Last updated · 2026-09-08

Privacy at Tabled.

This notice explains how Tabled handles information across usetabled.com, our signed-in web experiences, our mobile apps, and the business and team tools that support the service.

Browsing and signing in

You can browse public marketing pages, places, events, lists, and public profiles without signing in. An account is required for private or personalized features such as saving, posting, messaging, managing visits, and using account tools. Business administration requires an authorized business membership. Platform administration is restricted to authorized Tabled team members.

Information we collect

  • Account and sign-in data — your email address or phone number, authentication credentials, session and verification records, and identifiers from Apple, Google, or Microsoft if you choose one of those sign-in methods.
  • Profile and community data — details you add to your profile, taste and dietary preferences, posts, photos, comments, messages, friendships, blocks, reports, saved lists, follows, RSVPs, and other interactions.
  • Visits and transactions — check-ins and other visit history, streaks and recaps derived from that history, reservations, bookings, orders, redemptions, delivery details, and transaction status.
  • Business information — business profiles, ownership and staff roles, menus, offers, event details, customer-service activity, and information submitted through listing, event, or claim forms.
  • Location — when you allow location access, the website or app can send latitude and longitude to find nearby places or support a feature you requested. Public web browsing does not require location, and Tabled does not use precise location for advertising.
  • Payments — Stripe processes payment details for web and app purchases. Tabled receives transaction identifiers, totals, status, and fulfillment details, but not your full card number.
  • Forms and communications — contact forms collect your name, email, topic, and message. Waitlist and interest forms can also collect a city, food interests, or a limited first-party source category. We use these details to answer you, operate the requested program, and send updates you asked for.
  • Assistant conversations — if you choose the Tabled AI assistant, we and our service providers can process the voice or text you submit, generated replies, conversation metadata, and any contact details you choose to provide. Do not submit payment details to the assistant.
  • Connected-assistant activity — if you add and authorize Tabled as a connector in ChatGPT or Claude, we process the approved OAuth connection records, structured read-only tool requests that assistant sends on your behalf, and the Tabled results returned to it. The categories and limits are described below.
  • Technical and security data — live IP address and browser or environment signals can be processed transiently for rate limiting, bot detection, and security. App version, timestamps, response status, crash or diagnostic data, and other anti-abuse signals can also be processed by Tabled and its infrastructure providers. Tabled’s routine API application log omits raw IP address, user-agent, URL query values, and dynamic record identifiers; edge and infrastructure providers can maintain separate security logs.

Tabled AI assistant

The web and phone assistants are AI, not people. Immediately before you connect, Tabled tells you that Tabled, ElevenLabs, and their service providers—including third-party large-language-model providers—may record, view, store, and share the voice or text conversation to provide the service, improve products and services, train machine-learning models, and comply with applicable law. Choosing “Agree and continue,” and each later interaction with the assistant, means you consent to that processing.

You can ask for a human at any point or contact hello@usetabled.com without using the assistant. Assistant conversations are retained only as long as reasonably needed for support, service operation, quality, safety, and legal obligations, subject to provider settings and backup cycles. You may ask us to delete a support conversation.

Optional ChatGPT and Claude connectors

You can choose to add Tabled as a user-added Model Context Protocol connector in ChatGPT, provided by OpenAI, or Claude, provided by Anthropic. A connection works only after you sign in to Tabled and approve the scopes shown on Tabled's authorization screen. You can decline instead. Every Tabled connector tool is read-only: it cannot save, post, message, order, book, change an account, or administer a business. Availability as a custom connector does not mean that Tabled has been approved for or listed in an OpenAI or Anthropic marketplace or directory.

Local recommendations. If you approve recommendation access and direct the assistant to use it, the assistant can send a structured search request containing search terms, a place-or-event-or-deal category, city and state, and filters such as open now, maximum distance, and result limit. It can send precise latitude and longitude only when you or the assistant supplies them for that request; Tabled does not independently obtain your device location through MCP. Tabled can use your saved taste, drink, vibe, dietary, neighborhood, going-out-frequency, price, and travel radius settings internally to rank results. The assistant receives public place, event, and deal details; distance and open-state information when applicable; the public Tabled business slug needed to refer to that business in an authorized follow-up; and concise recommendation reasons, which can reveal that a result matched one of your preferences. It does not receive an internal ranking score, a candidate or business database identifier, or your complete preference profile as a tool result.

Operator market demand. This separate scope is available only when the signed-in account is a member of the requested verified, active business. The assistant sends that business's public slug and a 7-, 30-, or 90-day period. Tabled returns only completed dates and thresholded market-level request counts by limited categories such as intent, daypart, and results or no results. A daily cell is omitted unless at least five distinct consenting accounts contributed to that exact cell. The disclosed totals are request signals and lower bounds, not unique people. This tool does not return another business's private records, individual account activity, raw Ask Tabled prompts, saved Ask searches, query text, coordinates, or identifiers from the underlying demand aggregates.

