Privacy Policy

Plain words. Version 1.0 · July 6, 2026

The whole policy in five lines

  • We collect what a dinner needs — accounts, event details, chef storefronts, messages — and nothing more.
  • Exact addresses and phone numbers are shared with exactly one confirmed counterpart, never publicly.
  • A short list of named service providers processes data on our behalf; their servers are in the United States.
  • We never sell your personal information. Ever.
  • Ask us anything, or ask for your data, at hello@tableside.co.

1. Who this covers

The Tableside product and our early-access pages.

This policy covers tableside.co and our pre-launch pages (like join.tableside.co), based in British Columbia, Canada. It applies to hosts, chefs, and anyone who joins our early-access list or contacts us.

2. What we collect

Only what the product needs to do its job.

Account basics — name, email, password (stored as a hash — we never see it), role, and optional profile photo, city, and about-you line.

Chef storefronts — the business information chefs choose to publish: display name, bio, menus, photos, certifications, service area, pricing. This is public by design.

Event details, including sensitive ones — occasions, dates, guest counts, budgets, dietary needs — and after a booking is mutually confirmed, the exact address, kitchen and access notes, and a day-of phone number. These are shared with exactly one person: the confirmed counterpart. They are never public, never shown to competing chefs, and chefs are contractually bound to treat them as confidential and single-use.

Messages — proposal notes and event coordination threads, visible only to the two parties of that event (and to us where the law requires or safety demands).

Early-access signups — name, email, and what you're hoping to host, from our pre-launch pages.

Support messages — what you send through the contact form, kept so we can actually help.

3. Ads and measurement on our pre-launch pages

We disclose the pixel most startups hide.

Our early-access pages record where a visit came from (UTM parameters) and may use the Meta pixel, which tells Meta that a signup happened so our ads can be measured. The product itself (your dashboard, events, and messages) contains no advertising trackers.

4. Who processes your data

A short, named list — servers in the US.

We don't run our own data centres. These providers process data on our behalf:

  • Supabase — our database, authentication, and photo storage
  • Resend — sends our email (notifications, contact-form delivery)
  • Vercel — hosts the website
  • GoHighLevel — manages the early-access mailing list
  • Meta — ad measurement on pre-launch pages only

These providers store data on servers in the United States, which means it can be subject to US law while it's there. We share only what each provider needs to do its job, and we never sell personal information to anyone.

5. Email, and your consent

Marketing only with your express consent; unsubscribe always works.

Joining our early-access list is express consent (under Canada's anti-spam law) to receive Tableside updates by email — every one of them has a working unsubscribe. Transactional email — a proposal arrived, a booking confirmed — is part of using the product, and can be managed in your account settings.

6. How long we keep things

As long as the job needs, then gone.

Account and profile data lasts while your account does. Event records, commitments, and reviews are records of real commercial arrangements between two parties, so they persist as the trust history both sides rely on. Early-access list entries are deleted on unsubscribe or after launch outreach completes. Support messages are kept while the issue (and its lessons) stay relevant.

7. Your rights

Ask, and we answer — access, correction, deletion.

Email hello@tableside.co to see the personal information we hold about you, correct it, or ask for deletion. We'll act promptly, with one honest carve-out: records of completed commercial events (commitments, reviews, cancellation history) may be retained in de-identified or minimal form, because the other party relies on them. You can also complain to the Office of the Privacy Commissioner of Canada — but we'd rather you talk to us first.

8. Security and breaches

Least access, encrypted in transit, and we'll tell you if something goes wrong.

Data is encrypted in transit, access is role-restricted (a competing chef cannot see your proposals; nobody sees an address before confirmation), and secrets are never stored in code. If a breach ever creates real risk of harm, we will notify affected people and the authorities as the law requires — promptly and plainly.

9. Age, changes, and contact

19+, and we'll flag material changes.

Tableside is for people 19 and older; we don't knowingly collect information from anyone younger. When this policy materially changes, we'll say so on the platform or by email. Questions, requests, worries: hello@tableside.co.