Privacy
This page describes what the software does. It is not legal advice and it is not a substitute for your own, or your client's.

No third-party request, by default
On a default install of this theme with its companion plugin, and on the imported demo, the site makes no request to any third party on any page. That is a measured fact about the build, checked with the browser's network log on, on every route, not a claim about intent.
Concretely, there is none of:
| Google Fonts or any font CDN | The three families are WOFF2 files inside the theme. |
| An embedded map | See why there is no map. |
| Analytics of any kind | None ships, and none is added. |
| A social feed, a share widget, a like button | The Instagram field is a plain link. |
| A chat widget, an AI assistant bubble, a newsletter pop-up | None. |
| A captcha | See spam protection. |
| An icon font, a library CDN, a tracking pixel | None. |
Why there is no cookie banner
Because there is nothing to consent to. The theme sets no cookie and stores nothing about a visitor except one thing: if the visitor presses the light/dark control, their choice is remembered in their own browser's local storage, on their own device. It is never sent anywhere, it identifies nobody, and it exists only because they asked for it.
WordPress itself sets cookies when somebody logs in or leaves a comment; those are WordPress's, and its own privacy tools cover them.
Three things make this stop being true
- You set the booking mode to
provider. The partner's widget is a third-party script with its own cookies and its own policy, and the consent obligations attach that day. The settings screen says so where the field is, and so does the agent ability that writes it.- You add a third-party script — analytics, a font CDN, a map embed, a chat widget, a marketing pixel. Any one of them makes the sentence false.
- You tick "keep a copy of enquiries". See below.
If you do any of the three, edit the notices page to match. The page is written as a working shape for a fictional café, and it is the one page you edit rather than delete.
What the enquiry form collects
Six fields: what the enquiry is about, name, email address, how many people, a preferred date, and anything else the person wants to say.
By default nothing is stored. The mail is sent to your group address with a Reply-To of the
person who wrote, and the request ends. Your mail provider then holds it, under their terms, and it
is your job to say so.
Tick Settings › Site details › Booking › Keep a copy of enquiries and each one is kept as a private record on your site. That is personal data your site holds, nothing expires it on its own, and your privacy notice has to say so. The sentence under the submit button changes to match, in both states.
The privacy page's field list is generated from the form's own definition, so the notice cannot drift from the form it describes. The reasons beside each field are authored text — read every one of them against the site you are actually shipping.
The notices page
Settings › Site details › Privacy holds the record behind it: the responsible person, their role, an address that reaches them, the retention window as a number of months, and the date it was last reviewed. Fill all five.
Québec's Law 25 has required any business collecting personal information through a website to publish a plain-language privacy policy and name a reachable person since 22 September 2023, and it has no size floor — a five-person café is in scope exactly as a bank is. The GDPR and the UK equivalent have their own requirements. The page is a shape that covers the common ones; whether it covers yours is a question for somebody qualified to answer it.
Three things make one of its answers wrong:
- you changed the form's fields — the table and the notice have to agree;
- you added a third-party script;
- you set the booking mode to
provider.
WordPress's own generated privacy policy page is left untouched by the demo import. Use it as well, not instead: it covers WordPress's own cookies, embeds and comment data.
The demo importer, and the demo photographs
The one remote request this product makes is during the demo import, and it is deliberate.
- The importer fetches the demo's 22 photographs and 2 drawings from our asset server, because they are too large and too temporary to ship inside a zip. It runs once, when you press Import, from your server — not from a visitor's browser.
- Nothing about your site is sent to us. The importer requests files; it reports nothing back.
- Those images are AI-generated, are not included in your licence to redistribute, and are there so the demo looks like the demo. Replace them with your own before you launch. Every one is listed in Credits.
After the import finishes, nothing on your site talks to us again. There is no phone-home, no licence check on the front end, and no usage reporting.
Data you can export or erase
Every record this product creates is an ordinary WordPress post, term or option, so WordPress's own export, backup and erasure tools reach all of it. Stored enquiries, if you turned them on, are ordinary private posts and are exported and erased with everything else.