GDPR Compliance

Effective: 2026-04-27

Data Controller and Processor Roles

When your restaurant uses TableSnap, the legal roles are clear:

  • Your Restaurant (Data Controller): When you use TableSnap to manage menus and customer data, your restaurant is the Data Controller. You decide what data is collected, how it is used, and who can access it. You are accountable for compliance with GDPR regarding your own data processing.
  • TableSnap (Data Processor): TableSnap acts as your Data Processor. We process personal data only on your behalf, following your instructions. We implement technical and organizational measures to protect data and assist you in meeting your GDPR obligations.

Your Rights Under GDPR

As a restaurant (Data Controller) or your staff and customers (Data Subjects), you have the following rights. Exercise them by contacting [email protected] or via your account settings:

  • Right of Access: Request a copy of all personal data we hold about you or your customers.
  • Right to Rectification: Correct inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of personal data (the right to be forgotten).
  • Right to Restrict Processing: Limit how TableSnap processes your data while you dispute accuracy or legality.
  • Right to Data Portability: Receive your data in a portable, machine-readable format (e.g., CSV) to move to another service.
  • Right to Object: Opt out of processing for marketing, analytics, or other non-essential purposes.
  • Right to Withdraw Consent: If processing relies on your consent, withdraw it at any time without affecting past processing.

To exercise any of these rights, contact our Data Protection Officer at [email protected] with details of your request. We will respond within 30 days.

Lawful Bases for Processing

  • Performance of Contract: We process data to provide you with menu management and ordering services as agreed.
  • Legitimate Interests: We use analytics and improve our service features in ways that do not override your rights.
  • Consent: We process marketing communications only with your explicit consent, which you can withdraw anytime.

Subprocessors

We share your data with the following subprocessors to operate the platform:

  • AWS: Cloud hosting and data storage in Singapore (ap-southeast-1 region).
  • Cloudflare: Content delivery and image storage (R2).
  • Resend: Transactional email delivery (account confirmations, order notifications).
  • Firebase / Google: Push notifications for restaurant admin alerts.
  • Google OAuth: Authentication and sign-in via Google Accounts.
  • Polar: Polar Software Inc.: subscription billing as Merchant of Record. Polar receives the customer name, email, billing address, and payment instrument for paid plans, applies any required taxes, issues invoices, and processes refunds and chargebacks on our behalf. Polar acts as an independent data controller for the payment transaction.

Data Retention Periods

  • Account data and restaurant information: retained while your account is active, then deleted within 30 days of your deletion request.
  • Audit and system logs: retained for 1 year for security and compliance purposes.
  • Uploaded asset metadata (menu images): retained for 30 days after you delete the asset.

International Data Transfers

Your data is stored in Singapore on AWS ap-southeast-1. For EU/UK customers, this is an international transfer. We use Standard Contractual Clauses (SCCs) to ensure adequate data protection and GDPR compliance.

Data Breach Notification

If we discover a personal data breach, we commit to notifying affected individuals and supervisory authorities within 72 hours as required by GDPR Article 33.

Data Protection Officer

Our Data Protection Officer is available to assist with GDPR requests and privacy concerns. Contact them at:

TableSnap uses essential cookies to keep you signed in. With your consent we also use first-party measurement to improve the product. We never sell your data and we never run third-party trackers.

Read the full cookie policy