Privacy Policy
Last updated: July 24, 2026
Tade ("Tade," "we," "us," or "our") provides a reservation management platform for restaurants. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the choices and rights you have. It applies to our website, our customer-facing reservation pages, and our applications for restaurant staff (together, the "Services").
We act in two roles. For restaurant operators who sign up to use Tade, we handle their account information directly. For guests who make reservations or join a waitlist at a restaurant using Tade, we process their information on behalf of that restaurant so the restaurant can manage its bookings. If you are a guest and wish to access or delete information held by a specific restaurant, we will help direct your request to that restaurant.
Tade is operated by Taehyung Kim (a sole proprietorship operating as "Tade"), based in Vancouver, British Columbia, Canada. You can reach us at admin@thetade.com.
1. Information We Collect
Information from restaurant operators (our customers)
- Account details — name and email address used to create and sign in to your Tade account (including when you sign in with Google).
- Restaurant details — business name, contact information, hours, floor plan, table configuration, photos, and similar settings you enter.
- Billing information — subscription and payment details processed through our payment provider. We do not store full card numbers; we retain only limited details such as the last four digits to identify your payment method.
Information about guests (collected on behalf of restaurants)
- Contact details — name, phone number, and email address provided when making a reservation or joining a waitlist.
- Reservation details — party size, date and time, status, and any notes a guest or the restaurant adds to a booking (which may include preferences such as allergies or seating requests).
- Visit history — records associated with a guest at a restaurant, such as past or upcoming reservations and visit or no-show counts, used by the restaurant to manage its service.
Information collected automatically
- Essential technical data — to keep you signed in and to operate the Services securely, we store a sign-in token on your device (in your browser's local storage or your device's secure storage). This is required for the Services to function.
- Basic log data — our servers may record limited technical information such as IP address and request times for security, troubleshooting, and to prevent abuse.
We do not use advertising or third-party analytics or tracking cookies. We do not build advertising profiles, and we do not sell or share personal information for cross-context behavioral advertising. If this changes in the future, we will update this Policy before doing so.
2. How We Use Information
We use personal information only for the purposes described below:
- To provide, operate, and maintain the Services, including creating accounts, authenticating sign-in, and managing reservations and waitlists.
- To send transactional messages on a restaurant's behalf — reservation confirmations, changes, cancellations, and reminders by email; and waitlist status alerts (plus reservation texts for bookings a restaurant's staff create) by SMS, where a restaurant enables texting and the guest has consented.
- To process subscription billing for restaurant operators.
- To secure the Services, prevent fraud and abuse, and troubleshoot problems.
- To comply with legal obligations and enforce our terms.
We collect and use only the information reasonably necessary for these purposes, and we do not use it for unrelated purposes without your consent.
3. How We Share Information
We do not sell personal information. We share it only as needed to run the Services:
- With the relevant restaurant — guest reservation information is made available to the restaurant the guest booked with, so it can manage the booking.
- With service providers who process information on our behalf, under contract and only for the purposes we specify:
| Email delivery (Resend, United States) | Sending transactional emails (reservation confirmations, changes, cancellations, and reminders). Receives the guest's email address and the message contents. |
| SMS delivery (Twilio, United States) | Sending transactional text messages for waitlist status and for staff-created bookings, where enabled and consented to. Receives the guest's phone number and the message contents. |
| Maps & address lookup (Google Maps Platform, United States) | Address autocomplete and geocoding for a restaurant's own address during setup. Receives the address text a restaurant enters (not guest information). |
| Sign-in (Google, United States) | Authenticating a restaurant operator's account sign-in when they choose "Continue with Google". Receives the sign-in token issued by Google. |
| Hosting & database (Railway, United States) | Operating our servers and database. Stores the Service's data, including the personal information described in this Policy. |
| DNS & network security (Cloudflare) | Domain name resolution and edge network/security for our web addresses; handles the routing of web requests to our Services. |
| Payment processor (Stripe, United States) | Processing restaurant subscription payments, where subscription billing is enabled. |
- For legal reasons — if required by law, regulation, legal process, or to protect the rights, safety, or property of Tade, our users, or others.
