Legal

Privacy Policy

Last updated: July 10, 2026

How SimpleTable collects, uses, stores, and protects personal data across the website, owner app, public booking pages, and related services.

Plain-language summary. SimpleTable provides reservation and table-management technology to hospitality businesses. We act as a data controller for information connected with our own website, business accounts, subscriptions, security, support, and direct communications. When we process restaurant guest information on a hospitality business's instructions, that business is normally the data controller and SimpleTable is its data processor.

This Privacy Policy explains how SIA “Simple Systems Group”, trading as SimpleTable (“SimpleTable”, “we”, “us”, or “our”), collects and processes personal data through mysimpletable.com, restaurant administration tools, public booking pages, and related services that link to this Policy (collectively, the “Services”).

This Policy should be read together with our Terms of Service. For Business Customers, Appendix A of the Terms contains the Data Processing Addendum that applies when SimpleTable processes personal data on the Business Customer's behalf.

1. Who We Are

The identity and contact details of the company responsible for this Policy are:

SIA “Simple Systems Group”
Trading name: SimpleTable
Registration number: 40203744434
Legal address: Bauskas iela 73 k-1 - 31, Rīga, LV-1004, Latvia
Email: simpletable19@gmail.com
Phone: +371 20 408 625

References in this Policy to “Business Customers” mean restaurants, cafés, bars, hospitality businesses, and other organisations that create or use a SimpleTable business account. “Authorised Users” are individuals permitted by a Business Customer to use its account. “Guests” are individuals who use a public booking page or otherwise make or manage a reservation.

2. Who This Policy Applies To

This Policy applies to personal data relating to:

  • Business Customers, prospective Business Customers, and their representatives;
  • Authorised Users, employees, contractors, and business contacts;
  • Guests and prospective Guests using public booking pages;
  • website visitors, support requesters, and people who communicate with us; and
  • other individuals whose personal data is submitted to the Services.

This Policy does not replace a Business Customer's own privacy notice. Restaurants and other Business Customers remain responsible for explaining how they use Guest Data for their own purposes, including venue operations, reservation management, marketing, profiling, no-show management, loyalty programmes, and legal compliance.

3. Our Data-Protection Roles

3.1 When SimpleTable is a controller

SimpleTable acts as a data controller when we determine why and how personal data is processed. This generally includes processing connected with:

  • business account creation, authentication, subscriptions, invoices, and payments;
  • our website, support, security, fraud prevention, and service administration;
  • communications about SimpleTable and our own business-to-business marketing;
  • compliance with legal obligations and the establishment or defence of legal claims; and
  • limited technical, security, and abuse-prevention data generated when Guests use the platform.

3.2 When SimpleTable is a processor

When a Business Customer uses SimpleTable to collect, store, manage, export, or communicate using Guest Data, the Business Customer normally determines the purposes of the processing and acts as controller. SimpleTable processes that data on the Business Customer's documented instructions and acts as processor under the Data Processing Addendum in Appendix A of the Terms.

Requests concerning a particular restaurant booking, guest profile, restaurant marketing campaign, loyalty record, or venue-specific preference should normally be directed to the relevant Business Customer. We will assist Business Customers with such requests as required by the Data Processing Addendum and applicable law.

4. Personal Data We Process

4.1 Business account and identity data

Names, business email addresses, telephone numbers, job titles, venue or company details, legal and billing addresses, registration or tax information supplied by the Business Customer, account identifiers, authentication data, language, time zone, and account preferences.

4.2 Subscription, billing, and transaction data

Subscription plan, trial and renewal dates, invoices, payment status, transaction identifiers, billing contact details, billing country, refund or chargeback information, and communications about payment. Where a third-party payment provider hosts the payment form, full payment-card details are provided directly to that provider rather than stored by SimpleTable. We may receive limited card metadata such as card brand, last four digits, expiry information, and payment status.

4.3 Guest and reservation data

Depending on the Business Customer's configuration, this may include a Guest's name, email address, telephone number, reservation date and time, party size, venue and table information, booking status, cancellation information, booking history, notes, preferences, accessibility requests, dietary or allergy information, consent and opt-out records, and reservation-related communications.

4.4 Customer Content and communications

Restaurant descriptions, policies, opening hours, menus or service descriptions, logos, booking settings, support messages, feedback, uploaded files, email content, and other information submitted through or in connection with the Services.

