Security and trust posture
Plain-language summary of how we handle your menus, your guests, and the keys to it all.
Encryption
All traffic between your browser and TableSnap is encrypted with TLS 1.3. At rest, menu data, account records, and uploaded images are stored on encrypted volumes managed by our infrastructure providers. Keys are rotated on the schedules our providers publish; we do not roll our own cryptography.
Data residency
Menu photos and dish images live in Cloudflare R2, served from a global edge so guests load menus quickly wherever they are. You can request a full export of your account's data at any time from your dashboard, or ask us to delete it permanently.
Authentication
Sign-in uses signed JSON Web Tokens with short-lived access tokens and rotating refresh tokens. Passwords are hashed with a modern, memory-hard algorithm; we never see them in plaintext. Optional OAuth providers (such as Google) are available for teams that prefer single sign-on.
Privacy by default
Guests do not need to sign up to view a menu. We do not embed third-party advertising trackers, and our product analytics are anonymised at collection. If you turn analytics off, the product still works exactly the same.
Vendor stack
We rely on a focused set of vendors: Cloudflare R2 for object storage, Google Gemini for AI menu extraction, and Polar for billing. The full data-processing relationship for each is documented in our privacy policy.
