Legal

Privacy and cookies policy

What data table2book collects, why, who it is shared with, how long it is kept, which cookies are used and what rights you have.

Last updated:

Contents

1.Who we are

The controller for the data covered by this policy is Xolo Go OÜ - Avel Papalapas (Estonian registry code 14717109, EU VAT number EE102156920), Paju tn 1a, 50603 Tartu, Estonia. For any personal data matter: esites.gr@gmail.com.

2.What data we collect

From whomData
Restaurants with an accountUsers' name and email, team role, the restaurant's details and settings, the activity log of the console.
SubscriptionsBilling name, email, address and VAT number, plan and billing history. You enter card details with Stripe and they never pass through us.
Restaurants' guests (on their behalf)Name, phone, email and, if the restaurant fills them in, company and address; bookings, the guest's notes and internal staff notes, visit history, table orders, payment amounts (no card details) and, with the phone assistant, the call recording and transcript; the assistant tells the caller so in its first sentence.
Visitors of this siteVisit statistics through Google Analytics, only if you allow it.

When something does not work, on any page, we log the error to fix it: browser, page and, where relevant, details of the action at that moment (for example the page address or the subject of an email). Your IP address is used temporarily, in the server's memory, for the request limits that protect public pages from abuse; we do not store it in our database.

3.Why, and on what legal basis

PurposeLegal basis (GDPR)
Running the account and the servicePerformance of a contract (Art. 6(1)(b))
Subscription billing, receipts, accounting recordsPerformance of a contract and legal obligation (Art. 6(1)(b) and (c))
Security, request limits, error loggingLegitimate interest in running the service securely (Art. 6(1)(f))
Site visit statistics (Google Analytics)Consent (Art. 6(1)(a)), which you can withdraw at any time
Restaurants' guest dataThe restaurant ensures the basis; we act only on its instructions

We do not sell data, do not use it for advertising and do not make decisions about people solely by automated means.

4.Who we share data with

Only with providers needed to run the service, under contracts that require them to protect the data:

ProviderPurposeLocation
Hetzner Online GmbHHosting of the application and databaseEU
Clerk, Inc.User sign-in (with Cloudflare Turnstile protection at sign-up)USA
Stripe Payments Europe LtdSubscription billing, invoices, card storageEU (Ireland) and USA
ResendSending email (booking confirmations, notifications)USA
Functional Software, Inc. (Sentry)Error loggingEU (Germany)
Retell AI, Inc.Phone assistant, only with the add-on: call, recording, transcript, through its voice and language-model providersUSA
Twilio Inc.The assistant's phone number and call routingUSA
Google Ireland Ltd / Google LLCVisit statistics, only with consentEU and USA
Browser push services (Google, Mozilla, Apple)Notifications on staff devices, with encrypted contentDepends on the browser

Where a restaurant enables table payments or electronic receipts, the payment details go to the payment and receipt provider the restaurant has chosen. We also disclose data to public authorities when the law requires it.

5.Transfers outside the EU

Where a provider processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework, where the provider is certified, or on the European Commission's Standard Contractual Clauses.

6.How long we keep data

  • Account data, bookings, guest book and orders: for as long as the account exists. After a deletion request, they are deleted within 30 days.
  • Billing details and receipts: for as long as tax law requires.
  • Assistant call recordings and transcripts: at Retell AI, for 30 days after the call; then they are deleted automatically.
  • Error logs at Sentry: up to 90 days.
  • Google Analytics statistics: up to 14 months.

7.Cookies and browser storage

We use only what the site needs to work, and Google Analytics only with your consent. You can change or withdraw your choice at any time from «Cookies» at the bottom of every page; withdrawing also deletes the Analytics cookies.

NameWhat it doesDuration
__session, __client_uat, __client (Clerk)Signing in to the console — necessaryFor the length of the session
t2b_checkoutRemembers the plan you picked on Pricing while you sign up — necessary1 hour
_ga, _ga_* (Google Analytics)Visit statistics — only with consentUp to 2 years
t2b.analytics (browser storage)Your Analytics choice1 year
t2b.guestName (browser storage)The name you entered when ordering at the table, for next timeUntil you delete it
t2b.pay.*, t2b.payResult.* (browser storage)Payments you started from this device, so they complete or cancel correctlyUntil the tab closes, or the last 5
t2b.orders.* (browser storage)Kitchen display preferences and actions waiting for a network connectionUntil you delete them
sentryReplaySession (browser storage)Technical details of the tab for error loggingUntil the tab closes

When an error is recorded together with the page's recent activity to help fix it, texts and form fields are masked before they leave the browser. Stripe's payment page, where you are taken for the subscription, uses its own cookies under Stripe's policy.

8.Your rights

  • Access to your data and a copy of it.
  • Correction of inaccurate data.
  • Deletion, where there is no obligation to keep the data.
  • Restriction of processing and objection to processing based on legitimate interest.
  • Portability: your data in a machine-readable format.
  • Withdrawal of consent at any time, without affecting what happened before.

Send your request to esites.gr@gmail.com. We reply within one month. If you believe your rights are being infringed, you can lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or with the authority of Estonia, where we are established (Andmekaitse Inspektsioon, www.aki.ee).

9.Security

All communication with the site is encrypted (HTTPS). Each restaurant sees only its own data, and within a team access is set by roles. The application and database are hosted in a data centre in the EU. No measure rules out every risk; if a breach affects you, we inform you as the law requires.

10.Changes to this policy

When the service changes, this policy changes too; the date at the top shows the latest change. For material changes we notify users with an account by email.