What the assistant provider receives. OpenAI or Anthropic already processes the request you make in its assistant under that provider's terms and settings. Through the connector, the chosen provider also sees the structured tool input it sends and the result Tabled returns. Tabled's MCP service does not receive the surrounding ChatGPT or Claude conversation, and it does not send stored raw Ask Tabled prompts. Tabled never includes your password, Tabled product session, authorization code, access token, or refresh token in a tool result, and it does not send connector credentials to the other assistant provider or to a business operator.

Connection and credential records. To establish and protect a connection, Tabled processes your Tabled account identifier; the chosen client's verified identifier and redirect address; the approved scopes and protected resource; a PKCE challenge; a random token-family identifier; and creation, code-use, expiry, revocation, and scheduled deletion times. Tabled stores only one-way hashes of OAuth authorization codes, access tokens, and refresh tokens—not their raw values at rest. An authorization code is single-use and expires after five minutes, an access token after 15 minutes, and a refresh token after 30 days. Authorization-code records are scheduled for deletion 30 days after code expiry, and token-family records 30 days after refresh-token expiry.

Rotation, disconnecting, and account security. Each successful refresh retires the old refresh token and issues a new pair; replaying a retired refresh token revokes the whole token family. A standard connector revocation, when sent by the provider, also revokes that family. You can remove or disconnect Tabled in the provider's connector settings to stop future connector use through that provider, or decline a later authorization request; the provider's handling of its copy follows its own controls and privacy policy. Changing, setting, or resetting your Tabled password revokes existing connector token families at Tabled and invalidates unused authorization codes. Suspending the Tabled account makes access and refresh credentials unusable. Self-service account deletion deletes the account's OAuth codes and token records along with its active sessions.

How we use information

We use information to provide and personalize Tabled, maintain accounts and permissions, show relevant places and events, support community and messaging features, fulfill transactions, respond to requests, measure service performance, prevent fraud and abuse, moderate content, troubleshoot problems, and keep financial and operational records.

Tracking and measurement

Optional web analytics. Google Analytics 4 is off until you choose Allow analytics. When allowed, it uses first-party cookies and pseudonymous client and session identifiers to measure public page use and page-performance measures such as loading, responsiveness, and visual stability. It can also process approximate location and browser or device information. Both event types use approved page types only; public profile handles and record identifiers are collapsed to route shapes before measurement. We do not intentionally send search terms, URL query values, URL fragments, raw referrer paths, or referrer query values. Same-site referrers may be reduced to an approved route shape, and cross-site referrers are reduced to their origin. Performance totals cover only opted-in page loads where measurement was active in time and can omit the first page on which you make that choice. Google Analytics is disabled on sign-in and sign-up, account, administration, contact, submission, business-claim, deletion, invite, order-link, and driver-link routes. Advertising storage, advertising personalization, and Google Signals are disabled.

Mobile product analytics. Tabled mobile apps can use Google Analytics for Firebase and Tabled's first-party analytics service to record bounded app-use events such as screen views and feature interactions. First-party events are linked to the signed-in account so consent and deletion apply to the correct person. These events help us understand reliability and product use. Mobile analytics starts off and both services run only after you enable it in the app's privacy settings; neither is used for third-party advertising.

First-party business activity counters. Public place and event pages send aggregate actions such as a profile view, directions click, calendar add, or RSVP to Tabled. The counter record contains the business, action, web-or-app source, and time—not a Tabled account ID, session ID, device ID, or unique-visitor identifier. These counters are not a count of unique people and operate separately from your optional Google Analytics choice. The live IP can still be processed in memory for rate limiting or by infrastructure security systems without becoming part of the activity counter.

Account presence. When a signed-in app or browser is active, Tabled records a last-active time linked to that account. Presence visibility currently starts on for new accounts; accepted friends can see an “active now” indication for a short window. Turning presence visibility off prevents that friend-facing display, but does not currently stop the internal last-active update, which also supports service operation and aggregate active member reporting.

Analytics choices

You can allow or decline optional website analytics at any time. Declining disables future Google Analytics collection and removes Google Analytics cookies available to this site. The choice does not disable required sign-in storage, security logging, aggregate business activity counters, or signed-in presence.

Current choice: No choice yet. Google Analytics is off until you allow it.

Cookies and browser storage

  • Required session storage and secure cookies keep signed-in members signed in and protect account requests.
  • Your website analytics choice is stored in your browser so we can remember it. Clearing site storage resets the choice.
  • Google Analytics cookies are permitted only after you allow analytics and are expired when you later decline.

