Draft for legal review
Privacy policy
1. Who is responsible
[to be filled by the owner], [to be filled by the owner], [to be filled by the owner], [to be filled by the owner]. Email: hello@tablenote.io.
We act in two roles:
- As the controller for this website, for restaurant owner accounts and for team logins.
- As a processor for restaurants (Art. 28 GDPR) when guests rate a visit. For that feedback the restaurant is the controller. Every rating page links the restaurant's own privacy notice, which is the guest's primary notice. Our contract with restaurants is the data processing agreement (German: AVV).
2. Visiting this website
We set no cookies on the public pages and use no analytics, no advertising and no tracking pixels. Fonts are served from our own server. Our application does not log your IP address. To limit abuse, it counts requests per address for a short time under a keyed hash that is held in memory only and never stored or logged.
Our hosting provider ([to be filled by the owner]) processes your IP address to deliver the pages and may keep technical server logs. Legal basis: Art. 6(1)(f) GDPR, our interest in running the website securely.
3. Owner accounts and team logins
When a restaurant signs up or an owner invites a team member, we process the email address, the restaurant name and country, the role (owner or manager), the venue details the account enters (for example opening hours and the contact details for the restaurant's privacy notice) and the days on which a login used the dashboard (the date only, never the time).
Purpose: to provide the service. Legal basis: Art. 6(1)(b) GDPR (contract) for the account holder; for invited team members Art. 6(1)(f) GDPR, the restaurant's interest in giving its staff access.
- You sign in with a link we email to you. It works once and expires after 15 minutes. We store it only as a hash and delete it 1 day after it was used or expired.
- After sign-in we set one strictly necessary cookie,
tn_session. It keeps you signed in and expires after 14 days without use. The owner app sets no other cookies. Our internal founder admin area uses its own strictly necessary session cookie,tn_admin, which expires after 8 hours. - A removed team login is deleted 30 days after its removal. Invitation attempts are recorded with the account and the time only and deleted after 24 hours.
- If an owner deletes the account, all its data is deleted within 30 days. Cancelling a paid pack deletes nothing: the account moves to the free Starter pack, which shows the last 60 days and hides older history.
4. Emails
We send sign-in, sign-up and invitation links and service notices (for example a suspicious-code report or the monthly reminder to check the stickers). We use Resend (Resend, Inc., USA) as our processor to deliver them (transfers to the USA: section 7). Our emails contain no open or click tracking.
5. Guest feedback (on behalf of restaurants)
Anonymous by design. The restaurant never sees your individual feedback, only summaries that combine many guests. That's our guarantee.
- We store the stars, any quick picks, detail stars and comment, the channel (dine-in or delivery), the placement of the code and the business day of the visit. We never store the time of day. Hours before 05:00 count to the previous day. With a comment we store the language we detected, and with every rating the language of the page.
- The page also measures how long rating took, in ranges of 5 seconds. We only count how many ratings per venue and week fell into each range, never with the rating itself, to check that rating stays quick.
- From one address, more than 20 ratings for the same venue on one business day are held back for two business days. A held rating is discarded only if its comment repeats another comment for that venue; restaurants see only how many were discarded.
- A star you tap is saved even if you leave the page before pressing Send. Only the stars are sent then. Quick picks, details and comments are sent only with Send. If you come back within 30 minutes on the same business day, you can finish that rating once. It is then updated, not added a second time.
- The rating page needs no login, asks for no name and sets no cookies. It stores nothing on your device. A single-use token for each page load lives in the page only until you send the rating.
- Against spam we store a hash of your IP address with a salt that changes every day, together with the page token and the time of receipt. This is kept separately, never shown to the restaurant and deleted after at most 48 hours. Old salts are deleted after 48 hours.
- Software on our own servers removes names and other personal details from comments. The original text is deleted within 24 hours. Cleaned comments are deleted 90 days after they were sent.
- AI summaries (planned, not yet switched on): Anthropic, PBC (USA) will turn cleaned comments into summaries for the restaurant. It receives comments only after names and personal details have been removed, never an IP address or page token.
- Restaurant owners and their team see only combined figures for closed weeks and months. Each figure is built from at least 5 ratings, a quick-pick count from at least 3. They never see a single rating, comment or time.
- A report of a suspicious code contains a fixed reason and the code's placement, no free text and no contact details.
We never sell, publish or share your feedback. Our technical partners process it only on our behalf.
6. Recipients and processors
- Hosting: [to be filled by the owner].
- Email delivery: Resend, Inc., USA (section 4).
- AI summaries of cleaned comments (planned): Anthropic, PBC, USA (section 5).
We never sell your data and never use it for advertising. We will update this policy before we add online payments or any further service provider.
7. Transfers outside the EU
We may process data in the USA as well as in the EU. Resend and Anthropic are located in the USA. Transfers to countries outside the EU or EEA follow Art. 44 to 49 GDPR. Transfer mechanism for each provider (for example the EU-US Data Privacy Framework or the EU standard contractual clauses): [to be filled by the owner].
8. How long we keep data
| Data | Deleted |
|---|---|
| Original comment text | within 24 hours |
| IP hash, page token and time of receipt | after at most 48 hours |
| Cleaned comments | 90 days after sending |
| Ratings, combined figures and timing counts | while the restaurant uses Tablenote; within 30 days of account deletion |
| Sign-in links | 1 day after use or expiry |
| Account, logins and dashboard days | within 30 days of account deletion; a removed team login after 30 days |
9. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). Write to hello@tablenote.io.
You can also complain to a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work or where you think the infringement happened. The authority responsible for us: [to be filled by the owner].
For guest feedback, please contact the restaurant, which is the controller. We help it respond.
10. No automated decision-making
We make no automated decisions with legal or similarly significant effects on you (Art. 22 GDPR) and do no profiling.
11. Status of this policy
This is a draft for legal review. It is not yet in force.