Skip to content
TBTexBite
HomePrivacyTermsData deletion

Privacy Policy

Effective date: 2026-09-20

1. Scope and responsible parties

Rawad Khaled Moukheiber, trading as TexBite ("TexBite", "we", "us", or "our"), operates TexBite, a software service that enables participating restaurants to offer ordering and management experiences through WhatsApp (the "Service"). Our identity and contact details appear in the Legal Notice.

TexBite operates the platform and determines how personal data is used for platform administration, security, support, configuration, and legal compliance. Each participating restaurant determines its menu, accepts customer orders, and is responsible for preparation, delivery or pickup, customer service, and any records it must keep for those activities. The restaurant identified in the WhatsApp business profile, Flow, or order is therefore responsible for its own order and fulfillment processing. We process that restaurant's order data to provide the Service and coordinate privacy requests. Contact us if you are unsure which party handles a particular request.

This policy applies to customers who use the ordering Flow, authorised restaurant managers who use the management Flow, and visitors to these legal pages. Meta and WhatsApp independently process information under their own terms and privacy policies.

2. Personal data we process

Depending on how the Service is used, we process:

  • Customer identity and contact data: WhatsApp phone number, WhatsApp profile/display name, customer name, delivery address, and information provided to support.
  • Order and fulfillment data: restaurant and branch, cart contents, quantities, modifiers, prices, fees, pickup or delivery selection, order number, order status, timestamps, and item or order notes.
  • WhatsApp and Flow data: messages used to start or operate the Service, Flow responses, WhatsApp message and media identifiers, message type, timestamps, delivery state, and related webhook event payloads received from Meta.
  • Restaurant-management data: authorised manager phone number and display name, authentication and lockout records, management sessions, test-access lists, configuration workbook metadata and contents, validation results, and audit records.
  • Technical and security data: request, event, order, and message identifiers; response times; delivery attempts; error codes; and security events. Hosting providers may also process ordinary connection data such as IP address, device/browser information, and request time.

These static legal pages do not intentionally set first-party cookies or use advertising analytics. The Service does not provide a payment-card field or process online card payments. Payment is currently cash on delivery. Do not enter card numbers, financial-account numbers, identity-document numbers, medical information, or other sensitive information in WhatsApp messages or free-text order notes.

3. Sources of data

We receive data:

  • from customers when they message a participating restaurant, complete a Flow, place an order, provide delivery details, or contact support;
  • from Meta and WhatsApp when they deliver messages, profile information, Flow responses, media, and message or delivery metadata;
  • from restaurant managers when they configure branches, menus, assets, test access, and service availability; and
  • automatically from the systems used to host, secure, and operate the Service.

4. Purposes and legal grounds

We use personal data only as reasonably necessary to:

  • start and maintain an ordering session, calculate a cart, route an order to the correct restaurant, and support pickup or delivery;
  • send the Flow invitation, receipt, restaurant-configured order-status messages, and support replies;
  • authenticate managers, validate and publish restaurant configurations, and preserve an audit trail;
  • prevent duplicate orders, fraud, abuse, and unauthorised access, and diagnose failures;
  • operate, secure, maintain, and improve the reliability of the Service;
  • comply with accounting, tax, food-safety, consumer-protection, privacy, and other legal duties; and
  • establish, exercise, or defend legal claims and answer lawful requests.

Where applicable, processing is based on steps requested before or needed to perform an order, legitimate interests in securely operating and supporting the Service, compliance with legal obligations, and consent where the law requires it.

The Service currently supports customer-initiated and transactional messages only. We do not use WhatsApp-derived data for unrelated advertising, data brokerage, or cross-restaurant profiling. Promotional WhatsApp messaging is not currently offered.

