Data Processing Agreement and EU SCCs. OpenAI's API product does not use customer-submitted data for model training.
11. Cookies and Tracking
We use cookies and similar technologies for:
Essential: Required for Service functionality
Performance: Analytics to improve user experience
Functional: Remember your preferences and settings
You have the right to lodge a complaint with a supervisory authority if you believe we have violated data protection laws:
UK: Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
13. Contact Information
For privacy-related questions or to exercise your rights:
Privacy Team
booteek AI Limited
Email: privacy@booteek.ai
Address: 71-75 Shelton Street, London WC2H 9JQ
We will respond to all privacy inquiries within one month.
14. donde-onde-where.com Supplementary Notice
donde-onde-where.com (DOW) is an AI-powered venue discovery platform operated by booteek AI Limited. This notice supplements the main Privacy Policy for visitors to that site.
Venue data: DOW ranks hospitality venues based on publicly available review data (aggregate ratings, review counts) sourced from Google via SerpAPI. Aggregate scores and ranking positions are displayed publicly.
Anonymised review excerpts: DOW zone pages may display short, curated excerpts derived from public Google reviews. These excerpts are selected and anonymised by automated AI processing — no reviewer names, profile links, or identifying information are displayed alongside them.
Reviewer identities: Individual reviewer identities are never displayed on DOW. Reviewer names are stored as initials internally and are not surfaced publicly.
Visitor analytics: DOW collects standard anonymised website analytics (page views, session duration, device type, approximate country). No personal profiling is conducted on DOW visitors.
Venue operators: Venue operators whose venues appear on DOW may contact privacy@booteek.ai to update business information, correct inaccuracies, or request removal from the platform.
DOW is a proof-of-concept platform demonstrating AI visibility optimization. It does not offer subscription services and does not collect payment data from venue discovery users.
This Privacy Policy is effective as of 20 April 2026 and applies to the booteek platform, including the booteek.ai website, the booteek Chrome Extension, and the Breo AI companion, operated by booteek AI Limited.