Privacy Policy
Seating a table well needs to know things about you — what you cannot eat, what you speak, who you would sit with again. So this policy is specific. It lists every field we hold, why we hold it, and the short list of companies that touch it. It also lists what we deliberately do not collect, because that list is unusually short for a service like this: no analytics, no advertising, no tracking, and not even your IP address.
Effective date · [EFFECTIVE DATE]
Who is responsible for your data
Cityfolk is the service. RAGE AGENCY LTD is the company behind it, and the controller of the personal data described here — a private limited company registered in England and Wales, company number 16311448, registered office [REGISTERED OFFICE — TO BE FILED].
Privacy questions, access requests and deletions go to [DPO OR PRIVACY CONTACT].
Because the controller is established in the United Kingdom, the UK GDPR and the Data Protection Act 2018 are the primary regime for everything below. Two others apply on top of it, because of where our members are:
- If you are in the EU or EEA, the EU GDPR applies to you, since we offer this service to people there.
- If you are in Switzerland — and most members are, because Zurich is the live city — the revised Federal Act on Data Protection (revDSG) applies to you for the same reason.
The rights in section 07 are written so that they hold under all three. Where one regime gives you more, you get the more.
What we collect
Everything below is either something you typed in or something the act of booking a seat produced. We do not buy data, and we do not enrich your profile from other sources.
Your account
- Email address and password. The password is stored as a scrypt hash — we cannot read it, and neither can anyone who takes a copy of the database.
- Your name, the city you joined, and the date you joined.
- Your role (member or admin), your plan, and your membership status: active, paused or cancelled.
- Your date of birth. We ask for it to enforce the 18+ rule and nothing else. Your age is worked out at the moment of the check and is never written down. The date cannot be changed once given.
- The blurb shown next to your name on a guest list, and how many guest passes you hold.
Seating you well
- Your diet: none, vegetarian, vegan, pescatarian, halal or kosher.
- Your allergies, as a list, plus a free-text note if you want to explain them.
- The languages you speak and the language you would prefer your table to be in.
- Your spend level: modest, middling or generous.
- Your profession.
- Your country of origin, chosen from a fixed list on which "prefer not to say" is one of the options.
Your nights
- Every booking: which sitting, and whether you joined, waitlisted, attended, did not turn up, or cancelled.
- Your position on a waitlist while you are on one.
- Whether a booking recorded a strike, under the rule in the terms.
- The hearts you gave a night after it happened.
- Table likes: when you say you would sit with someone again. A one-way like is never shown to the other person, and never will be. When both of you have said it, it becomes an introduction on both sides — and an introduction exchanges email addresses. Section 05 sets out exactly what that means, because it is the one place where the platform gives another member a way to reach you off it.
Getting here and asking for more
- Your referral code, who referred you, and whether that person has had their reward.
- If your city is not open yet: the name, email, city and referrer you gave the waiting list.
- Table proposals: the free-text suggestion of a place and a night you sent us.
What we do not collect
This is a complete statement, not a summary.
- No IP addresses. We do not log them, store them or process them. Sign-in throttling — the thing that stops somebody guessing at your password — counts failed attempts against the account, in the memory of the running process, not against a network address. It is deliberately built so that no address has to be kept.
- No user agent, no device fingerprint, no location beyond the city you chose.
- No analytics. No Google Analytics, no Plausible, no product analytics, no session recording, no heatmaps.
- No advertising. No Meta pixel, no Google tag, no conversion tracking, no remarketing lists.
- No third-party embeds loading from somebody else's server, and nothing written to localStorage to follow you around.
- No card details. We have not connected a payment processor, so there is no card number, no billing address and no payment history on our side. Membership fees are settled with us directly, outside the platform.
- No marketing email. Our email provider sends sign-in and account mail. It sends nothing else, and there is no mailing list to be on.
We do not sell your personal data, and we never have. We do not share it for cross-context behavioural advertising. There is no arrangement under which anybody pays us, in money or in kind, for information about our members.
Why we use it, and on what legal basis
- Running your account and signing you in — email, password hash, name, role, status. Basis: performing our contract with you.
- Taking a booking, holding a waitlist place, seating a table — bookings, waitlist position, plan, city, languages and preferred table language, spend level, profession, country of origin. Basis: performing our contract with you.
