Privacy Policy

Effective date: July 19, 2026

This Privacy Policy explains how TableNote collects, uses, discloses, retains, and protects information in connection with the TableNote service available through tablenote.ca and embedded chat widgets used on restaurant websites.

TableNote is operated by Pengda Chen, a sole proprietor based in Manitoba, Canada. In this Privacy Policy, "TableNote," "we," "us," and "our" refer to Pengda Chen operating TableNote.

This Privacy Policy applies to two groups:

  • Restaurant owners and other business users who sign up for and manage TableNote accounts
  • Diners and other website visitors who interact with a TableNote chat widget embedded on a restaurant's website

1. Overview

TableNote provides an AI-powered chat widget that restaurant owners can add to their own websites. The widget is intended to answer diner questions using information the restaurant provides, such as menus, hours, and policies.

Because the service involves free-text conversations, information entered into chats is not necessarily anonymous. Please do not submit sensitive medical information or other unnecessary personal information through the widget or through our service.

2. Information We Collect

The information we collect depends on how you interact with TableNote.

A. Information from restaurant owners and account users

We may collect:

  • Account and authentication information, such as email address and related sign-in or authentication data
  • Business profile and content information, such as restaurant name, menus, hours, policies, and other text or materials submitted for use with the service
  • Contact information that an owner chooses to provide
  • Subscription and billing information, such as subscription status, plan, billing history, invoices, and limited payment-related metadata

B. Payment information

Payments are processed through Stripe.

  • Full payment card details are handled by Stripe, not by TableNote
  • We may receive limited billing-related information from Stripe, such as payment status, subscription status, billing period, and similar transaction metadata needed to manage the account

C. Information from diners and widget users

When a diner or other visitor uses a TableNote widget on a restaurant's website, we may collect:

  • Questions submitted through the chat
  • AI-generated answers
  • Escalation content, such as messages that are forwarded to the restaurant when the system cannot answer or when follow-up is needed
  • Conversation history associated with the widget session or restaurant account

A diner may also voluntarily include personal information in free text, even when we do not ask for it. For example, a user might type their name, phone number, allergy details, order details, or other personal information into a message. We ask users not to include unnecessary personal information.

C2. Reservation and waitlist information

If a restaurant has reservations turned on, a diner who books a table through the chat — or who asks to be told when a table frees up — gives us information we do ask for directly, and which is needed to hold the table:

  • Name
  • Phone number
  • Email address, if the diner provides one
  • Party size, date, and time
  • Any notes the diner gives, such as an allergy, a birthday, or an accessibility need
  • Whether the reservation was kept, cancelled, or not attended
  • Where a restaurant requires a deposit for a large party, whether that deposit has been paid

We use the phone number to match a reservation to earlier reservations at the same restaurant, so that its staff can see how many times a guest has visited and any notes from those visits. This matching never crosses between restaurants: one restaurant cannot learn that a guest has eaten at another.

A diner who gives an email address receives a confirmation containing a link they can use to view or cancel that reservation themselves. A diner who gives a phone number may receive a text message reminder before the sitting. Both relate to a reservation the diner asked for; we do not use these details for marketing.

D. Technical, device, cookie, and log information

Depending on how the service is configured and used, we or our service providers may collect technical information such as:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • Referrer URL
  • Dates and times of access
  • Usage events and page interactions
  • Cookie or similar identifier information
  • Application, error, audit, and security logs

Not all categories of technical information are necessarily collected in every circumstance, but these are the types of information typically associated with operating and securing a web-based service.

