Legal

Privacy policy

TableSpark builds and hosts websites for restaurants. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and the rights you have — whether you run a restaurant on TableSpark or you're a guest of one.

Last updated 6 August 2026 · Contact hello@tablespark.uk

Who we are

TableSpark Ltd ("TableSpark", "we", "us") operates tablespark.uk, a website builder and hosting platform for restaurants. We are a company registered in England and Wales under company number 17384916, with our registered office at Studio 9, 50–54 St Paul's Square, Birmingham, England, B3 1QS. Restaurant websites built with TableSpark are published at addresses like yourname.tablespark.uk or on the restaurant's own domain, but they run on our infrastructure.

That means we wear two hats, and this policy covers both:

  • For our customers (restaurant owners and their teams) we are the data controller: we decide how account data is used to provide the service.
  • For guests of those restaurants (people who book a table, place an order, send an enquiry or join a mailing list on a restaurant's site) we are a data processor: we store and handle that data strictly on the restaurant's behalf and instructions. The restaurant is the controller — contact them first about data you gave them; we'll help them honour any request. For online orders we store the details you give with the order (name, phone number, optional email, your dishes and any notes) so the restaurant can prepare and confirm it; order contact details are anonymised automatically after 24 months. When you pay online, your card payment is processed by Stripe directly for the restaurant's own Stripe account — TableSpark never receives or stores your card number, only whether the order was paid and a payment reference.

For anything in this policy, you can reach us at hello@tablespark.uk, or write to TableSpark Ltd, Studio 9, 50–54 St Paul's Square, Birmingham, England, B3 1QS.

What we collect from platform customers

Account data

When you create a TableSpark account we store your email address and, if you provide them, your name and phone number. Sign-in is handled by our authentication provider (Supabase); passwords are stored only as secure hashes and are never visible to us. Account and transactional emails (sign-in confirmations, password resets, team invites) are delivered through Resend, our email provider.

Your restaurant's content

Everything you put into the builder — menus, photos, opening hours, your restaurant's public contact details — is stored so we can publish your site. It's your content; you can edit or delete it at any time, and deleting a site removes its content, leads and analytics with it.

Billing and plan information

We keep a record of which plan your account is on. Subscription payments are processed by Stripe, our payment provider — you enter card details on Stripe's secure checkout and card numbers never touch our servers. We store only your plan and a Stripe customer/subscription reference.

Support

If you email us, we keep the correspondence so we can help you and refer back to it. We use it for nothing else.

Menu scan files

If you use the AI menu scan, the images, PDFs, Word documents, text files or spreadsheets you upload are kept in private temporary storage and used only to recognise your menu. The default retention window is up to 24 hours: once the temporary scan task expires, the files are deleted. If deletion is interrupted, our cleanup process automatically retries it. We send the files to OpenAI for menu recognition during this process; OpenAI does not use API data to train its models by default.

Legal basis: we process account, content and billing data because it's necessary to provide the service you signed up for (contract), and support correspondence on the same basis or our legitimate interest in running the service well.

Journal reading and signup attribution

If you allow Analytics storage, our first-party measurement can record that a Journal article was viewed and, after the stated active-reading and page-progress threshold, engaged with. If you separately allow Marketing storage, it can connect a Journal call-to-action with signup start and signup completion. A Marketing-only choice can measure the signup path without recording Journal reading events.

The attribution record contains an allowlisted, signed article and call-to-action context plus a one-way SHA-256 hash of a random browser journey ID. We do not put the raw journey ID, signed token, email, name, phone, referrer or IP address in that table. Only on signup completion do we attach the authenticated TableSpark account identifier, so one account cannot be counted as more than one new signup completion.

This measurement is based on your consent, is first-party, and does not require an advertising pixel. You can withdraw either category through Cookie Preferences; the relevant browser attribution state is then removed. Journal attribution events are deleted after 14 months.

What we process for restaurants' guests

Restaurant sites on TableSpark can take bookings, enquiries, gift-card requests, event RSVPs and newsletter signups. When you submit one of these forms, the details go straight into that restaurant's private inbox on TableSpark. Depending on the form, that can include:

  • your name, email address and phone number;
  • booking details — date, time, party size, seating preference, occasion and any notes you add;
  • allergy or dietary notes, if you choose to share them, so the restaurant can look after you. Please share only what the restaurant needs for your visit;
  • for gift cards, the recipient's name and your personal message;
  • for newsletters, just your email address.

