Skip to content
Policies

Privacy Policy

Last updated: 23 September 2026

At a glance

This summary is for convenience only — the full text below governs. Each point links to the section it summarises.

  • Who looks after your data — ResoFlow is a trading name of Caleonix LTD, registered with the ICO (ZC127147). We are the data controller for venue accounts and our own site and support; for guest data — bookings, tickets, gift cards, loyalty and orders — the venue the guest dealt with is the controller and we process it on the venue’s behalf.
  • What we collect — For venues: account, business and payment details — card details are handled by Stripe, never held by us. On venues’ behalf: guests’ contact details, bookings, orders, tickets, gift cards, loyalty balances and the profile a venue keeps about its guests. Plus automatic data such as IP address, browser and device information.
  • Extra care for allergies — Allergy and dietary information is special category data. The venue is the controller and relies on the guest’s explicit consent when a guest chooses to share it, and guests can ask their venue to remove it at any time.
  • How we use it — To run the Services — bookings, payments, loyalty, gift cards, ordering and support (including Rezo, our EU-hosted AI assistant; support correspondence is never used to train any AI model) — to keep the platform reliable and secure, to meet legal obligations, and, with consent, to send marketing.
  • Our lawful bases — Performance of contract for delivering the Services; legitimate interests for things like fraud prevention, security and service emails; consent for marketing, non-essential cookies and allergy data; and legal obligation for tax and regulatory records. Consent can be withdrawn at any time.
  • Who we share it with — A small, vetted list of subprocessors, published at /policies/subprocessors — payment, email, SMS, hosting and similar providers. We never sell personal data. Where a venue switches on its own integration (Zapier or a webhook), that onward transfer is the venue’s own, to a destination the venue configures.
  • Where it lives — Our database and functions are hosted in Google Cloud’s europe-west1 region in Belgium. Where a subprocessor takes data outside the UK, we rely on recognised transfer safeguards — the UK IDTA, or the EU Standard Contractual Clauses with the UK Addendum.
  • How long we keep it — Only as long as needed, with the full retention table in section 8. Guest profiles are kept for a period the venue chooses (default 2 years, maximum 3, from last activity); payment records keep their anonymised money facts for the life of the venue’s account while the person’s details are removed; billing records are kept up to 7 years for HMRC.
  • How we protect it — Encryption in transit and at rest, multi-factor authentication available on every account, audit logging and least-privilege access controls — while being honest that no system can be guaranteed 100% secure.
  • Your rights — Access, correction, erasure, restriction, portability, objection, and withdrawing consent. Guests should contact their venue first — it is the controller, and we forward requests if the venue can’t help. We respond to verified requests within 7 working days, and you can always complain to the ICO.
  • No ad tracking — We don’t run advertising campaigns or build profiles for ad targeting, and analytics never run without your explicit consent — so a Do-Not-Track browser is covered by default.
  • If this policy changes — We give 14 days’ advance notice, in-app and by email, before any material change takes effect; minor clarifications just update the “Last updated” date at the top.

1. Who we are

In short: ResoFlow is a trading name of Caleonix LTD, a UK company. We act as the data controller for our own tenants and as a data processor for the guests that tenants serve.

Caleonix LTD (company number 17162652) is a company registered in England and Wales with its registered office at 71-75 Shelton Street, London, England, WC2H 9JQ. We trade as ResoFlow and operate the website at https://resoflow.co.uk.

For data protection matters, contact us at [email protected].

We are registered with the UK Information Commissioner’s Office (ICO), the UK’s independent data-protection regulator, under registration number ZC127147. We are not required to appoint a statutory Data Protection Officer; data-protection queries go to [email protected].

Controller and processor roles

ResoFlow is a B2B platform. Our relationship with you depends on who you are. Throughout this policy, “guests” means the people a venue serves through ResoFlow — the venue’s own customers (which is what a venue’s dashboard calls them): anyone who books or joins a waitlist, asks to be told when a table frees up, orders, buys a ticket, buys or receives a gift card, or joins a loyalty scheme.

We are a data controller for:

  • Tenant accounts (the business that signs up for a subscription or product).
  • Caleonix's own billing and payment records.
  • Site-visitor analytics, cookies, and marketing communications we send to tenants.
  • Support tickets and chat transcripts directed to ResoFlow.

We are a data processor for:

  • All guest data uploaded by tenants (bookings, customer profiles, history).
  • Tenant-side staff data (members the owner adds to their dashboard and PIN portal).
  • Outbound communications a tenant sends to its guests through our Resend and Twilio infrastructure.

The Data Processing Agreement governs the processor relationship between Caleonix and each tenant.

2. What information we collect

In short: We collect information directly from tenants, on behalf of tenants from their guests, and automatically when you use our Services.

Information from tenants (we are controller)

  • Owner name, email address, mobile phone number.
  • Business name, address, and basic operating details.
  • Authentication credentials. Passwords are hashed by Firebase Authentication; we never see your password in plain text.
  • Payment method. Card details are handled directly by Stripe; we receive only non-sensitive references (such as the card brand, last four digits, and Stripe token references) — never the full card number.
  • Plan, any standalone products you subscribe to, your chosen business type, usage counters, and audit log of administrative actions.

Where a venue has not opted out, the public details it already publishes (its name, town, cover image or logo, strapline and a link to its booking page) may also appear in our venue directory at resoflow.co.uk/venues while the venue is actively used. The directory never shows information about guests.