3. How We Use Information

We use information for the following purposes:

PurposeExamples
Provide the serviceCreating accounts, authenticating users, storing restaurant content, generating chat responses, and displaying conversations
Process subscriptions and account administrationManaging plans, billing status, renewals, cancellations, invoices, and customer support
Operate chat functionalityMatching diner questions with restaurant-provided information, generating answers, and escalating questions when needed
Take and manage reservationsRecording a reservation, holding a table, adding a guest to a waitlist, telling a waiting guest a table has opened, and letting a guest view or cancel their own booking
Send reservation messagesEmailing a confirmation with a cancellation link, and sending a text message reminder before the sitting
Recognise returning guestsMatching a reservation to earlier reservations at the SAME restaurant using the phone number, so staff can see previous visits and notes such as an allergy
Take reservation deposits where a restaurant requires oneCreating a payment for a large party and confirming whether it was paid. Deposits are paid to the restaurant's own payment account, not to TableNote
Maintain and improve service performanceTroubleshooting issues, monitoring reliability, reducing duplicate processing, and understanding usage patterns
Security and fraud preventionDetecting abuse, unauthorized access, suspicious activity, and service misuse
Communicate with usersSending service notices, billing notices, account messages, and escalation-related emails
Comply with legal obligationsMeeting recordkeeping, tax, legal, regulatory, dispute, and enforcement requirements
Protect rights and safetyEnforcing our terms, investigating incidents, and protecting TableNote, restaurants, users, and the public

4. Our Privacy Basis and Consent Approach

TableNote operates in Canada and is intended to align with PIPEDA and other applicable privacy laws.

In plain terms, we generally collect, use, and disclose information:

  • with the knowledge and consent of the individual, where consent is appropriate
  • because it is necessary to provide the service requested
  • because it is reasonably necessary for security, fraud prevention, legal compliance, or related operational purposes
  • as otherwise permitted or required by law

For restaurant owners, using the service, submitting business content, and subscribing to TableNote generally indicates consent to the collection, use, and disclosure of information needed to operate the service.

For diners, use of a widget after being presented with or given access to notice about the chat may indicate consent to the collection, use, and disclosure of information reasonably necessary to answer the question, route escalations, and operate the service.

You may withdraw consent in some cases, subject to legal or contractual restrictions and subject to our ability to continue providing the relevant service.

5. Important Chat and Sensitivity Notice

Please do not submit:

  • detailed medical information
  • government identification numbers
  • payment card information in chat messages
  • highly sensitive personal information that is not necessary for your question

If you use the widget, your messages may be:

  • processed by TableNote and its service providers
  • visible to the restaurant that operates the widget
  • retained for a limited period as described below
  • associated with technical data such as time, device, or network information

Because users may include personal details in free text, chat conversations are not necessarily anonymous.

6. When Restaurants Can Access Conversations

Restaurant owners using TableNote may be able to review conversations associated with their widget, including:

  • diner questions
  • generated answers
  • escalated questions or notices
  • related conversation history and timestamps

This access allows restaurant owners to monitor the service, review escalations, and follow up where appropriate.

7. Service Providers and Disclosures

We share information with service providers where reasonably necessary to operate TableNote. Current providers used in connection with the service may include:

ProviderGeneral role
AnthropicAI model provider used to generate responses
Voyage AIEmbeddings or similarity-processing provider
StripePayment processing and subscription billing
ResendTransactional email delivery
TwilioText message (SMS) delivery for reservation reminders
SupabaseAuthentication, database, and related infrastructure services
VercelApplication hosting and deployment infrastructure

We may disclose information to these providers as needed for them to perform services on our behalf.

We may also disclose information:

  • to comply with law, regulation, court order, or legal process
  • to respond to lawful requests from public authorities
  • to investigate fraud, abuse, or security incidents
  • to enforce our agreements or protect rights, property, or safety
  • in connection with a sale, transfer, financing, reorganization, or similar business transaction, subject to applicable legal requirements

We do not state that every provider is prohibited from all use of data beyond service delivery in every circumstance; provider practices are governed by their own agreements and policies as applicable.

8. Processing Outside Canada

TableNote and its service providers may process or store information outside Canada.

As a result:

  • information may be transferred to or accessed from other countries
  • information may be subject to the laws of those jurisdictions
  • courts, law enforcement, national security authorities, or regulators in those jurisdictions may be able to access information in accordance with local law

By using the service or interacting with a widget, you understand that cross-border processing may occur.

