Legal · Updated July 2026
Privacy Policy
This policy explains what Reserved collects, why, and the rights you and your guests have. We keep it in plain English; a formal notice reviewed by counsel replaces this text at general availability.
Who we are
Reserved is operated by Reserved Technologies Ltd, a company registered in England and Wales. Contact us at privacy@reserved.app for any privacy matter.
Our role
For your account and billing data, Reserved is the data controller. For the guest data your venue enters into Reserved (bookings, guest CRM, feedback, messaging), Reserved is a data processor and you are the controller. See our Data Processing Addendum for the processor terms.
What we collect
- Account data — name, work email, venue details, role, authentication metadata.
- Billing data — company name, billing address, VAT number, payment token (card details are held by Stripe, not us).
- Guest data your venue records — name, phone, email, booking history, dietary/allergy notes, tags, spend, notes staff add. Only the fields your venue chooses to store.
- Product telemetry — page views, feature usage, device/browser metadata, error reports, needed to operate and improve the service.
- Communications — SMS and email you send to guests through Reserved, plus delivery receipts.
Why we use it (lawful bases)
- Contract — to deliver the service you're paying for (reservations, CRM, marketing, analytics).
- Legitimate interests — product security, fraud prevention, and analytics on aggregated, non-identifying usage.
- Legal obligation — tax records, subject-access responses, lawful requests.
- Consent — where required (e.g. marketing to guests who opted in through your venue).
What we don't do
- We do not sell personal data.
- We do not use your guest data to train third-party AI models. Our current AI providers are contractually barred from training on your data.
- We do not enrich guest records by scraping the open web.
Where data is stored
All customer and guest data is stored in the United Kingdom (London region) on managed Postgres, with backups in-region. Some sub-processors (see Trust) operate in the EEA under Standard Contractual Clauses. We do not transfer guest data to the US or other third countries for operational use.
Retention
- Account data — while your account is active, plus 12 months.
- Guest data — for as long as your venue retains it. You can delete individual guests at any time; deleting your account exports and then erases guest data within 30 days.
- Billing records — 7 years, to meet UK tax obligations.
- System logs — 90 days.
Your rights
You (and, through your venue, your guests) have the right to access, correct, export, restrict, or delete personal data, and to object to processing. Guests should ask their venue first; we support your venue end-to-end. Email privacy@reserved.app and we'll respond within 30 days. You can also complain to the UK ICO at ico.org.uk.
Cookies
We use strictly-necessary cookies to keep you signed in and to remember preferences. Analytics is first-party and aggregated; we do not run cross-site advertising trackers.
Sub-processors
Current list is on the Trust page. We notify customers by email at least 30 days before adding a new sub-processor.
Changes
Material changes are announced by email at least 30 days before they take effect. The "Updated" date at the top of this page always reflects the current version.
See also our Terms and Data Processing Addendum.