4.5 Device, usage, and security data

IP address, approximate location derived from IP, browser and device type, operating system, language, referring page, timestamps, session and authentication events, pages or features used, error reports, diagnostic information, audit logs, security events, and cookie or similar identifiers.

4.6 Marketing and preference data

Communication preferences, newsletter or product-update subscriptions, campaign interactions, consent records, unsubscribe records, survey responses, and interests inferred from interactions with SimpleTable's own business communications.

4.7 Data relating to integrations

Where a Business Customer enables an integration, we may receive or transmit identifiers, configuration data, reservation data, contact data, and operational information required for that integration. The information exchanged depends on the integration selected by the Business Customer.

5. Where Personal Data Comes From

We obtain personal data:

  • directly from you when you create an account, book a table, contact support, or communicate with us;
  • from a Business Customer or its Authorised Users, including when they create a reservation or add a staff member;
  • from other Guests, for example when one person makes a group booking;
  • automatically from devices, browsers, cookies, logs, and security systems;
  • from payment, authentication, email, messaging, hosting, and integration providers;
  • from publicly available business sources where necessary to verify or contact a business; and
  • from professional advisers, authorities, or counterparties where necessary for legal or compliance purposes.

We do not routinely purchase consumer marketing databases containing Guest reservation data.

6. Purposes and Legal Bases

The legal basis depends on the context and on whether SimpleTable acts as controller or processor. Where SimpleTable acts as processor for a Business Customer, that Business Customer is responsible for identifying the applicable legal basis. Where SimpleTable acts as controller, we rely on the following bases under applicable data-protection law:

Purpose Typical personal data Legal basis when SimpleTable is controller
Create and administer business accounts, trials, subscriptions, and Authorised Users Identity, contact, account, authentication, plan, and configuration data Performance of a contract or steps requested before entering into a contract for the person or sole trader entering the subscription; legitimate interests in administering access for other Authorised Users and the Business Customer's workforce
Process subscriptions, invoices, payments, refunds, and accounting Billing, transaction, company, and contact data Performance of a contract; compliance with tax, accounting, and legal obligations
Provide, maintain, troubleshoot, and support the Services Account, configuration, support, device, diagnostic, and usage data Performance of a contract; legitimate interests in operating and improving a reliable service
Enable and transmit Guest booking requests Reservation and Guest Data Normally processed as a processor on the Business Customer's instructions. Limited platform-security processing may rely on legitimate interests.
Protect accounts, prevent fraud and abuse, investigate incidents, and enforce the Terms Authentication, IP, device, audit, communications, and security data Legitimate interests in protecting SimpleTable, Business Customers, Guests, and the integrity of the Services; legal obligations where applicable
Analyse performance and improve features Usage, diagnostic, feedback, and aggregated data Legitimate interests, provided those interests are not overridden by individual rights; consent where required for non-essential cookies or similar technologies
Send service notices and respond to enquiries Contact, account, support, and reservation-related data Performance of a contract; legitimate interests in customer service and platform administration
Send SimpleTable product news and business marketing Business contact, preference, and campaign interaction data Consent where required; otherwise legitimate interests where permitted by law. You may opt out at any time.
Comply with law, respond to lawful requests, and establish or defend claims Any information reasonably necessary for the relevant matter Legal obligation; legitimate interests in protecting legal rights
Manage a merger, financing, reorganisation, or sale Account, contract, operational, and due-diligence data Legitimate interests in managing and developing the business, subject to appropriate safeguards

Where we rely on legitimate interests, we consider the necessity and proportionality of the processing and the likely impact on individuals. You may object to processing based on legitimate interests as described in Section 13.

Some information is necessary to create an account, enter into a subscription, process payment, or make a reservation. If required information is not provided, the relevant account, payment, booking, or feature may not be available.

7. Guest Bookings and Sensitive Information

The restaurant or other Business Customer shown on the booking page is normally responsible for deciding why Guest Data is collected and how long it is kept. SimpleTable provides the technical platform and processes Guest Data for that Business Customer.

Booking forms do not normally require special-category personal data. However, Guests or Business Customers may choose to enter information concerning allergies, health, accessibility, religion-related dietary requirements, or other sensitive matters in a booking note or preference. Such information should only be provided where relevant and necessary.

