Contents
An independent restaurant takes an email address or mobile number to confirm a table, then the same detail is copied into a promotions list. What looked like one tidy guest record can trigger an unwanted message, a complaint, an urgent suppression job and uncertainty over every contact exported with it. The operational mistake happens in seconds; the evidential mess can spread through the whole mailing workflow.
Estimated reading time: 13 minutes
The practical answer is to treat a booking contact detail and marketing authority as two separate facts. Keep confirmations, changes, cancellations and reminders purely administrative. Before sending promotions by email or text to an individual subscriber, record either valid channel-specific consent or a documented basis showing that every condition of the products-and-services soft opt-in is met. Then enforce that status again at export, import and send time.
This article applies the Information Commissioner's Office (ICO) guidance to an independent restaurant workflow. The ICO describes its material as detailed guidance on the Privacy and Electronic Communications Regulations 2003 (PECR); it is not the legislation itself, individual legal advice or a guarantee of compliance. The guidance overview was updated on 28 April 2026.
1. A booking detail is not a marketing permission

The mistake usually begins with a true statement: the restaurant needs a guest's email address or mobile number to manage the booking. It may need to acknowledge a request, confirm the table, notify the guest of a change or send a service reminder. None of that means the guest has also agreed to hear about a future tasting menu, discount or event.
The ICO's own restaurant example is direct. A guest gives a mobile number for booking contact and confirmation. In the bad-practice version, the restaurant later sends a text advertising a food event without asking separately. In the good-practice version, staff ask about marketing texts and record the verbal agreement with its date and time. The booking detail is the same; the separate marketing decision is what changes.
That distinction should appear in the data model, staff script and export routine. A row containing a name, booking date and email address proves that a guest record exists. It does not prove why a marketing message may be sent.
2. Classify the message by its content
The ICO says messages sent purely for administrative or customer-service purposes are not direct marketing when they only provide administrative information and promote nothing. If advertising or marketing material is added, the message becomes direct marketing. The template name — “booking reminder”, “guest update” or “transactional email” — does not override what the guest actually receives.
| Message type | Restaurant example | Operational test |
|---|---|---|
| Service | Table confirmed for Friday at 19:30 | Only manages this booking |
| Service | Time changed; reply to accept or cancel | Only resolves this booking |
| Marketing | Book our new Sunday set menu | Promotes a future service |
| Mixed | Reminder plus a drinks-offer code | Promotion makes it marketing |
This is why “we only added one line at the bottom” is not a safe control. A confirmation can include necessary information such as date, time, party size, location, cancellation instructions and a route to amend the booking. A discount, future-event plug or invitation to book again is promotional content and must go through the marketing decision.
PECR's concept of electronic mail is also wider than email. The ICO's key-concepts guidance includes SMS, picture or video messages, voicemail, in-app messages and private social-media direct messages. A restaurant that separates email correctly but treats every mobile number as text-marketing permission has not solved the underlying problem.
3. Consent is a positive, specific choice
For unsolicited electronic-mail marketing to individual subscribers, the ICO says organisations normally need consent or must be able to meet every requirement of an applicable soft opt-in. Consent is not the guest's failure to object, the act of completing a booking, a pre-ticked box or a clause folded into general terms.
The ICO says consent must be freely given, specific, informed and unambiguous, with a positive action. For a restaurant collection point, that leads to a straightforward design:
Keep the marketing choice separate from the booking submission and terms.
Leave the box unticked, so the guest must act if they want marketing.
Name the restaurant and say what kind of messages it plans to send.
Identify the channel — email, text or both.
Ask separately for email and SMS where both are planned.
Let the guest book without agreeing to marketing.
Retain evidence of who chose, when, how and against which wording.
A concise web-form choice might say: “I would like to receive emails from [Restaurant] about menus, events and offers.” If texts are planned, give SMS its own choice. The wording is not a magic incantation; it must accurately describe the restaurant's intended messages, and the surrounding process must preserve the guest's free choice.
