Skip to content

Privacy Policy

How Saffron and Sage looks after your information. Last updated 7 August 2026.

Who we are

Saffron and Sage — 12 Welsh Back, Bristol BS1 4SP · 0117 946 0102 · hello@saffronandsage.co.uk.

For the purposes of UK data-protection law (UK GDPR and the Data Protection Act 2018), Saffron and Sage is the data controller for the personal information collected through this website. The site is built and operated on TableSpark (tablespark.uk), which acts as a data processor on our behalf and only on our instructions.

We are not required to appoint a Data Protection Officer — our processing is not large-scale monitoring, and a restaurant's records do not meet the threshold in Article 37. Data-protection questions go to the contact details above and are handled by the restaurant's management.

This policy covers this website. Anything separate — CCTV in the dining room, a paper booking diary, a till system, or a social media page — is handled under its own notice, and you can ask us about any of them.

The information we collect

We only collect what each service needs, when you choose to use it:

Booking a table — your name, phone number and/or email address, party size, the date and time, and anything you add in the notes (for example allergies, access needs or a special occasion).

Ordering food — your name and contact details, your order items, and for delivery your address; if you order at the table, the table number.

Joining the waitlist — your name, contact details and party size.

Newsletter — your email address (and name if you give one), stored with a record of your consent.

Enquiries, events and gift cards — the details you enter in the relevant form.

Securing a booking with a card — where we ask for a card to hold a booking or take a deposit, the card is collected and stored by our payment provider Stripe. The full card number never touches this website or our systems.

Technical basics — our hosting provider keeps short-lived security and delivery logs (such as IP addresses) to keep the site online and defend it from abuse.

We do not use your information for advertising, we do not build marketing profiles from your visits, and we never sell it.

Where your information comes from

Almost always from you, when you fill in a form on this site.

It can also reach us from our own team — if you book or order by phone or in person, a member of staff enters the same details for you.

And it can reach us through a booking or ordering link we publish elsewhere — for example a listing or a map profile that sends you here to finish the booking. In that case we receive only what you submitted on the way through, and the service you came from handles your data under its own privacy policy, not this one.

We do not buy contact lists, and we do not collect information about you from data brokers or social networks.

Do you have to give us this?

There is no legal obligation on you to give us anything. But some of it is needed for a booking or an order to exist at all:

Needed — a name and at least one way to contact you, plus the date, time and party size for a booking, or the items and collection/delivery details for an order. Without these we cannot hold a table or accept an order, because we would have no way to confirm it, change it or reach you if something goes wrong.

Optional — everything else: notes, occasion, dietary and access needs, and joining the newsletter. Leaving them blank does not affect your booking or order; it only means we know less about how to look after you.

Why we use it, and our lawful bases

To provide the service you asked for (taking, changing and honouring your booking or order; sending its confirmation and reminder) — this is performance of a contract.

To run the restaurant safely and well (knowing about allergies you tell us, keeping simple records of past bookings, preventing no-shows and fraud) — our legitimate interests, balanced against yours.

To send you news and offers — only with your consent, which you can withdraw at any time using the unsubscribe link in every email.

To meet legal obligations — for example keeping transaction records for tax purposes.

Allergies, health and access needs

When you tell us about an allergy, an intolerance, a medical diet or an access need, that is special category data under Article 9 of the UK GDPR — the law treats health information more strictly than a name or a phone number.

We rely on your explicit consent: you choose to tell us, in your own words, so that the kitchen and the floor team can keep you safe and seat you properly. You never have to — but if you do not tell us, we cannot take it into account.

We use it for that one purpose. It is passed to the kitchen and service team who need it for your visit, is never used for marketing, is never used to make decisions about you, and is removed or anonymised on the same timetable as the booking or order it belongs to. You can withdraw it at any time by asking us to delete it — though we would then no longer know about it for future visits.

Cookies

This site sets no advertising or cross-site tracking cookies. Essential storage keeps things like your cookie choice and order basket working; anonymous visit counting happens only if you choose Accept on the notice; and third-party content (maps, videos) stays blocked until you load it.

