Privacy Policy
Last updated: August 12, 2026
1. Introduction
This Privacy Policy explains how Trudy's Table Inc. ("we," "us," "our") collects, uses, discloses, and protects personal information when you use our reservation management platform. We follow the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).
Two different roles apply, depending on whose information it is. For guest information, the restaurant is the person responsible and we act as its service provider: we handle that information on the restaurant's instructions and for no purpose of our own. For information about restaurant owners, managers, staff, and visitors to our website, we are the person responsible ourselves. Our obligations toward restaurants are set out in our Terms of Service.
2. Information We Collect
We collect the following personal information.
Guest information: phone number, name, email address, preferred language, and payment card details. Card details are tokenized by Stripe; we store only the last four digits, the card brand, and Stripe identifiers.
Reservation details: date, time, party size, seating preference, and anything written into the free-text special requests field. There is no separate dietary or allergy field on the platform, so if a guest mentions an allergy or a dietary restriction, it is stored in that free-text field.
Notes and tags recorded by restaurant staff: staff can attach internal notes and tags to a guest profile at their restaurant, such as a seating preference or a repeat-guest marker. These records are kept separately for each restaurant. A note or tag written at one restaurant is visible only to that restaurant, and never to another restaurant where the same guest has also booked. That content is written by the restaurant, and the restaurant is responsible for it.
Restaurant operator information: phone number, name, email address, restaurant details (name, address, hours, capacity), and billing information.
Staff information: phone number, name, and role within the restaurant.
Prospect information: when someone uses our no-show calculator or begins our sign-up flow, we store the phone number along with any details entered, which may include name, email address, restaurant name and address, and the figures entered into the calculator. We keep these records even when someone does not finish signing up, so that a partly completed sign-up can be resumed and so we can follow up about our product.
Contact form submissions: the name, email address, restaurant name, and message sent to us through the contact form on our website.
Usage data: how visitors interact with our marketing site and how staff use the dashboard, including pages viewed, features used, and device and browser information. Section 9 sets out where this does and does not apply.
Technical records: IP addresses and account identifiers held briefly to rate limit our public endpoints and to lock out repeated incorrect PIN attempts, plus error diagnostics generated when something fails.
Communication records: reservation confirmations, reminders, offer emails, unsubscribe requests, and support correspondence.
3. How We Use Your Information
We use personal information to:
Provide and maintain the reservation management service.
Process reservations and send booking confirmations, changes, cancellations, card requests, and reminders by email and text message.
Save cards on file through Stripe and process a no-show fee when a restaurant applies one.
Maintain guest profiles and reservation history for the restaurant's guest management features.
Send offer emails on a restaurant's behalf where the restaurant uses that feature, each carrying a working unsubscribe link.
Keep the platform secure and available, through rate limiting, PIN lockout, abuse prevention, and error monitoring.
Understand how our marketing site and our staff dashboard are used, so we can improve them.
Respond to enquiries, follow up on sign-ups, and communicate about your account.
Meet our legal and financial reporting obligations.
4. Third-Party Services
We share personal information with the service providers below, only as needed to run the platform. Each is bound by contract to protect the information it handles.
Stripe: payment processing, card tokenization, no-show fee charges, and restaurant payouts. Stripe is PCI DSS compliant.
Supabase: database hosting and authentication. Reservation, guest, and account records live here.
Vercel: application hosting and delivery.
Telnyx: text message delivery for one-time login codes and reservation messages.
Resend: email delivery for reservation confirmations, reminders, and offer emails, and receipt of email sent to our platform addresses.
Sentry: error monitoring. Sentry is configured to send no personal information: the personal-data option is turned off, and session replay, which would record what is on screen, is deliberately not enabled because this platform handles payment flows. Diagnostics carry record identifiers, counts, and statuses only, never card data, phone numbers, email addresses, or guest names.
Upstash: a short-lived key-value store used for rate limiting and PIN lockout. It holds IP addresses and account identifiers as counters, which expire within minutes.
