Terms of ServicePrivacy PolicyData Processing Agreement
Privacy Policy
Last updated 5 October 2026.
This policy explains what personal data Tafels collects, why, and what your rights are. It covers two different roles at once, because Tafels is booking software used by restaurants:
- For restaurant accounts (owners and staff who sign up), Tafels (Memocom Solutions B.V.) is the data controller — we decide why and how that data is used, and this policy tells you directly what we do with it.
- For guests who make a reservation, buy a gift card, or leave a review, the restaurant is the data controller, and Tafels processes that data on the restaurant’s behalf and instructions as a processor — see the Data Processing Agreement. If you’re a guest with a question about your own data, please contact the restaurant you booked with first; they can involve us if needed.
1. Data about restaurant accounts
When you or your team sign up and use Tafels, we collect:
- name, email address, and a password (stored as a salted PBKDF2-SHA256 hash — we never store or see your actual password);
- your restaurant’s business details (name, address, phone, description) as you enter them;
- your language preference, and technical data needed to keep you signed in (a session identifier in a cookie);
- billing information, handled by Stripe on our behalf — we store your subscription status and plan, never your card details;
- support requests you send us.
We use this to provide the service, secure your account, bill you correctly, and respond when you contact us. The legal basis is performance of our contract with you (these Terms), and, for fraud/abuse prevention, our legitimate interest in keeping Tafels working for everyone.
2. Data processed on a restaurant’s behalf (guest data)
When someone books a table, buys a gift card, redeems a deal, or answers a review request, we process on the restaurant’s behalf:
- name, email address, phone number (if given);
- reservation details: date, time, party size, table, status, and any notes the guest or restaurant adds — which can include dietary or accessibility information. That can be “special category” data under data protection law, so please only collect what your restaurant actually needs, and make sure guests know why you’re asking;
- online payment status for deposits and gift cards (paid, refunded, amount) — never full card details, which Stripe handles directly;
- a review rating and any written feedback, if the restaurant uses that module;
- a hashed version of the booking IP address, used only to prevent abuse (for example, one connection creating many fake bookings) — we don’t keep or use the raw IP address.
We only use this data to run the reservation, payment, review and related features the restaurant has switched on, and as instructed by the restaurant. We don’t use it for our own marketing, and we don’t sell it.
If the restaurant uses Email marketing, we also process, on its behalf, its marketing contacts: email address, name (optional), language, how and when they gave consent (for example the booking they ticked the box on), their status (subscribed, waiting for confirmation, unsubscribed or not reachable) and which campaigns were sent to them. People who unsubscribe or whose address bounces stay on the list as a suppression entry (an address and a status) so they are not added or emailed again by accident, until the restaurant deletes the contact on request. We only email people with consent.
If the restaurant uses Staff planning, we also process, on its behalf, data about its employees and other people it plans: name, optional email address and phone number, position, contracted hours and a private note written by the manager; the shifts planned for them; the days they mark as unavailable or ask off, with their note; the hours they confirm; and, if onboarding is used, short text answers to the checklist the restaurant wrote (for example an emergency contact or a clothing size). Each person reaches their own page through a private link; we store only a random code for it. We do not collect copies of identity documents or citizen service numbers, and our instructions tell restaurants not to ask for them.
3. Who else sees this data
We share personal data with a small number of service providers who help us run Tafels (our “sub-processors”):
- Stripe — payment processing, for Tafels’ own subscription billing and, separately, for each restaurant’s own deposits/gift cards through their own connected Stripe account;
- SendGrid (Twilio) — sending confirmation, reminder and other transactional emails on a restaurant’s behalf;
- our infrastructure provider, DirectVPS, which hosts the server Tafels and its database run on and is based in the Netherlands.
Stripe and SendGrid (Twilio) are based in the United States; both are certified under the EU-U.S. Data Privacy Framework and additionally rely on the European Commission’s Standard Contractual Clauses. DirectVPS, our hosting provider, is based in the Netherlands, so no international transfer applies there. We don’t use any other third parties to process this data, and we don’t use advertising or analytics trackers on the booking pages guests use.
4. How long we keep data
We keep account and reservation data for as long as the restaurant’s account is active, or as needed to provide the service. If an account is closed, we delete the underlying data within a reasonable period, except where we need to keep it for legal, tax or dispute-resolution purposes. Staff planning data is deleted when the restaurant deletes the employee (their details, shifts, requests and onboarding answers go with them), when the restaurant clears an employee’s onboarding (their answers go), or when the account is closed. Marketing contacts are kept while the restaurant uses Email marketing and are deleted when the restaurant deletes them or closes its account; the record that someone unsubscribed is only removed when the restaurant deletes that contact on request. Automatic backups of the database are kept for 14 days on the same server before being overwritten; we don’t currently keep backups at a separate location, which we plan to improve. Data deletion and full data export are currently handled by request (see Contact below) rather than automatically; we plan to make both self-service in future.
5. Security
Passwords are hashed (PBKDF2-SHA256, 100,000 iterations) and never stored in plain text. Sessions use hashed, HttpOnly cookies. All traffic to Tafels is encrypted with HTTPS. We rate-limit requests to reduce abuse, and card payments are handled entirely by Stripe — card numbers never reach Tafels’ own servers. No system is perfectly secure, and we keep improving these measures over time.
6. Your rights
If you’re a restaurant account holder, you can access, correct or export most of your own data directly in Tafels (Settings, and Insights → Export on paid plans). For anything else — including deleting your account, or any request under data protection law (access, correction, erasure, restriction, objection, or portability) — contact us at privacy@tafels.app. If you’re not satisfied with our response, you can complain to the Dutch data protection authority (Autoriteit Persoonsgegevens) or your own country’s supervisory authority.
If you’re a guest, please contact the restaurant you booked with — they are the controller of your data and best placed to help; they can ask us to assist where needed under the Data Processing Agreement.
7. Cookies
Tafels uses two kinds of cookie: a session cookie (so you stay signed in, and so a guest can manage their own booking via their private link) and a language-preference cookie. Both are needed for the service to work and aren’t used for advertising or tracking across other websites.
8. Children
Tafels is a business tool for restaurants and isn’t directed at children.
9. Changes to this policy
We may update this policy as Tafels changes. For material changes, we’ll email restaurant account owners and update the date at the top of this page.
10. Contact
Memocom Solutions B.V., Strevelsweg 700 UNIT 509, 3083 AS Rotterdam. Privacy questions: privacy@tafels.app.