Current data posture: the public site collects waitlist email addresses. Invited beta participants may create test accounts and enter restaurant and menu data. We do not currently offer public diner ordering or live payment processing, and beta participants are instructed not to upload real diner, customer-list, payment, or sensitive personal data.
1. Scope and who is responsible
This Privacy Policy applies to the TableSpring marketing website, waitlist, and invitation-only beta. TableSpring decides how and why personal information is handled for these activities.
It does not yet cover a generally available restaurant ordering service. Before live diners or external restaurant customers use TableSpring in production, we will update this policy and publish the additional restaurant and diner terms needed for that service.
2. Information we collect today
2.1 Waitlist and marketing website
- Email address when you join the waitlist or contact us.
- Signup context, including the page or button used to join, the referring URL when available, and the submission time.
- Request and security information, such as IP address, browser and device information, and request timestamps. We use an IP address transiently to rate-limit the waitlist form; our hosting provider may also create ordinary request logs.
- A local preference recording whether you dismissed the site’s migration notice. The Cookie Notice gives the exact detail.
2.2 Invitation-only beta
- Account information, such as email address, authentication credentials managed by our authentication provider, user identifier, and optional name, phone number, or profile image.
- Restaurant and menu test data, such as restaurant name, contact details, location, hours, timezone, menu content, pricing, dietary or allergen labels, branding, photos, and publication history.
- Team and security records, such as roles, invitations, account events, session information, IP address, and request metadata.
- Google business lookup data, if you use that optional beta feature, including the search text, a short-lived lookup session identifier, the selected Google Place ID, and the business details Google returns.
- Content stored in your browser, including an in-progress restaurant setup draft and interface preferences. See the Cookie Notice.
- Feedback and support information that you choose to send us, including bug reports and related technical context.
2.3 Where it comes from
We receive information directly from you, automatically from your browser and our systems, from a person who invites you to a beta team, and from Google if you choose the business lookup feature.
3. What we do not collect or do at this stage
For the public waitlist and current internal beta:
- we do not process live diner orders or card payments;
- we do not ask beta participants to upload real diner or customer lists;
- we do not run advertising pixels, cross-site trackers, or session replay;
- we do not use a third-party product analytics service on the marketing site;
- we do not sell personal information or share it for targeted advertising; and
- we do not use beta content to train a general-purpose machine-learning model.
Please do not put payment-card data, government identifiers, health information, live diner data, or other sensitive personal information into beta forms, menu notes, uploads, or feedback. If we learn that such information was submitted, we may remove it.
4. How we use information
We use the information above to:
- maintain the waitlist and send waitlist, beta-access, and launch communications;
- create accounts, authenticate beta participants, and keep sessions secure;
- provide, test, debug, secure, and improve beta features;
- save and display the restaurant and menu test content a participant enters;
- respond to questions, feedback, and rights requests;
- detect abuse, enforce rate limits, and protect our systems and participants; and
- comply with law and establish, exercise, or defend legal claims.
5. How we disclose information
We disclose information only as reasonably needed for the purposes above. Current recipient categories include:
- Infrastructure providers that host the website and application and process ordinary request logs.
- Supabase and its infrastructure providers for database hosting, authentication, account email, and related backend services.
- Google when an invited participant chooses the Google business lookup; Google receives the lookup query, session token, Place ID, and request metadata needed to return results.
- Object-storage and delivery providers, when image upload is enabled for a beta participant, to store and serve submitted menu images.
- Professional advisers and authorities when reasonably necessary for legal, security, accounting, or compliance purposes.
- A successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice where required.
We may disclose de-identified or aggregated information that cannot reasonably identify you. We do not sell personal information or share it for cross-context behavioral advertising.
6. Cookies, tracking, GPC, and Do Not Track
Our Cookie Notice lists the cookies and browser storage used today. We use only storage needed for authentication, security, beta workflows, saved test carts, and interface preferences. We do not use advertising cookies or cross-site tracking.
Because we do not sell personal information, share it for targeted advertising, or run cross-site advertising trackers, a Global Privacy Control signal does not change the website’s current behavior. We do not respond separately to the older, non-standardized “Do Not Track” header. Other parties do not collect information through our site to track your activity over time across unrelated websites.
7. How long we keep information
We keep waitlist information while we are developing and launching TableSpring, unless you ask us to remove it sooner. We keep beta account and test content while the beta account is active and for a limited period afterward when reasonably needed for security, backup, troubleshooting, or legal purposes.
Retention depends on why we hold the information, whether the beta is still active, whether it is needed to resolve a problem, and any legal obligation. Data in provider backups is removed as those backups age out under the provider’s normal cycle. We may keep aggregated or de-identified information that no longer identifies a person.
8. Your choices and privacy requests
- Waitlist: unsubscribe using the instructions in an email or ask us to remove your address.
- Beta account: update information in available beta controls or contact us to request access, correction, export, or deletion.
- Browser storage: clear cookies and site data in your browser. Clearing required beta cookies will sign you out.
Depending on where you live, privacy law may give you rights to access, correct, delete, or obtain a copy of personal information, or to appeal a denied request. We will honor rights that apply and will not discriminate against you for making a request. We may need to verify your identity before acting.
Send requests to hello@tablespring.com. An authorized agent may submit a request where applicable law permits, but we may ask for proof of authority and may verify the request directly with you.
9. Security
We use technical and organizational safeguards appropriate to the current beta, including encrypted connections, managed authentication, HTTP-only session cookies, server-side access to the database, role-based access, and database row-level security. No safeguard is perfect, and the beta should not be used to store sensitive or production data.
10. United States operation and international use
TableSpring is currently a U.S.-first service, and information is primarily processed in the United States. If you access the Services from another country, your information may be transferred to a country whose data-protection rules differ from those where you live. Do not use the internal beta to process regulated production data outside the United States unless we have agreed in writing to the necessary terms first.
11. Children
The Services are not directed to children under 13, and beta accounts are limited to people who are at least 18. We do not knowingly collect personal information from children under 13. If you believe a child submitted information, contact us so we can investigate and delete it where appropriate.
12. Changes and contact
We may update this policy as TableSpring changes. We will post the revised policy here and change the date above. If a change materially affects an invited beta participant, we will also provide reasonable notice through the beta or by email.
Privacy questions and requests: hello@tablespring.com.