Privacy Policy

What we hold, why, and for how long.

Eightish handles two different kinds of personal data with two different sets of responsibilities, and most privacy policies blur them. This one separates them at the top, because the difference decides who you should ask about what.

Last updated: 24 August 2026. Version 1.0.

The two roles, first

Guest data — the restaurant decides

Names, phone numbers, bookings, notes and message history belong to the restaurant you booked with. They are the controller; Eightish is their processor. We only act on their instructions.

If you are a diner and want your data corrected or erased, ask the restaurant. If you cannot reach them, contact us and we will pass it on within 5 working days.

Account data — we decide

The names and email addresses of restaurant staff who use Eightish, billing details, and how the product is used. Here we are the controller, and the rest of this policy applies directly.

Who we are

Eightish is a product of Mensia Limited, a private limited company registered in England and Wales.

  • Company number: 17231746
  • Registered office: 10 Hudson Drive, Preston, PR4 2ER, United Kingdom

Contact for any data protection question: hello@eightish.co.uk.

What we collect

From restaurants (we are controller)

  • Account — name, work email, password hash, venue details, role.
  • Billing — plan, subscription status, invoice history. We never see or store your card. Card details go directly to Stripe; we hold only a token, the brand and the last four digits.
  • Usage — counts of bookings and messages per month, for billing and for showing you your allowance.
  • Technical — IP address, browser and error logs, for security and diagnosis.

From guests, on a restaurant’s behalf (we are processor)

  • Booking — name, mobile number, email if given, party size, date and time, and any dietary or access note the guest chose to share.
  • History — previous visits, no-shows, cancellations, and tags or notes the restaurant adds.
  • Messages — the confirmations and reminders sent, their delivery status, and any replies.
  • Consent — whether the guest agreed to marketing, when, how, and when they withdrew it. This record is append-only: withdrawing consent adds an entry, it does not erase the history of having given it.

We do not collect special category data. A dietary note a guest volunteers may imply health or religious information, so restaurants should treat that field with care and guests should share only what they want the kitchen to know.

Why, and on what lawful basis

PurposeBasis
Providing the product to a restaurantContract
Taking paymentContract
Booking confirmations and remindersContract, between guest and restaurant — these are service messages, not marketing
Marketing messages to guestsConsent, or the soft opt-in where the guest has booked before and was given a clear chance to refuse
Security, fraud prevention, diagnosing faultsLegitimate interests
Keeping accounting recordsLegal obligation

Who else processes it

We use a small number of sub-processors. Restaurants will be told at least 30 days before we add one, and may object.

WhoWhat forWhere
SupabaseDatabase and authenticationEU (London region)
VercelApplication hostingEU / UK edge
StripePayments and card storageEU / US — UK adequacy and SCCs
TwilioSending and receiving text messagesEU / US — UK adequacy and SCCs

We do not sell personal data. We do not share it with advertisers. We have no advertising on Eightish.

How long we keep it

  • Guest records — for as long as the restaurant’s account is open, because a guest history that expires is not a guest history. Restaurants can delete any guest at any time.
  • After an account closes — exportable for 30 days, then deleted within 90 days.
  • Consent records — kept for 6 years after the last contact, because they are the evidence that a message was lawful.
  • Invoices and accounting — 6 years, as UK tax law requires.
  • Technical logs — 90 days.

Text messages, opting out, and what STOP does

Every marketing message tells you how to stop. Replying STOP is honoured immediately and permanently for that restaurant, and recorded. You will still receive confirmations and reminders for bookings you actually make, because those are part of the booking, not marketing — if you do not want those either, tell the restaurant.

Replying CANCEL TABLE cancels your booking. It does not opt you out, and opting out does not cancel your booking. These are deliberately separate, because confusing them has real consequences at both ends.

Your rights

Under UK GDPR you can ask for access, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Where consent is the basis, you can withdraw it at any time without affecting what came before.

Ask the right party: for booking and guest data, ask the restaurant, who decides. For account data, ask us. Either way we respond within one month.

If you are unhappy with how we have handled it you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first, but it is your right either way.

Security

Data is encrypted in transit and at rest. Access between restaurants is separated at the database level, so one venue’s staff cannot read another’s guests even if the application has a bug. Billing fields can only be written by our payment webhook, never by a browser. Access to production data is limited to those who need it and is logged.

If a breach affects your data and is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell affected restaurants without undue delay.

Cookies

Eightish uses only what it needs to work: a session cookie so you stay signed in, and local storage on the host stand so it keeps working through a wifi drop. No advertising or third-party tracking cookies. Nothing that needs a consent banner, which is why there isn’t one.

Children

Eightish is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16 other than a name that may appear in a party size.

Changes

Material changes are emailed to account holders 30 days before they take effect, and the version and date at the top of this page always tell you which version you are reading.