AlpineTable

AlpineTable

Privacy Notice

Effective 31 August 2026

AlpineTable is operated by Pedro Marques in Saint-Gervais-les-Bains, France. This notice explains how AlpineTable handles personal data for restaurant accounts, restaurant staff, guests making bookings, and visitors to the website.

Who controls your data

Pedro Marques, trading as AlpineTable, is the data controller for the AlpineTable website and platform. For privacy questions or rights requests, email hey@pedromarques.io.

Data we collect

We collect account identity and login data; restaurant profile, ownership-claim and operational data; booking and guest contact details; menus, photos and messages submitted to the service; integration activity; consent and email-delivery records; and technical information such as IP address, browser, referrer and security events.

Why we use it

We use data to create and secure accounts, verify restaurant ownership, provide restaurant pages and bookings, deliver transactional emails, operate requested integrations, prevent abuse, support users, improve the service, and meet legal obligations. Our legal bases are performance of a contract, legitimate interests in operating and protecting the service, consent where requested, and compliance with law.

Restaurant guest data

Restaurants use AlpineTable to manage their own guests. The restaurant decides why guest booking and CRM data is processed and is normally the controller for that data; AlpineTable acts as its processor. Restaurants must provide their own guest-facing notice and use marketing features only where they have a valid legal basis.

Service providers and transfers

We use service providers only where needed to run AlpineTable. These currently include Railway for application and database hosting, Resend for email, Cloudflare for image storage and bot protection, Roaarrr for consent-based website analytics, Anthropic and OpenAI for requested AI features, and Kapso, WhatsApp and Telegram for integrations a restaurant chooses to connect. Some providers may process data outside the EEA using applicable transfer safeguards.

Analytics and local storage

Optional Roaarrr analytics is disabled until a visitor accepts analytics in the privacy control. The choice is stored in the browser. Cloudflare Turnstile is used as an essential security measure on signup. It is not used for advertising.

Retention

We keep account and restaurant data while an account is active and as needed to provide the service. Verification tokens expire after 30 minutes. Security, audit, transaction and legal records may be retained longer where necessary. When a valid deletion request is completed, data is removed or anonymised unless law or another overriding obligation requires retention.

Your rights

Depending on your location, you may ask to access, correct, export, restrict, object to, or delete your personal data, and withdraw consent at any time. Email the address above. You may also complain to the French data-protection authority, the CNIL, or your local supervisory authority.

Security and account approval

Passwords are hashed. New restaurant listings remain private until email and restaurant-ownership checks are complete. No internet service can guarantee absolute security; please report suspected account misuse immediately.

Changes

We may update this notice as AlpineTable changes. Material changes will be shown on the service and the effective date above will be updated.

Read the Terms of Service

Privacy Notice | AlpineTable