Only the restaurant you contacted can see these details (plus TableSpark staff where needed to run and support the platform). We never sell guest data, never use it for advertising, and never contact guests ourselves.

First-party, cookieless analytics

Restaurant sites include a deliberately minimal, first-party visit counter so owners can see how their site is doing. It records the type of action (page view, tap-to-call, directions, booking click), the page path, a coarse traffic source (direct, search, social), device type (mobile or desktop) and a random identifier stored in your browser. It does not record your IP address, your precise location, or what you do on any other website, and it sets no cookies. Restaurants may show a notice letting you decline this measurement.

How long we keep things

  • Account data and site content: for as long as your account is open. Deleting your account, or a site, permanently removes the associated content, leads and analytics.
  • Guest leads (bookings, enquiries and similar): kept for the restaurant until the restaurant or the guest asks for deletion, or the restaurant's account or site is deleted. We are introducing automatic retention limits so old leads don't linger indefinitely.
  • Analytics and consented Journal attribution events: deleted after 14 months.
  • Menu scan files: kept in private temporary storage only for menu recognition. The default retention window is up to 24 hours. After the scan task expires, the files are deleted; if deletion is interrupted, cleanup is retried automatically.

Who we work with

We use a small number of service providers to run TableSpark. They process data only on our instructions:

ProviderWhat they doWhat they handle
CloudflareHosting and delivery of the platform and all restaurant sitesAll site traffic in transit; short-lived technical logs
SupabaseDatabase, authentication and media storageAccount data, site content, guest leads, analytics and consented Journal attribution events
Google Fonts & FontshareDeliver the typefaces used on our pages and templatesYour IP address receives the font files (a standard web request; no cookies)
PexelsFree stock photography that restaurants can use on their sitesYour browser fetches chosen images from Pexels' image servers
OpenAIReads menu images and documents for the AI menu scan (customers only)Menu files for recognition, handled through private temporary storage for up to 24 hours by default
StripeProcesses subscription payments (customers only)Billing details entered on Stripe's secure checkout; we store only your plan and a Stripe customer/subscription reference
ResendDelivers account & transactional emails (sign-in, password reset, invites)Recipient email address and message content

Some restaurant sites also choose to embed third-party content — a Google map, a YouTube video, an external booking widget. Loading those hands a standard web request to that provider; we are moving all such embeds to click-to-load, so nothing loads until you choose it. See our cookie declaration.

Where a provider processes data outside the UK/EEA, transfers are covered by that provider's data-processing agreement and standard contractual clauses.

Your rights

Under UK and EU data-protection law you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. You can also withdraw consent at any time where consent is the basis (for example a newsletter).

  • Guests: the restaurant you dealt with is the controller of your booking or enquiry — contacting them directly is usually fastest, and we give them the tools to delete your details. You can always email us at hello@tablespark.uk and we will pass the request on and make sure it's honoured.
  • Customers: email hello@tablespark.uk from your account address for a copy, correction or deletion of your account data.

You also have the right to complain to the Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority — though we'd appreciate the chance to sort things out first.

Unsubscribing and deletion, in practice

  • Newsletters: every mailing sent through TableSpark will carry a one-click unsubscribe link that works instantly, without a login. Until you unsubscribe, only the restaurant you signed up with can email you through us.
  • Booking and enquiry details: ask the restaurant, or us, and the records are deleted from the restaurant's inbox and our database. Deletion requests made through a restaurant site land in the owner's inbox with a one-click delete action.
  • Whole accounts: account deletion removes the profile, its sites, and everything beneath them.
The self-serve versions of these controls (tokened unsubscribe links and an on-site "your data" request form) are rolling out across all restaurant sites; in the meantime the same outcomes are available by email and are actioned promptly.

Changes to this policy

If we change this policy in a way that matters — new processors, new data, new purposes — we'll update this page, revise the date at the top, and for significant changes notify account holders by email. The current version always lives at tablespark.uk/privacy.