- In a business transfer — if Tade is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
4. Text Message (SMS) Notifications
Where a restaurant enables text messaging, Tade sends transactional SMS text messages on the restaurant's behalf, and each message identifies the restaurant. Texts are limited to two situations: (a) waitlist status — such as a "table ready" alert — for guests who join a restaurant's waitlist, and (b) reservation messages (confirmation, changes, cancellation) for bookings that a restaurant's staff create on a guest's behalf and for which the staff recorded the guest's consent. Guests who book online themselves do not receive reservation texts — those bookings are handled by email only. We send texts only where consent applies:
- Waitlist — joining a restaurant's waitlist online requires a phone number, and by joining you agree to receive waitlist status texts (such as a "table ready" alert) at that number. The join form states this before you submit. You can reply STOP at any time to opt out (you will then no longer receive texts and can track your status on the waitlist web page instead).
- Staff-created bookings — if a restaurant's staff create a reservation for you (for example, when you book by phone or in person), they may ask for your consent to receive reservation texts and record it. If no consent is recorded, we do not send texts.
- Online reservations — when you book online yourself, we do not send reservation texts; your confirmation and any changes are sent by email.
Message frequency varies with your waitlist or booking activity — typically a small number of messages per visit. Message and data rates may apply. Consent to receive SMS is not a condition of any purchase. Reply STOP to opt out at any time, or HELP for help. You may also contact the restaurant or reach us at admin@thetade.com.
We do not send marketing or promotional text messages. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
5. Data Stored Outside Canada
Tade is based in Canada, but our hosting and database provider (Railway) and several of our service providers — including Twilio (SMS), Resend (email), Stripe (payments), and Google (sign-in and address lookup) — are located in the United States. This means your personal information may be stored and processed in the United States. In particular, when a text message is sent, the recipient's phone number is transmitted to Twilio in the United States, and the data we store is held with our hosting provider in the United States.
When personal information is handled outside Canada, it is subject to the laws of that country, and may be accessible to courts, law enforcement, and authorities there. We require our service providers to protect personal information with safeguards comparable to those we use, through our agreements with them.
6. How We Protect Information
We use reasonable administrative, technical, and physical safeguards designed to protect personal information against loss, theft, and unauthorized access, use, or disclosure. These include encryption of data in transit, hashing of passwords, restricted access to data, and account protections such as authentication controls. No method of transmission or storage is completely secure, but we work to protect your information and to maintain its accuracy.
7. How Long We Keep Information
We retain personal information only for as long as it is needed for the purposes described in this Policy. In general:
- Restaurant account information is kept while the account is active and for a reasonable period afterward.
- Guest reservation information is kept while the associated restaurant maintains its account and uses it to manage bookings and guest history, after which it may be deleted or anonymized.
- We may retain certain information longer where required to comply with legal, accounting, or security obligations, or to resolve disputes.
When information is no longer required, we take reasonable steps to securely delete or anonymize it.
8. Your Privacy Rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you and learn how it is used and disclosed.
- Correct information that is inaccurate or incomplete.
- Withdraw consent or opt out of communications (note that some withdrawals may limit our ability to provide the Services).
- Delete your personal information, subject to legal retention requirements.
- Challenge our compliance with this Policy or applicable privacy law.
To exercise any of these rights, contact us at admin@thetade.com. We will respond within the time required by applicable law. If you are a guest, some requests may need to be directed to the restaurant you booked with, and we will help facilitate this.
For California residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and how we use it, the right to delete personal information, the right to correct inaccurate information, and the right to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights. To make a request, contact us at admin@thetade.com.
9. Consent
By using the Services or providing your information, you consent to the collection, use, and disclosure of your personal information as described in this Policy. For sensitive information or new purposes, we will seek your consent as required by law. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting us.
10. Children's Privacy
The Services are intended for restaurants and adult guests. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, provide additional notice. We encourage you to review this Policy periodically.
12. Contact Us
If you have questions about this Privacy Policy or how we handle personal information, or to exercise your privacy rights, please contact our privacy contact:
Tade — Privacy
Email: admin@thetade.com
If you are in Canada and have an unresolved privacy concern, you may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
