Privacy
Last updated 30 June 2026 · BespokeWorks, London, United Kingdom
The short version
We store what is needed to run bookings and nothing more. We never sell personal data, we never use your customer list to market other businesses, and you can export or delete your data whenever you like.
If you run a business on TallyUp
We hold your account details (name, email, password hash), your venue’s settings, and the booking records your business creates. We are the data controller for this. We use it to provide the service, to tell you about material changes to it, and for nothing else without asking.
If you booked with a business that uses TallyUp
Your name, contact details and booking notes belong to the business you booked with; they are the controller and we process the data on their instructions. Notes you add (such as dietary needs) are shown to that business so they can look after you. If you want something corrected or removed, ask the business, or contact us and we will help.
Where data lives
Data is stored in a Postgres database on Google Cloud in the European Union, and the application is served from Google Cloud in Europe. Payments, where a business has switched them on, are handled by Stripe; card numbers never touch our servers. Transactional email is delivered by Resend using the minimum necessary details. Every company that can reach personal data is named on our sub-processors page.
If you run a business here, we are your processor
You decide what happens to your clients’ data and we carry it out, which makes you the controller and us the processor. UK GDPR requires that in writing, so it is: see our data processing agreement. It applies to every business on TallyUp automatically, with nothing to sign.
What we do not do
No selling of data. No advertising trackers on booking pages. No AI training on your customer lists. Our AI features (such as the booking concierge) read the venue’s live availability to answer a request; requests are rate-limited and logged with a hashed IP for abuse prevention.
Retention and deletion
Booking records are kept while the business account is active, because they are the business’s trading records. When an account closes we delete or irreversibly anonymise its data within 90 days, except where law requires longer.
Your rights
Under UK GDPR you can ask for access, correction, deletion, restriction or portability of your personal data, and you can complain to the ICO. Write to privacy@bespokeworks.ai and we will respond within a month.