When you create an account we record which version of the Terms, the Privacy Policy and the Data Processing Agreement you accepted, when you accepted them, and your confirmation that your business operates in the UK. We keep this record with your account as evidence of the agreement, for as long as the account exists and for 30 days afterwards.

Venue setup codes (prospective customers)

Where we visit or speak with a prospective venue, we may prepare its account setup in advance. For this we store the venue’s own details (its name, address, telephone number, contact email address and website), the proposed configuration (such as opening hours, table layout and operating preferences), and the name and email address of the owner we are dealing with. Where the venue gives us a logo or cover image for their public pages, we hold those too.

Access to the prepared setup is given by a one-time setup code, which we share with the owner privately ourselves — we never send one automatically. The code works once, and only for the email address we recorded. While we prepare a venue’s setup we keep those details — and any files and answers sent through a setup upload link — for 30 days after we last worked on the setup, and never more than 90 days from the day we started it. They are deleted then, or as soon as the setup is cancelled, and once a venue has used it what was prepared becomes part of that venue’s account.

Where we are setting a venue up remotely, we may also send the owner a private upload link so they can send us what we need to prepare the account: a logo and photos, a menu, photos of the rooms, and typed details such as opening hours, cancellation wording, the first names and roles of their team and their Google review link. The owner can also choose to send a list of their customers or the bookings they already hold, so that we can move them across; the venue remains responsible for making sure it is entitled to share those details with its booking system. The link can only be used to send us files and answers — it cannot open an account — and it stops working when the setup code does.

We keep this information for up to 30 days. If the code is not used within that time it expires and the information, including any images, is automatically deleted. If it is used, the prepared setup becomes part of the venue’s account records and is kept under the tenant retention periods in section 8.

Launch and industry-interest waitlist (prospective customers)

If you ask us to keep you posted — for example by registering interest in ResoFlow for your type of venue on our website, or during signup when we are not yet ready for your industry — we store your email address, the industry you told us about (where you chose one, or the short description of your business you typed if you chose “Something else”), the exact consent wording you agreed to and when, and basic anti-abuse details (a one-way-hashed network identifier and your browser’s user-agent string). We use this only to confirm your signup and to email you when ResoFlow is ready for you — it is never used for general marketing without a fresh choice from you.

You can remove yourself from the list at any time using the link in your confirmation email, or by contacting us (section 14) — either way we delete your entry.

Booking a call with us (prospective customers)

If you book a call with us on our website, we collect your first name (and last name if you give it), email address, phone number, the topic you choose, any notes you add, and your chosen time slot, together with a one-way-hashed network identifier used only to prevent abuse of the booking form. We use these details only to arrange and hold the call — including sending you a confirmation email with a calendar invite, and a cancellation email if we have to cancel — never for general marketing without a fresh choice from you.

Information from venue staff (we process it for the venue)

When a venue owner adds staff members to their dashboard, we process the following personal data on the venue's behalf as a data processor. The venue is the data controller; we hold this data under its documented instructions. See our Data Processing Agreement for full details.

  • Identity — name, username (chosen by the venue), assigned role, and any per-staff permission overrides set by the owner or admin.
  • Contact (optional) — work email address, work phone number, and job title, only if the owner chooses to record them.
  • Security — a one-way cryptographic hash of the staff PIN (we never see or store the plaintext PIN), a device token bound to a specific browser or tablet the owner has enrolled, and the IP addresses the staff member signs in from. Sign-in IPs are kept only as needed for security alerts and the venue's audit log.
  • Preferences — the staff member's chosen theme (light, dark, or system).
  • Push alerts (optional) — if the venue turns on alerts for a paired staff device (the ResoFlow app on a tablet or phone), we store a push token for that device (an identifier issued by the device’s browser or operating system), the device type and browser, and when it was last used, so we can send the alerts the venue asked for. The alert itself carries a first name and initial, a party size and a time — never a phone number, email address, allergies or notes. It is deleted when alerts are turned off, when the device is removed, or after 60 days of not being used.
  • Activity metadata — last sign-in time and active session records (device, last-seen time) so the owner can review and revoke sessions.

Staff personal data is displayed only to authorised accounts at the venue. Staff can view and edit their own optional contact details and theme preference from the staff portal Profile page.

Information from guests (we process it for the venue)

