TableReq Back to home
Legal

Privacy Policy

Last updated: 20 July 2026

This Privacy Policy explains how TableReq(“TableReq”, “we”, “us” or “our”) — the trading name under which [your full name] operates as a self-employed sole trader registered in Latvia (tax registration No. [VID registration number]) — collects, uses, shares and protects personal data when you use our website and the TableReq table-service platform (together, the “Service”).

We are committed to protecting your privacy in line with the EU General Data Protection Regulation (“GDPR”) and applicable Latvian data-protection law. For the purposes of the GDPR, TableReq is the data controller for the personal data described in this policy, except where we act as a data processoron behalf of a restaurant (see “Our role” below).

In short: guests never need an account and are not asked for their name, email, or payment details to send a request. Restaurant accounts store the minimum needed to run the Service, and card payments are handled entirely by Stripe — we never see or store full card numbers.

1. Who this policy covers

The Service has two groups of users, and this policy applies to both:

  • Restaurant users — owners and staff who create an account, manage tables, and use the staff dashboard.
  • Guests — diners who scan a table’s QR code to send a service request (for example, to call staff, signal they are ready to order, or request the bill).

2. Our role (controller vs. processor)

We act as a data controllerfor personal data relating to restaurant accounts, billing, and the operation of our website. When a restaurant uses TableReq to handle its guests’ requests, we act as a data processorand process that request data on the restaurant’s instructions; the restaurant is the controller for its own guest interactions. Restaurants are responsible for informing their own guests about how table-service requests are used within their premises.

3. Information we collect

Restaurant account data

  • Owner email address and an authentication password (stored securely and salted-and-hashed by our authentication provider — we never store passwords in plain text).
  • Restaurant name and configuration (tables, table display names, language, request-cooldown and sound settings).
  • A shared staff login (username and password) that the owner creates and manages for their floor staff.

Service (request) data

  • Request events created when a guest scans a QR code — the request type, the table number, status (pending/done), and timestamps. This data does not include a guest’s name, email, phone number, or payment details.

Billing data

  • Subscription plan, status, and billing history metadata (such as invoice dates and amounts).
  • Identifiers linking your account to our payment processor (Stripe customer and subscription IDs).
  • Card and payment details are collected and processed directly by Stripe. We do not receive or store full payment-card numbers.

Technical data

  • Standard server and log information such as IP address, browser and device type, and pages or actions requested, used to operate, secure, and debug the Service.
  • Locally stored preferences (see “Cookies and local storage” below).

4. How we use your information and our lawful bases

PurposeLawful basis (GDPR Art. 6)
Creating and operating your account and delivering the ServicePerformance of a contract
Processing subscriptions, payments, and invoicesPerformance of a contract; legal obligation
Securing the Service, preventing abuse, and troubleshootingLegitimate interests
Responding to your support requestsLegitimate interests; performance of a contract
Meeting tax, accounting, and other legal dutiesLegal obligation
Optional product updates or marketing, where applicableConsent (which you may withdraw at any time)

5. Cookies and local storage

We use cookies and browser local storage that are strictly necessaryto run the Service — for example, to keep you signed in, remember your dashboard language, and enforce the per-table request cooldown on a guest’s device. We do not use third-party advertising or cross-site tracking cookies. If we ever introduce non-essential analytics, we will ask for your consent first.

6. Sub-processors and sharing

We do not sell your personal data. We share it only with trusted service providers who help us run the Service, under contracts that require them to protect it:

ProviderPurpose
SupabaseAuthentication, database, and secure hosting of account and service data
StripePayment processing, subscriptions, and invoicing
[hosting/CDN provider]Application hosting and content delivery

We may also disclose data where required by law, to enforce our agreements, or to protect the rights, safety, and security of TableReq, our users, or the public.

7. International transfers

Some of our providers may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards recognised under the GDPR, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, to ensure your data receives an equivalent level of protection.

8. How long we keep your data

We retain personal data only for as long as necessary for the purposes described above. Account and configuration data are kept for the life of your account and deleted or anonymised within a reasonable period after account closure. Billing and invoice records are retained as required by applicable tax and accounting law (typically several years). Service request data is retained to operate the dashboard and completed-request history and may be periodically pruned.

9. Your rights

Subject to the GDPR, you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request erasure of your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at hello@tablereq.com. You also have the right to complain to the Latvian Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv) or the supervisory authority in your country of residence.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed credentials, access controls, and strict data isolation between restaurants (multi-tenant separation). No system can be guaranteed perfectly secure, but we work continuously to protect your data.

11. Children

The Service is intended for restaurants and their staff, and is not directed at children. Guests can send requests without providing any personal data or creating an account.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after an update constitutes acceptance of the revised policy.

13. Contact us

For any privacy question or to exercise your rights, contact [your full name] (trading as TableReq) at hello@tablereq.com, or by post at [correspondence address].

Questions about this document?

hello@tablereq.com
TableReq
HomePrivacy PolicyTermsContact

© 2026 TableReq. All rights reserved.