Privacy Policy
Last updated 26 July 2026
Entrline Ltd · Website: entrline.com
1. Introduction
1.1 Entrline Ltd ("we", "us", "our") is committed to protecting and respecting the privacy of our website visitors, the people who contact us or sign up through our website, and the business contacts we reach out to.
1.2 This policy applies where we act as a data controller with respect to that personal data - in other words, where we determine the purposes and means of processing it. It covers personal data we collect through our website (entrline.com) and personal data we collect and use for our own business outreach.
1.3 This policy does not cover personal data that we process on behalf of our customers within the Entrline point-of-sale software (for example, data a venue enters about its own employees, suppliers, or customers). For that data the venue is the controller and we act as a processor; that processing is governed by our customer agreement and data processing terms, not this policy.
1.4 We are registered with the UK Information Commissioner's Office (ICO) as a data controller under registration reference ZC169977.
2. What personal data we collect
2.1 Data you give us through our website. When you complete our sign-up (waitlist) form or our contact form, we collect the details you provide:
- Sign-up form: your name, email address, country, business type, and - for UK sign-ups - your business name, city, and (optionally) phone number and any message you add.
- Contact form: your name, email address, and (optionally) your business name, together with your message.
We do not operate user accounts on our website and do not collect or store passwords or login credentials.
2.2 Business contact data we collect for outreach. We collect publicly available business contact details for hospitality venues (such as cafés, bars, and restaurants) in order to introduce our product. This is described in section 7 below. Where a business contact detail identifies an individual (for example, a named email address such as [email protected]), it is personal data and is covered by this policy.
2.3 Technical data. When you visit our website, our servers and infrastructure providers automatically receive certain technical data, including your internet protocol (IP) address, browser type and version, operating system, and similar information. Our website is protected and delivered through Cloudflare, and standard server request logs are generated.
2.4 Usage data. We use Plausible Analytics, a privacy-friendly, cookieless analytics tool, to understand in aggregate how visitors use our website (such as which pages are viewed). Plausible does not use cookies, does not collect personal data, and does not track visitors across websites.
2.5 Correspondence data. If you email us or reply to our messages, we keep the content and metadata of that correspondence.
3. How we collect and hold website form data
3.1 Contact form. When you submit our contact form, your details are sent to us by email through our email provider (Resend) and received in our business inbox (hosted on Google Workspace). We do not store contact form submissions in a separate database; they live in our email inbox, which we control, and are transiently processed and logged by Resend in the course of delivering them.
3.2 Sign-up (waitlist) form. When you submit our sign-up form, in addition to notifying us by email (via Resend), we store the details you provide in a private spreadsheet hosted on Google Workspace (Google Sheets). We use this record to manage our pre-launch waitlist, to contact you about our launch, and to ensure we do not send you duplicate or unwanted communications. Access to this spreadsheet is restricted to us.
4. How we use your personal data
4.1 We process personal data for the following purposes:
(a) responding to your enquiries and providing information or services you have requested;
(b) managing our pre-launch waitlist and keeping you informed about our launch and related updates, where you have signed up to hear from us;
(c) contacting relevant hospitality businesses to introduce our product (see section 7);
(d) analysing use of our website, in aggregate, to improve it;
(e) complying with our legal and regulatory obligations.
4.2 You can opt out of our marketing and outreach emails at any time using the unsubscribe link included in those emails, or by contacting us using the details in section 13.
5. Legal basis for processing
5.1 We only process personal data where we have a lawful basis to do so:
(a) Consent - where you have submitted your details through our website asking to hear from us (for example, joining our waitlist), we rely on your consent, which you may withdraw at any time.
(b) Legitimate interests - where we contact hospitality businesses to introduce our product, we rely on our legitimate interest in promoting our business to relevant commercial prospects. We have carried out a legitimate interests assessment balancing this against the rights of the individuals concerned, and we provide an opt-out in every message. You may object to this processing at any time.
(c) Legal obligation - where processing is necessary for us to comply with the law.
6. Sharing your personal data
6.1 We share personal data with the following categories of third-party service providers, who process it on our behalf and under our instructions:
- Resend - sends our website form emails and our outreach emails.
