- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Websites, dashboards, HostedTable and booking widgets
On this page
Cookie & Storage Technologies Policy
This policy explains how cookies, local storage, device identifiers, pixels and similar technologies may be used across DM Digital UK, HostedTable, customer portals and booking widgets.
1. What these technologies do
Cookies and storage technologies can remember a session, protect a login, store preferences, measure performance, prevent fraud, support accessibility, deliver communications and help us understand how a service is used.
2. Categories
| Category | Purpose | Typical status |
|---|---|---|
| Strictly necessary | Authentication, session continuity, CSRF protection, security, load balancing, consent record and core requested functionality | Used without optional consent where legally permitted |
| Functional | Remembering venue, layout, language, accessibility, trusted device and user choices | Consent or a permitted storage exception, depending on function and law |
| Analytics and performance | Understanding errors, journeys, aggregate usage and service performance | Consent unless an applicable statutory exception is used with required safeguards |
| Marketing | Advertising, campaign measurement, profiling or cross-service promotion | Prior consent where required |
3. Typical first-party storage
Names vary by deployment, but first-party technologies may include:
- session identifiers used to keep a user signed in;
- CSRF and security tokens;
- consent and privacy-choice records;
- selected venue, date, theme, layout and accessibility preferences;
- trusted-device or MFA state;
- booking-journey state and anti-abuse identifiers; and
- diagnostic correlation identifiers.
Strictly necessary storage is normally short-lived or expires when the browser session ends, although security and preference records may persist for a reasonable period.
4. Third-party technologies
Third-party services such as payment, video, maps, support, analytics or security tools may set or access storage. Where they are optional, they should not load until the required choice has been made. Their own notices may also apply.
5. Consent and control
Where consent is required, it must be freely given, specific, informed and indicated by a clear positive action. Rejecting optional technologies must be as straightforward as accepting them. Consent can be withdrawn using the privacy or cookie controls available on the relevant service.
Browser settings can block or delete storage, but doing so may prevent login, booking, security or other core features from working.
6. Permitted exceptions
Data protection and electronic-communications law allows certain storage or access without consent, including technologies strictly necessary to provide a service explicitly requested by the user and other statutory exceptions where their conditions are met. We will not describe an optional advertising or profiling technology as necessary merely because it is commercially useful.
7. Booking widgets
A venue booking widget may operate on a venue website while being supplied by HostedTable. The venue is responsible for ensuring its website consent mechanism and privacy information cover all technologies loaded by the page. HostedTable is responsible for technologies it controls within the widget.
8. Retention
Storage duration depends on purpose. Session technologies are normally deleted or expire quickly; preference and consent records may remain longer so choices can be respected; security logs may be retained in accordance with the Retention Schedule.
9. Updates
We may update categories, providers and durations as services change. The live consent interface, where present, provides the most current technology-level information.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
