Privacy

Privacy

The short version: we collect the least we can get away with, your table data is only visible to the people at your table, and reports are confidential.

Last updated 30 August 2026

What we collect

Only what the product needs to work.

  • Your account: email address and the display name you choose.
  • A confirmation that you are 18 or over — the date you confirmed it, not your date of birth. We never ask for identity documents.
  • What you write: table titles and descriptions, table chat messages, reservation notes, reports you file.
  • What you do: which tables you joined or left, and when — this is what makes seat counts and notifications truthful.
  • Basic technical data needed to serve and secure the site.

What we do not collect

No date of birth, no government ID, no phone number, no payment details, no precise location tracking, no advertising or cross-site tracking profiles. We do not sell personal information.

Who can see what

  • Public: a table's title, description, restaurant, time, seat counts and diners' first initials.
  • Diners at that table: table chat, reservation details and each other's display names — only from the moment they joined, and not after they leave.
  • Only you: your email address and your notification settings.
  • Our safety team: reports, and the table and account context needed to act on them.

Reports are confidential

When you report someone, your name is never shown to the person you reported. Reports are readable only by our safety team, enforced by the database itself rather than by hiding a page.

Table chat has a lifespan

Chat opens when a table reaches its minimum, stops accepting new messages shortly after the meal, and stops being viewable after that. You cannot read messages sent before you joined or after you left.

Email

We use your email address for account and security messages, such as confirming your address and resetting your password — those are not optional. Notifications about your tables are optional and you control them in your notification settings, or by using the unsubscribe link in any of those emails.

Where your data lives

ToShareAMeal runs on Lovable Cloud, which stores data using Supabase and Cloudflare infrastructure. Access is restricted by row-level security rules so that one diner's data is not reachable from another diner's session.

How long we keep it

Account data is kept while your account exists. Table chat expires on the schedule above. Reports and moderation records are kept longer, because a safety history is only useful if it persists. Ask us to close your account and we will remove your profile and personal data, keeping only what we must for safety and legal reasons.

Your choices

  • See or correct your profile from your account.
  • Turn optional notification email off, per type or all at once.
  • Ask for a copy of your data, or ask us to delete it: hello@tosharameal.com.
  • Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.

Children

ToShareAMeal is for adults. It is not intended for anyone under 18, and we remove accounts we learn belong to minors.

Contact

Privacy questions: hello@tosharameal.com. Safety concerns: safety@tosharameal.com.

This notice describes the data the product actually stores today. It is pending review by ToShareAMeal's legal counsel before public launch, including the regional rights wording.