Security and trust posture

Plain-language summary of how we handle your menus, your guests, and the keys to it all.

Encryption

All traffic between your browser and TableSnap is encrypted with TLS 1.3. At rest, menu data, account records, and uploaded images are stored on encrypted volumes managed by our infrastructure providers. Keys are rotated on the schedules our providers publish; we do not roll our own cryptography.

Data residency

Menu photos and dish images live in Cloudflare R2, served from a global edge so guests load menus quickly wherever they are. You can request a full export of your account's data at any time from your dashboard, or ask us to delete it permanently.

Authentication

Sign-in uses signed JSON Web Tokens with short-lived access tokens and rotating refresh tokens. Passwords are hashed with a modern, memory-hard algorithm; we never see them in plaintext. Optional OAuth providers (such as Google) are available for teams that prefer single sign-on.

Privacy by default

Guests do not need to sign up to view a menu. We do not embed third-party advertising trackers, and our product analytics are anonymised at collection. If you turn analytics off, the product still works exactly the same.

Vendor stack

We rely on a focused set of vendors: Cloudflare R2 for object storage, Google Gemini for AI menu extraction, and Polar for billing. The full data-processing relationship for each is documented in our privacy policy.

TableSnap uses essential cookies to keep you signed in. With your consent we also use first-party measurement to improve the product. We never sell your data and we never run third-party trackers.

Read the full cookie policy