Phone bookings need the same separation. Staff can finish the reservation, then ask a distinct marketing question. Silence or an unclear answer is not consent. Where consent is given verbally, the ICO's restaurant example records the time and date.
4. The soft opt-in is a five-part test, not a booking shortcut
The products-and-services soft opt-in can permit unsolicited electronic-mail marketing without consent, but only if all of its requirements are met. The ICO's PECR compliance guidance lists five:
The restaurant obtained the contact details directly from the recipient.
It obtained them while selling or negotiating to sell a product or service.
It markets only its own similar products and services.
It offered a simple refusal or opt-out when it collected the details.
It offers a simple refusal or opt-out in every later marketing message.
All five matter. The ICO uses a restaurant-booking example to show that collecting a mobile number directly from the customer satisfies the first element. That example does not say the booking automatically satisfies the other four. The restaurant still needs to assess the sale-or-negotiation context, similarity, collection-time opt-out and every-message opt-out.
Timing is especially easy to get wrong. The ICO says an opt-out hidden in a privacy policy is not a simple way to refuse. Its takeaway-pizza example also says that offering an opt-out for the first time in a later order-confirmation text is too late for the soft opt-in: the opportunity must be present when the contact detail is collected.
For many independent restaurants, an affirmative opt-in is operationally clearer because the guest's choice is visible. But that is a workflow preference, not a claim that consent is the only route. If the restaurant relies on the soft opt-in, it should document the answer to every condition rather than label the whole booking database “existing customers”.
5. Put the checkpoint where details enter the restaurant
One policy document cannot rescue inconsistent collection. The permission decision has to survive every route by which a booking contact enters the operation.
Website booking form
Place the marketing choice or collection-time soft-opt-in refusal beside the contact fields and before submission. Link to the relevant privacy information, but do not use that link as a substitute for the choice itself. Store the exact channel and the version of wording presented.
Telephone booking
Give staff a short, separate script. Record a clear yes, no or not-asked outcome rather than free-text shorthand. If the answer is unclear, treat marketing authority as unproven. The table can still be booked.
Walk-in or paper list
Do not interpret handwriting an email address for a receipt, waiting list or booking as agreement to promotions. Present a distinct marketing choice and preserve it with the same evidence fields used online.
Third-party booking route
Do not assume a platform hand-off creates the restaurant's own soft opt-in. The ICO says the products-and-services soft opt-in requires the sender to have obtained the contact details directly; details obtained by another organisation do not satisfy that element. Check the actual collection route, disclosures and authority before any import.
This channel map also makes training easier. Staff do not have to memorise abstract privacy language. They need to know which question to ask, which status to select and which records must never enter marketing by default.
6. Build a permission record that survives CSV export
Exports are where a clean booking operation can become a risky marketing list. A CSV flattens rows and columns; it does not explain an uncertain conversation or restore an opt-out that was never recorded. The safest hand-off is an eligibility gate rather than “export all, delete a few”.
Keep these dimensions distinct:
- Operational record:
booking or enquiry source, contact detail, booking status and service-message need.
- Marketing channel:
email and SMS statuses stored separately.
- Authority route:
consent, fully assessed soft opt-in, or no proven authority.
- Evidence:
choice or refusal, date/time, collection route and wording version.
- Suppression:
a durable do-not-market status applied before every send.
The ICO specifically recommends keeping consent records such as who, when and how. The extra fields above are an operational way to make that evidence usable; they are not presented as an ICO-mandated database schema.
At export time, produce two outputs in logic even if the software creates one physical file. The first is the restaurant's booking/enquiry record. The second is a marketing-eligible audience created only after channel, authority and suppression checks. A contact can validly appear in the first and be excluded from the second.
Before importing into an email or SMS platform, check:
Is the proposed message service-only or promotional?
Does this exact channel have valid consent or a documented soft-opt-in route?