PostHog: product analytics, on our marketing site and on the staff dashboard only. It is never loaded on the booking widget, so a guest booking a table is not tracked by analytics. Session recording is disabled, and we do not use it for advertising.
Google: address autocomplete when a restaurant enters its address during sign-up. No guest information is sent to Google.
OpenAI: image generation for articles on our blog. No guest, staff, or operator information is sent.
We do not sell personal information, and we do not share it for advertising.
5. Where Your Information Is Processed
Our primary database is hosted in Canada, in the Canada Central region (ca-central-1), so reservation, guest, and account records are stored in Canada.
Some of the providers listed above process information outside Canada. Email received at our platform addresses is handled by Resend's inbound service in the United States (us-east-1), and PostHog runs on its United States cloud. Others may process limited data outside Canada in the course of delivering their service.
Before relying on a provider that processes personal information outside Quebec, we assess the transfer as Law 25 requires, weighing the sensitivity of the information, the purpose it is used for, the protections in place, and the legal framework of the destination country. If you would like details about a specific provider, write to us at privacy@trudystable.com.
6. Data Retention
We keep personal information for as long as the account it belongs to is active, and for as long as we need it to provide the service. Guest reservation history is kept so that a restaurant can see a guest's history with that restaurant.
Deletion requests are handled manually. Write to privacy@trudystable.com and we will complete the request within 30 days, or tell you within that time why we cannot and what we are keeping. We retain information where the law requires it. Payment records may be kept for up to seven years to meet financial reporting obligations.
Technical records expire on their own: rate-limit and PIN-lockout counters within minutes, and error diagnostics within our monitoring provider's retention window.
7. Security
We use technical and organizational measures appropriate to the sensitivity of the information: encryption in transit and at rest, role-based access controls, row-level security in the database so each restaurant reaches only its own records, and phone-based authentication for staff accounts. Card numbers never reach our servers; they are collected directly by Stripe.
One point is worth knowing as a guest. The link in your confirmation email that lets you view, change, or cancel your reservation contains a random token, and that token is what proves the reservation is yours. Anyone holding the link can see and change that booking. Treat the link as private, and do not forward it to people you would not want to have that access.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Under PIPEDA and Quebec's Law 25, you have the right to:
Access the personal information we hold about you.
Have inaccurate or incomplete information corrected.
Ask us to delete your personal information, subject to legal retention requirements.
Receive the computerized personal information you provided to us in a structured, commonly used technological format, or ask us to transfer it to another organization where that is technically feasible. This is the right to data portability.
Withdraw your consent to processing that is not necessary to provide the service.
Be informed of a decision based exclusively on automated processing, and to have it explained. We do not make such decisions today.
File a complaint with the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
To exercise any of these rights, write to us at privacy@trudystable.com. Where your request concerns a restaurant's guest records, we will pass it to the restaurant responsible for those records and help that restaurant answer you.
9. Cookies and Tracking
We use essential cookies to keep you signed in and to remember preferences such as your language.
On our marketing site we use PostHog for analytics and show a consent banner on your first visit. Until you accept, analytics runs without persistent storage, so nothing is kept between visits. If you decline, it stays that way. You can change your mind at any time by clearing your browser cookies for our site.
On the staff dashboard, analytics runs without a separate banner, on the basis of the Terms of Service accepted when the account was created. This applies to restaurant staff, not to guests.
On the booking widget there is no analytics at all: no product analytics, no banner, no tracking of any kind. A guest booking a table is not analytics-tracked.
We do not use advertising cookies or tracking pixels, and session recording is disabled everywhere.
10. Children's Privacy
Trudy's Table is not directed at children under 13. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 13, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the platform. The "Last updated" date at the top of this page shows when the policy was last revised.
12. Contact
If you have questions about this policy or about our data practices, write to us at privacy@trudystable.com.
The person responsible for the protection of personal information at Trudy's Table is our Privacy Officer, who can be reached at the same address.
If you are not satisfied with our response, you may contact the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.