Legal
Privacy and cookies policy
What data table2book collects, why, who it is shared with, how long it is kept, which cookies are used and what rights you have.
Last updated:
Contents
1.Who we are
The controller for the data covered by this policy is Xolo Go OÜ - Avel Papalapas (Estonian registry code 14717109, EU VAT number EE102156920), Paju tn 1a, 50603 Tartu, Estonia. For any personal data matter: esites.gr@gmail.com.
2.What data we collect
| From whom | Data |
|---|---|
| Restaurants with an account | Users' name and email, team role, the restaurant's details and settings, the activity log of the console. |
| Subscriptions | Billing name, email, address and VAT number, plan and billing history. You enter card details with Stripe and they never pass through us. |
| Restaurants' guests (on their behalf) | Name, phone, email and, if the restaurant fills them in, company and address; bookings, the guest's notes and internal staff notes, visit history, table orders, payment amounts (no card details) and, with the phone assistant, the call recording and transcript; the assistant tells the caller so in its first sentence. |
| Visitors of this site | Visit statistics through Google Analytics, only if you allow it. |
When something does not work, on any page, we log the error to fix it: browser, page and, where relevant, details of the action at that moment (for example the page address or the subject of an email). Your IP address is used temporarily, in the server's memory, for the request limits that protect public pages from abuse; we do not store it in our database.
3.Why, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Running the account and the service | Performance of a contract (Art. 6(1)(b)) |
| Subscription billing, receipts, accounting records | Performance of a contract and legal obligation (Art. 6(1)(b) and (c)) |
| Security, request limits, error logging | Legitimate interest in running the service securely (Art. 6(1)(f)) |
| Site visit statistics (Google Analytics) | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Restaurants' guest data | The restaurant ensures the basis; we act only on its instructions |
We do not sell data, do not use it for advertising and do not make decisions about people solely by automated means.
4.Who we share data with
Only with providers needed to run the service, under contracts that require them to protect the data:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database | EU |
| Clerk, Inc. | User sign-in (with Cloudflare Turnstile protection at sign-up) | USA |
| Stripe Payments Europe Ltd | Subscription billing, invoices, card storage | EU (Ireland) and USA |
| Resend | Sending email (booking confirmations, notifications) | USA |
| Functional Software, Inc. (Sentry) | Error logging | EU (Germany) |
| Retell AI, Inc. | Phone assistant, only with the add-on: call, recording, transcript, through its voice and language-model providers | USA |
| Twilio Inc. | The assistant's phone number and call routing | USA |
| Google Ireland Ltd / Google LLC | Visit statistics, only with consent | EU and USA |
| Browser push services (Google, Mozilla, Apple) | Notifications on staff devices, with encrypted content | Depends on the browser |
Where a restaurant enables table payments or electronic receipts, the payment details go to the payment and receipt provider the restaurant has chosen. We also disclose data to public authorities when the law requires it.
5.Transfers outside the EU
Where a provider processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework, where the provider is certified, or on the European Commission's Standard Contractual Clauses.
6.How long we keep data
- Account data, bookings, guest book and orders: for as long as the account exists. After a deletion request, they are deleted within 30 days.
- Billing details and receipts: for as long as tax law requires.
- Assistant call recordings and transcripts: at Retell AI, for 30 days after the call; then they are deleted automatically.
- Error logs at Sentry: up to 90 days.
- Google Analytics statistics: up to 14 months.
8.Your rights
- Access to your data and a copy of it.
- Correction of inaccurate data.
- Deletion, where there is no obligation to keep the data.
- Restriction of processing and objection to processing based on legitimate interest.
- Portability: your data in a machine-readable format.
- Withdrawal of consent at any time, without affecting what happened before.
Send your request to esites.gr@gmail.com. We reply within one month. If you believe your rights are being infringed, you can lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or with the authority of Estonia, where we are established (Andmekaitse Inspektsioon, www.aki.ee).
9.Security
All communication with the site is encrypted (HTTPS). Each restaurant sees only its own data, and within a team access is set by roles. The application and database are hosted in a data centre in the EU. No measure rules out every risk; if a breach affects you, we inform you as the law requires.
10.Changes to this policy
When the service changes, this policy changes too; the date at the top shows the latest change. For material changes we notify users with an account by email.