Skip to main content

Restaurant Booking System from just £99+VAT per month. Get in touch for more information.


Last updated: 08 September 2026

1. Who we are

This privacy policy explains how The Only Way Togo Ltd (“Togo”, “we”, “us”, “our”) collects, uses and protects personal data. We provide booking systems, marketing tools, websites, branding and photography services to hospitality businesses across the UK.

  • Registered address: Holmfield Mills, Holdsworth Road, Halifax, HX3 6SN
  • Company number: 08311570
  • Email: hello@togo.uk.net
  • Telephone: 0113 328 1109

We are the “data controller” for the personal data described in this policy, which means we decide how and why it is used. We comply with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

2. What this policy covers

This policy covers personal data we collect through:

  • Our website at togobookingsystem.co.uk
  • Enquiry forms, demo requests and newsletter sign-ups
  • Email, telephone and social media contact with us
  • Our marketing activity, including advertising on Meta platforms

Important distinction. When a diner books a table through a Togo booking widget on a restaurant’s website, that booking data belongs to the venue. The venue is the data controller and Togo acts as its data processor under a written agreement. If you have booked a table at a venue and want to exercise your data rights, please contact the venue directly. This policy covers data where Togo is the controller in its own right.

3. Information we collect

Information you give us

  • Name, job title and venue name
  • Email address, telephone number and website address
  • The content of your enquiry and any preferred contact times
  • Newsletter subscription details
  • Correspondence with our team

Information collected automatically

  • IP address and approximate location
  • Browser type, device type and operating system
  • Pages visited, time on page, referring website and exit pages
  • Cookie and similar identifiers (see section 4)

Information from third parties

  • Business information from publicly available sources such as Companies House, company websites and business directories
  • Company-level identification data from our website visitor identification provider (see section 5)
  • Engagement data from advertising and social media platforms where you have interacted with our content

4. Cookies and tracking technologies

We use cookies and similar technologies on our website. When you first visit, you are shown a consent banner. Non-essential cookies are only set if you accept them. You can change your preferences at any time through the cookie settings link on our site, or by clearing cookies in your browser.

Essential cookies

Required for the website to function, including page navigation, form submission and remembering your cookie choices. These do not require consent.

Analytics cookies – Google Analytics

We use Google Analytics (provided by Google Ireland Limited) to understand how visitors use our website, which pages are most useful, and where visitors come from. This helps us improve the site. Google Analytics sets cookies that collect information including your IP address, pages viewed and session duration. IP addresses are truncated before storage. Analytics cookies are only set with your consent.

You can opt out of Google Analytics across all websites using the Google Analytics Opt-out Browser Add-on. Google’s privacy policy is available at policies.google.com/privacy.

Marketing cookies – Meta Pixel

We use the Meta Pixel (provided by Meta Platforms Ireland Limited) on our website. The pixel allows us to:

  • Measure the effectiveness of advertising we run on Facebook and Instagram
  • Show relevant adverts to people who have previously visited our website (“retargeting”)
  • Build audiences of people with similar characteristics to our existing customers

The pixel may collect your IP address, browser information, pages visited and actions taken on our site, and where you have provided them, hashed versions of your email address or telephone number. Hashing converts this information into an irreversible string of characters before it is transmitted, so Meta cannot read the original values but can match them against its own records.

Meta Pixel cookies are only set with your consent. You can control how Meta uses your data for advertising in your Facebook Ad Preferences. Meta’s privacy policy is available at facebook.com/privacy/policy.

Business intelligence – website visitor identification

We use a website visitor identification service to help us understand which businesses are interested in our products. Full details are set out in section 5 below.

5. Website visitor identification

We work with Dynamic Leads (which delivers this service using the Leadfeeder platform, operated by Dealfront Group GmbH) to identify the organisations that visit our website. This is a common practice in business-to-business marketing.

How it works

When you visit our website, your IP address is recorded and compared against a database of IP addresses registered to businesses. Where a match is found, we may learn the name of the company you work for, its industry, its approximate size and location, and which pages were viewed during the visit. A cookie is used to group page views into a single session.

What we do and do not learn

This service is designed to identify companies, not individuals. We do not learn your name, email address or job title from it, and we cannot identify you personally from a visit alone. However, we recognise that an IP address is personal data under UK GDPR, and that in the case of a very small business a company identification could indirectly relate to an individual. We therefore treat this data with the same care as any other personal data.