  • Contact details — name, email address, and phone number.
  • Booking details — date, time, party size, table assignment, any special-occasion or other notes you add, and your booking history. Date of birth is optional and used only for birthday messages where the venue enables them and, if you are a loyalty member of a scheme with a birthday gift, an automatic once-a-year birthday bonus on your loyalty card.
  • “Notify me” requests — If a date is fully booked, a guest can leave their name and their email address or mobile number, with the date, the times and the party size they wanted, to be told if a table frees up. When a booking on that date is cancelled, we send each person on the list one email or text, in the order they asked; the first to book gets the table.
  • Allergies and dietary preferences — see section 3.
  • Pre-orders — where a venue offers pre-ordering for larger bookings and your party chooses its food in advance: the dishes selected (with any choices and quantities), any first names the organiser adds against a dish so the kitchen knows who it’s for, and the order’s total. You may make these choices while placing your booking, or afterwards from your booking’s manage page. This is stored on the booking and visible to the venue. If the venue takes payment for pre-orders online, your card is handled directly by Stripe on the venue’s own Stripe account (never by ResoFlow) and we hold only Stripe payment references.
  • Order & Pay orders (at the table, collection and delivery) — where a venue offers ordering from your table by QR code, or ordering ahead for collection or delivery: the dishes you order (with any choices, quantities and notes you add for the kitchen), your table (for at-table orders), any tip, your email address (so we can send your receipt and any service emails about your order — for example when it’s ready, or if the venue has to reject and refund it) and, optionally, your name. For collection and delivery orders we also collect your name and phone number (required, so the venue can reach you about your order) and the time you asked for. For delivery orders we collect your delivery address and any door notes you add for the driver — the address is used to check it falls inside the venue’s delivery area and to work out the delivery charge (see the Google Maps entry on our Sub-processors page), and it is shown to the venue and its driver to deliver your order. If the venue accepts cash, we record whether you chose to pay in cash at hand-over. If a card refund fails and the venue records a completed bank or cash repayment, we keep the amount, method, date, transaction or receipt reference, reason and staff authorisation, linked to the original failed refund. We distinguish these venue-recorded repayments from refunds verified by Stripe. These fields must not contain bank account details or card numbers. If outstanding gift value is returned on a linked replacement card, we retain its amount, expiry and link to the original card and order, with the reason and staff authorisation. We do not store the full replacement code on the gift-card record. If you have a customer account and are signed in, you can save delivery addresses to your account for next time — you can edit or delete saved addresses at any time from your customer portal, and they are removed if you ask to be erased. If you’re a member of that venue’s loyalty scheme, your email address is also used to add the visit to your loyalty balance — exactly as a booking visit would be. Paying for a table order creates or updates the guest profile the venue keeps about you, exactly as making a booking does, and the checkout offers the same choice about the venue’s marketing: we record whether you left the marketing box as it was or ticked it to opt out, together with evidence of that choice — when it was made, which page it was made on, the exact wording you were shown, and the choice itself — so the venue can demonstrate the basis for any marketing it later sends. If your order contains alcohol we also record your confirmation that you’re 18 or over. Your card is handled directly by Stripe on the venue’s own Stripe account (never by ResoFlow) and we hold only Stripe payment references.
  • Reviews you leave — where a venue switches customer reviews on: your star rating, the words you write and the display name you choose to show publicly, held with a pseudonymous link to the completed order, booking or event ticket the review came from — never your email address on the review itself. You can edit your review for 30 days. The venue can reply publicly and can report an abusive review to ResoFlow; the venue cannot delete your review, though ResoFlow can remove one the venue has reported. If you ask to be erased, your reviews are deleted outright.
  • Profile the venue keeps about you — a VIP flag, tags (e.g. “regular”), free-text notes, a seating preference, and family details for your party (number of children, whether a highchair or children’s menu is needed). This is entered and controlled by the venue.
  • Activity the platform derives for the venue — attendance history (no-shows, cancellations, abandoned waitlist places), lifetime spend on deposits and tickets, average party size, and previous names or phone numbers seen on your profile.
  • Event tickets — where a venue runs ticketed events: the buyer’s name, email and phone, and any additional attendee names the buyer provides. If you save a ticket to a device wallet, a device identifier and push token, stored only so we can send updates if the event details change.
  • Payments (deposits / no-show protection) — where the venue switches these on. Your card is handled directly by Stripe on the venue’s own Stripe account and is never seen, stored, or processed by ResoFlow; we hold only Stripe references (such as a token, a saved-card mandate for no-show protection, and any charge or refund reference).
  • Loyalty scheme membership — where a venue runs a loyalty scheme and you choose to join it: your membership status and join details (including a random member code used for scanning your card), your stamp or points balance and lifetime totals, and a history of each earn, redemption, and any staff adjustment. On schemes that award points by the amount you spend, this includes the single bill amount a staff member types in for a visit — there is no connection to the venue’s payment systems and no card-payment feed. Because a loyalty scheme is, by nature, a record of your visits (and, on spend-based schemes, your spend) at that venue, this recording only happens for the scheme you actively joined, so the venue can run it — you are never enrolled automatically, and you can end your membership yourself at any time from your customer portal (your remaining balance and rewards progress are permanently cleared when you leave). If you save your loyalty card to a device wallet, a device identifier and push token, stored only so your card can update when your balance changes.
  • Loyalty invitations — If you join a venue’s loyalty scheme through another member’s invitation, the venue’s records note which member invited you (their internal customer reference and the date) so the venue can pay the rewards it promised. The inviting member is never shown your details, and you are never shown theirs; ResoFlow does not contact a person who has been invited but has not joined.
  • Promotions and offer codes — where a venue runs its own promotions: which offer codes you have used, when, and on what, so the venue can honour per-person limits and see how an offer performed; and, if you save an offer to your loyalty account, that saved coupon and whether it has been redeemed.
  • Gift cards — where a venue sells gift cards, a gift card record involves up to two people: the buyer (for online purchases, their name and email; for purchases at the venue these are optional) and, where the card is a gift, the recipient (their name and email, plus the buyer’s personal message, so the card can be delivered and its balance updates and expiry reminder sent). The spendable code itself is stored only in a protected one-way form; each card also carries its value, balance, movement history, expiry, and — for online purchases — Stripe payment references only (your card is handled by Stripe on the venue’s own account, never by ResoFlow). Buying a gift card also creates or updates the guest profile the venue keeps about you (the buyer) with the purchase details, as making a booking does — for venue purchases only where you gave an email address. Buying alone never signs you up to marketing: the gift page offers an optional tick-box to receive the venue’s news and offers, and we record a marketing choice only if you tick it — together with evidence of that choice (when it was made, which page it was made on, the exact wording you were shown) — while an unticked box records nothing at all. Recipients never receive marketing from us or the venue on the basis of receiving a gift card, and no customer profile is created for a recipient. If you save a gift card to a device wallet, a device identifier and push token, stored only so the pass can update when the balance changes.

