Legal · Updated July 2026
Trust
Reserved runs UK restaurants. That means UK data, UK support, and standards we can actually name — not a marketing badge.
Where your data lives
All customer and guest data is stored in the United Kingdom. Backups stay in-region. We do not replicate data outside the UK or EEA for operational use.
GDPR
Reserved is a data processor for the guest data your venue collects, and a data controller for account and billing data. Our Data Processing Addendum reflects UK GDPR and EU GDPR requirements; enterprise customers can request a countersigned PDF. Guests can request access or erasure through your venue; we support you end-to-end.
Payments and PCI
Card details are handled by Stripe, a PCI DSS Level 1 provider. Reserved never sees a full card number. Deposits, pre-auths, and no-show charges all run through Stripe's tokenised flow, so your PCI scope stays minimal.
Uptime
Our target is 99.9% monthly uptime for the booking widget and owner app. Live status is at reserved.app/status. Planned maintenance is announced at least 48 hours ahead and scheduled outside UK service hours where possible.
Access control
Role-based access on every venue. Row-level security in the database means one venue can never see another venue's data — enforced at the database, not just the app. Staff access to production data is limited, logged, and reviewed.
Subprocessors
We keep this list short and current:
- Supabase — managed Postgres, UK region. Database, auth, storage.
- Stripe — payments, deposits, subscription billing.
- Vonage — SMS delivery to UK guests.
- AWS SES (eu-west-2) — transactional and marketing email.
- Cloudflare — CDN, DDoS protection, edge runtime.
We notify customers by email at least 30 days before adding a new subprocessor.
What we will never do
- Sell your guest data.
- Use your guest data to train AI models — neither we nor our AI providers train models on your data under our current contracts.
- Charge you a per-cover fee.
- Lock your data behind an export paywall — CSV export is one click, always.
Reporting a vulnerability
Email security@reserved.app. We acknowledge within one UK business day, and we do not pursue researchers acting in good faith.
See also our Privacy Policy, Terms, and Data Processing Addendum.