Legal

Privacy Policy

ReserveDio is booking infrastructure used by businesses to take bookings from their own customers. This policy explains what data we hold, why we hold it, and how it is kept separated between businesses.

Last updated: 7 September 2026

Who is responsible for your data

When a business uses ReserveDio to take bookings, that business decides what it collects from its customers and is responsible for how it uses that information. ReserveDio processes the data on the business's behalf and is responsible for the platform itself — storage, access control, and security.

If you booked with a business through ReserveDio and want your booking data changed or deleted, contact that business first. If they cannot help, contact us through our contact page and we will assist them.

What we collect

  • Account data — the email address and name used to create a ReserveDio account, and the team memberships and permissions attached to it.
  • Business data — business name, address, contact details, branding, offerings, availability, resources and policies configured by the business.
  • Booking data — the details a customer submits when booking: name, contact details, chosen offering, date and time, party or ticket quantity, and any notes the business asks for.
  • Payment records — payment status, amount, currency, and the reference returned by the payment provider. Card numbers never reach ReserveDio; they are entered with the payment provider.
  • Operational records — notification delivery attempts, check-in records, and an immutable audit history of sensitive actions.
  • Technical data — request metadata such as IP address, used for abuse prevention and rate limiting.

Why we hold it

To deliver the booking service: confirming and managing bookings, controlling ticket and capacity inventory, sending booking notifications, recording payment status, supporting check-in, and giving the business an accurate operational and financial history. We also use technical data to protect the platform from abuse.

We do not sell personal data, and we do not use booking data for advertising.

How data is separated and protected

  • Every record belongs to exactly one business, and access rules are enforced in the database, not only in the interface.
  • Team members only see what their assigned permissions allow.
  • Payment provider credentials are encrypted at rest and are never sent to a browser; only masked values are ever displayed.
  • Financial and audit history is append-only, so past records cannot be silently rewritten.
  • Sensitive operations are validated on the server, so a modified browser cannot alter amounts, paid status or inventory.

Retention

Booking, payment and audit records are retained while the business account is active, because businesses need an accurate operating and financial history. When a business closes its account, its data is removed on request, except records we must keep for legal, tax or fraud-prevention reasons.

Your rights

You can ask for a copy of the personal data we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it. Requests are handled through the business you booked with, or directly through our contact page.

Changes to this policy

When this policy changes materially, the date above is updated and account holders are notified by email. Continuing to use ReserveDio after a change means the updated policy applies.