9. Retention of Information

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

Default retention periods

CategoryDefault retention approach
Raw diner chat contentUp to 180 days
Reservation and waitlist records (guest name, phone, email, party size, notes)Up to 180 days, measured from the date of the sitting rather than the date of booking
Security, audit, and access logsGenerally up to 90 days
Closed-account operational dataDeleted or anonymized within 30 days after account closure or deletion request processing, subject to the exceptions below
BackupsRemoved through ordinary backup rotation and related technical processes
Billing, legal, dispute, and accounting recordsRetained as reasonably necessary for tax, accounting, legal, security, or dispute purposes

Important retention qualifications

We may keep information for a shorter period where operationally appropriate.

We may also retain information for a longer period where reasonably necessary to:

  • investigate abuse, fraud, or security incidents
  • comply with legal obligations
  • preserve evidence relevant to claims, disputes, or enforcement
  • satisfy accounting, tax, or recordkeeping requirements
  • complete technical backup rotation or restoration processes

Where practical and appropriate, we may de-identify or anonymize information instead of retaining identifiable records.

10. Cookies and Similar Technologies

TableNote or its service providers may use cookies or similar technologies for purposes such as:

  • keeping users signed in
  • maintaining session state
  • improving performance and reliability
  • understanding usage and diagnosing issues
  • supporting security controls

Browsers may allow you to manage cookies through browser settings. If you disable certain cookies or similar technologies, some parts of the service may not function properly.

11. Safeguards

We use administrative, technical, and organizational measures intended to help protect information against loss, theft, misuse, and unauthorized access, use, disclosure, alteration, or destruction.

Because no method of transmission or storage is completely secure, we do not guarantee absolute security. Safeguards may change over time as the service evolves.

12. Access, Correction, Deletion, and Withdrawal Requests

Subject to applicable law, individuals may request to:

  • access personal information we hold about them
  • correct inaccurate or incomplete information
  • request deletion of information
  • withdraw consent to certain processing

Requests may be sent to the contact information at the end of this Privacy Policy.

How we handle requests

We may:

  • request information reasonably necessary to verify identity and authority
  • ask for clarification to help locate relevant records
  • decline or limit a request where permitted or required by law
  • retain certain information despite a request where legally permitted or necessary for security, dispute, accounting, or compliance purposes

If you are a diner and your request relates to a conversation with a restaurant widget, we may direct you to contact the relevant restaurant as well, depending on the nature of the request and the restaurant's role in the interaction.

13. Privacy Complaints

If you have a complaint about our privacy practices, please contact us first using the details below.

Please include:

  • your name and contact information
  • the nature of your concern
  • the restaurant involved, if applicable
  • any relevant dates or screenshots, if available

We may ask for additional information to verify identity and investigate the issue. If we cannot resolve your concern satisfactorily, you may have the right to contact the appropriate privacy regulator or authority.

14. Breach Response

If we become aware of a breach of security safeguards involving personal information, we will assess the incident and take steps we consider appropriate in the circumstances, which may include:

  • containing and investigating the incident
  • reducing the risk of harm
  • documenting the incident as required
  • notifying affected individuals, regulators, or others where legally required

Any notification will be provided in accordance with applicable law, including where there is a legal duty to report or notify.

15. Children

TableNote is intended for use by restaurant businesses and by diners or website visitors making ordinary restaurant-related inquiries. It is not directed to children.

We do not knowingly collect personal information from children in circumstances where consent from a parent or guardian would be required by applicable law. If you believe a child has provided personal information inappropriately, please contact us.

16. Restaurant Responsibilities

Restaurants that use TableNote are responsible for their own compliance with applicable laws in connection with their websites and customer interactions, including where required:

  • providing appropriate notice that a chat widget is in use
  • obtaining any necessary consents
  • maintaining accurate restaurant content
  • responding appropriately to escalated or sensitive inquiries
  • complying with their own privacy obligations to diners and other visitors

A restaurant's own privacy practices may also apply when a diner uses that restaurant's website.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

When we make changes, we will post the updated version on tablenote.ca and update the effective date at the top of this page. Material changes will apply from the updated effective date unless otherwise stated.

18. Contact Information

Privacy Officer: Pengda Chen
TableNote — Website: tablenote.ca
Email: contactus@tablenote.ca

If you have questions, requests, or complaints about this Privacy Policy or our handling of personal information, please contact us at the email address above.