Legal
Privacy Policy
We respect your privacy. This policy explains what we collect through the Chef's Table website, why we use it, who helps us run the service, and the choices available to you.
Last updated: March 2026
At a glance
- We use Google Analytics on public pages to understand traffic and engagement, with consent controls where enabled.
- Forms and applications are stored securely and processed to respond to you, including via email notifications.
- Infrastructure runs on Cloudflare and Google (Firebase) as described below.
Overview
Chef's Table ("we", "us") operates this website to present our luxury private dining and events services, primarily in Dubai and the United Arab Emirates. This policy applies to information collected through chefstable.ae and related pages we operate (excluding separate terms that may apply to specific contracts).
This document is provided for transparency. It is not legal advice. If you need certainty for your situation, consult a qualified professional.
Information collected automatically
When you browse the public site, certain technical data is processed to deliver pages, protect the service, and measure performance.
- Google Analytics 4 may record page views, approximate location and device category, and events such as navigation and CTA clicks. Where a consent banner is enabled, analytics storage follows your choice; limited activity may still occur in a privacy-oriented mode before acceptance. Advertising personalization is not enabled in our configuration.
- Cookies and local storage— Analytics may use cookies when permitted. Your consent choice may be stored in browser local storage so we remember it between visits.
- Cloudflare Turnstile may run on forms to reduce spam; Cloudflare processes technical data needed to verify the challenge.
- Google reCAPTCHA v3 may load on certain administrative flows when configured, to protect sign-in and recovery.
- Server and security logs — Our hosting infrastructure may process IP addresses, user agent strings, and timestamps. For form submissions we store a one-way hash of the IP address and the user agent string to support abuse prevention and support.
- Admin session — If you access the staff admin area, an essential session cookie is used to keep you signed in.
Information you provide
When you contact us or apply for a role, you choose what to send. Typical fields include name, email, phone, company, event details, budget, and message content. Career applications may include a CV or portfolio link and the role you are applying for.
Files you upload (for example a CV or media provided through our workflows) may be stored in secure cloud storage so our team can review them.
How we use information
- To respond to enquiries, proposals, and booking-related requests.
- To operate and improve the website, including understanding which content is useful.
- To detect, prevent, and address abuse, fraud, and technical issues.
- To send operational emails related to your request (for example confirmations or follow-up).
- To evaluate career applications and manage recruitment workflows.
- To comply with applicable law or enforce our terms.
Service providers
We use reputable infrastructure and software providers. They process data on our behalf under appropriate agreements and only as needed to deliver their service.
| Provider | Role |
|---|---|
| Analytics (GA4); optional reCAPTCHA; Firebase (authentication, database, file storage for content and certain uploads). | |
| Cloudflare | Website hosting, security, Turnstile verification, databases and queues used for enquiry handling and rate limiting. |
| Resend | Transactional email delivery for form notifications. |
Each provider publishes its own privacy documentation; we encourage you to read those materials for details on how they handle data.
Retention
We keep personal data only as long as needed for the purposes above, including legal, accounting, and dispute-resolution requirements. Analytics data is subject to settings in our analytics product. Enquiry records and application materials are retained according to operational and legal needs and are reviewed periodically.
Security
We implement administrative, technical, and organizational measures appropriate to the nature of the data we handle, including access controls for staff systems, encryption in transit, and abuse-prevention tooling. No method of transmission or storage is completely secure; we work to reduce risk in line with industry practice.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or restrict certain processing of your personal data, or to object to processing. You may also have the right to lodge a complaint with a supervisory authority where that applies.
To exercise rights or ask questions about this policy, please reach out through our contact page. We will respond within a reasonable timeframe.
International transfers
Our providers may process data in multiple countries, including outside the UAE. Where required, we rely on appropriate safeguards such as contractual protections offered by vendors or applicable legal frameworks.
Children
Our services are directed to adults planning events and hospitality experiences. We do not knowingly collect personal information from children. If you believe a child has provided us data, please contact us and we will take appropriate steps.
Changes to this policy
We may update this page from time to time to reflect changes to our practices or legal requirements. The "Last updated" date at the top will be revised when we publish material changes. Continued use of the site after updates constitutes your acknowledgment of the revised policy, to the extent permitted by law.
Contact
For privacy-related requests or questions, please use the contact section of this website. For contractual matters, your booking or proposal correspondence may list an additional point of contact.
