Tablewide Privacy Policy
Last updated: October 1, 2026
This policy explains how Aaron Vontell, an individual doing business as Tablewide (a sole proprietorship based in New York, USA) ("we", "us") handles personal data in connection with Tablewide, our website at tablewide.com, and our support. We are a small US business. We collect little, we do not sell data, and we do not run ads.
1. Who this covers and our role
| Who you are | What we hold | Our role |
|---|---|---|
| Website visitor | Minimal technical data (Section 3.1) | Controller |
| Trial or customer contact (admin, billing contact, person who emails us) | Account, billing and support data (Sections 3.2–3.4) | Controller |
| User of a customer's workspace, or someone mentioned in its content | Sign-in data and whatever the customer puts in its workspace ("Customer Content") | Processor for our customer |
For Customer Content and workspace users, the customer (usually your employer) decides what is stored and why. We process it only on their instructions under our Data Processing Agreement. If you have questions or requests about that data, contact the customer first; if you contact us, we will pass your request to them.
Controller contact: Aaron Vontell d/b/a Tablewide, New York, NY, USA, privacy@tablewide.com. EU and UK representative: we have not appointed one. Contact us at privacy@tablewide.com.
2. What we do not collect
- Passwords. Users sign in with a Google or Microsoft account: usually their organisation's, but admins and invited guests may use a personal one. We never see or store passwords.
- Full card numbers. Link, a Stripe service, handles payments as the merchant of record. We see only the card brand, last four digits and expiry date.
- Tracking cookies or ad pixels. Our website and product have no advertising or cross-site tracking.
3. What we collect and why
3.1 Website visitors
- Cookieless visit counts. Our website records page views, the campaign or site that referred you, use of the price calculator, and sign-up form steps, in our own database hosted by Cloudflare. It uses no cookies, stores no IP addresses and builds no profiles of individuals. If you submit the founding sign-up form, we keep what you entered (name, work email, company, team size and answers) to reply to you.
Legal basis: legitimate interests (understanding which pages are useful), with minimal impact because no individual is identified. - Server logs. Our web servers record IP address, time, requested page and browser (user agent), for security and troubleshooting. Kept 30 days.
Legal basis: legitimate interests (keeping the site secure and working).
3.2 Account data (trial and customer contacts, workspace users)
When someone signs in, their identity provider (Google or Microsoft) sends us their name, email address, a user identifier, and organisation/tenant identifier, and, if provided, a profile picture. We use this to create and secure the account, recognise the user on sign-in, and send service emails (for example trial reminders, billing and security notices). Legal basis: for customer contacts, performance of our contract with the customer and our legitimate interest in running the account; for workspace users, we act as processor for the customer.
3.3 Billing data
Company name, billing contact name and email, billing address, VAT or tax ID, plan and payment history. Link, a Stripe service, sells you the subscription as merchant of record and collects card details directly. For the payment itself, Link handles your data under its own privacy policy as a separate controller; it shares the billing data above with us so we can run your account. Legal basis: performance of contract; legal obligation (tax and accounting records).
3.4 Support and communications
Emails and tickets you send us, including anything you attach. Please do not send passwords or sensitive data. Legal basis: performance of contract; legitimate interests (helping people who contact us).
3.5 Service operation data
Usage and technical data about workspaces (storage used, errors, performance, access logs with IP address and user agent). Legal basis: legitimate interests (operating and securing the Service); for data inside a workspace, as processor.
3.6 Customer Content
Pages, diagrams, files and comments in a workspace. We host it for the customer and access it only to operate the Service, to perform a migration or support request the customer asked for, or where the law requires. We do not use it for marketing, analytics profiling or AI model training.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on anyone.
4. AI operators
We run much of our business with AI agents (currently Claude, a commercial AI service from Anthropic, PBC), supervised by a human. We want you to know this plainly.
- What AI agents do: answer support emails, carry out migrations, and help operate the infrastructure.
- Customer Content: AI agents access Customer Content only when needed for a migration or support request the customer asked for, and only the content that request needs.
- EU region: only if the customer consents for that specific request (for example by confirming in the ticket). Without consent, the request is handled without AI access to Customer Content.
- US region: the customer can ask for any request to be handled without AI access to Customer Content.
- Support emails: messages you send to our support address may be read and drafted replies written by an AI agent, supervised by a human. If you are writing about an EU-region workspace, do not paste Customer Content into an email unless you are happy for it to be processed this way; the consent rule above applies to access to your workspace.