The Business Customer is responsible for establishing a valid legal basis, including an applicable condition under Article 9 of the GDPR where special-category data is processed. SimpleTable processes this information only as necessary to provide the configured Services, follow the Business Customer's instructions, maintain security, and comply with law.

Restaurant marketing messages sent through SimpleTable are sent on behalf of the Business Customer. The Business Customer is responsible for obtaining any consent required for marketing and for honouring objections and unsubscribe requests. Operational messages needed to confirm, remind, modify, or cancel a requested reservation may still be sent where legally permitted.

8. Who Receives Personal Data

We may disclose personal data to the following recipients where necessary:

  • Business Customers and their Authorised Users. Guest booking information is made available to the relevant restaurant or hospitality business.
  • Service providers and subprocessors. Providers supporting cloud hosting, databases, authentication, payment processing, email, messaging, customer support, analytics, monitoring, security, backups, and other technical functions.
  • Integrations selected by a Business Customer. Data may be sent to a third-party service when the Business Customer enables or requests that integration.
  • Professional advisers. Lawyers, accountants, auditors, insurers, and consultants where reasonably necessary.
  • Authorities and legal recipients. Courts, regulators, law-enforcement bodies, tax authorities, or other recipients where disclosure is required by law or reasonably necessary to protect rights, safety, and security.
  • Corporate transaction recipients. Actual or prospective buyers, investors, lenders, or advisers in connection with a merger, financing, reorganisation, or sale, subject to confidentiality and data-protection safeguards.

We require processors and subprocessors to protect personal data and use it only for the agreed purposes. An up-to-date subprocessor list will be made available through the Services, on our website, or upon request at simpletable19@gmail.com, consistently with the Data Processing Addendum.

SimpleTable does not sell Guest Data or Business Customer personal data. We do not use restaurant reservation data for third-party behavioural advertising.

9. Cookies and Similar Technologies

The Services may use cookies, local storage, pixels, and similar technologies. These may include:

  • Strictly necessary technologies used for authentication, security, session management, load balancing, and core booking functions;
  • Preference technologies used to remember language, time zone, display, or consent choices;
  • Analytics technologies used to understand performance and how features are used; and
  • Marketing technologies, if introduced, used only as separately disclosed and where legally permitted.

Strictly necessary technologies may be used without optional consent where permitted by law. Where consent is required, non-essential cookies and similar technologies will not be placed or accessed until you make a choice. You may withdraw or change your choice through the cookie settings made available on the Site. Withdrawal does not affect processing that occurred before the choice was changed.

Blocking strictly necessary cookies may prevent authentication, account security, reservations, or other essential parts of the Services from working. When non-essential technologies are used, further details, including the names, purposes, providers, and lifetimes of cookies in use, will be provided in the applicable Cookie Policy or cookie settings interface.

10. International Transfers

SimpleTable is established in Latvia. Our service providers and subprocessors may process data in the European Economic Area and, where necessary, in other countries.

When personal data is transferred outside the European Economic Area to a country that has not been recognised as providing an adequate level of protection, we use an applicable lawful transfer mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary technical, contractual, or organisational measures where appropriate.

You may request information about the relevant transfer safeguards by contacting us. Access to a copy may be limited or redacted where necessary to protect confidential information or the rights of others.

11. How Long We Keep Personal Data

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, comply with law, resolve disputes, maintain security, and enforce agreements. The applicable period depends on the type of data and our role.

Data category Typical retention approach
Business account and subscription data For the duration of the account or subscription and for a limited period afterwards where needed for reactivation, contractual administration, security, or legal claims.
Invoices, payment, tax, and accounting records For the period required by applicable Latvian accounting and tax law. Supporting accounting documents are generally retained for at least five years, and certain accounting records may require longer retention.
Guest Data processed for a Business Customer For the period configured or instructed by the Business Customer. Following termination, export, retrieval, and deletion are handled under Section 12 of the Terms and Appendix A.
Support communications Normally for up to three years after the matter is closed, unless a longer period is needed for a continuing account, dispute, security incident, or legal obligation.
Security, authentication, and audit logs Normally for up to twelve months, but longer where reasonably necessary to investigate an incident, prevent abuse, or comply with law.
Marketing preferences Until you unsubscribe, withdraw consent, or object. We may retain a minimal suppression record afterwards so that we continue to honour the opt-out.
Cookie and consent records For the lifetime disclosed in the cookie settings and for a period reasonably necessary to demonstrate and honour your choices.

