Last updated: 28 July 2026
Privacy policy
This policy explains what data is processed when you use a booking form managed with Mibu and what it is used for.
1. Processing roles
The restaurant receiving the booking acts as data controller for managing its relationship with the diner.
Mibu acts primarily as the restaurant's technology provider and, where applicable, as controller of its own processing related to security, maintenance, abuse prevention and platform operation.
2. Data that may be collected
Identification and contact data: name, phone, email and chosen language.
Booking data: restaurant, date, time, service, number of guests, zone, assigned table, booking status and related communications.
Data you provide: special requests, allergies, accessibility needs, preferences, group notes or comments to the restaurant.
Technical data: IP address, browser, device, request date and time, anti-abuse checks, security events and minimal technical logs.
3. Purposes
Managing the booking, checking availability, confirming or reviewing requests, enabling modifications or cancellations and sending transactional communications.
Helping the restaurant prepare the service, including special requests, accessibility needs or dietary information where the customer provides it.
Protecting the platform against fraud, spam, bots, abusive use, technical errors or unauthorised access.
Improving the product's stability and quality through technical metrics and aggregated data. Mibu's usability tracking is limited to the restaurant's internal surfaces, not the public booking form.
4. Legal basis
Managing the booking is based on the performance of a pre-contractual or contractual request with the restaurant.
Commercial communications require consent where applicable. You can withdraw it through the means indicated in each communication or by contacting the restaurant.
Security, abuse prevention and technical logging are based on the legitimate interest in protecting the service.
5. Recipients
The necessary data is shared with the restaurant you book with.
Essential technical providers may also be involved: hosting, email, anti-abuse security, messaging, internal technical analytics or integrations configured by the restaurant.
We do not sell diners' personal data.
6. Retention
Data is kept for as long as necessary to manage the booking, handle incidents, comply with legal obligations and maintain reasonable operational records.
The restaurant may keep customer history in accordance with its own obligations and internal policies.
7. Your rights
You may request access, rectification, erasure, objection, restriction or portability where applicable.
For Mibu's own processing you can write to mibu@gastroonic.com. For a specific booking, the most direct channel is the restaurant that received it.
8. Security
Mibu applies technical and organisational measures to protect information: access control, per-restaurant separation, validation, security logs, anti-abuse protection and encrypted communications where the browser allows it.
No system is infallible, but the product is designed to minimise data, permissions and unnecessary exposure.