We do not sell or otherwise disclose guest data outside the strict bounds of delivering the Services to the venue you booked with. Guests should direct questions to the venue in the first instance.

Information from other sources. A venue may also give us guest data it already holds, rather than you entering it directly — for example by importing its existing customer list into its account. We process any data imported this way on the venue’s behalf in exactly the same way as data entered directly through the platform.

Information collected automatically

  • IP address, browser type, operating system, and device information.
  • If you turn on push alerts on one of your own devices (the ResoFlow app on your phone, tablet or computer), a push token for that device (an identifier issued by its browser or operating system), the device type and browser, when it was last used, and your alert choices (which alerts, and any quiet hours). The token is deleted when you turn alerts off, sign out, remove the device, or after 60 days of not being used.
  • Cookies and similar technologies (see our Cookie Policy).
  • Camera (event-ticket scanning) — where a venue scans event tickets at the door, a staff device may request permission to use its camera to read the ticket’s QR code. No photo or video is captured or stored — only the ticket code is decoded to check the ticket in.
  • Map images on venue pages — where a venue’s public page shows a map of its location, your browser fetches that map image directly from Google Maps, so Google receives your IP address and browser details alongside the venue’s address. It is a plain image — no cookies are set and none of your personal details are sent. See our Sub-processors page.
  • Sentry error reports, which may contain user IDs and technical context necessary to debug a fault, plus — on signed-in screens only — a short, fully masked session replay around an error. See our Cookie Policy for the full detail.
  • Email engagement — marketing emails sent through the platform, and certain service emails a venue sends its customers (such as a loyalty birthday treat), contain a small tracking pixel and tagged links that record whether the email was opened and which links were clicked, so the sender can measure how it performed. For marketing a venue sends, the venue is the sender and we act on its behalf; for the occasional service or product email we send you about your own ResoFlow account, we are the sender. See our Cookie Policy.

Support correspondence

When you contact us via the in-app chat or by emailing support@, billing@ or [email protected], we collect:

  • The messages you send and any file attachments you choose to include.
  • Your IP address and browser user-agent at the time you send the message.
  • Interaction logs from Rezo, our AI support assistant (an EU-hosted Google large-language model). Internal model diagnostics are stripped from any data export.
  • Pictures you attach in a support conversation are read by Rezo (the same EU-hosted model) so it can help with what you have shown it — a screenshot of a settings page, for example. They are never used to train any AI model.
  • When you ask Rezo whether a booking email or text message was sent, it can look up recent delivery records for your own venue — the recipient (shown partly masked), the message type, whether it was sent and when. It never sees the message contents and never another venue’s records.
  • Recent support conversations are summarised to help with your next one: when a conversation with Rezo closes, a short summary (who asked, the topic, the outcome, the date — never the transcript) is kept for 30 days so Rezo can pick up where you left off. You can switch this off at any time in Account → Personal details.

For external (non-tenant) senders who email support@ or use the chat on our website: we also retain the sender email, the name you give us (first name and surname, where you provide them so a reply can reach you), IP and user-agent on the conversation record so we can reply and identify duplicate or abusive senders.

We use Google sign-in and email/password authentication only. We do not use Apple, Microsoft, Facebook, or X as login providers and we do not buy intent data or social-network friend lists from third parties.

3. Special category data — allergies and dietary preferences

In short: Allergies and dietary information are special category data under UK GDPR. The venue is the controller and relies on your explicit consent (Article 9(2)(a)); ResoFlow processes it only on the venue's behalf.

Allergy and dietary information is treated as special category data under Article 9 of the UK GDPR. The venue is the controller for this data and relies on your explicit consent (Article 9(2)(a)) when you choose to tell it about an allergy or dietary need so it can be catered for. You provide it voluntarily and can ask the venue to remove it at any time.

ResoFlow processes this information only on the venue's instructions, as its processor — displaying it accurately to authorised staff. The venue is responsible for ensuring its kitchen and front-of-house teams act on it.

4. How we process your information

In short: We process personal data only for the specific purposes set out below.

