Privacy Notice

Last updated:

This notice explains how ResRes handles personal data when restaurants use our reservation software and when diners book a table through a restaurant using ResRes. It is written in plain English and is intended to reflect how the service actually works.

1. Who we are

ResRes provides reservation management software for restaurants: a staff console for managing bookings, tables and service configuration, and a public booking widget that restaurants can offer to their diners. Our website is https://resres.com.

You can reach us using the routes described on our Support page. Full legal entity and registered address details will be published here once finalised; we have deliberately not stated them until they can be given accurately.

2. Our role, and the restaurant's role

ResRes and the restaurants that use it play different roles under UK data protection law, and this matters for your rights:

  • Restaurant account users and staff. For the people who hold or use a restaurant's ResRes account, we act as controller of their account, authentication and support data — we decide how that data is used to provide and secure the service.
  • Diners and reservation data. The restaurant decides why and how diner and reservation data is collected and used. In general the restaurant is the controller of that data and ResRes processes it on the restaurant's instructions in order to provide the software.
  • Our own limited purposes. We act as controller for a narrow set of operational purposes such as securing the platform, preventing abuse, keeping accurate technical logs, and meeting our own legal obligations.

If your question is about a specific booking — changing it, cancelling it, a deposit or a refund — you should normally contact the restaurant directly, because the restaurant holds that relationship. Where we are acting as processor, we will support the restaurant in responding to you.

3. Who this notice covers

  • restaurant owners, managers and staff who use the ResRes console;
  • people invited to join a restaurant's ResRes team;
  • diners who book through a restaurant's ResRes booking page;
  • people who contact us for support or about the service.

4. What data we handle

  • Account and authentication data: name, email address, credentials handled by our authentication provider, team membership and role, invitation status, password-reset activity.
  • Restaurant configuration: venue and location details, service times, tables and capacity, pacing, booking and deposit policies. This is business data, though it can include staff names or contact details.
  • Reservation and guest details: booking date and time, party size, guest name and contact details as provided, booking status and reservation history.
  • Free-text and special-category-adjacent notes: if a diner or a member of staff supplies dietary requirements, allergy information, accessibility needs or other notes, those are stored with the reservation. Please only include information that is necessary for the booking.
  • Technical and security data: IP address and request metadata, device and browser information, rate-limiting signals, error and audit records used to keep the service reliable and to prevent abuse.
  • Payment and deposit data: the status of a deposit, amounts, currency, and identifiers issued by our payment infrastructure provider. We do not receive or store full card numbers.
  • Support correspondence: messages you send us and our replies.

5. Why we use it, and our lawful bases

  • Providing the service to a restaurant customer — creating and running accounts, managing reservations, sending transactional messages. Lawful basis: contract with the customer, or our legitimate interests in providing the service to individuals who are not themselves party to that contract.
  • Security, fraud and abuse prevention — authentication, rate limiting, logging, investigating misuse. Lawful basis: legitimate interests in protecting the platform, our customers and their guests.
  • Operating, maintaining and improving the service — diagnosing faults, monitoring reliability, improving features. Lawful basis: legitimate interests.
  • Administration of transactional email and deposits — booking and payment confirmations, account and invitation emails. Lawful basis: contract or legitimate interests, depending on the recipient.
  • Meeting legal and regulatory obligations — for example accounting, responding to lawful requests, and data-protection duties. Lawful basis: legal obligation.
  • Consent — we rely on consent only where a specific feature genuinely requires it. Where consent is used you can withdraw it at any time, without affecting processing that already happened.

Where we rely on legitimate interests, we have considered the impact on individuals and you have the right to object (see section 11).

6. Deposits and payments

When a restaurant takes a deposit through ResRes, the payment is made as a direct charge on that restaurant's own connected Stripe account. The restaurant is the merchant of record for those payments and controls refunds and disputes. ResRes currently takes a 0% application fee on restaurant deposits.

Card details are collected and processed by Stripe, not by ResRes. We do not receive card numbers. Stripe processes payment data under its own terms and privacy notice, and may act as controller for its own compliance and fraud-prevention purposes.

7. Who we share data with

We share personal data only where necessary, and only with the categories of provider we actually use to run the service:

  • cloud hosting, application and database infrastructure;
  • transactional email delivery;
  • payment infrastructure (Stripe) for deposits and refunds;
  • security, logging and monitoring tooling used to operate the platform;
  • professional advisers, and authorities where we are legally required to disclose.

The restaurant you booked with also has access to its own reservation data, as its controller. We do not sell personal data.

8. International transfers

Some of our providers may process data outside the UK. Where personal data is transferred outside the UK, we rely on an appropriate transfer mechanism — such as UK adequacy regulations or the International Data Transfer Agreement / UK Addendum with appropriate safeguards — and take account of additional measures where required. We do not claim that all data is held only in the UK.

9. How long we keep data

We do not apply a single fixed period to everything. Instead we keep personal data for as long as it is needed for the purpose it was collected for, applying criteria such as:

  • how long the restaurant's account remains active, and the customer's own instructions;
  • operational need — for example reservation history used to run the venue;
  • short-lived technical records such as expiring holds, tokens and other ephemeral data, which are purged automatically on a routine schedule;
  • legal, accounting, tax and dispute-resolution requirements;
  • security and abuse-prevention needs.

When data is no longer needed, we delete it or place it beyond routine use.

10. Security

We use technical and organisational measures appropriate to the risk, including authentication, tenant-level access controls in the database, restricted server-side write paths for reservation and payment data, signed webhooks, transport encryption and audit logging. No online service can be guaranteed to be completely secure, and we do not claim otherwise.

11. Your rights

Under UK GDPR you may have the right to:

  • ask for access to your personal data;
  • ask us to correct inaccurate data;
  • ask for erasure in certain circumstances;
  • ask us to restrict processing;
  • data portability where applicable;
  • object to processing based on legitimate interests;
  • withdraw consent where processing relies on consent.

If your request relates to a booking with a particular restaurant, contact that restaurant first — it is normally the controller. If we act as processor, we will pass the request on and assist the restaurant in responding.

You can also complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.

12. Children

ResRes is business software and is not intended for children to create or operate accounts. A restaurant booking may include information supplied by an adult about people in their party, which can include minors — for example party size or a dietary need. Please supply only what the booking requires.

13. Cookies and essential storage

We use necessary cookies and browser storage to sign users in, keep sessions active and protect the service against abuse. These are required for the product to function.

Non-essential analytics or marketing technologies are used only where they have been configured and where the law allows, with consent obtained where consent is required. We do not claim to operate a cookie consent banner on this website today.

14. Changes to this notice

We may update this notice as the service develops or the law changes. The date at the top of this page shows when it was last updated. Material changes affecting restaurant customers will be communicated through the account or by email.

15. Contact

See our Support page for how to reach us, and our Terms of Service for the contractual terms that apply to restaurant customers.