Security, data ownership and what happens to your guest records
A reservation system holds the names, phone numbers and habits of your guests. This page says plainly where that data lives, who can reach it and what you can take away. It claims no certification we do not hold and names no auditor we have not used.
The guest records belong to the venue
Guest names, contact details, visit history, notes and every booking are your data, not ours. We do not sell them, we do not rent them, we do not market to your guests, and we do not use one venue's records to help another venue.
- Export in CSV whenever you want, from inside the account
- Deletion of a guest record on request, including on a guest's own request to you
- We do not send marketing to your guests, ever
- A cancelled account can be exported before it closes
Hosting and location
The service runs on managed cloud infrastructure in the European Union and the United States, with each account's data held in the region chosen when the account is created. Enterprise accounts can pin a region in the contract.
Encryption in transit over TLS on every connection
Encryption at rest on the database and on every backup
Isolation per account, so one venue's board cannot be queried from another's session
Payment card details for deposits are held by the payment processor, never on our servers
Who can reach your data, and how that is limited
- Staff logins are per person and per venue, with roles that decide what each one sees
- Our own access is limited to the people who operate the service, with individual accounts and multi-factor authentication
- Support looks at an account only when you ask us to look at it
- Enterprise adds SAML single sign-on, SCIM provisioning, custom roles and a full audit log of who did what
Backups, retention and what happens on a bad day
- Automated daily backups, kept for 30 days, encrypted at rest
- Point-in-time restore on the primary database
- Retention policy on Enterprise, set by you, for how long old bookings are kept
- 99.9 percent uptime commitment written into Enterprise contracts
- A status page and an email to account owners when something is not working
Working with your own obligations
We act as the processor for the guest data you collect, and you remain the controller of it. A data processing agreement is available, and Enterprise accounts get a security review before signing.
- Data processing agreement on request
- Named onboarding contact per region on Enterprise
- Subprocessor list available on request to [email protected]
- The full privacy policy covers what we collect on this website itself
Questions a security review usually asks
Write to [email protected] and we answer the questionnaire your team uses, in writing, before you commit to anything.