Legal

Privacy Policy

Pavlova social dinners · Effective date: August 17, 2026 · Version 1.0.1

The short version. We collect what we need to run your dinner: your name, contact details, any dietary needs, and your answers to a short guest survey that helps us seat the table well. Payment is handled by Stripe — we never see your card number. We share your first name and dietary needs with the restaurant, and nothing else with anyone, except the service providers that run our website, payments, messages, and advertising. You can ask us to delete your data at any time.

1. Who we are

Rockup Ltd., a company registered in Cyprus (VAT Reg. No. CY60153093Z) (“we”, “us”), operates pavlova.com under the Pavlova brand and organizes the dinners booked through it. For data-protection purposes, we are the controller of the personal data described in this policy. Contact for privacy matters: legal@pavlova.com.

2. What we collect

When you book a seat: your name, email address, mobile number, your gender (asked of every guest — see Section 3), and the details of your purchase, with payment processed by our provider, Stripe. Your card details are collected and processed by Stripe directly; we never receive or store your full card number.

When you complete the guest survey after booking (via Google Forms): your preferred first name; your age band; how you’d describe your social energy; what you’re hoping for from the dinner; topics you’re interested in; how you feel about debates at the table; and any food allergies or special requests regarding the menu.

When we message you: the content and delivery records of SMS and email messages between us.

After the dinner: your feedback form responses, and — only if you separately agree — notes from a feedback call.

When you join the waitlist: your email address.

When you visit our website: device and usage data collected through cookies and similar technologies — see Section 7 (Advertising & analytics).

3. A note on sensitive information

Two pieces of information deserve special mention. Food allergies and dietary requests can reveal information about your health or beliefs; we collect them for one purpose only — arranging your meal — share them with the restaurant together with your first name only, and ask for them on the basis of your explicit consent. You can leave them blank, though we can’t accommodate needs we don’t know about. Your gender is asked of every guest at booking: our tables are composed with gender balance in mind, and we use your answer only to compose the table.

4. Why we use your data, and on what legal basis

To run your booking — confirmations, reminders, refunds, and the dinner itself: performance of our contract with you.

To arrange your meal (allergies and dietary requests): your explicit consent.

To plan the table — using your gender to balance the table (performance of our contract with you: a balanced table is part of the service) and your survey answers (age band, social energy, interests, debate comfort, expectations) to seat guests and shape the group: your consent, given by answering the survey.

To tell you about future dinners by email or SMS, if you’ve attended a dinner or joined the waitlist: your consent, withdrawable at any time (Section 6).

To improve the service — feedback analysis, aggregate statistics on bookings and attendance: our legitimate interest in understanding and improving what we offer.

To keep dinners safe — maintaining records of guests removed for conduct violations so we can decline future bookings: our legitimate interest in the safety of our guests.

To meet legal obligations — accounting and tax records of transactions.

To advertise and measure advertising (Section 7): your consent where required, otherwise our legitimate interest.

5. Who we share data with

We share personal data only with: the restaurant hosting your dinner (your first name and dietary needs); Stripe (payments); Google (business email, internal spreadsheets, Google Forms, and Google Analytics); Meta and TikTok (advertising and measurement — Section 7); Quo (text messages); Framer (website hosting); and professional advisers or authorities where the law requires it. We do not sell your personal data.

6. Marketing, and how to stop it

If you’ve attended a dinner or joined the waitlist, we may email or text you about upcoming dinners. Every marketing email includes a way to opt out — an unsubscribe link or a simple reply is enough; reply STOP to any text to stop texts. Opting out of marketing does not affect transactional messages about a dinner you’ve booked.

7. Advertising & analytics

Our website uses the Meta pixel, the TikTok pixel, and Google Analytics 4. These set cookies or similar identifiers and collect information about your visit (pages viewed, actions taken, approximate location, device information) so that we can measure our advertising, understand how the site is used, and show you relevant ads — including retargeting you on those platforms after you visit. Each provider processes this data under its own privacy policy. You can limit this through your browser’s cookie settings, your Meta and TikTok ad preferences, and the Google Analytics opt-out browser add-on.

8. International transfers

We are based in Cyprus (EU); our guests and some of our service providers are in the United States. Where personal data is transferred internationally, we rely on our providers’ participation in the EU–US Data Privacy Framework or on standard contractual clauses.

9. How long we keep data

Booking and payment records: 7 years (accounting and tax law). Food allergy and dietary information: deleted 30 days after the dinner. Guest survey answers, your gender, and feedback responses: 24 months. Marketing contacts: until you opt out. Conduct-related records (Section 4): 24 months. Analytics data: per the retention settings of each tool.

10. Your rights

You can ask us at any time to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw any consent you’ve given. Write to legal@pavlova.com and we’ll respond within one month. If you’re in the EU, you may also complain to the Cyprus Commissioner for Personal Data Protection; depending on your US state of residence, you may have additional rights, which you can exercise through the same email address.

11. Age

Our dinners and website are intended for adults aged 21 and over. We do not knowingly collect personal data from anyone under that age; if you believe we have, contact us and we will delete it.

12. Changes

We’ll post any changes to this policy on this page and update the effective date. For material changes, we’ll notify guests with upcoming bookings directly.

13. Contact

Privacy matters: legal@pavlova.com · General: support@pavlova.com · +1 (844) 702-0110