Last updated: 6. Mai 2026

Privacy policy

This page describes how TableLoop processes personal data during the pilot.

Controller

TableLoop, Rahul Narasimman
Contact: support@tableloop.app

Data we process

  • Customer name, phone number, and optional email address.
  • Orders, cart items, notes, and order status.
  • Marketing consent, consent timestamp, and withdrawals.
  • Loyalty events such as points, visits, and redeemed rewards.
  • Technical events, IP address, and device information via Cloudflare, PostHog EU, and Sentry, to the extent required for operations, security, error analysis, and product improvement.
  • The tl_consent cookie, which stores the analytics consent decision.

Purposes and legal bases

We use data to provide digital menus, process order requests, manage customers and loyalty programs, communicate with restaurant operators, prevent abuse, and improve the product. Legal bases are Art. 6(1)(b) GDPR for orders, Art. 6(1)(a) GDPR for marketing and analytics with consent, Art. 6(1)(c) GDPR for legal obligations, and Art. 6(1)(f) GDPR for operational security and error analysis.

Retention

Order and customer data are stored for the duration of the pilot and thereafter only as long as required for operations, support, consent records, or legal obligations. Analytics events are used only in pseudonymised or aggregated form for product metrics. The tl_consent cookie expires after one year.

When a restaurant deletes a customer, the customer profile, phone number, and email address are removed. Order history and the loyalty ledger are retained for operational auditability, but are detached from the customer profile; orders show only the name snapshot saved at order time.

Processors

TableLoop uses Neon for Postgres databases, Cloudflare for hosting, DNS, R2 media, and security, Resend for email delivery, PostHog EU for product analytics, and Sentry for error reporting. Appropriate data processing agreements with these providers will be in place before production use, where required.

Data subject rights

Data subjects have rights under Art. 15–22 GDPR including access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. Requests can be sent to support@tableloop.app. You also have the right to lodge a complaint with a supervisory authority.