Privacy Policy
What we hold, why, and for how long.
Eightish handles two different kinds of personal data with two different sets of responsibilities, and most privacy policies blur them. This one separates them at the top, because the difference decides who you should ask about what.
Last updated: 24 August 2026. Version 1.0.
The two roles, first
Guest data — the restaurant decides
Names, phone numbers, bookings, notes and message history belong to the restaurant you booked with. They are the controller; Eightish is their processor. We only act on their instructions.
If you are a diner and want your data corrected or erased, ask the restaurant. If you cannot reach them, contact us and we will pass it on within 5 working days.
Account data — we decide
The names and email addresses of restaurant staff who use Eightish, billing details, and how the product is used. Here we are the controller, and the rest of this policy applies directly.
Who we are
Eightish is a product of Mensia Limited, a private limited company registered in England and Wales.
- Company number: 17231746
- Registered office: 10 Hudson Drive, Preston, PR4 2ER, United Kingdom
Contact for any data protection question: hello@eightish.co.uk.
What we collect
From restaurants (we are controller)
- Account — name, work email, password hash, venue details, role.
- Billing — plan, subscription status, invoice history. We never see or store your card. Card details go directly to Stripe; we hold only a token, the brand and the last four digits.
- Usage — counts of bookings and messages per month, for billing and for showing you your allowance.
- Technical — IP address, browser and error logs, for security and diagnosis.
From guests, on a restaurant’s behalf (we are processor)
- Booking — name, mobile number, email if given, party size, date and time, and any dietary or access note the guest chose to share.
- History — previous visits, no-shows, cancellations, and tags or notes the restaurant adds.
- Messages — the confirmations and reminders sent, their delivery status, and any replies.
- Consent — whether the guest agreed to marketing, when, how, and when they withdrew it. This record is append-only: withdrawing consent adds an entry, it does not erase the history of having given it.
We do not collect special category data. A dietary note a guest volunteers may imply health or religious information, so restaurants should treat that field with care and guests should share only what they want the kitchen to know.
Why, and on what lawful basis
| Purpose | Basis |
|---|---|
| Providing the product to a restaurant | Contract |
| Taking payment | Contract |
| Booking confirmations and reminders | Contract, between guest and restaurant — these are service messages, not marketing |
| Marketing messages to guests | Consent, or the soft opt-in where the guest has booked before and was given a clear chance to refuse |
| Security, fraud prevention, diagnosing faults | Legitimate interests |
| Keeping accounting records | Legal obligation |
Who else processes it
We use a small number of sub-processors. Restaurants will be told at least 30 days before we add one, and may object.
| Who | What for | Where |
|---|---|---|
| Supabase | Database and authentication | EU (London region) |
| Vercel | Application hosting | EU / UK edge |
| Stripe | Payments and card storage | EU / US — UK adequacy and SCCs |
| Twilio | Sending and receiving text messages | EU / US — UK adequacy and SCCs |
We do not sell personal data. We do not share it with advertisers. We have no advertising on Eightish.
How long we keep it
- Guest records — for as long as the restaurant’s account is open, because a guest history that expires is not a guest history. Restaurants can delete any guest at any time.
- After an account closes — exportable for 30 days, then deleted within 90 days.
- Consent records — kept for 6 years after the last contact, because they are the evidence that a message was lawful.
- Invoices and accounting — 6 years, as UK tax law requires.
- Technical logs — 90 days.
Text messages, opting out, and what STOP does
Every marketing message tells you how to stop. Replying STOP is honoured immediately and permanently for that restaurant, and recorded. You will still receive confirmations and reminders for bookings you actually make, because those are part of the booking, not marketing — if you do not want those either, tell the restaurant.
Replying CANCEL TABLE cancels your booking. It does not opt you out, and opting out does not cancel your booking. These are deliberately separate, because confusing them has real consequences at both ends.
Your rights
Under UK GDPR you can ask for access, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Where consent is the basis, you can withdraw it at any time without affecting what came before.
Ask the right party: for booking and guest data, ask the restaurant, who decides. For account data, ask us. Either way we respond within one month.
If you are unhappy with how we have handled it you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first, but it is your right either way.
Security
Data is encrypted in transit and at rest. Access between restaurants is separated at the database level, so one venue’s staff cannot read another’s guests even if the application has a bug. Billing fields can only be written by our payment webhook, never by a browser. Access to production data is limited to those who need it and is logged.
If a breach affects your data and is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell affected restaurants without undue delay.
Cookies
Eightish uses only what it needs to work: a session cookie so you stay signed in, and local storage on the host stand so it keeps working through a wifi drop. No advertising or third-party tracking cookies. Nothing that needs a consent banner, which is why there isn’t one.
Children
Eightish is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16 other than a name that may appear in a party size.
Changes
Material changes are emailed to account holders 30 days before they take effect, and the version and date at the top of this page always tell you which version you are reading.