5. Disclosures

We disclose only what is necessary to:

  • The selected restaurant: its authorised managers, kitchen, support, and delivery personnel receive the customer, contact, address, and order details needed to accept and fulfill the order. One restaurant does not receive another restaurant's customer records through the Service.
  • Meta and WhatsApp: to receive and send messages and operate WhatsApp Flows. See the WhatsApp Privacy Policy and WhatsApp Business Terms.
  • Supabase: to provide the database, storage, and server-function infrastructure used by the Service. The production project is configured in region ap-northeast-1. See the Supabase Privacy Policy.
  • Professional advisers and authorities: when reasonably necessary for legal, accounting, security, insurance, dispute, or regulatory purposes.
  • A genuine business successor: subject to appropriate confidentiality and legal safeguards.

No payment processor, analytics provider, external helpdesk, or external delivery company is currently integrated by TexBite. Participating restaurants may use their own personnel or providers outside the Service and are responsible for explaining that use. Zapier is not active in production. We do not sell personal data.

6. International processing

Meta, WhatsApp, Supabase, and their service providers may process data outside Lebanon or the country where a user is located. We limit transfers to what is needed for the Service and use contractual or other recognised safeguards where applicable. Contact us for available information about safeguards relevant to a request.

7. Retention

Unless a shorter period is appropriate, deletion is requested, or a documented legal hold applies, our maximum operational periods are:

  • incomplete carts and expired ordering sessions: up to one day after the cart or session expires;
  • completed order and fulfillment records: up to one year after completion;
  • raw inbound WhatsApp webhook payloads: up to one year after receipt;
  • outbound message payloads and delivery-attempt records: up to one year after the final delivery attempt;
  • manager authentication, session, and audit records: up to one year after expiry or the relevant action;
  • uploaded configuration workbooks and validation records: up to one year after upload or supersession; and
  • minimal records of deletion requests and outcomes: up to one year after completion.

When a period ends, data is deleted or irreversibly anonymised unless continued retention is required by law or needed for a documented claim. Residual encrypted backups may persist for up to one year after removal from the live system and are not used for ordinary operations.

8. Security and access

Measures used for the Service include access controls, row-level database security, server-side credentials, WhatsApp webhook-signature verification, encryption for Flow exchanges, content-minimised monitoring fields, and duplicate-processing controls. Direct restaurant access is limited to authorised managers for their assigned business scope. Strictly necessary operator administration is limited to support, security, configuration, deletion, and legal-compliance tasks. No system is completely secure; contact us promptly if you suspect misuse.

9. Rights and choices

Subject to applicable law, a person may ask to access, correct, update, complete, delete, anonymise, restrict, or object to processing of their personal data, and may request a portable copy where that right applies. A person may withdraw consent for future processing where consent is the legal basis.

Use our Data Deletion Instructions or email rawadmkhbr@hotmail.com. We verify control of the relevant WhatsApp number using the minimum information necessary and coordinate with the selected restaurant where its records are involved. A person may also complain to a competent privacy, consumer-protection, or judicial authority. Rights under Lebanese Law No. 81/2018 may include access, correction, updating, completion, and erasure in applicable circumstances.

Blocking a business in WhatsApp stops future contact through that chat but does not automatically erase records already held by the restaurant or the Service.

10. Children

The Service is not intended for a child acting without appropriate adult involvement. A person under 18 may order only with the supervision and authorisation of a parent or legal guardian who accepts responsibility for the order. Contact us if you believe a child supplied personal data improperly.

11. Changes

We may update this policy when the Service, providers, participating restaurants, or applicable law changes. We will publish the new version at the same public URL, update the effective date, and provide additional notice where required.

12. Contact

Platform operator: Rawad Khaled Moukheiber, trading as TexBite
Address: Aber Chmoun, Main Street, Khaled Mokheiber Building, Ground Floor, Lebanon
Privacy and deletion contact: Rawad Mokheiber
Privacy email: rawadmkhbr@hotmail.com
Support: rawadmkhbr@hotmail.com · +961 3 150 340
Support hours: 09:00–17:00 Beirut time on operating days

TexBite
Operated by Rawad Khaled Moukheiber, trading as TexBite.

Privacy Terms Data deletion Legal notice

WhatsApp is a product of Meta Platforms, Inc. TexBite is an independent service and is not endorsed by or affiliated with Meta or WhatsApp.