Privacy Notice
How Thezi handles information about the people who run venues on it, and about visitors to this website.
If you are a diner who has booked a table at a restaurant using Thezi, this is not the notice you want. The restaurant is responsible for your booking information, not us. See the Diner Privacy Notice on the booking page.
Who we are
Datatreehaus, a sole trader business established in England and Wales. Thezi is our product.
For any question about your information, or to exercise any right below, contact hello@thezi.app. The name of the sole trader behind Datatreehaus and our full postal address are available on request from the same address.
When we are responsible, and when the venue is
- Your staff account, and this website. We decide what is collected and why. We are the controller and this notice applies.
- Diner booking data at a venue. The venue decides. They are the controller and we act on their instructions as their processor, under a Data Processing Agreement. Our handling of that data is described in the DPA, not here.
What we collect about you
If you create an account:
- Your name and email address
- A password, stored only as a one-way hash — we never hold the password itself and cannot tell you what it is
- If you sign in with Google, the identifier Google gives us for your account and the email address on it
- Records of your sign-ins and active sessions
- A record of every change you make to your venue's data, identifying your account and whether the change came from a person or from software acting under a key you issued
- The name, timestamp, IP address and document version recorded when you accept our terms
If you only visit the website, we collect page views, referrer and country through Cloudflare Web Analytics. It sets no cookies and does not identify you, which is why this site has no cookie banner.
Why we use it
- To provide the Services, which is necessary to perform our contract with you.
- To keep the platform secure and accountable — rate limiting, session management and the audit trail — on the basis of our legitimate interest in operating a service that can be reviewed and, where necessary, reversed.
- To contact you about your account: confirming your email address, resetting a password, and telling you about changes to the Services or to these documents. That is contractual and, for the security-related messages, a legal obligation.
- To prove what was agreed, on the basis of our legitimate interest in keeping evidence of a contract.
- To understand how the website is used, on the basis of our legitimate interest in improving it, using analytics that cannot identify you.
We do not use your information for advertising, we do not profile you, and we do not sell or share it with anyone for marketing.
Who it is shared with
- Cloudflare, Inc., which hosts the platform, stores its database and sends its email. Data is held in Cloudflare's Western Europe (London) region.
- Google, only if you choose to sign in with Google, and only to verify that sign-in.
- Anyone we are legally required to disclose to.
That is the whole list. There are no advertising networks, no data brokers, and no third-party trackers on any page we serve.
Where it is stored
In the UK and Western Europe, on Cloudflare infrastructure. We do not transfer it outside the UK.
How long we keep it
- Your account and its data: for as long as your account is open. If you close it, we delete or return your venue's data as described in clause 6.5 of the Terms of Service and clause 8 of the DPA.
- Sign-in and session records: sessions expire and are removed; sign-in records are kept for up to 12 months for security purposes.
- The audit trail: for the life of the account, because its purpose is to show what happened over time.
- Acceptance records: for the term of the agreement and six years afterwards, which is the ordinary limitation period for a contract claim.
Cookies
We set one cookie when you sign in, which keeps you signed in, plus a short-lived one during a Google sign-in to prevent the sign-in being tampered with. Both are strictly necessary and neither tracks you. We use no analytics or advertising cookies anywhere.
Your rights
You have the right to ask for a copy of your information, to have it corrected or deleted, to object to or restrict how we use it, to withdraw consent where we rely on it, and to receive it in a portable format. Write to hello@thezi.app and we will respond within one month.
If you are not satisfied with our response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.
Changes
If this notice changes we will publish the updated version here. Where a change is material we will tell account holders by email.
Last updated: 10 September 2026