tm
tablemenu
Legal

Subprocessors

Last updated: 2026-04-23 · Next review: 2026-07-15

Table Menu engages the following third-party service providers (subprocessors) to operate the platform. Each subprocessor has a contractual obligation to protect personal information at a standard comparable to Table Menu's own practices, consistent with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Principle 4.1.3.

Some subprocessors are located in the United States. Personal information transferred to these providers may be subject to access by US authorities under applicable US law. Table Menu mitigates this risk through data minimization, encryption in transit and at rest, and contractual safeguards with each provider.

This list is reviewed and updated on a quarterly basis. Operators are notified at least fourteen days before a new subprocessor begins processing personal information, or immediately if an existing subprocessor is replaced due to a security or compliance concern.

ProviderServiceData accessedLocationDPA
SupabaseDatabase, authentication, and file storageOperator and guest data including names, email addresses, order history, loyalty records, and phone numbersCanada (ca-central-1, primary) and United States (control plane)View DPA
StripePayment processing and subscription billingBilling information, payment method tokens, and transaction recordsUnited StatesView DPA
Stripe ConnectPayout processing for restaurant operatorsOperator bank account details, KYC identity documents, and payout historyUnited StatesView DPA
Clover / FiservOptional point-of-sale integrationOrder data and item-level transaction records for restaurants using Clover POSUnited StatesView DPA
TwilioSMS one-time passwords for guest phone verificationGuest phone numbers and SMS message content (OTP codes only, not retained)United States (Canadian carrier routing)View DPA
VercelApplication hosting and global content deliveryRequest and response data in transit; application logsUnited States (with global CDN edge nodes)View DPA
SentryError monitoring and performance tracingStack traces, request metadata, and anonymized user identifiers in error contextUnited StatesView DPA
Apple / PassKitApple Wallet loyalty pass issuanceGuest name (optional), loyalty tier, pass identifier, and device push tokenUnited States and global Apple infrastructureView DPA
Google WalletGoogle Wallet loyalty pass issuanceGuest name (optional), loyalty tier, and pass identifierUnited StatesView DPA
AnthropicAI-powered admin features (menu board design, text generation)Admin-submitted prompts containing menu and branding content (no guest data)United StatesView DPA
Google Gemini (Vertex AI)Menu board background image generationAdmin-submitted prompts containing menu descriptions and style instructions (no guest data)United StatesView DPA

Subprocessor change notification

Table Menu notifies affected restaurant operators by email at least fourteen (14) days before a new subprocessor begins processing personal information. If a subprocessor must be replaced urgently due to a security incident or service failure, notice is provided as soon as practicable and no later than the date the new subprocessor begins processing. This page is updated at the same time.

Questions

For questions about this subprocessor list or our data processing practices, contact privacy@tablemenu.app.