Providers and other recipients

We disclose information as needed to operate the service, fulfill your requests, and protect Tabled. Recipients can include:

  • Amazon Web Services for application hosting, storage, delivery, and operational logs.
  • Stripe for payment processing and related fraud controls.
  • Google for optional web analytics, mobile Firebase analytics, and Google sign-in when selected.
  • Cloudflare Turnstile for bot and abuse detection on forms. Turnstile can process IP address and browser or environment signals to produce a verification token; the contact message itself is sent through Tabled, not as part of the Turnstile check.
  • ElevenLabs for the optional Tabled AI voice and text assistant. ElevenLabs and its service providers can record, process, store, and share the conversation as described in the notice shown before you connect.
  • OpenAI when you add and authorize Tabled as a ChatGPT connector, to hold the OAuth credentials issued to its client, send the structured tool calls you direct, and receive the resulting Tabled data under OpenAI's terms and settings.
  • Anthropic when you add and authorize Tabled as a Claude connector, to hold the OAuth credentials issued to its client, send the structured tool calls you direct, and receive the resulting Tabled data under Anthropic's terms and settings.
  • Resend to relay contact-form messages and transactional email, plus communications providers used for verification, push notifications, or other requested messages.
  • Apple and Microsoft when you choose their sign-in services, and a business operator when it must receive the order, booking, delivery, or diner information needed to fulfill your request.
  • Other members for information you choose to make public or share with them, and authorities or advisers when reasonably necessary for safety, legal process, or protecting rights.

We do not sell personal information, and we do not disclose it to third parties for cross-context behavioral advertising.

Retention and account deletion

Retention depends on the record and why it exists. Account information remains while your account is active. Messages, transactions, moderation records, support correspondence, security logs, analytics, and business records are kept only as long as reasonably needed for the service, safety, accounting, fraud prevention, dispute handling, or applicable recordkeeping requirements. Provider settings and backup cycles can affect when a deleted item disappears from every system.

Account-scoped first-party mobile analytics events expire after 180 days. Anonymous first-party business activity counters and de-linked aggregate market-demand counts expire after 800 days, which preserves two complete year-over-year reporting windows without keeping an open-ended event history. When you withdraw analytics consent or delete your account, Tabled immediately deletes the short-lived, account-linked demand guards and subtracts each recent contribution that is still linked by one of those guards. Tabled normally keeps a guard for the current partial date plus two completed dates; the daily deletion sweep can add up to one grace day. After that period, an older count has no account identifier by which Tabled can attribute or reverse it; that anonymous aggregate remains until its 800-day expiry. Optional Google Analytics data currently follows a two-month event-data and fourteen-month user-data retention setting in Tabled’s Analytics property.

OAuth authorization codes, access tokens, and refresh tokens for optional ChatGPT and Claude connectors follow the five-minute, 15-minute, and 30-day lifetimes described above. Only their hashes are stored. Authorization-code rows are scheduled for deletion 30 days after code expiry, and token family rows 30 days after refresh-token expiry. Revocation makes a credential unusable before that scheduled deletion; account deletion removes the account's connector credential rows immediately.

New password-recovery and email-verification records are scheduled for deletion within 30 days after the link expires. Tabled does not add raw IP address or browser user-agent fields to new application audit, waitlist, or one-time-link records. Older records and provider-managed security logs can follow a separate reviewed cleanup or provider retention cycle.

Self-service account deletion disables the account, removes sign-in credentials and active sessions, and scrubs profile fields from the account record. A deactivated technical row and records needed for financial, operational, fraud, safety, or referential-integrity purposes may remain. Business owners must transfer ownership or close the business before deleting their account. See account deletion instructions.

Security and service logs

Tabled uses HTTPS, access controls, scoped administration, and provider security features to protect information. The web service runs through CloudFront and application servers, with static assets stored in S3. Routine API application logs keep request time, method, an approved route shape, response status, latency, and request ID; they omit raw URLs, query values, dynamic path identifiers, IP addresses, and browser user-agent strings. CloudFront, hosting, identity, email, analytics, and anti-abuse providers can process or retain separate network and browser security data under their controls. Access and retention vary by system. No method of transmission or storage is completely secure.

Your controls and requests

  • Change optional web analytics in the control above.
  • Change location, camera, photo, and notification permissions in your browser or device settings.
  • Change profile visibility and supported presence settings in the app, or contact us if a control is not available on your platform.
  • Decline a ChatGPT or Claude connector authorization, remove or disconnect Tabled in that provider's settings, or change or reset your Tabled password to revoke existing connector access at Tabled.
  • Unsubscribe through a message you receive or ask us to remove you from a waitlist.
  • Update account information in Tabled, delete your account, or ask us for access, correction, deletion, or a portable copy of information associated with you.

Available privacy rights and exceptions depend on where you live and the nature of the record. We may need to verify your identity before acting on a request.

Changes

We may update this notice as Tabled changes. The date above shows the latest revision; material changes may also be announced in the service.

Contact

Send privacy questions or requests to hello@usetabled.com. You can also use the contact form, which is protected by Cloudflare Turnstile and relayed to our inbox through Resend.

Analytics cookies help us see which pages work. Nothing tracks you across the web either way. Read the privacy notice.