Privacy notice
Last updated 8 September 2026
TableTango is a reservation service for independent UK restaurants, operated by TableTango Ltd, a company registered in England & Wales (company no. 17287615) whose registered office is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. For the personal data we control — your account details and any enquiries you send us — TableTango Ltd is the data controller, and we are registered with the UK Information Commissioner’s Office (ICO), registration reference ZC178111. This page explains, in plain English, what personal information passes through TableTango, why, and what your rights are. Questions or requests: hello@tabletango.co.uk.
The short version
- We collect what a booking needs — your name, a way to reach you (a mobile number and/or an email address), party size, date and time — and use it to make, manage and remind you about that booking. If the restaurant holds a card to secure your table, Stripe collects the card itself — we never see the full number — and we keep only the record needed to run and account for that hold.
- We never sell your personal data, and TableTango never uses it to market to you. A restaurant may ask, when you book, whether you would like their news and offers by email or text — both boxes start empty, either or neither is fine, your booking is unaffected either way, and you can change your mind at any time from the link on your confirmation. Unless you choose that, the only messages a restaurant sends through us are about your booking (confirmation, reminder, waitlist and cancellation); we do not send review-request or marketing texts. Automatic review invitations aren't part of v1 — they return later as an opt-in feature — and whenever one is offered it is via a Google review link, never a marketing text, and it is the same link for every guest, never gated.
- We set no advertising or tracking cookies of our own — only essential storage for things like restaurant logins. Booking pages embed no third-party maps or trackers that load automatically: your browser makes no connection to Google (or any other third party) just from viewing a booking page. A “Get directions” link is provided, and it only contacts Google if you choose to click it (details below).
What we collect, and why
- When you book a table — your name, a mobile number and/or an email address, party size, date and time, and any notes you add (like "birthday" or dietary needs). We need a way to reach you about the booking. On most restaurants' booking pages a mobile number is required and an email address is optional; a few ask for an email address instead. If you give an email address, it's used for your booking confirmation and day-before reminder emails. Where the restaurant has text messages switched on, you may also get those by text on the mobile number you gave. Used to create and manage the reservation, assign your table, and send your confirmation and a reminder. Legal basis: taking steps you've asked for (contract), and the restaurant's legitimate interest in reducing no-shows.
- When you chat with the booking assistant — your messages are processed in real time by our AI provider (Anthropic's Claude) so the assistant can understand and respond. Conversations are not used to train AI models, and we don't keep chat transcripts on our servers after the conversation.
- When a restaurant signs up — the owner's email address and login, used to run their dashboard. Legal basis: contract.
- Text messages (where the restaurant has text messages switched on) — the number, message text and delivery status of each text we send (confirmation, reminder, waitlist or cancellation) are logged so the restaurant can see what was sent.
- When a restaurant secures your booking with a card (the No-show Shield, where that restaurant has switched it on) — the card itself is collected by Stripe into the restaurant's own Stripe account: your full card number and security code never reach TableTango's servers and we never store them. To set the hold up we send your name, phone number and email address to that restaurant's Stripe account, so Stripe can hold the card against a customer record for your booking. What we keep is the record needed to run and account for the hold — Stripe's own references for the checkout session, the customer, the saved card and any payment; the card's brand and last four digits; when you agreed and the fee policy in force at that moment; the status of the hold or fee; any amount charged or refunded; and whether a payment was disputed. Legal basis: contract, and the restaurant's legitimate interest in charging a no-show fee you agreed to.
- When you email us — we use your details to reply. Legal basis: legitimate interests.
- Security & abuse prevention — when you use a booking page we briefly process your device's IP address to rate-limit requests and prevent abuse and fraud. Legal basis: legitimate interests (keeping the service secure and available).
Who helps us run TableTango
Like nearly every online service, we use a small number of specialist providers, each handling only what their job requires: Supabase (our booking database, hosted in London, UK), Netlify (website hosting), Anthropic (AI chat processing), The SMS Works (UK-based, sending text messages), Zoho Mail / ZeptoMail (EU-hosted — our mailbox, and the Zoho service that sends your booking confirmations and account emails), Stripe (payment processing — our subscription billing; holding a guest's card for the No-show Shield at restaurants that have it switched on; and, if and when deposits, prepayments and booking add-ons become available and a restaurant turns them on, collecting and settling those — with the restaurant as merchant of record on its own Stripe account), and Bouncer (email-deliverability checks for our own outreach to restaurants). Where a provider processes data outside the UK (for example in the United States), the transfer is covered by UK-approved safeguards such as the UK Extension to the EU-US Data Privacy Framework or standard contractual clauses.
Restaurant booking pages show the restaurant's address as text only — they do not embed a Google Maps view or any other third-party content that loads with the page, so your browser makes no connection to Google (or any other third party) just from viewing a booking page. We provide a “Get directions” link, which is an ordinary link that contacts Google only after you click it — at which point Google's own privacy policy applies.
How long we keep things
We don't keep personal booking data forever. A booking is kept while the restaurant uses TableTango so it has an accurate history, but 24 months after the booking date we automatically anonymise the personal details (name, phone, email, notes) — the restaurant keeps the anonymous record for its statistics, but the personal information is removed. Text and email logs, and unused waitlist and feedback records, are automatically deleted after 24 months. On request, or when the restaurant leaves, your identifying details go, and so does the card information we display (its brand and last four digits). Two things deliberately do not go at that moment: a limited set of payment references, so a payment can still be settled, refunded, reconciled or defended if it is disputed; and, only while a fee you agreed to could still be charged, the reference to your saved card — the service needs that reference to make the agreed no-show charge if the restaurant marks the booking as a no-show. Asking Stripe to delete the customer record it holds for you is a separate step that stays open until Stripe confirms it, so it is not always immediate. The 24-month anonymisation above clears most of those payment references too, though the reference to a fee checkout and to any refund currently remain. Account details are kept until the account closes. Our demo restaurant's data is reset periodically.
Booked through a restaurant?
Your rights
UK law gives you rights over your personal data: to ask for a copy, have it corrected or deleted, object to or restrict how it's used, and ask for it in a portable format. For the data TableTango controls — your account details and any enquiries you send us — email hello@tabletango.co.uk and we'll respond within a month. For a booking you made at a restaurant, that restaurant is the controller of your data, so please contact them — though you're welcome to email us too and we'll pass your request on and help them honour it. If you're unhappy with how we've handled something, you can complain to the UK's regulator, the Information Commissioner's Office, at ico.org.uk.
Changes
If this notice changes meaningfully, we'll update the date at the top and, for significant changes, say so on the website.