  • To create and maintain tenant accounts.
  • To enable tenants to manage bookings, communicate with guests, and run their venue.
  • To process subscription payments and send invoices.
  • To email you about your account credit: Account credit returned — sent when a refund puts money back onto your account credit; Account credit expiring — sent 30 days before some of your account credit expires.
  • Where a venue enables deposits or no-show protection: to provide the technical means, through Stripe Connect, for the venue to collect a deposit, save a guest's card, or charge a no-show fee on its own Stripe account. A no-show fee is charged when the venue deliberately marks a booking as a no-show, or — where the venue enables it — automatically when you cancel after the free-cancellation deadline you agreed to at booking; either way the fee and that deadline are shown to you before you confirm. ResoFlow facilitates the payment on the venue's behalf and does not handle the guest's card details; the deposit or no-show fee is paid to the venue, although ResoFlow may deduct a platform fee.
  • Where a venue runs a loyalty scheme or promotions and you take part: to record your membership and keep your balance and earning history accurate, to validate offer codes and apply per-person limits, to update a loyalty card you have saved to a device wallet, and to send the scheme’s emails on the venue’s behalf. Those emails are: a membership confirmation or welcome when you join; a reward unlocked notice when you earn a reward (you can switch this off in the customer portal); an optional monthly points digest, which is a marketing email — only sent where the venue switches it on and you are opted in to that venue’s marketing, and always with an unsubscribe link; and a scheme closure notice if the venue closes its scheme. Separately, two data-protection service messages are sent to scheme members even if you have opted out of marketing, because they are administration of the scheme and record you hold: a warning before your customer record is deleted at the end of the venue’s retention period, and a warning before an unused loyalty balance expires through inactivity (where the scheme sets an expiry).
  • Where a venue sells gift cards and you buy or receive one: to process the purchase and deliver the card (including on a future date the buyer chooses), to keep its balance and movement history accurate, to update a gift card you have saved to a device wallet, and to send the card’s transactional emails on the venue’s behalf — the buyer’s receipt, the gift email carrying the card, a balance update after each redemption (where the venue has these on), and one expiry reminder about 30 days before the card expires. These are service messages about value you hold — never marketing — and receiving a gift card never adds you to any marketing list.
  • To respond to support requests via the in-app chat and email channels.
  • To provide AI-assisted first-line support replies from Rezo, our support assistant, through an EU-hosted Google large-language model (see Sub-processors). We do not use support correspondence to train any AI model: the model is off-the-shelf, with no fine-tuning, and there is no per-tenant or per-conversation persistence at Google.
  • So that Rezo can answer questions about your own setup, each reply includes a short summary of your venue’s current settings (for example your booking window, deposit rules and which features are switched on), your plan and your current usage figures, and the page of the dashboard you are on. It never receives your customers’ personal data, and nothing in that summary is used to train any AI model.
  • If you leave your email address with Rezo on our public contact page so that a member of our team can follow up (for example after a pricing question), we store that address together with the exact consent wording you agreed to and use it only for that follow-up. This is a sales and marketing purpose based on your consent; you can withdraw it by replying to the follow-up or emailing [email protected].
  • To show a signed-in account owner their own billing summary (current plan, next billing date and amount, and the last four digits of the card on file) inside the support chat, on request and only after they re-confirm their identity. The figures are assembled on our servers from Stripe and shown only to the verified owner; our AI assistant never receives them.
  • To read a menu a venue chooses to import (a photo, PDF or menu web page) using the same EU-hosted Google large-language model, so the venue’s dishes can be set up automatically. The uploaded file is deleted as soon as it has been read and is never used to train any AI model. The same read happens when we import a menu for you from a file you sent us through a setup upload link: the copy we read is deleted as soon as it has been read, and the file you sent stays with your other setup uploads until those are deleted.
  • Floor-plan import. If you choose to import a floor plan from a picture, the picture you upload (a photograph, drawing, printout or screenshot) is sent to the same EU-hosted Google model to read the table numbers, seat counts, shapes and positions. Photographs are stripped of camera and location metadata in your browser before upload. The picture is deleted the moment it has been read, whether or not the read succeeded, and is never used to train any model. Only the table list you review and save is kept, as part of your floor plan. The same applies when we read a floor plan for you during an in-person setup visit, or from a picture you sent us through a setup upload link: the copy we read is deleted in the same way, and only the table list you checked with us is kept, on your setup code until you apply it. A picture sent through an upload link reaches us exactly as you sent it — it is not stripped of camera or location details first — and the original stays with your other setup uploads until those are deleted.
  • Where a venue uses the optional AI marketing assistant in the campaign composer: to draft the venue’s campaign text (and, where enabled, a campaign image) from the brief the venue types, using the same EU-hosted Google large-language model. The model receives only the venue’s own facts — its name, the brief, the design’s fields, anything the venue has already typed, the short descriptions the venue has saved on its own image-library photos (so the AI can suggest fitting pictures), and the details of a promotion the venue attaches. It never receives customer personal data — no names, email addresses, booking history or customer lists — and nothing sent to it is used to train any AI model.
  • Where a venue asks the AI to draft a promotion: to suggest the shape of one offer from the goal the venue types, using the same EU-hosted Google large-language model. The model receives only the venue’s own facts — its name, the goal it has typed, the promo codes it already uses (so the same code is not suggested twice), and whether Order & Pay and events are switched on. It never receives customer personal data— no names, email addresses, booking history, customer lists or spend figures — and nothing sent to it is used to train any AI model.
  • To find the right help guide when you search our Help Centre. The words you search for are sent to an EU-hosted Google text-embedding model, which turns them into a list of numbers so we can match them by meaning against our own help guides rather than only by exact wording. This model does not write text and does not answer your question — it only compares meaning. Your search wording is never used to train any AI model.
  • Where a venue uses the optional “Check my wording” tool in their policy settings: to give that venue an advisory read of the policy wording they have written, using the same EU-hosted Google large-language model, so we can point out anything that appears to contradict the fixed clauses we provide. It runs only when the venue clicks the button, it is advice only — it can never block or change what they save — and the wording is never used to train any AI model. The text checked is the venue’s own policy copy, not your personal data.
  • To forward support messages to Slack so we can monitor them and, where needed, respond (see Sub-processors).
  • To monitor performance, detect bugs, and improve the platform.
  • To detect and prevent fraud, abuse, or unauthorised access.
  • To comply with our legal obligations (tax records, ICO orders, court orders).
  • With your consent, to send marketing or product-update emails.

