Privacy Policy
What personal data Tablorix handles, why, for how long, and what you can ask us to do about it.
- Version
- 0.6
- En vigueur depuis
Tablorix is booking software for restaurants. Restaurants use it to manage their tables; their guests use it to reserve one. This policy explains what we do with personal data on both sides of that.
We act in two different roles, and it matters which
Almost every question about your data has a different answer depending on which of these two situations you are in.
When you have a Tablorix account — you own or work at a restaurant, or you contacted us — we decide why and how your data is used. We are the controller, and this policy is the whole answer. That is Part A.
When you booked a table at a restaurant that happens to use our software, the restaurant decides what happens with your booking. We only hold it on their behalf. They are the controller; we are their processor. Their privacy notice governs, not ours, and requests about your booking go to them. That is Part B.
Who we are
Vanerps BV, a besloten vennootschap (BV) with its registered seat at Schepdaalstraat 46B, 1700 Dilbeek, Belgium, registered under enterprise number 0688.906.668 (RPR Brussel).
For anything in this policy, write to privacy@tablorix.be.
We have not appointed a Data Protection Officer. We assessed this against Article 37 GDPR and concluded one is not required: our core activity is providing software, not large-scale monitoring or large-scale processing of special categories of data. We will revisit that as we grow, and the address above reaches the person responsible in the meantime.
Part A: when we are the controller
Your account
To create and run an account we process your name, email address, chosen interface language, and a hash of your password — never the password itself. If you sign in with Google instead, we receive your name and email address from Google; we never receive your Google password. If you turn on two-factor authentication, we also keep the secret your authenticator app shares with us and your backup codes, both encrypted; turning it off deletes them.
We also keep the invitations you send or accept, because an invitation is how someone joins an organisation, and the record of who invited whom is what makes that auditable.
When you create an organisation, we keep the record that you accepted our terms on its behalf: which version of the terms and the Data Processing Agreement you accepted (and of this policy), when, and your name and email address as the person who accepted. That record is what shows the agreement exists and which text it is made of. Likewise, if the owner changes how long the organisation’s guest details are kept, we keep the owner’s email address and the time with that setting, as the record of the instruction.
- Why: to give you an account and let you use the product.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
- How long: for as long as the account exists. When an organisation is deleted it is first marked as deleted and then permanently erased after 30 days — the window exists so an accidental deletion can be undone.
Staying signed in
A signed-in session lasts 7 days, held in a cookie that we set. See Cookies and local storage.
Billing
To invoice you, we keep the details your invoices are made out to: the legal name of the company, its VAT number, the invoicing address and country, the address we send invoices to, and any reference of your own you ask us to print on them. You give us these when you create your organisation and can correct them at any time in the Tablorix app.
If your organisation pays for Tablorix, we also keep your subscription plan, its status and dates, and a record of each charge (amount, currency, status, date, and the payment reference our payment provider gives us).
We never see or store your card or bank details. Those go straight to Mollie, our payment provider, who handles them as a controller in their own right under their own privacy policy.
- Why: to charge you, to show you your invoice history, and to meet our bookkeeping obligations.
- Legal basis: performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for the accounting records.
- How long: the details in the app are deleted with your organisation, on the same 30-day window as everything else. An invoice we have already issued is an accounting record and is kept for the period Belgian accounting law requires, currently seven years.
When you contact us
Our contact form asks for your name, email address, an optional phone number and your message, and sends them to us by email.
The form is protected by a proof-of-work check that runs in your browser. It is not a third-party CAPTCHA: nothing is sent to another company, you are not asked to identify traffic lights, and no tracking cookie is set.
- Why: to answer you.
- Legal basis: our legitimate interest in responding to enquiries (Art. 6(1)(f)), or steps toward a contract at your request (Art. 6(1)(b)).
- How long: as long as the conversation is live, and then for as long as it may be relevant to a business relationship.
Error monitoring
When something breaks, our apps send a diagnostic report to Sentry so we can find out why. A report contains the error, a stack trace, the page or API route involved, and browser or server information.