- Keeping under-18s out — date of birth. Basis: our legitimate interest in an adults-only club, and the age rules that apply to serving dinner and drink at the venues we use.
- Cooking to your requirements — diet, allergies, allergy note. Basis: your explicit consent. These say something about your health, and for halal and kosher about your beliefs.
- Applying the strike rule and suspending accounts — bookings, attendance, strike flags. Basis: performing our contract, and our legitimate interest in a table where people turn up.
- Introducing two people who both said yes — table likes, and the name, email address and blurb that the introduction exchanges. Basis: your consent, given at the moment you like someone back. We do not rest this one on a general clause in the terms, because it is the only thing on Cityfolk that hands your email address to another member. You are told what a mutual like does before you do it, and doing it anyway is the consent.
- Paying out a referral — referral code, who referred you, reward status. Basis: performing our contract.
- Sending sign-in and account email — your email address. Basis: performing our contract.
- Stopping password guessing — a count of failed attempts against the account, held in memory only. Basis: our legitimate interest in keeping accounts secure.
- Keeping the books — records of what was owed and paid. Basis: our legal obligations as a UK company, under the Companies Act 2006 and HMRC's record-keeping rules.
Diet, allergies, an allergy note and country of origin are the sensitive fields — special category data under the UK and EU GDPR, sensitive personal data under the revDSG. You give them because you want the kitchen and the table to work, and you can withdraw them: clear the field, or ask us to. Clearing an allergy means the kitchen stops cooking to it, so tell us on the night if it still matters.
"Prefer not to say" on country of origin is a real answer. Choosing it costs you nothing.
Who else sees it
The venue. Before a sitting we send the venue what it needs to cook and seat: the number of people, the names on the table, and the dietary requirements, allergies and allergy notes for that sitting. Venues are independent businesses in Zurich and are responsible for what they do with it under their own agreement with us.
Other members, on a guest list. The people booked onto the same sitting see your name and your blurb. Nothing else from your profile is shown to them — not your languages, not your profession, not your spend level, not your diet, not your country of origin. A one-way table like is shown to nobody.
Other members, through an introduction. This is the one exception, and it is worth reading twice.
A table like on its own goes nowhere. When the other person likes you back, the introduction is made on both sides, and what each of you receives is the other's name, email address and blurb. Your email address is a direct identifier and a way to reach you away from Cityfolk, so:
- It happens automatically, the instant the second like lands. No screen asks you to confirm, because you already said yes by liking.
- It cannot be recalled. Once an address is in somebody's inbox, it is out of our hands — we cannot delete it, and neither can you.
- Deleting the like afterwards removes our record of it. It does not take the address back. Nothing can.
- What the other person does with it is between you and them. Our terms forbid using Cityfolk to sell to, recruit or harass people, and that applies to a message sent after an introduction as much as to anything said at the table. Tell us at [DPO OR PRIVACY CONTACT] if somebody misuses it.
If you would rather not hand out your address, do not like people back. That is the whole of the control, and it is entirely yours.
Our processors. Two companies process data on our instructions:
- [SMTP PROVIDER], which delivers sign-in and account email. It handles your email address and the contents of those messages.
- A cloud PostgreSQL host running in [DATABASE HOST REGION], which runs the database everything above is stored in.
We have data processing agreements with both. Neither may use your data for their own purposes.
Nobody else, except where the law or a court requires it, or where we need advice from our lawyers or accountants, or if the business is sold — in which case we would tell you before your data moved.
Sending data across borders
The company that decides what happens to your data is in the United Kingdom, and your data is processed there. If you are in Switzerland or the EEA, that is a transfer out of your country, so here is the basis for it.
- From the EEA to the UK: the European Commission's adequacy decision for the United Kingdom. It means the UK is treated as offering an equivalent level of protection, and no extra contract is needed for the transfer itself.
- From Switzerland to the UK: the Swiss Federal Council recognises the United Kingdom as providing adequate protection, on the list kept under the revDSG.
Where a processor sits outside the UK, the EEA and Switzerland, we rely on an adequacy decision for that country if one exists, and on standard contractual clauses — with the UK addendum, and the additional safeguards the revDSG requires — where one does not. Our processors are named in section 05. Ask at [DPO OR PRIVACY CONTACT] and we will tell you exactly where a given system runs and on what basis.
