01

Policy Overview

To deliver TableGreet's digital menu SaaS services, we engage third-party service providers ("Subprocessors") to assist in our data processing activities. Prior to engaging any subprocessor, we conduct thorough security and privacy reviews to ensure their practices align with our strict standards and applicable data protection regulations (including GDPR and Moroccan Law No. 09-08).

This Directory lists all authorized subprocessors currently utilized by TableGreet LLC.

02

Subprocessors Directory

The following subprocessors process personal data on behalf of TableGreet:

Subprocessor Services Provided Processing Location Entity Location
Supabase, Inc. Cloud database, authentication hosting, and secure data storage. Ireland / United States USA
Stripe, Inc. Payment processing infrastructure, fraud prevention, and SaaS billing operations. United States USA
Cloudflare, Inc. Content delivery network (CDN), DDoS prevention, SSL certificates, and application security shields. Global Edge Locations USA
Resend, Inc. / Twilio SendGrid Transactional email delivery services (account activation, alerts, billing). United States USA
Google LLC (Firebase Analytics) Product usage analytics and conversion tracking. Processes aggregated, anonymised event data only. No diner data is sent to this service. United States USA
Google LLC (Firebase Performance Monitoring) Application performance telemetry — page load times, API response latency traces. Data is aggregated and pseudonymised. United States USA
Google LLC (Firebase Remote Config & A/B Testing) Feature flag delivery and controlled product experiments. Variant assignments are linked to session identifiers only, not individual user profiles. United States USA
Google LLC (Firebase Cloud Messaging) Browser push notification delivery to authenticated venue staff. FCM registration tokens are stored against user accounts. Message payloads are not retained by Google after delivery. United States USA
Google LLC (Firebase App Check / reCAPTCHA) API integrity verification to prevent automated abuse. Processes device attestation signals via reCAPTCHA Enterprise to issue short-lived app check tokens. United States USA
03

Modifications and Notifications

TableGreet updates this Subprocessor Directory as new vendors are engaged or current contracts expire. We will notify registered administrators of our customers in writing (including email) of any additions or replacements to our Subprocessor Directory at least 30 calendar days prior to authorizing the new subprocessor to process any personal data.

Customers may object to the engagement of a new subprocessor on reasonable grounds related to data protection within 14 calendar days of receiving notice, by contacting us:

TableGreet LLC, Legal Department

Subject: Subprocessor Objection

Contact: legal@tablegreet.com