Privacy policy
Last updated: 1 October 2026
1. Who we are
Match Table (“we”, “us”) operates the website at www.match-table.com. We connect football fans with sports bars and handle table bookings on behalf of venue owners. Contact us at info@match-table.com for any privacy-related matter.
2. Data we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, phone & party size | Fulfil your table booking and send confirmation / reminder emails | Contract performance (Art. 6(1)(b) GDPR) |
| Booking history | Allow you to manage or cancel bookings; admin diagnostics | Contract performance & legitimate interest |
| Your past no-shows at the bar you are booking | Let that bar see, when it decides on your request, how many earlier bookings with your email you did not turn up for there. Counts from other bars are never shown | Legitimate interest (Art. 6(1)(f) GDPR): protecting bars from repeated no-shows |
| Owner: name, email, business name, city, country | Create and manage your venue account | Contract performance |
| Owner: payment / billing info | Process subscription and featured placement payments | Contract performance |
| Anonymised analytics (page views, no cookies) | Understand how the site is used and improve it | Consent: analytics (Plausible, cookieless) loads only if you accept it |
| Error reports (IP address, browser, page URL, error details) | Find and fix errors on the site | Legitimate interest (Art. 6(1)(f) GDPR): keeping the booking service working |
| Session replays (how a page was used, with all text masked) | See what went wrong when a page breaks | Consent: recorded only if you accept analytics |
You can object to this no-show processing at any time by contacting info@match-table.com. We keep no-show counts for 24 months from the booking date, the same period we keep your other booking records (see Section 4), and older no-shows drop off automatically.
3. Who we share your data with
We share your booking details (name, email, phone, party size, date) with the bar you booked, to prepare for your visit. If you have missed earlier bookings at that same bar, the bar also sees how many, so it can decide on your request. We do not sell personal data.
We use the following processors under Data Processing Agreements. Two of them also act as independent data controllers for part of their own processing, noted next to each below:
- Supabase (Ireland): database and authentication hosting
- Vercel (Vercel Inc., US company; EU serverless region): web hosting, serverless functions, and privacy-friendly aggregated analytics (Vercel Analytics, cookieless)
- Stripe: payment processing for owner subscriptions. For its own compliance, fraud-prevention and regulatory checks (for example anti-money-laundering and know-your-customer screening), Stripe acts as an independent data controller rather than our processor
- Resend: transactional email delivery
- Plausible: cookieless, aggregated analytics, loaded only after you accept analytics and proxied through our own domain
- Sentry (Functional Software Inc., US): error monitoring and session replay, active only where configured. It receives your IP address, browser information, the page URL and error context. Replays run only if you accept analytics. They then record how a page was used on 10% of visits and on every visit that hits an error, with all text masked and all images and media blocked
- Slack: when a bar has opted in to booking notifications, your booking details are sent to that bar's own Slack workspace via a webhook
- Nominatim / OpenStreetMap: address search text is forwarded from our server, not your browser, to look up matching addresses; your IP address is not forwarded
- Cloudflare Turnstile: bot protection on our contact, group RSVP and season-follow forms; Cloudflare processes your IP address and browser signals
- Google AdSense (Google Ireland Ltd): shows and measures ads, loaded only after you accept advertising cookies. For AdSense ad-serving and measurement, Google acts as an independent data controller rather than our processor, and its own privacy policy governs that processing. If you click a sponsor's link, that partner's own privacy policy applies from then on
- Carto: map tiles shown on bar and match pages; your browser requests these tiles directly from Carto, so Carto sees your IP address
4. How long we keep your data
- Customer booking records: deleted 2 years after the booking date
- Owner account data: deleted 90 days after account closure
- Email logs (admin diagnostics): deleted after 1 year
- Payment records: retained 7 years for tax / legal obligations
- Consent records (the choice you made, when, and a hashed IP address): kept 3 years
5. Your rights (GDPR)
Under GDPR you have the right to:
- Access: request a copy of the data we hold about you
- Erasure: ask us to delete your personal data
- Portability: receive your data in a structured, machine-readable format
- Rectification: correct inaccurate data we hold
- Restriction / Objection: limit or object to processing
- Withdraw consent: at any time where processing is based on consent
Venue owners can delete their account, venues and associated data at any time from owner settings. To exercise any other right, use our data request form or email info@match-table.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (Ireland: Data Protection Commission, dataprotection.ie).
6. International transfers
Primary data storage is within the EU: Supabase (Ireland) and Vercel's EU serverless region. Some of our processors are companies based outside the EU/EEA. Where that is the case, transfers are safeguarded by Standard Contractual Clauses under Art. 46 GDPR: Vercel, Stripe, Resend, Sentry, Slack, Cloudflare and Carto.
7. Cookies
We use strictly necessary cookies (session authentication). With your consent we also load privacy-friendly analytics (Plausible, cookieless) and, where enabled, advertising cookies. You can change your choices any time via the Cookie settings link in the footer. See our cookie policy for full details.
We also record the consent choice itself (a timestamp, the choice you made, a hashed version of your IP address, and the policy version) so we can demonstrate compliance with Art. 7(3) GDPR. This consent record is kept for 3 years.