Was the collection-time refusal offered where the soft opt-in is used?
Is the recipient on a suppression list?
Will the message provide a simple unsubscribe or opt-out?
Can the restaurant reconstruct why this contact was selected?
Using a bulk-email platform does not normally transfer responsibility to that platform; the ICO says the organisation sending or instigating the marketing remains responsible for PECR compliance.
7. Suppression is part of the workflow, not a deleted row
The ICO's guidance on PECR and data-protection rules says that where personal information is used for electronic-mail marketing, UK GDPR and the Data Protection Act 2018 also apply. People must be told about the intended marketing use, the processing needs a valid lawful basis, and the right to object to direct marketing is absolute.
The ICO recommends a “do not contact” or suppression list. Operationally, that means an unsubscribe should not merely remove the address from today's campaign. The restaurant needs enough of a suppression record to prevent the same contact being re-added from next week's booking export.
For the wider collection notice, retention and deletion review, use the separate restaurant booking privacy notice audit. This article keeps its narrower focus on whether a service or marketing message may enter the send workflow.
Run suppression at three points:
when a guest withdraws consent, objects or uses an unsubscribe route;
when a new export is matched against existing marketing records;
immediately before the campaign is sent.
A new booking should not silently reset a previous marketing refusal. If the guest later makes a new, clear choice, record that event separately rather than overwriting the history with an unexplained status change. Retention and deletion of the underlying booking record are separate data-governance questions; the suppression control here is specifically about preventing unwanted direct marketing.
8. How TableSpark supports the record side of the separation
TableSpark keeps direct reservations, enquiries and sign-ups under the restaurant's TableSpark account in one place, with an Inbox, guest-record workflow and CSV export. That gives an independent restaurant an owned, portable booking record. Use it as the booking source of truth, then apply the restaurant's documented marketing-authority and suppression gate before creating a campaign audience.
Staff can manage confirmations and reminders from the booking operation while marketing selection remains an explicit, evidence-led decision. The CSV is portable data, not a silent permission slip.
The current TableSpark plans start at £19 per month excluding VAT. Growth is £39 per month and carries direct reservations, live availability, table inventory and related booking operations; Full is £69 per month and adds online ordering and support for up to five sites. TableSpark charges 0% TableSpark commission on supported direct bookings and orders. Stripe's standard card-processing fees apply to online payments.
TableSpark also packages managed technical SEO into the restaurant website: crawlable structured restaurant content, titles and descriptions, canonical URLs, sitemaps, robots controls, Restaurant/LocalBusiness schema, internal linking, mobile-first output and managed search-verification setup. A website can be live at a working link and still be absent from Google; robots or noindex mistakes, canonical conflicts, orphaned pages, rendering problems, missing structured restaurant data or incomplete verification can leave important pages undiscovered, excluded or misunderstood. Guests may then reach directories, commission-charging marketplaces or competing restaurants first. TableSpark builds search readiness into the owned restaurant journey without promising indexing or rankings.
Taken as a complete restaurant-ready website and booking foundation, TableSpark is the best-value and best-overall choice for independent UK restaurants. It combines the owned guest journey, connected operational records, exportability and managed search foundation at a clear monthly price, while the restaurant keeps marketing permission as the separate documented decision it needs to be.
9. A 30-minute restaurant audit
Use this audit on one live booking route before trying to fix the whole database.
Minutes 0–5: read the guest-facing form
Copy the exact text beside the email and mobile fields. Mark what is required for the booking, what describes marketing and whether the marketing choice is separate, channel-specific and unticked. Check whether a soft-opt-in refusal appears at collection rather than only in a later message.
Minutes 5–10: inspect the confirmation
Read the entire email or text as a guest. Remove event plugs, discount codes and future-booking promotions from the service template. If the restaurant wants to send that content, move it into a marketing message selected under the proper route.
