Tavilio is reservation software for restaurants and cafés. This policy explains what we do with personal data when a venue uses Tavilio, and what a guest's data is used for when they book a table through it.
Who is responsible for what
Two different sets of data pass through Tavilio, and they are not ours in the same way.Your venue's account. When you sign up, run a venue and pay for a plan, we decide what is collected and why. For that data we are the controller.Your guests' reservations. When a guest books a table, the venue decides that it takes bookings, what it asks for and how long it keeps the answers. For that data the venue is the controller and we are its processor: we hold and move the data on the venue's instructions and do not use it for our own purposes. We do not sell it, we do not use it to advertise, and we do not use it to train anything.
What we hold
About you and your team: your name, email address and the role you were given in a venue. Sign-in is handled by our authentication provider; we hold the email address and, if you set one, a password hash — never the password itself.About your venue: its name, address, phone number, public email, opening hours, links, the images and logos you upload, your floor plan, your menu with its photos, prices and allergens, and the pages of your website.About a booking: the guest's name, email address, phone number, party size, the date and time, the tables assigned, and any note the guest wrote. A note is free text, so it is worth telling guests not to put anything sensitive in it.About your subscription: which plan you are on, when it renews, and the identifiers our payment provider gives us. We never see or store card numbers — those go straight to Stripe and stay there.Technical records: the ordinary request logs our hosting provider keeps, which include IP addresses, and the records of transactional emails we sent.
Why, and on what legal basis
To run the service you asked for — your account, your venue, your bookings, your website. This is the performance of our contract with you.
To take payment — a legal obligation once money changes hands, and the performance of the contract.
To send transactional email — a booking confirmation to a guest, a notification to a venue, a password reset. For a guest this is on the venue's instruction as its processor; for you it is the contract.
To keep the service working and secure — logs, backups, abuse prevention. Our legitimate interest in operating a service that stays up and is not abused.
To meet accounting and tax obligations — a legal obligation.
We do not do behavioural advertising, and Tavilio sets no advertising or analytics cookies. The only cookies we set are the ones that keep you signed in and remember your chosen language.
Who else processes it
We use a small number of providers, each for one job. They process data on our instructions and are bound by contract to do no more.
Supabase — the database and the file storage where everything above lives.
Vercel — hosting, the CDN that serves the pages, and the certificates for venue domains.
Stripe — payments and subscriptions. Stripe is an independent controller for the payment data it holds.
Resend — sending transactional email.
Where a provider processes data outside the European Economic Area, that transfer relies on the European Commission's standard contractual clauses.
How long we keep it
Reservations stay while they are useful to the venue and are removed when the venue removes them or closes its account. Venue content — the menu, the floor plan, the website — stays until you delete it. Account records are kept while the account is open.When a venue is deleted, its data goes with it: its content, its uploaded files and its bookings are removed, not hidden. Records we are required to keep for accounting — invoices and payment records — are kept for as long as the law requires, and no longer.Backups are kept for a short rolling window and then expire, so deleted data can persist in a backup briefly after it is gone from the service.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct it, to delete it, to limit what we do with it, to receive it in a portable form, or to object to processing we base on our legitimate interest. Write to the address below and we will answer within one month.If you are a guest who booked a table at a venue, the venue is the controller of that booking. Ask the venue first — it is the one that decides. If you ask us, we will pass the request on to the venue and help it answer.You also have the right to complain to a data protection supervisory authority, in the country where you live or work or where you think something went wrong.
Changes
If we change this policy in a way that matters, we will say so on this page and move the date at the top. Continuing to use Tavilio after a change means the new version applies.
Contact
Write to us at the address below with anything about this policy, or to exercise any of the rights above.Tóth Lóránt e.v.
1134 Budapest, Kassák Lajos utca 67/B, Hungary
Email: support@dopler.app
Governing law: Hungary