This Privacy Policy explains how TableFlow collects, uses, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read it carefully. By using our website or platform, you acknowledge that you have read and understood this policy.
TableFlow (“we”, “us”, “our”) is the data controller responsible for your personal data. We operate a QR-code ordering platform for UK restaurants and hospitality venues.
If you have any questions about this policy or how we handle your data, please contact us at info@table-flow.com.
We collect personal data in the following contexts:
We use personal data to:
We will never sell your personal data to third parties or use it for purposes materially different from those described here without first obtaining your consent.
Under the UK General Data Protection Regulation (UK GDPR), we rely on the following legal bases:
Consent
Processing your email address for marketing communications when you register via our waitlist form. You may withdraw consent at any time by clicking the unsubscribe link in any email or contacting us directly.
Contractual necessity
Processing account and billing data where required to provide the TableFlow service under our terms of service.
Legitimate interests
Processing technical and usage data to operate, secure, and improve our platform, where this does not override your rights and interests.
Legal obligation
Retaining certain records to comply with tax, financial reporting, or other regulatory requirements.
We retain personal data only for as long as necessary:
We use carefully selected third-party services to operate the platform. Each processor handles data under a data processing agreement and only to the extent necessary to perform their service.
Stripe
Payment processing and subscription billing
Location: USA (EU–US Data Privacy Framework) — Privacy policy
Clerk
Authentication and identity management
Location: USA (Standard Contractual Clauses) — Privacy policy
Vercel
Hosting and content delivery
Location: USA / EU (Standard Contractual Clauses) — Privacy policy
We do not transfer personal data outside the UK or EEA except where the processor operates appropriate safeguards as noted above.
Under the UK GDPR you have the following rights in relation to your personal data:
To exercise any of these rights, email privacy@tableflow.co.uk. We will respond within one calendar month. If you are unhappy with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. Payment card data is handled exclusively by Stripe and is never transmitted to or stored on our servers. All data in transit is encrypted using TLS. Access to production systems is restricted to authorised personnel only.
We may update this Privacy Policy from time to time. Where changes are material, we will notify registered users by email at least 14 days before the changes take effect. The “Last updated” date at the top of this page always reflects the most recent revision. Continued use of TableFlow after the effective date constitutes acceptance of the updated policy.
© 2026 TableFlow. All rights reserved.
← Back to TableFlow