This notice explains how [RESTAURANT NAME] uses personal information when you visit our website, make a reservation or contact us about a booking.
01 / Who looks after your information?
[LEGAL BUSINESS NAME], trading as [RESTAURANT NAME], is responsible for the personal information described in this notice. Our address is [BUSINESS ADDRESS, COUNTRY].
For privacy questions or requests, contact [PRIVACY EMAIL] or write to the address above. [Add data protection officer or representative details if applicable.]
02 / What we collect when you book
When you reserve a table, we collect your name, reservation date and time, number of guests, and any email address, telephone number or answers you provide. We also keep the assigned table, booking reference, creation time, booking status and notification status.
The form marks required fields. We need those details to accept the booking online. Optional fields can be left blank. If you do not provide an email address, we cannot send confirmation or cancellation emails. We may use a telephone number you provide to call about your reservation.
We receive these details from the person making the booking. If you book for someone else, please share this notice with them and only provide information you are entitled to share. The booking form does not collect payment card details.
03 / Why we use your details
We use reservation and contact details to arrange your table, manage changes or cancellations, and answer booking questions. Our legal basis is taking steps at your request before a contract and performing our booking arrangements with you (Article 6(1)(b) GDPR).
We use booking records and technical security checks to prevent spam and duplicate or abusive reservations. Our basis is our legitimate interest in protecting table availability and keeping the service reliable (Article 6(1)(f)). You can object to processing based on legitimate interests.
[Owner to complete: confirm these legal bases fit your service. Add any actual legal record-keeping obligation, purpose and applicable law.]
Making a reservation does not sign you up for marketing. Booking confirmations, cancellations and other messages about your table are service communications.
04 / Special requests and allergies
You can use optional questions for requests relevant to your visit. Please avoid unnecessary personal information about yourself or other people.
[Owner to complete: explain your approach to health information before enabling allergy questions. State the purpose, Article 6 basis and Article 9 condition, staff access, retention and any consent-withdrawal process. The supplied form does not record explicit health-data consent. Optional answers alone are not explicit consent.]
05 / The services behind your booking
Our authorised restaurant team uses the information needed to manage reservations. Our website is hosted by Framer. The Google booking form runs on Google Apps Script and stores reservations, contact details and question answers in our restaurant’s Google spreadsheet.
Google Calendar holds a booking mirror containing the reservation reference, name, contact details, party size and table. Question answers stay in the spreadsheet. Confirmation and cancellation emails are sent through our Google account when an email address has been supplied.
Cloudflare Turnstile helps distinguish genuine visitors from automated traffic. It processes browser and device signals for this purpose. Cloudflare also uses signals to improve its detection service, as described in its Turnstile Privacy Addendum.
The booking form loads a font from Google Fonts. This makes a request to Google’s servers, which receive technical connection information such as your IP address.
[Owner to complete: confirm the Google account and service terms that apply, provider legal entities and any other recipients. If you use Tablein instead, replace the Google booking description using the owner guide.]
06 / Where information is processed
The services we use may process information outside the country where our restaurant is based, including outside the EEA.
[Add the actual transfer destinations and applicable safeguards or adequacy decisions for your provider arrangements. Explain how guests can obtain more information or a copy of the safeguards.]
07 / How long we keep it
Booking and contact records: [RETENTION PERIOD OR CLEAR CRITERIA, MEASURED FROM THE VISIT OR CANCELLATION]. Special-request answers: [SHORTER PERIOD OR CRITERIA MATCHING THE NEED]. Correspondence and security records: [PERIODS OR CRITERIA FOR EACH].
After these periods, we [DESCRIBE YOUR ACTUAL DELETION OR ANONYMISATION PROCESS]. If particular records must be kept longer for a legal obligation or an actual dispute, we keep only what is needed and restrict its use. [SPECIFY ANY APPLICABLE OBLIGATION AND PERIOD.]
Moving a reservation into an archive does not delete it. Our retention process also covers archived bookings, Calendar copies and email records. [ADD ACTUAL BACKUP RETENTION AND DELETION ARRANGEMENTS.]
08 / Website, security and cookies
Visiting the website and opening the booking form sends technical information to the services that deliver and protect them. This can include IP address, browser information and request details.
[Owner to complete: describe your actual analytics, cookies, local storage and embeds, their purposes, providers and retention, and how visitors can change any required consent choices. Review the website and Google booking frame separately.]
09 / Your choices and rights
Where the GDPR applies, you can ask for access to your personal information, correction of inaccurate details, deletion, restriction, or a portable copy where the conditions apply. You can also object to processing based on legitimate interests. These rights have legal conditions and exceptions.
Where processing relies on consent, you can withdraw it at any time without affecting processing that was lawful before withdrawal. Contact [PRIVACY EMAIL] to make a request. We may need proportionate information to verify your identity.
We normally respond within one month. If a permitted extension is needed because a request is complex or numerous, we will explain within that month. You can complain to a supervisory authority, including in the EEA country where you live, work or believe an infringement occurred. [ADD RELEVANT AUTHORITY NAME AND LINK.]
10 / How availability is checked
The booking system checks opening hours, party size and available tables. It may also limit repeated bookings linked to the same email address or telephone number to reduce abuse. If you cannot book online or believe a check is wrong, contact [BOOKING EMAIL OR PHONE] so our team can help.
11 / Updates to this notice
We update this notice when our services or data practices change. The date above shows when it was last revised. [DESCRIBE HOW YOU WILL COMMUNICATE MATERIAL CHANGES WHERE REQUIRED.]