We run these reports through a filter before they leave, which strips out fields we know carry personal data — names, email addresses, phone numbers, tokens and authentication headers. It is a filter, not a guarantee: a stray value can end up in an error message, and we treat what reaches Sentry as potentially containing personal data rather than pretending otherwise.
On the marketing site the monitoring code is not loaded at all unless you interact with the contact form.
- Why: to keep the service working and secure.
- Legal basis: our legitimate interest in a reliable, secure service (Art. 6(1)(f)).
- How long: as retained by Sentry under our plan, currently 90 days.
Server logs
Our servers log requests — the time, the route, the response and the IP address — to operate the service and investigate abuse or security incidents. Request logs never record request bodies or authentication headers.
- Legal basis: legitimate interest in security and availability (Art. 6(1)(f)).
Part B: when we act for a restaurant
If you booked a table, the restaurant you booked with is the controller of that booking. We process it only on their documented instructions, under the data processing agreement every restaurant enters into with us.
What that covers, on their behalf:
- Your booking — name, email address, phone number, party size, date and time, seating preference, the language you booked in, any notes, and the status of the visit.
- Your guest record, if the restaurant recognises you as a returning guest — the same contact details, any notes staff keep about you, and how many times you have visited or not shown up, counted from the status its staff gave each of your bookings.
- Waiting list entries and the offers made to you from them.
- Marketing consent, if you gave it — including the exact wording you were shown, in the language you saw it, along with the time, your IP address and your browser’s user-agent string. That record is the proof that consent was given, so it is kept even after you withdraw it: withdrawing adds a new entry rather than erasing the old one. Asking to be erased withdraws that consent and takes the record with it: see below.
- Review invitations and reviews, including any comments you write.
- Attendance confirmations and the transactional emails we send you about your booking.
- Bookings imported from a restaurant’s previous booking platform, when it moves to us.
How long
For as long as the restaurant keeps its account with us and, within that, for 3 years after your last contact with the restaurant — your last booking in any status, waiting-list entry, marketing consent, or edit of your guest record by their staff. After that, your name, contact details and notes are erased automatically from your guest record and from every booking you made, and your review comments with them, in the way “If you ask to be erased” below describes; the visits themselves stay on the restaurant’s books with nothing that identifies you. The notes on an individual booking go sooner — see “A note about the notes field” below. If you book again, the 3 years start over. The restaurant can choose a shorter period for all of its guests (never a longer one) and can erase you sooner at any time, and when a restaurant closes its account everything under it is erased on the schedule in Part A.
A note about the notes field
Bookings and guest records have a free-text notes field. Restaurants use it for things like allergies and dietary requirements, which are health data — a special category under Article 9 GDPR.
We do not ask for it, and our software does not require it. But it is the restaurant’s field to use, and when a restaurant migrates from another platform, allergy information from that platform is carried into it. Our agreement with restaurants instructs them to collect health data only where it is strictly necessary and with your explicit consent.
Because a note on a booking is about that visit, the notes on a booking are erased automatically 1 year after the date of the booking, even if you keep coming back to the restaurant. Notes on your guest record — a lasting preference the restaurant keeps for your next visit — stay with the record and follow the rule under “How long” above.
What you should do
To see, correct, or delete your booking data, contact the restaurant. They decide; we act on their instruction. If you contact us instead, we will tell you so and, where we can identify the restaurant, point you to them. We will not act on your request ourselves, because doing so would mean overriding the controller.
Every booking confirmation email we send on a restaurant’s behalf also contains a link that lets you view, reschedule or cancel that booking yourself.
If you ask to be erased
The restaurant can erase you from our software directly, and what that does is worth being precise about, because it is not the same as deleting one booking:
- Your name, contact details and notes are removed from every booking you made with that restaurant. The visit stays on their books — the date, the time and how many people sat down — because that is the restaurant’s own record of what it served, and with your details gone it no longer identifies you.
- Your guest record and any waiting list entries are deleted, along with the emails we sent you about your bookings. The self-service links in those emails stop working, the link to review your visit included.
