Cookie Policy
Last updated:
This page explains the cookies and similar technologies ResRes uses — small pieces of information stored on, or read from, your device — what each one is for, and how you can control them.
1. Your choices
Necessary technologies are always on because the service cannot work without them. Everything else is off until you allow it. Your choice is remembered for 183 days (six months), after which we ask again. We also ask again if the technologies we use change.
You can change or withdraw your choice at any time: . The same link is in the footer of our website and in the console menu after you sign in. Withdrawing Preferences removes the preference data ResRes stored on your device.
2. Necessary
These are required to sign in, keep bookings and payments safe, and remember your choice.
sb-<project>-auth-tokenKeeps restaurant staff and operators signed in to the console.
- Type
- Browser storage (local)
- Provider
- ResRes (sign-in service)
- Duration
- Until you sign out (session is refreshed while in use)
- Where
- Sign-in, staff console and operator admin
isenta_pbAnonymous random value used to rate-limit booking and contact requests only when no network address is available. HttpOnly; holds no personal data.
- Type
- Cookie
- Provider
- ResRes
- Duration
- 6 hours
- Where
- Booking pages, booking management and contact form
isenta.booking.*Remembers a one-time request key so refreshing mid-booking cannot create a duplicate reservation or payment.
- Type
- Browser storage (this tab)
- Provider
- ResRes
- Duration
- Until the tab is closed (removed after the booking completes)
- Where
- Booking pages
Sign-in link captureMoves a one-time sign-in, invitation or password-reset link out of the address bar so it is used exactly once. Held in page memory only; nothing is written to your device.
- Type
- Page memory only
- Provider
- ResRes
- Duration
- Until the page is closed or reloaded (15 minutes at most for password reset)
- Where
- Sign-in, invitation and password reset
resres_consentRemembers your cookie choices (version, the three optional choices and when you decided). Contains no identifier.
- Type
- Cookie
- Provider
- ResRes
- Duration
- 183 days (six months), then you are asked again
- Where
- All pages
__cf_bmSet by Cloudflare, the network that delivers this website, to tell people apart from automated bots and protect the site from abusive traffic. It is a hosting security cookie: ResRes does not read it and does not use it for analytics, advertising or profiling. HttpOnly and Secure.
- Type
- Cookie
- Provider
- Cloudflare (our hosting network), not ResRes
- Duration
- 30 minutes
- Where
- All pages on resres.com
__dplSet automatically by the platform that hosts this website when a page is served. ResRes does not set, read or use it, and not for analytics, advertising or profiling. The hosting provider does not publicly document its exact purpose; it appears to relate to delivering the published version of the site, and we will update this entry once confirmed.
- Type
- Cookie
- Provider
- Our hosting platform, not ResRes
- Duration
- 24 hours
- Where
- All pages on resres.com
Stripe.js and payment formLoads the secure card form and Stripe’s fraud-prevention checks when a restaurant asks for a deposit. Stripe may set its own cookies or storage.
- Type
- Third-party script
- Provider
- Stripe
- Duration
- Set by Stripe; names and durations are controlled by Stripe (see Stripe’s cookie policy)
- Where
- Only the payment step of booking and deposit pages
3. Preferences (optional)
These remember choices you make in the ResRes console. If you do not allow them the console still works; it simply forgets these choices when you reload the page.
isenta.staff.locationIdRemembers which of your venues you last worked in. Without Preferences it is remembered only until the page is reloaded.
- Type
- Browser storage (local)
- Provider
- ResRes
- Duration
- Until you change it, sign out on this device, or withdraw Preferences
- Where
- Staff console
sidebar_stateRemembers whether a collapsible side menu is open. Only written with Preferences consent.
- Type
- Cookie
- Provider
- ResRes
- Duration
- 7 days
- Where
- Console screens that use a collapsible side menu
4. Analytics (optional)
Our public website can use Google Analytics to understand which pages are visited. It is off by default: it only loads after you allow Analytics in Cookie settings, only on our public marketing and legal pages, and only on resres.com once we have configured it. It is never used on booking, payment, sign-in or console pages, advertising features and Google signals are switched off, and we never send names, emails, booking details or page addresses with query strings. If you withdraw permission, we stop measuring and delete the Google Analytics cookies we can reach.
Google Analytics 4 (_ga, _ga_<id>)Measures visits to our public website only (pages viewed, trial-button clicks, plan choices and accepted contact enquiries) without names, emails or booking details. It loads only after you allow Analytics, and never on booking, payment, sign-in or console pages. Advertising features and Google signals are off, so nothing is used for advertising or connected to your Google account.
- Type
- Cookie
- Provider
- Duration
- _ga: up to 2 years; _ga_<id>: up to 2 years (set by Google only after you allow Analytics)
- Where
- Public website pages only — never booking, payment, sign-in or console pages
5. Campaign links in restaurant emails
Campaign link identifier (#mkv=…)
Links in a restaurant’s marketing email can carry a short, random identifier in the part of the address after “#”. It lets the booking page apply the offer in that email and lets the restaurant see that a booking came from that campaign. It does not contain your name or email address, and ResRes does not copy it into cookies or browser storage.
Provided by: ResRes, on behalf of the restaurant that sent the email.
Because this identifier supports both offer fulfilment and campaign attribution, how it is treated under the storage and access rules is under separate review. This page describes how it works today; it is not a statement that it is exempt.
7. More information
Our Privacy Notice explains how personal data is handled more generally. For questions, see our Support page.