- Google Workspace (Google) - hosts our email inboxes.
- Cloudflare - provides DNS, security, and delivery for our website and domains.
- Hetzner - hosts our website server infrastructure.
- Zapmail - provides the email inboxes and infrastructure we use for outreach.
- Smartlead - the platform we use to send and manage outreach emails and replies.
- Hunter.io - assists us in finding and verifying business email addresses for outreach.
- MillionVerifier - verifies the validity of email addresses before we contact them.
- Plausible - provides cookieless website analytics.
- Stripe - processes subscription payments (Stripe handles card details directly; we do not collect or store card numbers).
6.2 We may also disclose personal data to law enforcement agencies, regulators, or other authorities where we are legally required or permitted to do so.
6.3 We require all our third-party providers to respect the security of your personal data and to process it only in accordance with our instructions and the law. We do not permit them to use your personal data for their own purposes.
7. How we collect and use business contact data for outreach
7.1 We identify potential customers by searching publicly available sources for hospitality businesses in the United Kingdom. Specifically:
(a) We use the Google Maps Places API to find hospitality venues in particular areas, collecting the business listing information Google publishes - such as business name, address, phone number, website, and rating. We do not collect Google account data, reviews, or reviewer identities.
(b) For venues with a website, we read publicly accessible pages (such as the homepage and contact pages) to find a published business email address. We only access pages that are publicly available; we do not use logins, bypass access controls, or access private information.
7.2 We use this data solely to contact the business to introduce our product. Because we collect this data from public sources rather than from you directly, we provide the information required under Article 14 of the UK GDPR - including our identity, our purpose, our lawful basis, and your rights - in our first message to you and by linking to this policy.
7.3 Our legal basis for this processing is our legitimate interests, as described in section 5. Every message includes a clear way to opt out, and if you opt out we will stop contacting you.
8. International data transfers
8.1 Some of our service providers are based outside the United Kingdom and the European Economic Area (for example, in the United States). Where we transfer personal data to such countries, we ensure appropriate safeguards are in place - including reliance on UK adequacy regulations / the UK-US data bridge where applicable, and Standard Contractual Clauses or the UK International Data Transfer Agreement where not.
8.2 You may request further information about these safeguards by contacting us using the details in section 13.
9. Data retention
9.1 We keep personal data only for as long as reasonably necessary for the purposes described in this policy, and to meet any legal, accounting, or reporting requirements.
9.2 Contact form submissions remain in our email inbox, which we control, and we delete them when they are no longer needed. Sign-up (waitlist) details stored in our spreadsheet are kept only for as long as necessary to manage our launch and pre-launch communications, and are deleted when no longer needed for that purpose.
9.3 If you opt out of our outreach or ask us to stop contacting you, we retain the minimum information necessary to ensure we honour that request and do not contact you again.
10. Your rights
10.1 Under data protection law you have the right to: request access to your personal data; request correction of inaccurate data; request erasure of your data; restrict or object to our processing; and request the transfer of your data. Where we rely on consent, you may withdraw it at any time.
10.2 To exercise any of these rights, please contact us using the details in section 13. You will not usually have to pay a fee. We may charge a reasonable fee, or decline to act, if a request is clearly unfounded, repetitive, or excessive.
11. Cookies
11.1 Our website does not set any cookies. We use Plausible for analytics, which is cookieless and stores no information on your device. Because we do not use cookies or any tracking that requires consent, we do not display a cookie consent banner. If this changes, we will update this policy and seek your consent where required.
12. Children's privacy
12.1 Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.
13. How to contact us
13.1 If you have any questions about this policy or how we handle your personal data, or if you wish to exercise your rights, please contact us:
- By email: [email protected]
- By post: Entrline Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
14. Complaints
14.1 You have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at any time. The ICO's contact details are at https://ico.org.uk/make-a-complaint/. We would appreciate the chance to address your concerns first, so please contact us before approaching the ICO.
15. Changes to this policy
15.1 We may update this policy from time to time by publishing a new version on our website. Where changes are significant, we will take reasonable steps to notify you.