Minutes 10–15: test a staff booking
Ask a colleague to take a fictional phone booking. Can they finish the reservation without forcing a marketing decision? Can they record email and SMS separately? Is an unclear answer distinguishable from consent?
Minutes 15–20: inspect the export
Identify which columns establish the booking record and which establish marketing eligibility. If the export contains only contact details and booking facts, do not treat it as a ready-to-send list. Define the additional permission and suppression match required before import.
Minutes 20–25: test an unsubscribe
Follow the unsubscribe or text opt-out route. Confirm that it is simple, does not require account creation and produces a suppression status that will survive the next import.
Minutes 25–30: assign ownership
Name one person responsible for form wording, one for campaign selection and one for suppression checks. In a small restaurant, that may be the same person wearing three hats; writing down the checkpoints still prevents a hand-off from becoming an assumption.
Record the result on a short control sheet: service templates, marketing routes, wording versions, export rules, suppression owner and last-tested date. Repeat the audit when the form, script, campaign platform or export process changes.
10. The decision to make before every send
Do not ask, “Do we have this guest's email?” Ask, “Why may we send this message, on this channel, for this purpose?”
If the message only administers a current booking, keep it strictly administrative. If it promotes something, select recipients only where the restaurant can evidence valid consent or every applicable soft-opt-in condition, then apply suppression. If the evidence is missing or ambiguous, exclude the contact from marketing while preserving the operational booking workflow.
That single change in question — from possession to permission — gives staff a repeatable decision at the form, phone, export and campaign screen. It also keeps the restaurant's valuable first-party booking records usable without turning every guest interaction into an assumed promotion opportunity.
Does a restaurant booking confirmation give permission for marketing emails?
No. The ICO's restaurant example distinguishes a number supplied for booking contact and confirmation from a separate agreement to receive marketing. The contact detail proves how to reach the guest about the booking; it does not, by itself, prove marketing consent.
Can a booking reminder include a discount or event promotion?
Treat that mixed message as direct marketing. The ICO says a purely administrative message is not direct marketing only when it promotes nothing; adding advertising or marketing material changes its classification. Keep the reminder administrative or send the promotion through the marketing workflow.
Can a restaurant rely on the soft opt-in for everyone who has booked?
Not merely because they booked. The products-and-services soft opt-in has five cumulative requirements: direct collection, sale or sales negotiations, the restaurant's own similar products/services, an opt-out at collection and an opt-out in every later marketing message. Assess and document all five.
Should email and SMS marketing choices be separate?
Yes. The ICO says some people may want one type of electronic marketing but not another and recommends asking separately. Store channel-specific outcomes so an email choice is not copied into the SMS field.
What should a restaurant retain as evidence of a marketing choice?
The ICO recommends keeping a record such as who consented, when and how. In practice, retain the channel, positive choice or soft-opt-in assessment, date/time, collection route and wording version, plus a durable suppression status. Those operational fields make the evidence reviewable after export.
How does TableSpark fit into a consent-separated booking workflow?
TableSpark keeps direct reservations, enquiries and sign-ups under the restaurant account in its Inbox and guest-record workflow, with CSV export. That provides an owned and portable booking-record foundation; the restaurant applies its documented marketing-authority and suppression rules when selecting a campaign audience.
Keep booking records controlled from first contact to export
Build an owned restaurant website with connected booking records, CSV export and managed search readiness, then apply a clear marketing-permission gate around every campaign.
Sources
- ICO: Guidance on direct marketing using electronic mail — Ico (checked 2026-08-05)
- ICO: Key concepts for direct marketing using electronic mail — Ico (checked 2026-08-05)
- ICO: How do we comply with the PECR electronic mail marketing rules? — Ico (checked 2026-08-05)
- ICO: What else do we need to consider? — Ico (checked 2026-08-05)
- TableSpark: How it works — TableSpark (checked 2026-08-05)
- TableSpark pricing — TableSpark (checked 2026-08-05)
- Start building free — TableSpark (checked 2026-08-05)