- The comments you wrote in a review are deleted; your star ratings stay, without your name, as part of the restaurant’s overall scores.
- Being erased withdraws any marketing consent you had given, and the record of it goes with you. This is the one case where that record is deleted, and it follows from what you agreed to: permission to send marketing to you. With you erased there is nobody left to mail, and keeping your email address on file to prove you once agreed would defeat the erasure you asked for. If you book with that restaurant again you start with no consent, and they have to ask you again.
If you have a booking coming up, the restaurant has to cancel it before it can erase you — until the visit happens, your details are still needed for it.
Who else sees the data
We use a small number of service providers. They process data on our instructions only, under contracts that meet Article 28 GDPR, and none of them may use it for their own purposes.
The current list — what each one does, where it is, and what it touches — is maintained as a separate page: Sub-processors. We keep it separate so that restaurants can watch one page for changes rather than diffing this policy.
Beyond that list, we share personal data only where the law requires it, or where it is necessary to establish or defend a legal claim.
We do not sell personal data, and we do not use it to advertise to you.
Transfers outside the EEA
Our infrastructure is in the European Union (Paris, France). We chose providers with EU hosting deliberately.
Some providers are EU-hosted but have a parent company outside the EEA, which can mean support access from a third country. Where a transfer happens, it is covered by the European Commission’s Standard Contractual Clauses together with the additional measures our providers commit to. The sub-processor page records the position for each one.
Cookies and local storage
The marketing site sets no cookies at all and makes no third-party requests. Fonts, styles and scripts are served from our own domain — we deliberately do not load fonts from Google’s CDN, because that would send your IP address to a third country before you had done anything.
The Tablorix app, which only restaurant staff use, sets one cookie: your signed-in session. It is strictly necessary — without it you cannot stay signed in — so it does not require consent. If you turn on two-factor authentication there are two more, both there only because you asked for the feature: one that lasts the 10 minutes between your password and your code, and — only if you tick “trust this device” — one that lets that browser skip the code for 30 days.
It also keeps a few things in your browser’s local storage, purely so the app behaves the way you left it: your light or dark theme, whether you folded the sidebar, which venue you were last working in, your chosen interface language, the progress of an import you are part-way through, and — until you finish setting up a venue imported from another platform — what that import created and which details it asks you to check. None of it is sent to us, none of it identifies you to anyone, and clearing your browser data removes it.
The booking widget your guests use stores nothing at all — no cookies, no local storage. A guest can make a booking without anything being kept on their device.
We run no analytics, no advertising pixels, and no third-party trackers anywhere. This is why you are not being asked to dismiss a cookie banner: there is nothing to consent to.
How we protect it
Data is encrypted in transit. Passwords are stored only as hashes. Access to production systems is limited to the people who need it. Links we email to guests — to manage a booking, confirm attendance, leave a review, or unsubscribe — use unguessable tokens rather than exposing an identifier, and each one only reaches the single booking it was issued for.
If a breach affects you and the law requires it, we will notify you and the supervisory authority within the deadlines the GDPR sets.
To report a security problem, write to security@tablorix.be.
Your rights
Under the GDPR you may ask us to give you access to your personal data, correct it, erase it, restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you may withdraw it at any time, without affecting what we did before you did.
Write to privacy@tablorix.be. We answer within one month, and will tell you if we need longer. We do not charge for this.
Where we rely on legitimate interest, you can object and we will stop unless we have compelling grounds that override your interests.
We make no automated decisions that produce legal or similarly significant effects for you, and we do not score, rank or profile you. For a restaurant, our software counts the visits and no-shows in your booking history with it and shows those numbers to its staff, alongside the history itself. It draws no conclusion from them and holds no bookings back because of them. What they mean for you is for the restaurant’s staff to judge.
If you booked a table, please read Part B first — those requests go to the restaurant.
Complaining
You can lodge a complaint with your local supervisory authority. In Belgium that is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels — gegevensbeschermingsautoriteit.be. We would rather you told us first, but it is your right either way.
Changes
If we change this policy in a way that matters, we will tell account holders before it takes effect. The version and date are at the top of this page.