Policy Overview
To deliver TableGreet's digital menu SaaS services, we engage third-party service providers ("Subprocessors") to assist in our data processing activities. Prior to engaging any subprocessor, we conduct thorough security and privacy reviews to ensure their practices align with our strict standards and applicable data protection regulations (including GDPR, UK GDPR, Saudi Arabia PDPL, UAE Federal Decree-Law No. 45 of 2021, and global standards).
This Directory lists all authorized subprocessors currently utilized by TableGreet LLC.
Subprocessors Directory
The following subprocessors process personal data on behalf of TableGreet:
| Subprocessor | Services Provided | Processing Location | Entity Location |
|---|---|---|---|
| Supabase, Inc. | Cloud database, authentication hosting, and secure data storage. | Ireland / United States | USA |
| Stripe, Inc. | Payment processing infrastructure, fraud prevention, and SaaS billing operations. | United States | USA |
| Cloudflare, Inc. | Content delivery network (CDN), DDoS prevention, SSL certificates, and application security shields. | Global Edge Locations | USA |
| Resend, Inc. / Twilio SendGrid | Transactional email delivery services (account activation, alerts, billing). | United States | USA |
| PostHog, Inc. | Product analytics, user behavioral telemetry, session replay, feature flag management, and controlled A/B testing with sensitive field masking. | United States | USA |
| Functional Software, Inc. (Sentry) | Application error tracking, performance latency monitoring, crash reporting, and diagnostics telemetry with automated PII sanitization. | United States | USA |
| Google LLC (Firebase Cloud Messaging) | Web push notification and mobile alert delivery to authenticated venue staff. FCM registration tokens are stored against user accounts. | United States | USA |
Modifications and Notifications
TableGreet updates this Subprocessor Directory as new vendors are engaged or current contracts expire. We will notify registered administrators of our customers in writing (including email) of any additions or replacements to our Subprocessor Directory at least 30 calendar days prior to authorizing the new subprocessor to process any personal data.
Customers may object to the engagement of a new subprocessor on reasonable grounds related to data protection within 14 calendar days of receiving notice, by contacting us: