Privacy Policy
Last updated: May 2026
Who is responsible for your data?
Each restaurant or business that uses this platform is the data controller for their guests' bookings — [Platform Operator Name] acts as the data processor. This means the business you are booking with decides why and how your data is used; we only process it on their behalf.
If you have questions about how a specific business handles your data, please contact them directly. For questions about this platform, contact [Platform Operator Name].
What data we collect
When you make a booking we collect:
- Your name
- Your email address
- Your phone number (optional)
- Special requests you include with your booking (e.g. dietary needs, accessibility requirements)
- Preference notes saved by the venue about your past visits (e.g. seating preferences)
We do not collect payment card details directly — payments are handled by Stripe (see Sub-processors below).
Why we use your data (legal basis)
We process your booking data on the basis of legitimate interest— both yours and the business's. You have a legitimate interest in having your reservation managed correctly; the business has a legitimate interest in running its operations and delivering the service you asked for.
Preference notes are kept to improve your future visits. You can have them deleted at any time (see Your rights below).
How long we keep your data
- Booking records — personal details (name, email, phone, special requests) are kept for 3 years from the date of your booking, after which they are automatically anonymised. The booking record itself is retained in anonymised form for statistical and legal purposes.
- Preference notes — kept for 3 years from your last visit to the venue. If you have not visited in 3 years, your preference profile is deleted automatically.
Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your personal details — contact the restaurant or business you booked with directly. Their contact email is shown on your booking confirmation page. They will remove your name, email, phone number, and special requests from the booking and delete any stored preference notes. Your data is also automatically anonymised after 3 years (see How long we keep your data above).
- Restrict or object to processing
- Lodge a complaint with a supervisory authority
To exercise any right other than self-service erasure, contact the business you booked with or reach us at [Platform Operator contact].
Sub-processors
We share your data with the following third-party services to operate the platform:
- Supabase— database and authentication infrastructure. Your booking data is stored in Supabase's managed Postgres database.
- Stripe — payment processing. If the venue you are booking with collects payment at the time of booking, your card details are handled directly by Stripe and are not stored on our servers.
Both sub-processors operate under their own data processing agreements and comply with GDPR.
Supervisory authority
If you are located in Sweden and believe your data has been mishandled, you have the right to file a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
www.imy.se
Changes to this policy
If we make material changes to this policy we will update the date at the top of this page. We encourage you to review it periodically.