Draft for legal review

Privacy policy

Deutsch

1. Who is responsible

[to be filled by the owner], [to be filled by the owner], [to be filled by the owner], [to be filled by the owner]. Email: hello@tablenote.io.

We act in two roles:

2. Visiting this website

We set no cookies on the public pages and use no analytics, no advertising and no tracking pixels. Fonts are served from our own server. Our application does not log your IP address. To limit abuse, it counts requests per address for a short time under a keyed hash that is held in memory only and never stored or logged.

Our hosting provider ([to be filled by the owner]) processes your IP address to deliver the pages and may keep technical server logs. Legal basis: Art. 6(1)(f) GDPR, our interest in running the website securely.

3. Owner accounts and team logins

When a restaurant signs up or an owner invites a team member, we process the email address, the restaurant name and country, the role (owner or manager), the venue details the account enters (for example opening hours and the contact details for the restaurant's privacy notice) and the days on which a login used the dashboard (the date only, never the time).

Purpose: to provide the service. Legal basis: Art. 6(1)(b) GDPR (contract) for the account holder; for invited team members Art. 6(1)(f) GDPR, the restaurant's interest in giving its staff access.

4. Emails

We send sign-in, sign-up and invitation links and service notices (for example a suspicious-code report or the monthly reminder to check the stickers). We use Resend (Resend, Inc., USA) as our processor to deliver them (transfers to the USA: section 7). Our emails contain no open or click tracking.

5. Guest feedback (on behalf of restaurants)

Anonymous by design. The restaurant never sees your individual feedback, only summaries that combine many guests. That's our guarantee.

We never sell, publish or share your feedback. Our technical partners process it only on our behalf.

6. Recipients and processors

We never sell your data and never use it for advertising. We will update this policy before we add online payments or any further service provider.

7. Transfers outside the EU

We may process data in the USA as well as in the EU. Resend and Anthropic are located in the USA. Transfers to countries outside the EU or EEA follow Art. 44 to 49 GDPR. Transfer mechanism for each provider (for example the EU-US Data Privacy Framework or the EU standard contractual clauses): [to be filled by the owner].

8. How long we keep data

Retention periods
DataDeleted
Original comment textwithin 24 hours
IP hash, page token and time of receiptafter at most 48 hours
Cleaned comments90 days after sending
Ratings, combined figures and timing countswhile the restaurant uses Tablenote; within 30 days of account deletion
Sign-in links1 day after use or expiry
Account, logins and dashboard dayswithin 30 days of account deletion; a removed team login after 30 days

9. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). Write to hello@tablenote.io.

You can also complain to a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work or where you think the infringement happened. The authority responsible for us: [to be filled by the owner].

For guest feedback, please contact the restaurant, which is the controller. We help it respond.

10. No automated decision-making

We make no automated decisions with legal or similarly significant effects on you (Art. 22 GDPR) and do no profiling.

11. Status of this policy

This is a draft for legal review. It is not yet in force.