- Safeguards: AI agents cannot delete customer data or backups without human approval, their actions on our systems are logged, and data sent to the AI provider is not used to train its models under our commercial terms with it, and the provider keeps it only for a limited period under those terms.
- Location: the AI provider processes data in the United States (see Section 7).
5. Sharing
We share personal data only with:
- Subprocessors and service providers that help us run the Service (hosting, backup storage, payments, email, support inbox, AI operators). They are listed, with purpose and location, at subprocessors (tablewide.com/subprocessors), and are bound by contract to protect the data and use it only for us.
- Professional advisers (lawyers, accountants) under confidentiality.
- Authorities, when the law requires it. We will challenge overbroad requests and, where allowed, tell the affected customer first.
- A buyer or successor, if our business is sold or merged, under this policy's protections. We will give notice.
We do not sell personal data and do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA. We have not done so in the past 12 months.
6. Retention
| Data | How long |
|---|---|
| Customer Content and workspace user data | For the subscription; then 30 days export-only; then deleted within a further 30 days. Backups roll off within 30 days after deletion |
| Trial workspaces not converted | Self-serve trials: deleted within 60 days after the trial ends. Free migration previews: deleted automatically 7 days after creation, or at the end of any extension we agree in writing (no more than 30 days after creation). Backups roll off within 30 days after deletion |
| Account contact data (admins) | For the subscription, plus up to 12 months for account questions and disputes |
| Billing and invoice records | 7 years, to meet US tax and accounting record rules |
| Support emails | 2 years after the ticket is closed, or sooner if you ask and we have no legal reason to keep them |
| Web and application access logs | 30 days |
| Admin/audit logs of our own systems | 90 days |
| Founding sign-up form entries | Until you ask us to delete them, or 12 months after our last contact |
| Website visit counts | No personal data; kept indefinitely |
| Migration source exports you send us | Deleted within 30 days after the migration is complete |
7. Where data is stored and international transfers
- Customer Content stays in the customer's region, which is the US by default, with the EU on request: EU region (Germany and/or Finland, with backups in the EU) or US region (United States).
- We are a US company. Account, billing and support data is processed in the United States, and some service providers (Stripe and Link, email, support inbox, AI provider) are in the United States.
- EU-region Customer Content leaves the EU only when (a) our supervisory staff access it remotely to operate the Service, or (b) the customer consents to AI-assisted handling of a specific request. It is never moved to the US for storage.
- For transfers of personal data from the EEA, UK or Switzerland to the US, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss amendments), and, where a provider is certified, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You can ask us for a copy of the relevant safeguards at privacy@tablewide.com.
8. Your rights
8.1 EEA, UK and Switzerland
Where we are controller, you can ask us to: access your data; correct it; delete it; restrict or object to processing (including processing based on legitimate interests); and receive your data in a portable format. Where we rely on consent, you can withdraw it at any time. You can complain to your local data protection authority, though we would appreciate the chance to help first.
8.2 United States (CCPA and other state laws)
State privacy laws such as the California Consumer Privacy Act apply to businesses above certain size or data-volume thresholds. As a small company we likely do not meet them yet. We honour the following requests anyway, for anyone, wherever they live: to know what personal data we hold about you and how we use it; to get a copy; to correct it; and to delete it. We do not sell or share personal data, so there is nothing to opt out of, and we do not use sensitive personal information to infer characteristics. We will not treat you differently for making a request. You may use an authorised agent; we may ask for proof of authorisation.
8.3 How to make a request
Email privacy@tablewide.com. We will verify your identity (usually by confirming you control the email address on file) and reply within 30 days (45 days where US law allows, if we tell you we need more time). If the request is about Customer Content held for your employer or another customer, we will forward it to that customer, as their processor.
9. Security
We protect data with: a separate container and database per customer; encryption in transit (TLS); nightly encrypted backups with a separate key per customer; servers in our hosting provider's secured data centres; multi-factor authentication on all administrative accounts; least-privilege access; logging; regular patching; and monthly restore tests. AI agents cannot delete customer data or backups without human approval. More detail is in our security overview. No system is perfectly secure; if we have a breach affecting your data, we will notify as the law and our contracts require.
10. Children
Tablewide is a business service. It is not directed to children, and we do not knowingly collect data from anyone under 16. Our terms prohibit customers from storing children's personal data in the Service. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We will post changes here with a new "Last updated" date. For material changes we will email customer admins at least 30 days before they take effect, unless a change is required sooner by law.
12. Contact
Aaron Vontell d/b/a Tablewide New York, NY, USA (postal address on request) privacy@tablewide.com