Data protection
Privacy notice.
This notice explains what personal information is used by the website and reservation service, why it is used, how long it may be kept and the choices available to you.
Updated: 21 August 2026
Who is responsible for your information
The restaurant operator identified on this website and on the Contact page is the controller of personal information collected for table reservations and restaurant enquiries. Questions or data-rights requests should be sent using the restaurant’s published contact details.
Information collected for reservations
To create and manage a table reservation we collect the customer’s name, phone number and email address together with party size, reservation date and time, selected seating area and any optional note supplied by the customer. The system also creates operational data such as a booking reference, assigned table, booking source, status and timestamps. Authorised staff may add limited internal notes needed to operate the booking.
The same customer profile may be reused for later reservations when the phone number or email address matches. This prevents unnecessary duplicate profiles and allows authorised staff to see relevant reservation history such as completed visits and no-shows.
Why reservation information is used
Information that is necessary to create, administer, amend and fulfil a reservation is processed because it is needed to provide the reservation service requested by the customer and to take steps at the customer’s request before that service is provided. This includes confirming availability, preventing double booking, allocating a table, identifying the booking and contacting the customer about it.
Security logging, rate limiting, abuse prevention and protection of the booking service may also be carried out where necessary for the restaurant’s legitimate interests in operating a secure and reliable service, subject to applicable data-protection law.
The required checkbox on the booking form confirms that the customer has been shown this Privacy Notice and accepts the Reservation Terms. It is not used as a substitute for the lawful basis required to process information that is necessary to provide the reservation.
Optional marketing
Email marketing is separate from the reservation. If an optional marketing box is shown, it is unchecked by default and marketing is recorded only when the customer chooses it. A customer can withdraw that choice at any time using the unsubscribe method in a marketing message or by contacting the restaurant. Declining marketing does not affect the ability to make a reservation.
Anti-spam and security verification
The public reservation form uses Cloudflare Turnstile to distinguish legitimate booking attempts from automated abuse. Turnstile processes technical and security signals needed to perform that verification. The booking details typed into the restaurant form are submitted to the restaurant’s booking service, not to Turnstile as form content. Cloudflare acts under its own service and privacy terms for the security verification it provides.
How long reservation data is kept
Personal reservation information should not be kept indefinitely. Customer profiles with no reservation activity for 24 months are automatically reviewed and personal identifiers are deleted or anonymised when they are no longer needed, unless a longer period is required for an active dispute, a legal obligation, fraud/security investigation or another documented lawful reason.
Completed booking statistics may be retained in anonymised form after personal identifiers are removed. The platform also provides an authorised erasure process for eligible customer requests. The restaurant operator remains responsible for periodically reviewing the retention schedule and documented exceptions.
Erasure requests: Correction and erasure
Customers may ask the restaurant to correct inaccurate personal information. They may also ask for erasure where applicable law gives them that right. The right to erasure is not absolute, for example where information is still necessary for an active booking, a legal obligation or the establishment, exercise or defence of legal claims.
For eligible reservation records, Menu Studio can remove the customer’s name, phone number, email address and notes, replace previous booking references and delete the identifiable customer profile. Minimal non-identifying operational information, such as date, time, party size, status and table allocation, may remain in anonymised form. Only an authorised Owner or Admin can perform erasure.
Service providers and storage
Restaurant, reservation and customer data is stored using Cloudflare services, including Cloudflare D1, and the website is delivered through Cloudflare infrastructure. Uploaded menu media may be stored in Cloudflare KV. Google is used for authorised Menu Studio sign-in and may also be used for Google Business Profile if the Owner connects that service.
If a customer chooses an “Add to calendar” link, the customer intentionally sends the event details to the selected calendar provider, such as Google or Microsoft. Apple/Android calendar downloads are generated in the browser as an iCalendar file.
Where a service provider processes information in another country, the restaurant should ensure that an appropriate transfer mechanism or other legal safeguard required by applicable law is in place through the relevant provider terms.
Menu Studio users
The protected administration area uses Google sign-in for authorised staff. The site receives identity information needed to match the Google account to an authorised Menu Studio user and does not receive or store the Google password. A signed, secure, HTTP-only session cookie is used. Administrative and security-relevant actions may be recorded in an audit log.
Automated table allocation
The reservation engine automatically checks table capacity and availability and may select the smallest suitable free table. This is an operational allocation process and does not make a legal or similarly significant decision about the customer. Staff can review bookings where necessary.
Your data-protection rights
Depending on the circumstances and applicable law, customers may have rights to access personal information, correct inaccurate data, request erasure or restriction, object to certain processing, receive portable information and withdraw consent where consent is the lawful basis. The restaurant may need to verify the identity of the person making a request before acting on it.
If you are in the United Kingdom and are unhappy with how a data-protection concern is handled, you also have the right to complain to the Information Commissioner’s Office (ICO). You should normally give the restaurant an opportunity to resolve the issue first.
Cookies and similar technologies
Necessary browser storage, administration cookies, optional analytics choices and the security technologies used by the website are described in the Cookie Notice. Optional analytics must not be activated unless the visitor has made the corresponding choice.
Changes to this notice
This notice should be reviewed whenever the restaurant changes its reservation, marketing, analytics, payment or third-party integrations. The date shown above identifies the current published version.
Book a table