TableTing
Home About Contact
Sign In
Legal

Privacy Policy

Last updated: June 14, 2026


1. Introduction

Node 13 ("we," "us," or "our") operates the TableTing platform (the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use the Service. Please read this policy carefully. By using the Service, you consent to the practices described here.

This policy applies to Restaurant Operators (restaurant owners and their staff) who register for and manage the Service, as well as customers who interact with the Service through QR code-based service requests.

2. Information We Collect

Information you provide to us:

  • Account information: When you register, we collect your name, email address, restaurant name, and a hashed password. Restaurant Operators may also provide business details such as location and contact information.
  • Staff information: Restaurant Operators may add wait staff accounts, providing each staff member's name and email address.
  • Service request data: When customers submit service requests via QR code, we collect the table identifier, the type of request, and any additional notes provided.
  • Payment information: When you subscribe to a paid plan, payment details (card number, expiry, CVV) are collected directly by our payment processor, Stripe. We do not store your full payment card details on our servers.
  • Communications: If you contact us, we may retain your correspondence and contact details.

Information collected automatically:

  • Log data: Our servers automatically record information including your IP address, browser type, pages accessed, and timestamps.
  • Cookies and similar technologies: We use session cookies for authentication and a CSRF protection cookie for security. See Section 8 for more detail.
  • Usage data: We collect data about how the Service is used, including request volumes, table activity, and feature interactions, to provide analytics to Restaurant Operators and to improve the platform.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, maintain, and improve the Service;
  • Process subscription payments and manage billing;
  • Send transactional emails such as account setup confirmations, password reset links, and two-factor authentication codes;
  • Provide Restaurant Operators with analytics dashboards showing service request patterns, staff performance, and table activity;
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities;
  • Comply with legal obligations;
  • Respond to your inquiries and provide customer support.

We do not use your information to serve third-party advertising.

4. Payment Processing

All subscription payments are processed by Stripe, Inc. When you enter payment information, it is transmitted directly and securely to Stripe. Node 13 receives only a payment confirmation token and summary details (e.g., last four digits of card, expiry month/year, subscription status) from Stripe. Your full card details are never transmitted to or stored on our servers.

Stripe's handling of your payment data is governed by Stripe's Privacy Policy. Stripe is certified to PCI Service Provider Level 1, the most stringent level of certification in the payment card industry.

5. Sharing of Information

We do not sell, trade, or rent your personal information to third parties. We may share information in the following limited circumstances:

  • Service providers: We engage trusted third-party companies to help us operate the Service, including hosting providers, email delivery services, and our payment processor (Stripe). These providers have access to your information only as necessary to perform their services and are contractually obligated to keep it confidential.
  • Legal requirements: We may disclose your information if required to do so by law, regulation, or valid legal process (e.g., a court order or subpoena).
  • Protection of rights: We may disclose information where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, or situations involving potential threats to the safety of any person.
  • Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information becomes subject to a different privacy policy.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account and restaurant data is retained for the duration of your subscription and for a reasonable period thereafter (typically 90 days) to allow for reactivation;
  • Service request and analytics data is retained indefinitely to support trend analysis and platform improvement, for as long as the associated account remains active. This data will be deleted upon a valid account deletion request, consistent with Section 9 (Termination) of the Terms of Use and Section 9 (Your Rights) of the Privacy Policy.
  • Password reset tokens and two-factor authentication codes expire within 1 hour and 10 minutes respectively and are deleted automatically;
  • Session data is cleared on logout or expiry.

When you request account deletion, we will delete your personal data within a reasonable timeframe, except where we are required to retain it to comply with legal obligations.

7. Security

We implement appropriate technical and organisational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • TLS encryption for all data in transit;
  • bcrypt hashing for all passwords stored in our database;
  • CSRF protection on all state-changing requests;
  • Optional two-factor authentication via email for all user roles;
  • Rate limiting on login and password reset endpoints;
  • Trusted device tokens to reduce friction while maintaining security.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

8. Cookies

We use a small number of cookies that are strictly necessary for the Service to function:

  • Session cookies (session_token, client_session, staff_session): HttpOnly cookies used to maintain your authenticated session. These expire when you log out or when the session expires.
  • CSRF cookie (csrf_token): Used to prevent cross-site request forgery attacks on state-changing operations.
  • Trusted device cookie: Set when you choose to trust a device after two-factor authentication. Valid for 30 days for restaurant owners and administrators, or per the configured frequency for staff.

We do not use cookies for advertising or third-party tracking. You may configure your browser to refuse cookies, but doing so will prevent you from using authenticated features of the Service.

9. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access: Request a copy of the personal information we hold about you;
  • Correction: Request correction of inaccurate or incomplete information;
  • Deletion: Request deletion of your personal information, subject to certain legal exceptions;
  • Portability: Request that we provide your data in a structured, machine-readable format;
  • Objection: Object to our processing of your information in certain circumstances.

To exercise any of these rights, please contact us via our contact page. We will respond within a reasonable timeframe and in accordance with applicable law.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information without parental consent, please contact us and we will take steps to remove that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where practicable, notify you by email. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at our contact page.

© 2026 Node 13. All rights reserved.
Terms of Use Privacy Policy