Privacy Policy

Last updated: 5 September 2026

1. Introduction

1.1 This Privacy Policy explains how TafelTips (“we”, “us”) collects, uses, and protects your personal data when you use the TafelTips iOS app or the website at tafeltips.nl (together, the “Service”). We are the controller for that processing. Our contact details are in section 14.

1.2 TafelTips is a restaurant discovery and table-availability service. We show which restaurants have open slots. We do not take bookings, process payments, or run a restaurant’s reservation system. If you book a table, you do so with the restaurant through its own booking provider (for example Tebi, Formitable, Zenchef, or Guestplan). Those providers process that booking under their own privacy policies.

1.3 TafelTips processes personal data in compliance with the EU General Data Protection Regulation (GDPR) and the Dutch implementing act (UAVG).

1.4 You can use much of the Service without an account. Creating an account, saving favorites, publishing a list, suggesting a restaurant, or signing in with a third-party identity provider means we process the data described below, on the legal bases in section 5.

1.5 The Service is intended for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has given us personal data, write to [email protected] and we will delete it.

1.6 This policy is published in Dutch and in English, alongside our Terms of Service. If you are a consumer and the versions differ, the Dutch version prevails.

2. Data We Collect

2.1 Data you provide

  • Account information via our authentication provider (Clerk), which may include name, email address, and Sign in with Apple details (including Apple’s Hide My Email relay address, if you choose it).
  • Favorites (restaurants you bookmark).
  • Shareable lists (a display name and a public share link for your favorites).
  • Restaurant suggestions (restaurant name, city, optional website URL), tied to your account if you are signed in.
  • Messages you send us (for example to [email protected]).

2.2 Data collected automatically

  • Device and technical data (device type, operating system, app or browser version).
  • A salted hash of your IP address when you are not signed in, used only to apply rate limits on refresh requests. We do not keep the raw address for that purpose.
  • Server and security logs. Our web server and our authentication provider record the raw IP address, timestamp, requested URL, and user agent of requests, as any web server does. We use these only to keep the Service running and secure, and we keep them for 30 days.
  • Usage data on the website via cookieless analytics, such as pages viewed, restaurant views, city, locale, and a random session identifier stored in your browser.
  • Search queries and filters you enter in the Service (for example free-text search, cuisine, neighborhood, price, date, time, party size).
  • Refresh requests you make to update availability for a restaurant, day, and party size (logged against your Clerk user id if you are signed in, or the hashed identifier above if you are not).

2.3 Data we do not collect

  • Precise GPS location. The map shows restaurant locations; it does not read your device location.
  • Payment card data. TafelTips has no in-app purchases and does not process payments.
  • Reservation, cancellation, no-show, or spending history. We never receive your booking from the restaurant’s reservation system.
  • Date of birth, gender, dietary information, friend lists, or reviews.
  • The advertising identifier (IDFA). The app does not ask for tracking permission and does not collect it.

2.4 Data from third parties

  • Restaurant and availability information from publicly available sources (used to show open tables, not to identify you). See section 3.
  • Account identifiers and profile fields from Clerk (and, on iOS, from Apple when you use Sign in with Apple).

3. Restaurant and Business Contact Data

3.1 The Service contains information about restaurants: name, address, opening hours, cuisine, price level, phone number, website, photos, and observed table availability. For a restaurant run as a sole proprietorship or partnership, some of this can also be personal data about the owner. This section is the information required by Article 14 GDPR for data we did not obtain from the person concerned.

3.2 Source. We obtain this data from publicly available sources: the restaurant’s own website and public booking page, public map and business listings, and information sent to us by users or by the restaurant itself.

3.3 Purpose and legal basis. We process it to operate a restaurant discovery service — to list the venue, show where tables appear to be open, and link people through to it. The legal basis is our legitimate interest, and the interest of the public and of the venue, in an accurate and useful directory of places to eat. We do not use it for advertising and we do not sell it.

3.4 Categories. Business contact and location details, opening and service information, publicly observable availability, and editorial descriptions we write or generate.

3.5 Retention. For as long as the venue is listed, and for a limited period afterwards for our own records.

3.6 Your rights as a venue or owner. You can ask us to correct or remove information about your venue, or object to its inclusion, by writing to [email protected]. We will review and, where appropriate, correct or remove it, and we will delist a venue on request from a person who can show they represent it.

