TablesHQ
  • Features
  • Pricing
  • Contact
Request a Demo
Features Pricing Contact Request a Demo
Legal

Privacy Policy

Last updated: 22 July 2026

Tables HQ is committed to protecting your personal data and respecting your privacy. This policy explains what data we collect, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.

1. Who We Are

Tables HQ is a product of Atelier Software Ltd, a company registered in England and Wales (Company No. 17298011), whose registered office is at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. We are registered with the Information Commissioner's Office (ICO Registration No. ZC182076).

Atelier Software Ltd ("we", "us", "our") operates the Tables HQ restaurant management platform and this marketing website. We act as the data controller for information collected through this website.

For enquiries about this policy or your personal data, contact us at: info@tableshq.com

2. Data We Collect

From this website

When you submit a demo request or contact form, we collect:

  • Your name and email address
  • Your restaurant name and phone number (if provided)
  • Your message

We do not use cookies for tracking or advertising on this website. Google Fonts are loaded from Google's CDN — Google may process your IP address as part of this request.

From platform customers

When a restaurant subscribes to Tables HQ, the restaurant operator is the data controller for their staff and guest data. Tables HQ acts as a data processor on their behalf. The categories of data processed through the platform include:

  • Staff accounts — name, email address, role, and PIN (hashed)
  • Guest profiles — name, contact details, dietary preferences, allergen notes, visit and order history, loyalty tier
  • Reservation and order records
  • Financial transactions (processed via Stripe — card data is never stored on our servers)

Guest allergen notes and dietary preferences may constitute special category health data under UK GDPR. Tables HQ processes this data solely as a data processor on the restaurant's instructions. The restaurant operator, as data controller, is responsible for ensuring an appropriate legal basis (such as explicit consent) is in place when collecting this information from guests.

Our use of this data is governed by a Data Processing Agreement (DPA) incorporated into our Terms of Service. We do not use customer data for any purpose beyond operating the platform.

3. How We Use Your Data

We use data collected through this website to:

  • Respond to your demo request or enquiry
  • Follow up on potential commercial arrangements
  • Improve our marketing and product communications

We do not sell your data to third parties. We do not use your data for automated decision-making.

4. Legal Basis for Processing

Under UK GDPR, our legal bases for processing are:

  • Legitimate interests — responding to demo enquiries and conducting pre-sales activities
  • Contract performance — processing platform customer data to deliver the service
  • Legal obligation — retaining financial records as required by law

5. Third-Party Services

We use the following sub-processors and third-party services:

  • FastHosts — provides the UK-based server infrastructure on which the Tables HQ platform and all customer data are hosted. See FastHosts' Privacy Notice.
  • Formspree — handles contact form submissions from this website. Formspree receives the data you enter in the contact form. See Formspree's Privacy Policy.
  • Stripe — processes all card payments, including subscription billing and in-venue card-present transactions. Stripe is independently PCI-DSS Level 1 certified. We never store or transmit raw card numbers. See Stripe's Privacy Policy.
  • Postmark (operated by ActiveCampaign) — sends transactional emails on the platform's behalf: password resets, reservation confirmations and reminders, payment receipts, and related account notifications. See ActiveCampaign's Privacy Policy.
  • Google Fonts — fonts are loaded from Google's servers. Google may process your IP address. See Google's Privacy Policy.
  • Twilio (optional) — if a customer enables WhatsApp notifications, guest messages are sent via Twilio. This is an optional feature enabled at the restaurant's discretion.
  • PeaSoup Cloud — stores an encrypted, off-site copy of database backups within the UK, for disaster recovery. Backups are encrypted before they ever leave our servers; PeaSoup does not hold the decryption key and cannot access the underlying data. See PeaSoup's Privacy Policy.

All sub-processors are required to process data only for the purposes we specify and in accordance with applicable data protection law.

6. Data Retention

  • Demo enquiries — retained for up to 24 months after our last communication.
  • Platform data — retained for the duration of your subscription plus 90 days after termination, to allow for account recovery and data export. Within an active subscription, retention of operational records (orders, invoices, reservations) and the audit log is fully configurable by you within the platform, from as little as 1 day upward, with sensible out-of-the-box defaults of 90–365 days depending on record type. As the data controller for your guests' and staff's data, you are responsible for setting retention periods that meet your own legal obligations — for example, UK businesses are generally expected to keep financial records for at least 6 years under HMRC guidance.
  • Anonymisation — upon request or after the retention period, personal data is either deleted or anonymised.

7. Data Security

We take security seriously. Measures include:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Passwords and PINs are hashed using PBKDF2/HMAC-SHA512 and are never stored in plain text
  • Two-factor authentication (MFA) is available for all staff accounts
  • Access to personal data is restricted to staff who need it to perform their role
  • Platform data is isolated per tenant using schema-level database separation
  • Staff sign-in is rate-limited, and an account is automatically locked out for 15 minutes after repeated failed password attempts, protecting against brute-force and credential-stuffing attacks
  • Database backups are encrypted before they ever leave our servers and stored both locally and off-site with a UK-based provider, so a hardware failure never means data loss

8. International Transfers

Some of our third-party sub-processors are based in the United States. Stripe, Twilio, and Google all process data on servers outside the UK and EEA. These transfers are covered by Standard Contractual Clauses (SCCs) approved by the UK ICO or by an applicable adequacy decision, ensuring an equivalent level of data protection applies.

Where we host platform data directly, we use infrastructure within the UK or EEA. We do not transfer Customer data to any jurisdiction without ensuring appropriate safeguards are in place.

9. Your Rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — ask us to delete your personal data where there is no lawful reason to retain it
  • Restriction — ask us to restrict processing of your data in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests

To exercise any of these rights, email info@tableshq.com. We will respond within 30 days.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). Our ICO registration number is ZC182076.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. For material changes, we will notify platform customers by email.

11. Contact

For any questions about this Privacy Policy or your data, please contact us at info@tableshq.com.

TablesHQ
Built for the world's finest restaurants.
Privacy Policy Terms info@tableshq.com
© 2026 Atelier Software Ltd. All rights reserved. Company No. 17298011.