After the applicable period, personal data is deleted, anonymised, or placed beyond active use. Data in secure backups may remain until overwritten through the ordinary backup cycle, provided it remains protected and is not used for another purpose.

12. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. Depending on the context, these measures may include encryption in transit, access controls, authentication, least-privilege permissions, logging, monitoring, secure development practices, backups, incident-response procedures, and security assessment of service providers.

No online service can guarantee absolute security. Business Customers are responsible for securely configuring their accounts, controlling Authorised Users, protecting credentials, and promptly notifying us of suspected account compromise.

13. Your Data-Protection Rights

Subject to applicable law and any relevant conditions or exemptions, you may have the right to:

  • obtain confirmation of whether personal data concerning you is processed and receive access to it;
  • correct inaccurate data and complete incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing;
  • receive information about safeguards used for qualifying international transfers; and
  • lodge a complaint with a competent supervisory authority.

13.1 Requests where SimpleTable is controller

Send your request to simpletable19@gmail.com. Describe the right you wish to exercise and provide enough information for us to locate the relevant data. We may request additional information where reasonably necessary to verify identity and prevent unauthorised disclosure.

We will respond without undue delay and normally within one month, subject to any extension permitted by law for complex or numerous requests. Requests are generally free, although a reasonable fee may be charged or a request refused where it is manifestly unfounded or excessive, as permitted by law.

13.2 Requests concerning restaurant-controlled Guest Data

Where the request concerns a particular restaurant booking, guest profile, venue communication, marketing consent, loyalty record, or restaurant-created note, contact the relevant Business Customer first because it is normally the controller. If you contact us, we may forward the request to the Business Customer and assist it in responding.

13.3 Account controls

Business Customers and Authorised Users may be able to update certain account information, manage communication preferences, export Customer Data, or request account closure through the Services. Closing an account does not require immediate deletion of information that must be retained for legal, security, accounting, or claims-related reasons.

14. Children and Minors

SimpleTable business accounts and paid subscriptions are intended for persons aged 18 or older who act for a business or professional organisation.

Public booking pages are provided for Business Customers and are not designed as services directed specifically at children. A restaurant may set its own age and booking requirements. Where a minor uses a booking page, the relevant Business Customer is responsible for ensuring that the processing is lawful and that any parental or guardian authorisation required by law has been obtained.

We do not knowingly use children's reservation data for SimpleTable's own marketing or behavioural profiling. If you believe personal data relating to a child has been processed unlawfully, contact the relevant Business Customer and us.

15. Automated Decision-Making

SimpleTable may use automated rules to calculate availability, suggest table assignments, detect suspicious activity, send reminders, or perform other operational functions. These functions are not intended to make decisions about individuals that produce legal effects or similarly significant effects solely through automated processing.

A Business Customer may configure its own booking rules, approval settings, cancellation rules, marketing segments, or integrations. The Business Customer is responsible for any automated decision-making it independently determines or configures and for providing any additional notices required by law.

16. Changes to This Policy

We may update this Policy to reflect changes in the Services, processing activities, providers, or legal requirements. The “Last updated” date identifies the latest revision.

Where a change materially affects how we use personal data or an individual's rights, we will provide reasonable advance notice through the Services, by email, or by another appropriate method, unless an immediate change is required for legal, security, or fraud-prevention reasons.

17. Contact and Complaints

Questions, requests, or complaints about this Policy or processing for which SimpleTable is controller may be sent to:

SIA “Simple Systems Group” / SimpleTable
Registration number: 40203744434
Bauskas iela 73 k-1 - 31, Rīga, LV-1004, Latvia
Email: simpletable19@gmail.com
Phone: +371 20 408 625

We encourage you to contact us first so that we can try to resolve the matter. You also have the right to lodge a complaint with the Latvian supervisory authority or, where applicable, the supervisory authority in the EU or EEA country of your habitual residence, place of work, or place of the alleged infringement.

Data State Inspectorate of Latvia (Datu valsts inspekcija)
Elijas iela 17, Rīga, LV-1050, Latvia
Email: pasts@dvi.gov.lv
Phone: +371 67 223 131
Website: dvi.gov.lv