Legal
Privacy Policy
Last updated: 30 September 2026
This policy explains what personal data Fork & Floor collects, why, and what you can do about it. Fork & Floor (“we”, “us”). You can contact us about privacy at privacy@forkandfloor.co.uk.
1. What we collect
When you sign up and use Fork & Floor
- Account details: whether it’s a Business or Individual Account and, for a Business Account, the business name.
- People: each person’s name, email address and role (the owner, or a role the owner sets up, such as Manager or Staff), and the names and permissions of those roles. In a Business Account, the owner and people whose role allows it add their own team members, and choose which of the business’s sites each person works at. An Individual Account has just its owner. One person can be in more than one account (their own, and businesses they’ve joined) with the same login: when a business adds an email address that already has a login, that person is invited, and only joins if they accept.
- Passwords: stored only as a one-way secure hash. We can’t see or recover your password.
- Account activity: when each person last signed in, when the person who signed up agreed to our terms, and failed sign-in attempts (used to lock an account briefly after repeated wrong passwords).
- Floorplans: the plans you create, including room sizes, table layouts, labels and zones, which site each belongs to, and which team member last saved each plan.
- Service mode: each table’s current status (reserved, seated, clearing, or a status your business adds), who set it and when, and, if your team enters them, a guest’s name, how many are in their party, whether they walked in, and notes on the party (birthday, high chair, VIP). This is shown to others in your account, and cleared from the table when the party leaves it.
- Allergy notes: if your team enters one at a table, a guest’s allergy note. This is health information, so it’s only shown to people whose role has the “Allergy notes” permission, it’s never copied into the day tracker or reports, and it’s deleted as soon as the party leaves the table, or a day after they sat down if the table isn’t cleared.
- The waiting list: parties waiting for a table: the name given, party size, notes, the wait they were quoted, when they were added and by whom. Each party is deleted as soon as they’re seated or taken off the list, and anyone still on it is deleted at the start of the next trading day.
- The day tracker: a record of each party seated (the table, party size, walk-in or not, when they sat down and left, who seated them, the table’s server section and server, and any guest name entered), used for your business’s reports. Guest names are removed from it after the number of days your business sets (30 unless changed; it can choose never to keep them); the rest is kept for as long as the account exists.
- Who’s on a plan: while you have a plan open, which plan it is, whether you’re designing or running service, and when your app last checked in (every few seconds). Others in your account see this, so they know who else is working on the plan. It’s only shown for 20 seconds after your last check-in, and cleared when you sign out.
- Custom items: items your team saves to the Custom list (names, sizes and similar settings), shared by everyone in the account.
- Version history: earlier versions of each plan, each with the name of the person who saved it and when, so your team can see what changed and put back an earlier version. A person’s name stays on the versions they saved even after they leave the team.
- The activity log: a record of changes made in the account (plans created, edited, deleted or moved; people added, removed or given another role; roles, sites and settings changed), each with the name of the person who made it and when, and for changes to people, the name of the person changed. It lets the owner and people whose role allows it see who changed what. Names stay on entries after people leave the team. Table statuses, guests and the waiting list aren’t in it.
Technical information
- Server logs: like most websites, our web server records requests, including IP address, browser type, the page requested and the time.
- Emails and links: we email you to confirm your email address when you sign up, when you ask to reset your password, when your password changes, and when a business adds you to its team, invites you, or gives you a temporary password. These emails contain one-use links; we keep a scrambled copy (a hash) of each link’s code, which email it went to, and when it was sent, used and expires, so a link only works once and for a limited time. We also record when you confirmed your email address. We don’t send marketing emails.
- Spam protection: the sign-up form uses Google reCAPTCHA, which collects information such as your IP address and browser details to check you’re a person (see section 3).
Plans shared by link
An account can send a read-only link to one of its floorplans to someone outside it, such as a landlord, contractor or licensing officer, who can open it without an account. If the link allows comments, commenting asks for your name and your comment, which the account that shared the plan can see, along with where on the plan you put it and when. To limit misuse we also keep a scrambled copy (a hash) of your IP address with each comment. The link’s creator is emailed when comments arrive. Your name is remembered in your browser so you don’t have to type it again. The plans shown by link never include table statuses, guests’ details or prices.
The demo
Plans you make in the demo stay in your own browser and are not sent to us. If you create a business from inside the demo, your demo plans are uploaded to your new business account.
2. How we use it
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service: accounts, sign-in, saving and syncing plans, team management | Account details, people, passwords, floorplans | Contract with the account holder |
| Sending account emails: confirming your email address, password resets and changes, and being added or invited to a team | Name, email address, business name, one-use link records | Contract with the account holder; legitimate interests (security) |
| Keeping accounts secure, e.g. temporary lockouts after wrong passwords | Account activity, server logs | Legitimate interests (security) |
| Preventing automated and spam sign-ups | reCAPTCHA data, server logs | Legitimate interests (preventing abuse) |
| Supporting customers and running the service: our platform administrators can see account details and team lists, and open floorplans read-only | Account details, people, floorplans; a log of which floorplans they opened and when | Legitimate interests (support, running and securing the service) |
| Showing plans shared by link, and passing on comments made through a link | The commenter’s name and comment, a hash of their IP address | Legitimate interests (of the account that shared the plan, and ours in preventing abuse) |
| Keeping a record that the terms were accepted | Terms acceptance time | Legitimate interests; legal obligations |
We don’t sell personal data, and we don’t use it for advertising.