The full detail — exactly what is stored, for how long, and how to change your mind — is in our Cookie Policy at /p/cookies.

Payments

Card payments are processed by Stripe, a payment provider regulated for this purpose, and go directly to the restaurant's own Stripe account. We see the status of a payment (paid, refunded) and the booking or order it belongs to — never the full card number. Stripe's own privacy policy applies to the card details it holds.

The emails we send

Service emails (booking confirmations, reminders, waitlist and order updates) are sent because you used the matching service — they are part of providing it, and are delivered for us by Resend, an email provider acting as a processor.

Newsletter email is sent only to people who signed up, and every one includes a one-click unsubscribe link that works immediately, no login needed.

How long we keep information

Orders — contact details on orders are anonymised automatically after 24 months; the anonymous record keeps the restaurant's accounts accurate.

Bookings and waitlist entries — kept while they are useful for running the restaurant (for example recognising a returning guest), then removed or anonymised. You can ask for earlier deletion at any time.

Newsletter — until you unsubscribe; unsubscribing takes effect immediately.

Enquiries — kept while the restaurant is still dealing with them, deleted automatically 24 months after the restaurant marks them as handled, and in any case deleted 36 months after they were sent.

Who we share information with

We share personal information only with the providers that make this website work, each acting as a processor under contract:

TableSpark (tablespark.uk) — the platform this site runs on.

Cloudflare — hosting, content delivery and security.

Supabase — the database where bookings, orders and sign-ups are stored.

Stripe — card payments, deposits and booking guarantees.

Resend — sending the emails described above.

Beyond these, information leaves us only if the law requires it. No data is sold or shared for advertising.

Where your information lives

Data is stored and processed primarily in the UK and the European Economic Area. Some of the providers above are US companies whose processing may involve transfers outside the UK; where that happens it is covered by UK-approved safeguards such as the UK International Data Transfer Addendum or an adequacy arrangement.

How we keep it safe

Everything on this site travels over an encrypted connection (HTTPS), and the database behind it is access-controlled so that each restaurant's records are reachable only by that restaurant's own signed-in team.

Card numbers never reach us: they are entered directly into Stripe, so there is no card data on this website to lose. Staff accounts are individual, access is removed when someone leaves, and the platform keeps a record of significant changes.

No system is perfectly secure, and we will not pretend otherwise. If a breach ever put your rights or freedoms at risk, we would report it to the ICO within 72 hours and tell you without undue delay where the law requires it.

Children

This website is meant for adults booking and ordering, and is not directed at children. We do not knowingly collect information from anyone under 13, and we do not profile children or market to them.

Families are of course welcome at the restaurant — where a booking is for a family, we expect the adult making it to provide the details, including the number of children in the party. If you believe a child has given us information directly, tell us and we will delete it.

Your rights

UK data-protection law gives you the right to:

Access — a copy of the information we hold about you.
Rectification — correction of anything inaccurate.
Erasure — deletion of your information ("the right to be forgotten").
Restriction — limiting what we do with it while a question is resolved.
Portability — your information in a portable format.
Objection — to processing based on legitimate interests.

Do it yourself from your account — if you have signed in to this site's Your account page, you can email yourself a copy of everything we hold and delete your account there, without asking anyone. Deleting removes your name, contact details and notes; booking and order records stay as anonymous entries in the restaurant's accounts.
Withdrawing consent — at any time, where consent is the basis (for example the newsletter).
Not being subject to automated decisions — this site makes no automated decisions with legal or similar effect about you.

To exercise any of these, email us at hello@saffronandsage.co.uk, or use the form below. We respond within one month, free of charge.

Complaints

If you are unhappy with how we have handled your information, please tell us first — most concerns can be put right quickly. You also have the right to complain to the UK regulator: the Information Commissioner's Office (ICO) — ico.org.uk, or by phone on 0303 123 1113.

Changes to this policy

If how we handle information changes, this page changes with it, and the date at the top is updated. Significant changes will be flagged clearly on this page.

Your data, your call

Ask us to show or delete everything we hold about you. We will confirm by email once it is done.