Privacy
Effective: 2026-09-21
TablePop is run by Sven Bosau, trading as Bosau Digital L.L.C. This page explains what the service stores, who else touches it, and how to get rid of it. It is written to be read, not to be survived.
The one thing to understand first: a published TablePop page is public. Anyone who knows or guesses its address can open it, and search engines can index it. There is no password on a published page. Do not publish a table you would not put on a public website.
1. What we collect
Three things, and nothing else.
| Your email address | This is your whole account. There is no password, no name field, no profile. You sign in by receiving a six-digit code at that address and typing it back. |
|---|---|
| Session tokens | When you sign in, one session cookie is set on the dashboard so you stay signed in. We store only a hash of the token, never the token itself, so a copy of our database cannot be used to impersonate you. |
| Your published tables | The rows, columns and settings of every page you publish, plus its title, description, theme and address. You chose to make this public; we store it so we can serve it. |
We do not ask for your name, your company, your address or your phone number. We never see your card details (see section 3). We do not read the rest of your workbook · the add-in sends only the range you selected when you press Publish or Update.
2. What we do not collect
- No cookies on published pages. A visitor reading one of your tables gets no cookie from us at all.
- No third-party analytics. Not on published pages, not on the dashboard, not on this page. No Google Analytics, no pixels, no tag manager.
- No visitor profiles. We count views as a number that goes up. We do not store who viewed, from where, on what, or in what order.
- No advertising, ever. We do not sell, rent or share personal data with anyone for marketing, and we never will. There is no version of this business where that makes sense.
About that view counter
Each published page has a counter so you can see whether anyone is reading it. It is an integer per page. It is not tied to an identifier, a session or an IP address, and it cannot be turned back into a list of visitors, by us or by anyone else.
3. Who else processes it
Four companies, each doing one specific job.
| Hetzner | Hosts the application and its database, in the EU. This is where your email address and your published tables live. |
|---|---|
| Cloudflare | Serves every published page from locations around the world, and issues the TLS certificates. A copy of each published page sits on Cloudflare's network so it loads quickly for your readers. Because their network is global, copies of your published, public table data exist outside the EU. |
| Postmark | Sends the two kinds of email we send: your sign-in code and your license key. They process your email address to deliver them. |
| Pabbly | Runs checkout and subscriptions if you buy Pro. Card details are entered on their systems and never reach ours. We receive the fact that a subscription exists and the email address attached to it. |
That is the complete list. If it ever changes, this page changes with it.
4. The dashboard cookie
The dashboard at my.tablepop.app sets exactly one cookie: your session. It
is strictly necessary to keep you signed in, so there is no consent banner to click
away. It is not used for tracking and it does not follow you anywhere else.
5. How long we keep things
- Delete a page and it stops being served within about a minute. The stored payload is removed, and the edge copy is dropped. Its address stops working.
- Backups age out. We keep rolling backups of the database so an outage does not lose your work. A deleted page can survive in those for a short window until they rotate. We do not restore deleted pages from backups on request.
- Sign-in codes expire ten minutes after they are sent.
- Your account is kept while you have one. Email sven@pythonandvba.com and we will delete it and everything attached to it.
6. Why we are allowed to hold it
Under the GDPR, we process your email address and your tables because we need them to provide the service you asked for · that is the contract basis. We keep minimal records of sign-ins and rate limits to stop abuse of the service, which is our legitimate interest in not letting TablePop be used for phishing. There is no processing based on consent, because there is nothing optional to consent to.
7. Your rights
If you are in the EU, the UK, or anywhere with comparable law, you can ask us to show you what we hold, correct it, delete it, or hand it over in a portable form. You can object to our processing and you can complain to your national data protection authority.
In practice, most of it is already in your hands: your pages are listed in the dashboard, you can edit or delete any of them yourself, and your account is one email address you already know. For anything else, email sven@pythonandvba.com. This is a small business · you will get a real reply, normally within a couple of days and always within one month.
8. Security, honestly stated
Traffic is encrypted in transit. Session tokens are stored hashed. Published payloads are size-capped and rate-limited. Access to the production systems is limited to one person.
No system is perfect, and we will not pretend otherwise. If something goes wrong that affects your data, we will tell you what happened rather than wait to be asked.
9. Children
TablePop is a business tool and is not aimed at children. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, tell us and we will remove it.
10. Changes
If this page changes in a way that matters, the effective date at the top changes and, for anything significant, we will email account holders. We will not quietly broaden what we do with your data.
11. Contact
Sven Bosau · Bosau Digital L.L.C.
Privacy and support: sven@pythonandvba.com
Abusive or illegal pages: abuse@pythonandvba.com
(see Report a page)