For a business’s team members, the business decides who to add and is responsible for having the right to add them. If you’re a team member with a question about your account, you can ask your manager or contact us.
Guest names and party details that a business enters in service mode or on the waiting list are that business’s information about its own customers: the business decides what to enter and is responsible for it, and we store it on its behalf and use it only to provide the service. Allergy notes are health information, a special category of personal data: the business is responsible for having a lawful reason and condition for recording them, and for choosing which roles can see them; we limit who sees them and delete them automatically, as described above. If you were a guest and have a question about your details, please ask the restaurant or venue.
3. Who we share it with
- Google reCAPTCHA (Google LLC / Google Ireland Ltd), on the sign-up form only. Its use is subject to Google’s Privacy Policy and Terms of Service.
- Google Fonts, which serves the typefaces on our pages. Your browser requests the fonts from Google’s servers, which receive your IP address.
- MailerSend (MailerSend, Inc.), which sends our account emails on our behalf and so receives each recipient’s name and email address and the email itself.
- Our hosting provider, OVH Cloud, which stores the service’s data on our behalf.
- Authorities, where the law requires us to.
In a Business Account, everyone on the team can see its floorplans and their version history (including who saved each version), and the owner and people whose role allows them to manage the team can see its team list; the owner and people whose role allows it can see its activity log (for the sites they work at); everyone on the team can see the names of its roles. An Individual Account’s floorplans are visible only to its owner. Outside the account, only our own authorised staff who run Fork & Floor (platform administrators) can see its data: each account’s details and team list, and, to support customers and run the service, its floorplans, which they can open to look at but not change. Every floorplan they open is logged. Anyone the account sends a share link to can see the plans it shows, and the comments made through that link, until the account removes the link or it expires.
4. Cookies and browser storage
forkandfloor_session: a strictly necessary cookie that keeps you signed in. It is deleted when you close your browser, and a session ends after 12 hours without use.- Browser storage (localStorage): the app keeps a copy of your plans in your browser so it can work without a connection and upload changes later. The demo keeps its plans here too. Signing out clears your account’s copy from that browser. It also remembers your display choices (light or dark theme, metres or feet and inches, measurements shown or hidden, the furniture list folded or open, whether the device is used as a host stand) and anything you’ve copied with Copy, so you can paste it into another plan. In the demo, and when the app is opened from a file, the waiting list is kept here too.
- Service worker: so the app can be added to a tablet’s home screen as a host stand, the app installs a small script in your browser that shows a “you’re offline” page when there’s no connection. It doesn’t store any of your data.
- Share links: if you comment on a plan shared with you by link, the name you typed is kept in your browser for next time.
- Google reCAPTCHA may set or read its own cookies when the sign-up form is open.
We don’t use analytics or advertising cookies.
5. How long we keep it
- Account data, floorplans and custom items: for as long as the account exists. The owner can delete it at any time: from Business & team for a Business Account, or from Account for an Individual Account. This immediately deletes the account, its sites, every floorplan and all version history from our database, and the logins of its team members, except those who are also in another account: they keep their login for that account.
- Version history: the newest 100 versions of each plan. Older versions, and all versions of a deleted plan, are deleted.
- Share links and their comments: a link lasts until the account removes it or it expires; its comments stay with the plan until the account deletes them, or the plan or account is deleted.
- The activity log: one year, then each entry is deleted; all of it goes when the account is deleted.
- A single team member: deleted when the owner, or someone whose role allows it, removes them from the team (or when they leave it), unless they’re also in another account, in which case only their place in this business is removed. Their name stays on plan versions they saved, until those versions are deleted as above.
- Server logs: kept for 30 days.
- The log of floorplans our administrators opened (the administrator, the account’s name, the plan and when): kept for 90 days, including after the account is deleted, as a record of who looked at what.
- Backups: deleted data may remain in backups for up to 30 days before being overwritten.
6. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to how we use it, and receive a copy in a portable format. To use these rights, contact privacy@forkandfloor.co.uk. You can also complain to your data protection authority, for example UK Information Commissioner's Office.
7. Security
Connections to Fork & Floor are encrypted with HTTPS. Passwords are stored as secure hashes, repeated wrong passwords lock an account for a few minutes, and every business’s data is kept separate from every other business’s. No system is perfectly secure, so please use a strong password that you don’t use elsewhere.
8. Children, international transfers and changes
Fork & Floor is a business tool and isn’t intended for children under 16.
Google may process reCAPTCHA and font requests outside your country, including in the United States, under its own safeguards. MailerSend may process account emails in the United States and the EU
If we change this policy, we’ll update the date at the top. For significant changes we’ll let account owners know in advance.
Contact
Fork and Floor. Email: privacy@forkandfloor.co.uk.