4. Purposes of Processing

TafelTips processes personal data to:

  • 4.1 Provide the Service (accounts, favorites, shareable lists, restaurant suggestions, showing availability).
  • 4.2 Let you request a refresh of availability for a restaurant, day, and party size, and to enforce fair-use limits on those requests.
  • 4.3 Provide customer support and handle requests (including GDPR requests).
  • 4.4 Understand how the Service is used, fix bugs, and improve search, browse, and availability features.
  • 4.5 Detect and prevent abuse, fraud, and excessive automated use.
  • 4.6 Measure whether our advertising works, in the limited way described in section 10.3.
  • 4.7 Comply with legal obligations and establish or defend legal claims.
  • 4.8 Remember basic preferences (for example the last city you browsed).

We do not sell personal data. We do not sell or share identifiable or aggregated user profiles with restaurants for commercial benchmarking.

5. Legal Basis

  • 5.1 Performance of a contract — to deliver the Service you requested (account, favorites, lists, showing availability).
  • 5.2 Consent — where required, for example marketing emails if we ever send them (we do not currently), or any non-essential cookie we might introduce. You can withdraw consent at any time, without affecting processing already carried out.
  • 5.3 Legitimate interest — security, rate limiting and abuse prevention, service improvement, first-party analytics that do not require a non-essential cookie, the restaurant data in section 3, and the advertising measurement in section 10.3. You may object at any time (section 9.6).
  • 5.4 Compliance with legal obligations, and the establishment, exercise, or defence of legal claims.

5.5 Our balancing test for advertising measurement. We rely on legitimate interest for the app events described in section 10.3. Our interest is knowing whether the money we spend on advertising brings people to a free service that would otherwise not be found. The impact on you is limited: the events say that an app action happened, not who you are; no advertising identifier is collected; there is no cross-app or cross-site tracking; and no profile about you is built for advertising. We consider this within your reasonable expectations for a free app that advertises. If you would rather not rely on that assessment, you may object under section 9.6.

6. Sharing of Data

6.1 We share personal data only with the parties below, and only as far as they need it:

  • Clerk — authentication, including Sign in with Apple (processor).
  • Apple — Sign in with Apple, and App Store delivery (independent controller).
  • Our hosting and infrastructure providers — servers, database, backups, and logs (processors).
  • OpenAI — generating and editing editorial descriptions of restaurants. We send restaurant information, not your account data, favorites, or lists (processor).
  • Google — map and place information used to enrich restaurant records (independent controller for its own services).
  • Meta Platforms — the limited advertising measurement in section 10.3 (joint controller with us for the collection and transmission of those events).
  • Email delivery, if we reply to you by email (processor).

6.2 Our website and app analytics run on our own self-hosted instance of the open-source Umami software, on our own infrastructure. There is no analytics company receiving your data, and the data is not combined with any other site’s.

6.3 TafelTips does not sell personal data to third parties.

6.4 If you open a restaurant’s booking page, that booking provider and the restaurant process your reservation data independently. TafelTips does not receive a copy of your booking.

6.5 If you publish a list, anyone with the share link can see the list title, the display name you chose, and the restaurants on that list. Treat the link as public.

6.6 We may disclose data if required by law, or where necessary to establish, exercise, or defend legal claims, or to protect the Service, our users, or others. If the Service is reorganised or sold, data may transfer to the acquiring entity under this policy.

7. Data Retention

  • 7.1 Account data: kept while your account is active. When you delete your account we delete it within 30 days, and from routine backups within 90 days. Clerk deletes its own account record according to its retention rules.
  • 7.2 Favorites and unpublished list data: stored until you remove them or delete your account.
  • 7.3 Published lists: stored until you unpublish the list or delete your account.
  • 7.4 Restaurant suggestions: kept as needed to review and (if accepted) add the venue, and for up to 12 months afterwards as a moderation record.
  • 7.5 Refresh-request logs: kept for up to 12 months, for rate limiting and abuse prevention.
  • 7.6 Search queries and analytics: kept for up to 12 months.
  • 7.7 Server and security logs: 30 days.
  • 7.8 Support emails: kept as long as needed to handle your request, and afterwards for our own records.
  • 7.9 We may keep data longer where we have to by law, or where it is needed for a legal claim that is ongoing or reasonably foreseeable. In that case we restrict it to that purpose.