How long we keep it
- Your account and profile: while your membership exists. Cancel it, and we delete or anonymise the account within [RETENTION PERIOD AFTER CANCELLATION].
- Your date of birth: for as long as the account exists, because the age check has to be repeatable.
- Diet, allergies, allergy note: deleted with the account, or immediately when you clear them.
- Bookings, attendance and strikes: kept while you are a member so the rule can be applied fairly, and deleted with the account, except where a record is needed for a dispute or for accounting.
- Table likes: deleted with either person's account, or whenever you withdraw one. That removes our record. It does not retract an introduction that has already been made: the other person has your email address, it left our systems the moment the second like landed, and no deletion on our side reaches into their inbox. Be clear about that before you like somebody back.
- City waiting lists: until the city opens and you join, or until you ask to come off, or after [WAITLIST RETENTION PERIOD] with no contact.
- Table proposals: kept while the suggestion is live, then deleted or stripped of who sent it.
- Accounting records: six years from the end of the financial year they relate to, which is what UK company and tax law requires.
- Failed sign-in counts: they live in the memory of the running server and disappear when it restarts. They are never written to disk.
Your rights
These rights hold wherever you are. Under the UK GDPR and the Data Protection Act 2018, under the EU GDPR if you are in the EEA, and under the revDSG if you are in Switzerland.
- Access — a copy of your data and an explanation of what we do with it.
- Rectification — correction of anything wrong. Date of birth is the exception: it is fixed at signup, so ask us and a human will handle it.
- Erasure — deletion, unless we must keep something to meet a legal duty or defend a claim.
- Restriction — freeze processing while a dispute about accuracy or basis is resolved.
- Portability — your data in a portable, machine-readable format, for the parts we hold on the basis of contract or consent, and we will hand it to another provider if you ask.
- Objection — object to anything we do on the basis of a legitimate interest, including the strike record.
- Withdraw consent — for diet, allergies and country of origin, at any time. That does not undo what was lawful before you withdrew it.
- No automated decisions — we do not make any decision about you by automated means alone. Seating is done by people. A strike is recorded automatically, but a suspension is decided by an admin.
Write to [DPO OR PRIVACY CONTACT]. We answer within one month. You do not need to give a reason, and asking costs nothing.
If you think we have got it wrong, tell us first — but you can go straight to a regulator if you would rather, and you do not lose anything by trying us first.
- United Kingdom: the Information Commissioner's Office, ico.org.uk.
- EU or EEA: the supervisory authority of the country you live or work in.
- Switzerland: the Federal Data Protection and Information Commissioner, edoeb.admin.ch.
Cookies
One cookie: cityfolk_session, which is how the site knows you are signed in. There are no others, no trackers, and nothing that follows you off the site. The cookie policy has the full detail.
Security
Passwords are hashed with scrypt, so a stolen database does not hand anyone a password. The session cookie is a signed token that carries your user id and nothing more; it is httpOnly, so scripts cannot read it, sameSite=lax, and sent only over HTTPS in production.
Whether an account is an admin is read from the record on every single request, not baked into the cookie when you signed in. Remove someone's admin rights and they lose them on their next click, not when their session runs out.
Access to the database is limited to the people who need it to run the club.
If a breach puts your rights at risk, we will report it to the ICO within 72 hours of finding out, tell the other authorities named in section 08 where their law requires it, and tell you — with what happened, what was affected, and what to do.
Children
Cityfolk is 18+. We do not knowingly hold data on anyone younger. If we find we do, we delete the account.
Changes
We update this policy when what we do changes. The effective date at the top tells you which version you are reading, and we email you before a material change takes effect. If we ever add analytics, advertising or a payment processor, that is a material change and you will hear about it first.
Want to see everything we hold on you?
RAGE AGENCY LTD, trading as Cityfolk Registered in England and Wales, company number 16311448 Registered office: [REGISTERED OFFICE — TO BE FILED] Privacy, access requests and deletions: [DPO OR PRIVACY CONTACT] Everything else: [CONTACT EMAIL]
[DPO OR PRIVACY CONTACT]