Tablez.ai Tablez.ai - The last reservation tool.
  • Home
  • The Product
  • Team
  • About
  • Sign in
  • Get started

Legal

Privacy notice

Version 1.0 · 25 August 2026

Two things worth knowing before you read on.

Booking a table and visiting this website are different. When you book, the restaurant decides what happens to your information and we act on its instructions. On this website, we decide. The next section explains what that means for you.

To have your data deleted, go straight to Deleting your data. It takes one email and we answer within thirty days.

Who we are

Tablez AS
Dalstoppen 15, 3145 Tjøme, Norway
Organisation number: NO 936 927 416 MVA
hello@tablez.ai

Tablez builds software that restaurants use to take and manage reservations. Guests reach the restaurant by phone, message, email or its website, and an AI assistant answers on the restaurant's behalf.

Who decides what happens to your data

This matters because it tells you who to ask, and we would rather be clear than tidy.

  • The restaurant you booked with is the controller of your reservation and of the record it keeps about you as a guest. It decides what to collect and why. Tablez is its processor: we hold and handle that information on the restaurant's instructions, and we do not use it for our own purposes.
  • Tablez is the controller for this website, for the accounts restaurant staff use to sign in, and for the technical records we keep to run and secure the service.

One consequence is worth stating plainly, because it is the opposite of what many people assume. Your record is held separately by each restaurant. If you book at two restaurants that both use Tablez, they hold two unrelated records of you. Neither can see the other, and there is no Tablez-wide profile of you. That is how the system is built, not a setting.

This website

This section describes what tablez.ai does today.

  • We use Google Analytics 4 under Google Consent Mode v2. On your first visit, analytics storage, ad storage, ad user data and ad personalisation are all set to denied. No analytics cookies are set unless you accept.
  • Your choice is stored in your browser's local storage as tablez_consent, either granted or denied, and read on each visit so you are not asked again. Clearing your browser data resets it.
  • If you decline, Google Analytics stays in its cookieless state. If you accept, it sets its cookies and collects usage data from that point.
  • We set no advertising cookies and run no advertising pixels.
  • If you email us or send us a form, we receive what you chose to send and use it to reply to you.

What the restaurant holds when you book

A reservation holds the date and time, the number of people, the name it is booked under, how the booking was made, any table or seating preference, and anything you asked for, including allergies.

Alongside it, the restaurant keeps a record of you as one of its guests: your name, phone number and email address if you gave one, any dietary or accessibility needs, seating preferences, notes its staff have added, how many times you have visited and when you last did, and whether you have asked not to receive messages.

Health and other sensitive information

Some of what a restaurant records about you is treated as a special category of data under Article 9 of the GDPR, and deserves to be called out rather than buried in a list:

  • Allergies, which are health information.
  • Dietary preferences, which can reveal a religion or belief even when nobody intended them to.
  • Accessibility requirements, which can reveal a disability.

It is collected so the kitchen and the floor can look after you safely, and it is used for nothing else. Two points follow from how restaurants actually work:

  • Someone else may have told us about you. If a colleague books a table and mentions that one of the party cannot eat dairy, that is recorded against the booking. You may never have spoken to us. You still have every right described below.
  • It is kept in two places for two different reasons. On the booking, because it applies to that meal, and on your guest record, because it usually applies every time.

If you call the restaurant

Calls are answered by an AI assistant speaking for the restaurant.

Tablez does not record your call and does not store a transcript of it. What we keep is a record that the call happened: its length, which restaurant it reached, how you were identified, what came of it, and the time. Nothing you said is stored on our systems.

We should be equally clear about the limit of that statement. The call is carried by our telephony provider and the conversation itself is run by our voice provider, both named below. What each of them keeps on its own systems is governed by its own terms, and saying otherwise here would be a claim we are not in a position to make.

If you message the restaurant

Messages you send by WhatsApp, SMS, email or a chat window are stored, including the text itself and the delivery record from the messaging provider. The AI assistant reads them to answer you, and the restaurant's staff can read them.

When a message is erased at your request, we blank its content and keep the empty shell of the record. What survives is that a message existed, when, and on which channel. What it said does not. We do this so the restaurant's own records stay consistent, and we mention it because "deleted" should mean what you expect it to mean.

Who else handles your data

These companies process data on our behalf so the service can work:

  • Google Cloud, hosting and databases
  • Google and Anthropic, the AI that reads and writes messages
  • ElevenLabs, the voice on the phone
  • Twilio, phone calls and text messages
  • Meta, WhatsApp, Instagram and Messenger
  • Postmark, email
  • Stripe, payments
  • Cloudflare, serving this website
  • Google Analytics, website statistics only, and only if you accept

Our own servers and databases run in the European Union, in Google Cloud's Belgium region. The companies above each operate their own infrastructure, and some of them process data outside the European Economic Area under their own transfer safeguards. We are working through those arrangements provider by provider and will name the safeguards here as that completes.

How long it is kept

Honestly, and this is deliberate: your guest record and your reservations are not on a deletion timer. A restaurant keeps them for as long as it is using them to run its business, and its booking history stays in its history.

What we do instead is act on requests. If you ask for your data to be deleted, we delete it, and the section below tells you how. We would rather offer that and mean it than publish a retention schedule we do not actually run.

Some of our own internal records do age out automatically. Where staff have filed a technical report that happens to mention a guest, the text of that report is erased after two years and only the engineering record of the problem is kept.

Two exceptions. Records that form part of a restaurant's accounts are kept for five years because Norwegian bookkeeping law requires it. And where information is needed to establish or defend a legal claim, it is kept until that is resolved.

Your rights

Under the GDPR you can ask to see the data held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive a copy in a portable form.

Ask the restaurant, or ask us and we will act. Because each restaurant is the controller of its own guest records, a request is properly made to the restaurant you booked with. In practice you can write to us instead and we will carry it out on that restaurant's behalf. If you have eaten at more than one restaurant that uses Tablez, tell us which ones, because their records are separate and we act on each one individually.

If you think your data has been handled wrongly, you can complain to the Norwegian Data Protection Authority, Datatilsynet, at datatilsynet.no. We would rather you told us first, but that is your right and it does not depend on us.

Deleting your data

Email privacy@tablez.ai with the subject Delete my data and tell us:

  • the phone number or email address you booked with, so we can find your records;
  • the restaurant or restaurants, if you know them.

We answer within thirty days, as the GDPR requires, and usually much sooner. We will tell you what was deleted rather than simply confirming that something was.

We may need to check that the request is really from you. Where we do, we will ask for the least we can get away with, and never for a copy of an identity document.

Two things we will not pretend about. Where the law requires a record to be kept, such as an accounting record, we keep that record and tell you which one and why. And as described above, deleting a message empties it rather than removing every trace that it existed.

If you contacted a restaurant through Facebook or Instagram, the same address works and the same thirty days apply. Say which page or account you messaged, and we will remove what we hold from that conversation.

Changes to this notice

When this notice changes materially we update the version and date at the top of the page. This is version 1.0, published 25 August 2026.

Contact

Anything about this notice or about how your data is handled: privacy@tablez.ai. Anything else: hello@tablez.ai.

Tablez AS

Dalstoppen 15, 3145 Tjøme, Norway
Organisation number: NO 936 927 416 MVA

  • Home
  • The Product
  • Team
  • About
  • Privacy
  • Terms

hello@tablez.ai

© 2026 Tablez AS. On your side of the table. Runs on LLM Bus

We use cookies to understand how visitors use our site. Accept to help us improve Tablez.