8. Security

8.1 TafelTips applies appropriate technical and organizational measures to protect personal data against loss, misuse, or unauthorized access (access controls, hashed identifiers for anonymous rate limiting, encrypted transport).

8.2 Where required by law, we will notify the Autoriteit Persoonsgegevens of a personal data breach within 72 hours of becoming aware of it, and we will inform you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

9. Your Rights

Under the GDPR, you have the following rights:

  • 9.1 Right of access — to obtain a copy of your personal data.
  • 9.2 Right to rectification — to correct inaccurate or incomplete data.
  • 9.3 Right to erasure — to request deletion of your data (“right to be forgotten”).
  • 9.4 Right to restriction — to limit processing under certain conditions.
  • 9.5 Right to data portability — to receive your data in a machine-readable format.
  • 9.6 Right to object — to object to processing based on legitimate interest.
  • 9.7 Right to withdraw consent, where processing is based on consent.
  • 9.8 Right to lodge a complaint with the Autoriteit Persoonsgegevens.

You can delete favorites and unpublish lists in the Service, and delete your account from the account screen in the app or on the website. For anything else, email [email protected].

We respond within one month. Where a request is complex, or where you have made several, we may extend that by two further months and will tell you why within the first month. We may ask for information to confirm your identity before we act, so that we do not disclose your data to someone else. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or refuse it, and we will explain why.

10. Cookies and Similar Technologies

10.1 The website uses strictly necessary cookies and similar storage: authentication (Clerk), the last city you browsed (tafel_city), and similar functional preferences. It also uses our self-hosted, cookieless analytics to count page and restaurant views. Those analytics are first-party only, are not used for advertising, are not shared, and are not used to build a profile of you, so under Dutch law they do not require a cookie banner.

10.2 The iOS app uses the same self-hosted analytics on a separate site (app.tafeltips.nl). Events are sent directly from your device to our own instance. A random device identifier is stored in the device keychain to distinguish sessions; it is not linked to your Clerk account or Apple ID.

10.3 Advertising measurement. The iOS app measures whether our advertising on Meta (Facebook and Instagram) works. It reports a limited set of app events — app opened, restaurant viewed, availability searched, and booking started — to Meta, together with your device type, operating system version, and language. We do not collect or share the advertising identifier (IDFA), we do not ask for tracking permission, and we do not track you across other apps or websites. Install attribution uses Apple’s SKAdNetwork, which reports to Meta in aggregate and does not identify you. Meta and TafelTips are joint controllers for the collection and transmission of these events; Meta then processes them for its own purposes as a controller, as described in its own privacy policy. You may object to this processing under section 9.6. SKAdNetwork is handled by iOS itself and can be limited in the device’s privacy settings.

10.4 You can manage cookies in your browser. Blocking strictly necessary cookies may prevent sign-in from working.

11. International Data Transfers

11.1 We aim to keep processing within the European Economic Area. Some parties — notably Clerk, Apple, OpenAI, Google, and Meta — may process data in the United States or elsewhere outside the EEA.

11.2 Where that happens we rely on appropriate safeguards: the European Commission’s Standard Contractual Clauses, an adequacy decision such as the EU–US Data Privacy Framework where the recipient is certified under it, and additional measures where needed. You can ask us for details at [email protected].

12. Profiling and Automated Decision-Making

12.1 TafelTips does not use AI or profiling to make decisions about you, to score you, or to show personalized commercial offers.

12.2 Restaurant ranking and “how busy a place looks” are based on publicly observed table availability, not on your personal profile.

12.3 Nothing in the Service produces legal effects or similarly significant effects on you through automated decision-making.

13. Changes to this Policy

13.1 TafelTips may update this Privacy Policy.

13.2 The current version is always available in the app and on the website.

13.3 We will notify you of material changes, for example the next time you open the app or sign in.

14. Contact

TafelTips

Email: [email protected]

TafelTips
live tables
ListsHelpAbout
ListsHelpAbout