Aggregated and anonymised information

We may also create and use aggregated or anonymised information — statistics and insights that do not identify, and cannot reasonably be used to identify, any individual (for example, total bookings processed, or trends in platform usage). Because this information is not personal data, we may use and share it freely, for purposes such as understanding how the Services are used, producing reports, and improving the platform.

6. Who we share your information with

In short: We share data only with carefully selected subprocessors that help us deliver the Services. Each is bound by a Data Processing Agreement.

The full list of current subprocessors lives at /policies/subprocessors. Categories include:

  • Payment processing.
  • Transactional and marketing email delivery.
  • SMS delivery (with per-tenant subaccounts).
  • An internal support-messaging bridge — support correspondence (name, email, message text and any image attachments) is forwarded so we can monitor it and respond where needed.
  • Cloud hosting, database, authentication, and the AI model behind Rezo, our support assistant.
  • CDN, DDoS protection, web application firewall, bot management, and cookieless performance analytics.
  • Website analytics, error tracking, and uptime monitoring.
  • Event-ticket and loyalty-card wallet passes (Apple and Google Wallet) — a ticket pass carries the ticket-holder name and event details; a loyalty-card pass carries the member's name, balance and member code. A pass exists only where you choose to save it to your wallet. If a venue switches it on, the wallet pass (Apple Wallet or Google Wallet) carries the venue's own address location so your phone can show the card when you are nearby. Your phone decides this by itself; your location is never sent to the venue or to ResoFlow. If a venue has saved its address, an event-ticket pass (Apple Wallet or Google Wallet) also carries that address location so your phone can show the ticket when you arrive at the venue. Your phone decides this by itself; your location is never sent to the venue or to ResoFlow.
  • Address geocoding and autocomplete — business address data only, no customer personal data.

The named providers behind each category, where they process data, and a link to each one’s data-processing terms are on the Sub-processors page.

We do not sell personal data.

Venue-configured integrations (Zapier / webhooks)

Where a venue chooses to switch on the Zapier or webhook integration, booking data — including a guest’s name, email address, phone number and any booking notes — is sent to the third-party URL the venue configures. The venue is the controller of that onward transfer and is responsible for the receiving tool and for any further processing it performs. ResoFlow only delivers the data to the destination the venue has set up; these destinations are not ResoFlow sub-processors.

Business transfers

If we are involved in a merger, acquisition, or sale of assets, we will provide notice before personal data is transferred and becomes subject to a different privacy policy.

7. International transfers

In short: Some of our subprocessors are based outside the UK. We use the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (with the UK Addendum where applicable) to safeguard those transfers.

Our Firestore database and Cloud Functions are hosted in Google Cloud's europe-west1 region (Belgium). Sentry hosts our error data in the EU. Cloudflare sits in front of our public websites (and, where a venue enables the optional Your domain product, in front of that venue's own connected domain) as a global edge network: request metadata such as your IP address and browser details transits the nearest Cloudflare data centre — including UK and EU locations — for security filtering and certificate handling. Cloudflare Turnstile also runs a bot check on our public forms; because we run it in invisible mode, Cloudflare requires us to point you at its Turnstile Privacy Addendum, which explains what that check collects. Other subprocessors are listed at /policies/subprocessors along with their primary processing location.

Where data leaves the UK, we rely on:

  • The UK International Data Transfer Agreement (IDTA) for UK to US transfers.
  • The EU Standard Contractual Clauses (SCCs) for EU to US transfers.
  • The UK Addendum to the EU SCCs where the underlying agreement uses EU SCCs.
  • Where a US subprocessor is certified under the EU-US Data Privacy Framework and its UK Extension, that framework may additionally apply alongside the mechanisms above.

Each subprocessor’s data-processing terms incorporate one of these mechanisms.

This description of our transfer mechanisms is provided on a best-effort basis and is not legal advice.

8. How long we keep your information

In short: We keep personal data only for as long as we need it for the purposes we collected it, plus any period required by law.

Data categoryRetention period
Active tenant account dataWhile the account is open + 30 days
Tenant payment / billing recordsUp to 7 years (HMRC’s 6-year requirement plus a short safety buffer)
Guest profile dataA period the venue chooses (default 2 years; maximum 3 years) measured from the guest’s last activity. Loyalty activity (earning, redeeming) counts as activity and restarts the clock. Loyalty members receive email warnings before their record is deleted
Loyalty membership and balanceLives with the guest profile above — kept while the record is kept, deleted with it (including on an erasure request, which permanently destroys the membership and any remaining stamps or points)
Loyalty earning / redemption history and offer-code usage historyLine-by-line detail kept for 2 years; older loyalty entries are then deleted (only the balance is kept) and older offer-usage entries are deleted
Loyalty membership confirmation links7 days, then the unused link expires and is deleted
Guest booking records (no payment attached)The same retention setting the venue chooses for guest profiles (default 2 years; maximum 3 years), measured from the booking date
‘Notify me’ requests (the name, email address or mobile number, date, times and party size a guest left when a date was fully booked)Deleted the day after the date they asked about, or sooner if they book or remove themselves.
Guest payment records (bookings that carry a deposit, full prepayment, event ticket, paid extras, pre-order payment, charged no-show fee or gift-card payment — and paid Order & Pay orders, whether at the table or for collection or delivery)The payment facts (amounts, dates, Stripe references) are kept as financial records for the life of the venue’s account. Once the venue’s retention period for the record passes (or if the guest asks to be erased), the guest’s personal details — name, contact details, phone number, delivery address and door notes, order and kitchen notes, allergies, dietary preferences, per-guest names — are permanently removed from the record; only the anonymised payment facts remain
Payment-link records (the secure page a guest pays on for a deposit, extras, pre-order, tickets, gift card, order top-up or tip)The person’s details are blanked once the venue’s retention period passes, and the record itself is deleted 13 months after it was created. The booking, order, ticket or gift-card record it paid for is the money record and follows the row above
Gift card records (value, balance, movement history, buyer/recipient contact details, Stripe payment references for online purchases; the spendable code is stored one-way hashed)A card with remaining balance is never auto-deleted. Spent, expired, and voided cards are retained as anonymisable financial records for the life of the venue’s account. If a buyer or recipient asks to be erased, that person’s identity details are removed from the card while the card itself stays live and spendable
Scheduled gift card deliveries (the card’s code held for a future delivery date the buyer chose)Until the gift email is sent or the delivery is cancelled, then deleted
Guest deposit / no-show fee transaction references (Stripe identifiers only; the card itself is held by Stripe, not by us)A live saved-card mandate is voided when the guest is erased, and is never charged after the booking is resolved. A charged deposit or no-show fee reference is retained as an anonymised financial record for the life of the venue’s account (see “Guest payment records” above)
Stranded payment recovery records (a guest was charged but the booking, order, event ticket or gift card could not be completed — the payment references plus the payer’s contact details, kept so we can refund automatically and send an apology)The payer’s contact details are removed automatically as soon as the recovery completes (the money is refunded, or the purchase turns out to have succeeded after all). If a refund needs manual attention, the contact details are kept only until it is resolved — we keep them for that period so the money can be returned (our contract and legal-claims bases). The anonymised payment facts are then retained as financial records for the life of the venue’s account (see “Guest payment records” above)
Order drafts (an order-and-pay checkout that was started but never paid for — the items chosen plus any contact details entered)Deleted as soon as the order is placed. An abandoned checkout expires after 48 hours and is then automatically deleted
Push alert tokens (the device identifier that lets us send alerts to a phone, tablet or computer that turned them on)Until alerts are turned off on the device, the person signs out (their own devices), the venue removes the device, or 60 days after the device was last used — whichever comes first
Routine audit logs (administrative actions, settings changes, logins)24 months on every plan (how far back they can be viewed in-app varies by plan)
Billing-related audit entries (refunds, plan changes, subscription cancels)7 years (UK HMRC requirement; copied to a tamper-resistant retained billing log)
Analytics aggregates (daily and monthly KPI snapshots, usage history)24 months rolling
SMS delivery logs (may contain templated guest details, e.g. a name in a booking confirmation)24 months rolling
Email delivery logs (the sent-email queue record — may contain templated guest details, e.g. a name in a booking confirmation)90 days, then deleted. Sends that failed permanently are kept for up to 12 months so we can investigate delivery problems, then deleted
Erasure records (one-way hashed identifiers only, no readable personal data; used so deletions survive backup restores)60 days
Tenant data export ZIPs (downloadable copy of your data)Until the secure download link expires (24 hours)
Scheduled analytics report PDFs (higher-tier plans)Until the secure download link expires (30 days)
Monthly accounts packs (Plus plan and above — a PDF summary and spreadsheets of a venue’s own sales, refunds, fees and VAT for a month; payments are listed by reference only, so a pack holds no customer names or contact details)Seven years from the month the pack covers, or until the venue’s account is closed, whichever comes first. An emailed download link stops working after 30 days
Emailed reports (“Email this” on a Reports tab)A report emailed with Email this is kept as a PDF for up to 8 days, then deleted; its link works for 7 days. It holds no customer names.
Sentry error reportsA short rolling period set by our error-tracking provider (Sentry)
Tenant support threads (in-app chat + emails to support@/billing@/policies@)Open conversations: indefinite while active. Resolved: 24 months, then archived. Archived: 6 months, then permanently deleted.
External (non-tenant) support threadsResolved threads are archived, then permanently deleted after a further retention period.
Support attachments (image uploads on a thread)Stored alongside the parent thread; deleted when the thread is hard-deleted.
Rezo conversation summaries (a short who / topic / outcome note written when a support chat closes — never the transcript)30 days, then automatically deleted. Switched off in Account → Personal details = no summary is written.
Email address left with Rezo on the public contact page for a sales follow-upKept with the conversation record under the external-thread schedule above, together with the consent wording shown at the time.
Cookie consent records6 months
Marketing consentUntil withdrawn
Marketing consent evidence (when a marketing choice was made, on which page, the exact wording shown, and the choice)Kept for as long as the marketing preference it evidences is relied on, and deleted with the guest’s profile (or on an erasure request). We keep the most recent evidence entries — a newer choice supersedes older ones
Backup snapshotsDaily backups retained 31 days, plus 7-day point-in-time recovery (managed by Google Cloud)
Deleted or terminated tenant accounts30-day window (during which you can request a final data export — see the Terms, section 13), then permanent deletion. Cancelling a paid subscription alone downgrades you to the free tier: the account stays open and this window does not start
Abandoned / incomplete signupsPermanently deleted 7 days after signup if onboarding is not completed
Venue setup codes (prospective customers — the venue’s own contact details, the owner’s name and email address, the proposed venue configuration, and any logo or cover image supplied)30 days after we last worked on the setup (each save, and anything the venue sends, starts the 30 days again), and never more than 90 days from the day we started it; an unused setup and everything held against it, including images, is automatically deleted when that time is up. Used codes become part of the venue’s account records
Files and answers a prospective customer sends through a setup upload link (a logo and photos, a menu, floor plan photos, typed opening hours, policies and team names, and — only if the owner chooses — a customer list or upcoming bookings)On the same clock as the setup they belong to (30 days after it was last worked on, never more than 90 days in all): deleted when the setup expires or is cancelled, and deleted once the code has been used (by then anything the venue asked us to set up is part of its account records)
Call bookings (prospective customers — name, email address, phone number, topic, notes and the chosen time slot from our book-a-call page)90 days after the call date, then automatically deleted
Launch / industry-interest waitlist signups (email address, chosen industry or your short business description, consent wording, anti-abuse identifiers)Kept while your registration waits for the launch you asked to hear about; deleted whenever you ask us to remove you — use the removal link in your confirmation email, or contact us any time

9. How we keep your information safe

In short: We use industry-standard technical and organisational measures, but no system is 100% secure. We acknowledge that risk transparently.

  • Encryption in transit and at rest.
  • Multi-factor authentication available on every account.
  • Audit logging of administrative actions.
  • Role-based access controls following least-privilege defaults.
  • Support access: ResoFlow staff may view a venue’s account data to provide support, investigate a fault or resolve a billing query. Viewing is read-only; changes are only made during a time-limited session the venue owner starts or approves — or, when the venue asks us in writing, a change of its name or web address — every access is recorded in the venue’s Activity Log, and the owner is emailed when a session ends or the web address changes. ResoFlow staff never see card numbers — those stay with Stripe.
  • Continuous Sentry monitoring and BetterStack uptime checks.

Despite these measures, no system can be guaranteed 100% secure. If you suspect unauthorised access to your account, contact [email protected] immediately.

10. Information from minors

In short: Account holders must be 18 or over. Guests booking a table should be 16 or over. We do not knowingly collect data directly from younger children.

Account holders and their staff must be aged 18 or over. Guests booking a table or buying a ticket should be aged 16 or over; the venue is the controller of guest data and is responsible for handling any younger guest’s data appropriately. A guest may also record family details about their party — for example, the number of children dining, whether a highchair is needed, or whether a children’s menu was requested. Where this information relates to a child, it is provided by the adult guest on behalf of their party; we do not collect information directly from young children or invite them to use the Services themselves.

If you believe we have inadvertently collected information directly from a minor, contact [email protected] and we will delete it promptly.

11. Your privacy rights

In short: Under the UK GDPR you have the right to access, correct, erase, restrict, port, and object to processing of your personal data. You can also lodge a complaint with the ICO.

If you are a guest, the venue you booked with — or bought from, ordered from, or whose scheme you joined — is the controller of your information — exercise your rights with them in the first instance (we assist them as their processor). The rights below describe how we handle requests where we are the controller (tenant account holders and people who contact us directly).

Under Articles 15 to 22 of the UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data erased ("right to be forgotten").
  • Restrict our processing of your data.
  • Receive your data in a portable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time.
  • Not be subject to fully automated decisions that have a legal or similarly significant effect.

Automated decisions. We do not make decisions about you using solely automated means that produce legal or similarly significant effects, such as profiling. A no-show fee is charged when a venue’s staff mark a booking as a no-show, or — where the venue enables it — automatically when you cancel after the free-cancellation deadline you agreed to at booking; either way the fee and that window are set by the venue and shown to you before you confirm. Loyalty earning and redemption are mechanical consequences of your own actions (a qualifying visit earns; a redemption you or staff trigger redeems) — any manual balance adjustment is made by a named member of the venue’s staff with a recorded reason, never automatically.Rezo, our AI support assistant, answers support questions directly, but it takes no actions on your account and makes no decisions about it — every change stays a click a person makes.

We respond to verified requests within 7 working days. To exercise your rights:

  • Tenants: email [email protected] from your account email to request a copy of your data (we produce the export and send a secure download link) or to delete your account.
  • Guests: contact the venue first. If they cannot help, email [email protected] and we will forward the request.
  • External (non-tenant) senders who have emailed support@, billing@ or policies@ can request access or deletion of their support correspondence by emailing [email protected] from the same address.

You also have the right to complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

12. Do-Not-Track signals

In short: Analytics only run with your explicit consent, so a Do-Not-Track browser is covered by default. We do not use your data for advertising.

ResoFlow does not run advertising campaigns or build profiles for ad targeting. Analytics and optional tracking cookies never run without your explicit consent through our cookie banner, so a Do-Not-Track browser is covered by default — nothing runs unless you opt in. See our Cookie Policy.

13. Updates to this policy

In short: We will give 14 days advance notice in-app and by email before any material change takes effect.

For non-material changes (typo fixes, formatting, clarifications) we will update the "Last updated" date at the top of this page without separate notice.

14. How to contact us

For privacy and data protection matters, email [email protected].

By post:
Caleonix LTD (Company No. 17162652)
71-75 Shelton Street
London
England, WC2H 9JQ
United Kingdom

Related documents

Please also refer to our main Terms of Service and our Cookie Policy.