Our lawful basis

We rely on legitimate interests (UK GDPR Article 6(1)(f)) for this processing. Our legitimate interest is understanding which businesses are interested in our services so we can market efficiently to a small and specialised audience. We have carried out a balancing assessment and consider that this processing is unlikely to affect your rights or freedoms, because it operates at company level, is limited to business context, and does not involve profiling of individuals or automated decision-making.

Your right to object

You have an absolute right to object to processing carried out for direct marketing purposes, and a right to object to legitimate interests processing generally. If you object, we will stop. Contact us at hello@togo.uk.net and we will exclude your IP range or company from identification. Declining non-essential cookies on our banner will also prevent the session-tracking element of this service.

6. How we use your information and our lawful bases

Purpose Lawful basis
Responding to enquiries and demo requests Legitimate interests / Steps prior to entering a contract
Providing and supporting our products and services Performance of a contract
Sending our newsletter and marketing emails Consent, or legitimate interests for existing business customers under the PECR soft opt-in
Advertising on Meta platforms, including retargeting Consent
Website analytics and performance measurement Consent
Identifying businesses that visit our website Legitimate interests
Business-to-business direct mail and outreach Legitimate interests
Preventing fraud and securing our website Legitimate interests
Meeting legal and accounting obligations Legal obligation

7. Marketing communications

If you subscribe to our newsletter or request information, we may send you updates about our products, features and hospitality industry insights. Every marketing email contains an unsubscribe link, and you can opt out at any time by clicking it or by emailing us.

Where we contact business addresses about products relevant to that business, we may do so on the basis of legitimate interests as permitted for corporate subscribers under PECR. You can ask us to stop at any time.

We may also contact venues by post. If you would prefer not to receive mail from us, let us know and we will remove your venue from our list.

8. Who we share your data with

We do not sell your personal data. We share it only with:

  • Service providers who process data on our behalf under contract, including our website host, email provider, CRM, form provider (Gravity Forms) and the analytics and marketing platforms named in this policy
  • Google Ireland Limited – website analytics
  • Meta Platforms Ireland Limited – advertising and measurement
  • Dynamic Leads / Dealfront Group GmbH – website visitor identification
  • Professional advisers such as accountants and solicitors where necessary
  • Law enforcement or regulators where we are legally required to do so

9. International transfers

Some of our providers process data outside the UK, including in the United States and the European Economic Area. Where data leaves the UK, we ensure appropriate safeguards are in place, such as UK adequacy regulations, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework. You can request details of these safeguards by contacting us.

10. How long we keep your data

  • Enquiries that do not become customers: up to 24 months from last contact
  • Customer records: for the duration of the contract and 6 years afterwards for accounting and legal purposes
  • Newsletter subscribers: until you unsubscribe, plus a suppression record so we do not contact you again
  • Website analytics: up to 14 months
  • Visitor identification data: up to 12 months
  • Cookies: as set out in your browser, typically between one session and 13 months

11. Your rights

Under UK data protection law you have the right to:

  • Be informed about how your data is used – this policy
  • Access a copy of the personal data we hold about you
  • Rectification of inaccurate or incomplete data
  • Erasure of your data in certain circumstances
  • Restrict processing in certain circumstances
  • Data portability – receive your data in a machine-readable format
  • Object to processing based on legitimate interests, and an absolute right to object to direct marketing
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email us at hello@togo.uk.net. We will respond within one month. There is no charge, although we may ask you to verify your identity.

12. Data security

We use appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS), access controls, and restricting access to those who need it. No transmission over the internet is completely secure, but we take reasonable steps to protect your information and have procedures in place to deal with any suspected breach.

13. Children

Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18 through our website.

14. Changes to this policy

We may update this policy from time to time. The date at the top shows when it was last revised. Where changes are significant, we will make this clear on our website.

15. How to contact us or complain

If you have questions about this policy or how we handle your data, contact us:

  • Email: hello@togo.uk.net
  • Post: Data Protection, The Only Way Togo Ltd, Holmfield Mills, Holdsworth Road, Halifax, HX3 6SN
  • Telephone: 0113 328 1109

If you are not satisfied with our response, you can complain to the Information Commissioner’s Office:

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF