Skip to main content
ResoFlow

Privacy Policy

Last updated: 12 August 2026

At a glance

This summary is for convenience only — the full text below governs. Each point links to the section it summarises.

  • Who looks after your dataResoFlow is a trading name of Caleonix LTD, registered with the ICO (ZC127147). We are the data controller for venue accounts and our own site and support; for guest data — bookings, tickets, gift cards, loyalty and orders — the venue the guest dealt with is the controller and we process it on the venue’s behalf.
  • What we collectFor venues: account, business and payment details — card details are handled by Stripe, never held by us. On venues’ behalf: guests’ contact details, bookings, orders, tickets, gift cards, loyalty balances and the profile a venue keeps about its guests. Plus automatic data such as IP address, browser and device information.
  • Extra care for allergiesAllergy and dietary information is special category data. The venue is the controller and relies on the guest’s explicit consent when a guest chooses to share it, and guests can ask their venue to remove it at any time.
  • How we use itTo run the Services — bookings, payments, loyalty, gift cards, ordering and support (including an EU-hosted AI assistant; support correspondence is never used to train any AI model) — to keep the platform reliable and secure, to meet legal obligations, and, with consent, to send marketing.
  • Our lawful basesPerformance of contract for delivering the Services; legitimate interests for things like fraud prevention, security and service emails; consent for marketing, non-essential cookies and allergy data; and legal obligation for tax and regulatory records. Consent can be withdrawn at any time.
  • Who we share it withA small, vetted list of subprocessors, published at /policies/subprocessors — payment, email, SMS, hosting and similar providers. We never sell personal data. Where a venue switches on its own integration (Zapier or a webhook), that onward transfer is the venue’s own, to a destination the venue configures.
  • Where it livesOur database and functions are hosted in Google Cloud’s europe-west1 region in Belgium. Where a subprocessor takes data outside the UK, we rely on recognised transfer safeguards — the UK IDTA, or the EU Standard Contractual Clauses with the UK Addendum.
  • How long we keep itOnly as long as needed, with the full retention table in section 8. Guest profiles are kept for a period the venue chooses (default 2 years, maximum 3, from last activity); payment records keep their anonymised money facts for the life of the venue’s account while the person’s details are removed; billing records are kept up to 7 years for HMRC.
  • How we protect itEncryption in transit and at rest, multi-factor authentication available on every account, audit logging and least-privilege access controls — while being honest that no system can be guaranteed 100% secure.
  • Your rightsAccess, correction, erasure, restriction, portability, objection, and withdrawing consent. Guests should contact their venue first — it is the controller, and we forward requests if the venue can’t help. We respond to verified requests within 7 working days, and you can always complain to the ICO.
  • No ad trackingWe don’t run advertising campaigns or build profiles for ad targeting, and analytics never run without your explicit consent — so a Do-Not-Track browser is covered by default.
  • If this policy changesWe give 14 days’ advance notice, in-app and by email, before any material change takes effect; minor clarifications just update the “Last updated” date at the top.

1. Who we are

In short: ResoFlow is a trading name of Caleonix LTD, a UK company. We act as the data controller for our own tenants and as a data processor for the guests that tenants serve.

Caleonix LTD (company number 17162652) is a company registered in England and Wales with its registered office at 71-75 Shelton Street, London, England, WC2H 9JQ. We trade as ResoFlow and operate the website at https://resoflow.co.uk.

For data protection matters, contact us at [email protected].

We are registered with the UK Information Commissioner’s Office (ICO), the UK’s independent data-protection regulator, under registration number ZC127147. We are not required to appoint a statutory Data Protection Officer; data-protection queries go to [email protected].

Controller and processor roles

ResoFlow is a B2B platform. Our relationship with you depends on who you are. Throughout this policy, “guests” means the people a venue serves through ResoFlow — the venue’s own customers (which is what a venue’s dashboard calls them): anyone who books or joins a waitlist, orders, buys a ticket, buys or receives a gift card, or joins a loyalty scheme.

We are a data controller for:

  • Tenant accounts (the business that signs up for a subscription or product).
  • Caleonix's own billing and payment records.
  • Site-visitor analytics, cookies, and marketing communications we send to tenants.
  • Support tickets and chat transcripts directed to ResoFlow.

We are a data processor for:

  • All guest data uploaded by tenants (bookings, customer profiles, history).
  • Tenant-side staff data (members the owner adds to their dashboard and PIN portal).
  • Outbound communications a tenant sends to its guests through our Resend and Twilio infrastructure.

The Data Processing Agreement governs the processor relationship between Caleonix and each tenant.

2. What information we collect

In short: We collect information directly from tenants, on behalf of tenants from their guests, and automatically when you use our Services.

Information from tenants (we are controller)

  • Owner name, email address, mobile phone number.
  • Business name, address, and basic operating details.
  • Authentication credentials. Passwords are hashed by Firebase Authentication; we never see your password in plain text.
  • Payment method. Card details are handled directly by Stripe; we receive only non-sensitive references (such as the card brand, last four digits, and Stripe token references) — never the full card number.
  • Plan, any standalone products you subscribe to, your chosen business type, usage counters, and audit log of administrative actions.

Venue setup codes (prospective customers)

Where we visit or speak with a prospective venue, we may prepare its account setup in advance. For this we store the venue’s own details (its name, address, telephone number, contact email address and website), the proposed configuration (such as opening hours, table layout and operating preferences), and the name and email address of the owner we are dealing with. Where the venue gives us a logo or cover image for their public pages, we hold those too.

Access to the prepared setup is given by a one-time setup code, which we share with the owner privately ourselves — we never send one automatically. The code works once, only for the email address we recorded, and expires after 30 days.

We keep this information for up to 30 days. If the code is not used within that time it expires and the information, including any images, is automatically deleted. If it is used, the prepared setup becomes part of the venue’s account records and is kept under the tenant retention periods in section 8.

Launch and industry-interest waitlist (prospective customers)

If you ask us to keep you posted — for example by registering interest in ResoFlow for your type of venue on our website, or during signup when we are not yet ready for your industry — we store your email address, the industry you told us about (where you chose one, or the short description of your business you typed if you chose “Something else”), the exact consent wording you agreed to and when, and basic anti-abuse details (a one-way-hashed network identifier and your browser’s user-agent string). We use this only to confirm your signup and to email you when ResoFlow is ready for you — it is never used for general marketing without a fresh choice from you.

You can remove yourself from the list at any time using the link in your confirmation email, or by contacting us (section 14) — either way we delete your entry.

Booking a call with us (prospective customers)

If you book a call with us on our website, we collect your first name (and last name if you give it), email address, phone number, the topic you choose, any notes you add, and your chosen time slot, together with a one-way-hashed network identifier used only to prevent abuse of the booking form. We use these details only to arrange and hold the call — including sending you a confirmation email with a calendar invite, and a cancellation email if we have to cancel — never for general marketing without a fresh choice from you.

Information from venue staff (we process it for the venue)

When a venue owner adds staff members to their dashboard, we process the following personal data on the venue's behalf as a data processor. The venue is the data controller; we hold this data under its documented instructions. See our Data Processing Agreement for full details.

  • Identity — name, username (chosen by the venue), assigned role, and any per-staff permission overrides set by the owner or admin.
  • Contact (optional) — work email address, work phone number, and job title, only if the owner chooses to record them.
  • Security — a one-way cryptographic hash of the staff PIN (we never see or store the plaintext PIN), a device token bound to a specific browser or tablet the owner has enrolled, and the IP addresses the staff member signs in from. Sign-in IPs are kept only as needed for security alerts and the venue's audit log.
  • Preferences — the staff member's chosen theme (light, dark, or system).
  • Activity metadata — last sign-in time and active session records (device, last-seen time) so the owner can review and revoke sessions.

Staff personal data is displayed only to authorised accounts at the venue. Staff can view and edit their own optional contact details and theme preference from the staff portal Profile page.

Information from guests (we process it for the venue)

  • Contact details — name, email address, and phone number.
  • Booking details — date, time, party size, table assignment, any special-occasion or other notes you add, and your booking history. Date of birth is optional and used only for birthday messages where the venue enables them and, if you are a loyalty member of a scheme with a birthday perk, an automatic once-a-year birthday bonus on your loyalty card.
  • Allergies and dietary preferences — see section 3.
  • Pre-orders — where a venue offers pre-ordering for larger bookings and your party chooses its food in advance: the dishes selected (with any choices and quantities), any first names the organiser adds against a dish so the kitchen knows who it’s for, and the order’s total. This is stored on the booking and visible to the venue. If the venue takes payment for pre-orders online, your card is handled directly by Stripe on the venue’s own Stripe account (never by ResoFlow) and we hold only Stripe payment references.
  • Order & Pay table orders — where a venue offers ordering from your table by QR code: the dishes you order (with any choices, quantities and notes you add for the kitchen), your table, any tip, your email address (so we can send your receipt and any service emails about your order — for example if the venue has to reject and refund it) and, optionally, your name. If you’re a member of that venue’s loyalty scheme, your email address is also used to add the visit to your loyalty balance — exactly as a booking visit would be. Paying for a table order creates or updates the guest profile the venue keeps about you, exactly as making a booking does, and the checkout offers the same choice about the venue’s marketing: we record whether you left the marketing box as it was or ticked it to opt out, together with evidence of that choice — when it was made, which page it was made on, the exact wording you were shown, and the choice itself — so the venue can demonstrate the basis for any marketing it later sends. If your order contains alcohol we also record your confirmation that you’re 18 or over. Your card is handled directly by Stripe on the venue’s own Stripe account (never by ResoFlow) and we hold only Stripe payment references.
  • Profile the venue keeps about you — a VIP flag, tags (e.g. “regular”), free-text notes, a seating preference, and family details for your party (number of children, whether a highchair or children’s menu is needed). This is entered and controlled by the venue.
  • Activity the platform derives for the venue — attendance history (no-shows, cancellations, abandoned waitlist places), lifetime spend on deposits and tickets, average party size, and previous names or phone numbers seen on your profile.
  • Event tickets — where a venue runs ticketed events: the buyer’s name, email and phone, and any additional attendee names the buyer provides. If you save a ticket to a device wallet, a device identifier and push token, stored only so we can send updates if the event details change.
  • Payments (deposits / no-show protection) — where the venue switches these on. Your card is handled directly by Stripe on the venue’s own Stripe account and is never seen, stored, or processed by ResoFlow; we hold only Stripe references (such as a token, a saved-card mandate for no-show protection, and any charge or refund reference).
  • Loyalty scheme membership — where a venue runs a loyalty scheme and you choose to join it: your membership status and join details (including a random member code used for scanning your card), your stamp or points balance and lifetime totals, and a history of each earn, redemption, and any staff adjustment. On schemes that award points by the amount you spend, this includes the single bill amount a staff member types in for a visit — there is no connection to the venue’s payment systems and no card-payment feed. Because a loyalty scheme is, by nature, a record of your visits (and, on spend-based schemes, your spend) at that venue, this recording only happens for the scheme you actively joined, so the venue can run it — you are never enrolled automatically, and you can end your membership yourself at any time from your customer portal (your remaining balance and rewards progress are permanently cleared when you leave). If you save your loyalty card to a device wallet, a device identifier and push token, stored only so your card can update when your balance changes.
  • Promotions and offer codes — where a venue runs its own promotions: which offer codes you have used, when, and on what, so the venue can honour per-person limits and see how an offer performed; and, if you save an offer to your loyalty account, that saved coupon and whether it has been redeemed.
  • Gift cards — where a venue sells gift cards, a gift card record involves up to two people: the buyer (for online purchases, their name and email; for purchases at the venue these are optional) and, where the card is a gift, the recipient (their name and email, plus the buyer’s personal message, so the card can be delivered and its balance updates and expiry reminder sent). The spendable code itself is stored only in a protected one-way form; each card also carries its value, balance, movement history, expiry, and — for online purchases — Stripe payment references only (your card is handled by Stripe on the venue’s own account, never by ResoFlow). Buying a gift card also creates or updates the guest profile the venue keeps about you (the buyer) with the purchase details, as making a booking does — for venue purchases only where you gave an email address. Buying alone never signs you up to marketing: the gift page offers an optional tick-box to receive the venue’s news and offers, and we record a marketing choice only if you tick it — together with evidence of that choice (when it was made, which page it was made on, the exact wording you were shown) — while an unticked box records nothing at all. Recipients never receive marketing from us or the venue on the basis of receiving a gift card, and no customer profile is created for a recipient. If you save a gift card to a device wallet, a device identifier and push token, stored only so the pass can update when the balance changes.

We do not sell or otherwise disclose guest data outside the strict bounds of delivering the Services to the venue you booked with. Guests should direct questions to the venue in the first instance.

Information from other sources. A venue may also give us guest data it already holds, rather than you entering it directly — for example by importing its existing customer list into its account. We process any data imported this way on the venue’s behalf in exactly the same way as data entered directly through the platform.

Information collected automatically

  • IP address, browser type, operating system, and device information.
  • Cookies and similar technologies (see our Cookie Policy).
  • Camera (event-ticket scanning) — where a venue scans event tickets at the door, a staff device may request permission to use its camera to read the ticket’s QR code. No photo or video is captured or stored — only the ticket code is decoded to check the ticket in.
  • Cookieless page-performance measurements via Cloudflare — load timings, browser type and country-level location, with no cookies or cross-site tracking.
  • Map images on venue pages — where a venue’s public page shows a map of its location, your browser fetches that map image directly from Google Maps, so Google receives your IP address and browser details alongside the venue’s address. It is a plain image — no cookies are set and none of your personal details are sent. See our Sub-processors page.
  • Sentry error reports, which may contain user IDs and technical context necessary to debug a fault, plus — on signed-in screens only — a short, fully masked session replay around an error. See our Cookie Policy for the full detail.
  • Email engagement — marketing emails sent through the platform contain a small tracking pixel and tagged links that record whether the email was opened and which links were clicked, so the sender can measure how it performed. For marketing a venue sends, the venue is the sender and we act on its behalf; for the occasional service or product email we send you about your own ResoFlow account, we are the sender. See our Cookie Policy.

Support correspondence

When you contact us via the in-app chat or by emailing support@, billing@ or [email protected], we collect:

  • The messages you send and any file attachments you choose to include.
  • Your IP address and browser user-agent at the time you send the message.
  • Interaction logs from our AI first-line responder (an EU-hosted Google large-language model). Internal model diagnostics are stripped from any data export.

For external (non-tenant) senders who email support@ or use the chat on our website: we also retain the sender email, the name you give us (first name and surname, where you provide them so a reply can reach you), IP and user-agent on the conversation record so we can reply and identify duplicate or abusive senders.

We use Google sign-in and email/password authentication only. We do not use Apple, Microsoft, Facebook, or X as login providers and we do not buy intent data or social-network friend lists from third parties.

3. Special category data — allergies and dietary preferences

In short: Allergies and dietary information are special category data under UK GDPR. The venue is the controller and relies on your explicit consent (Article 9(2)(a)); ResoFlow processes it only on the venue's behalf.

Allergy and dietary information is treated as special category data under Article 9 of the UK GDPR. The venue is the controller for this data and relies on your explicit consent (Article 9(2)(a)) when you choose to tell it about an allergy or dietary need so it can be catered for. You provide it voluntarily and can ask the venue to remove it at any time.

ResoFlow processes this information only on the venue's instructions, as its processor — displaying it accurately to authorised staff. The venue is responsible for ensuring its kitchen and front-of-house teams act on it.

4. How we process your information

In short: We process personal data only for the specific purposes set out below.

  • To create and maintain tenant accounts.
  • To enable tenants to manage bookings, communicate with guests, and run their venue.
  • To process subscription payments and send invoices.
  • Where a venue enables deposits or no-show protection: to provide the technical means, through Stripe Connect, for the venue to collect a deposit, save a guest's card, or charge a no-show fee on its own Stripe account. A no-show fee is charged when the venue deliberately marks a booking as a no-show, or — where the venue enables it — automatically when you cancel after the free-cancellation deadline you agreed to at booking; either way the fee and that deadline are shown to you before you confirm. ResoFlow facilitates the payment on the venue's behalf and does not handle the guest's card details; the deposit or no-show fee is paid to the venue, although ResoFlow may deduct a platform fee.
  • Where a venue runs a loyalty scheme or promotions and you take part: to record your membership and keep your balance and earning history accurate, to validate offer codes and apply per-person limits, to update a loyalty card you have saved to a device wallet, and to send the scheme’s emails on the venue’s behalf. Those emails are: a membership confirmation or welcome when you join; a reward unlocked notice when you earn a reward (you can switch this off in the customer portal); an optional monthly points digest, which is a marketing email — only sent where the venue switches it on and you are opted in to that venue’s marketing, and always with an unsubscribe link; and a scheme closure notice if the venue closes its scheme. Separately, two data-protection service messages are sent to scheme members even if you have opted out of marketing, because they are administration of the scheme and record you hold: a warning before your customer record is deleted at the end of the venue’s retention period, and a warning before an unused loyalty balance expires through inactivity (where the scheme sets an expiry).
  • Where a venue sells gift cards and you buy or receive one: to process the purchase and deliver the card (including on a future date the buyer chooses), to keep its balance and movement history accurate, to update a gift card you have saved to a device wallet, and to send the card’s transactional emails on the venue’s behalf — the buyer’s receipt, the gift email carrying the card, a balance update after each redemption (where the venue has these on), and one expiry reminder about 30 days before the card expires. These are service messages about value you hold — never marketing — and receiving a gift card never adds you to any marketing list.
  • To respond to support requests via the in-app chat and email channels.
  • To provide AI-assisted first-line support replies through an EU-hosted Google large-language model (see Sub-processors). We do not use support correspondence to train any AI model: the model is off-the-shelf, with no fine-tuning, and there is no per-tenant or per-conversation persistence at Google.
  • To show a signed-in account owner their own billing summary (current plan, next billing date and amount, and the last four digits of the card on file) inside the support chat, on request and only after they re-confirm their identity. The figures are assembled on our servers from Stripe and shown only to the verified owner; our AI assistant never receives them.
  • To read a menu a venue chooses to import (a photo, PDF or menu web page) using the same EU-hosted Google large-language model, so the venue’s dishes can be set up automatically. The uploaded file is deleted as soon as it has been read and is never used to train any AI model.
  • To find the right help guide when you search our Help Centre. The words you search for are sent to an EU-hosted Google text-embedding model, which turns them into a list of numbers so we can match them by meaning against our own help guides rather than only by exact wording. This model does not write text and does not answer your question — it only compares meaning. Your search wording is never used to train any AI model.
  • Where a venue uses the optional “Check my wording” tool in their policy settings: to give that venue an advisory read of the policy wording they have written, using the same EU-hosted Google large-language model, so we can point out anything that appears to contradict the fixed clauses we provide. It runs only when the venue clicks the button, it is advice only — it can never block or change what they save — and the wording is never used to train any AI model. The text checked is the venue’s own policy copy, not your personal data.
  • To forward support messages to Slack so we can monitor them and, where needed, respond (see Sub-processors).
  • To monitor performance, detect bugs, and improve the platform.
  • To detect and prevent fraud, abuse, or unauthorised access.
  • To comply with our legal obligations (tax records, ICO orders, court orders).
  • With your consent, to send marketing or product-update emails.

Aggregated and anonymised information

We may also create and use aggregated or anonymised information — statistics and insights that do not identify, and cannot reasonably be used to identify, any individual (for example, total bookings processed, or trends in platform usage). Because this information is not personal data, we may use and share it freely, for purposes such as understanding how the Services are used, producing reports, and improving the platform.

6. Who we share your information with

In short: We share data only with carefully selected subprocessors that help us deliver the Services. Each is bound by a Data Processing Agreement.

The full list of current subprocessors lives at /policies/subprocessors. Categories include:

  • Payment processing.
  • Transactional and marketing email delivery.
  • SMS delivery (with per-tenant subaccounts).
  • An internal support-messaging bridge — support correspondence (name, email, message text and any image attachments) is forwarded so we can monitor it and respond where needed.
  • Cloud hosting, database, authentication, and our AI support model.
  • CDN, DDoS protection, web application firewall, bot management, and cookieless performance analytics.
  • Website analytics, error tracking, and uptime monitoring.
  • Event-ticket and loyalty-card wallet passes (Apple and Google Wallet) — a ticket pass carries the ticket-holder name and event details; a loyalty-card pass carries the member's name, balance and member code. A pass exists only where you choose to save it to your wallet.
  • Address geocoding and autocomplete — business address data only, no customer personal data.

The named providers behind each category, where they process data, and a link to each one’s data-processing terms are on the Sub-processors page.

We do not sell personal data.

Venue-configured integrations (Zapier / webhooks)

Where a venue chooses to switch on the Zapier or webhook integration, booking data — including a guest’s name, email address, phone number and any booking notes — is sent to the third-party URL the venue configures. The venue is the controller of that onward transfer and is responsible for the receiving tool and for any further processing it performs. ResoFlow only delivers the data to the destination the venue has set up; these destinations are not ResoFlow sub-processors.

Business transfers

If we are involved in a merger, acquisition, or sale of assets, we will provide notice before personal data is transferred and becomes subject to a different privacy policy.

7. International transfers

In short: Some of our subprocessors are based outside the UK. We use the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (with the UK Addendum where applicable) to safeguard those transfers.

Our Firestore database and Cloud Functions are hosted in Google Cloud's europe-west1 region (Belgium). Sentry hosts our error data in the EU. Cloudflare sits in front of our public websites (and, where a venue enables the optional Your domain product, in front of that venue's own connected domain) as a global edge network: request metadata such as your IP address and browser details transits the nearest Cloudflare data centre — including UK and EU locations — for security filtering and certificate handling. Other subprocessors are listed at /policies/subprocessors along with their primary processing location.

Where data leaves the UK, we rely on:

  • The UK International Data Transfer Agreement (IDTA) for UK to US transfers.
  • The EU Standard Contractual Clauses (SCCs) for EU to US transfers.
  • The UK Addendum to the EU SCCs where the underlying agreement uses EU SCCs.
  • Where a US subprocessor is certified under the EU-US Data Privacy Framework and its UK Extension, that framework may additionally apply alongside the mechanisms above.

Each subprocessor’s data-processing terms incorporate one of these mechanisms.

This description of our transfer mechanisms is provided on a best-effort basis and is not legal advice.

8. How long we keep your information

In short: We keep personal data only for as long as we need it for the purposes we collected it, plus any period required by law.

Data categoryRetention period
Active tenant account dataWhile the account is open + 30 days
Tenant payment / billing recordsUp to 7 years (HMRC’s 6-year requirement plus a short safety buffer)
Guest profile dataA period the venue chooses (default 2 years; maximum 3 years) measured from the guest’s last activity. Loyalty activity (earning, redeeming) counts as activity and restarts the clock. Loyalty members receive email warnings before their record is deleted
Loyalty membership and balanceLives with the guest profile above — kept while the record is kept, deleted with it (including on an erasure request, which permanently destroys the membership and any remaining stamps or points)
Loyalty earning / redemption history and offer-code usage historyLine-by-line detail kept for 2 years; older loyalty entries are then deleted (only the balance is kept) and older offer-usage entries are deleted
Loyalty membership confirmation links7 days, then the unused link expires and is deleted
Guest booking records (no payment attached)The same retention setting the venue chooses for guest profiles (default 2 years; maximum 3 years), measured from the booking date
Guest payment records (bookings that carry a deposit, full prepayment, event ticket, paid extras, pre-order payment, charged no-show fee or gift-card payment)The payment facts (amounts, dates, Stripe references) are kept as financial records for the life of the venue’s account. Once the venue’s retention period for the booking passes (or if the guest asks to be erased), the guest’s personal details — name, contact details, notes, allergies, dietary preferences, per-guest names — are permanently removed from the record; only the anonymised payment facts remain
Gift card records (value, balance, movement history, buyer/recipient contact details, Stripe payment references for online purchases; the spendable code is stored one-way hashed)A card with remaining balance is never auto-deleted. Spent, expired, and voided cards are retained as anonymisable financial records for the life of the venue’s account. If a buyer or recipient asks to be erased, that person’s identity details are removed from the card while the card itself stays live and spendable
Scheduled gift card deliveries (the card’s code held for a future delivery date the buyer chose)Until the gift email is sent or the delivery is cancelled, then deleted
Guest deposit / no-show fee transaction references (Stripe identifiers only; the card itself is held by Stripe, not by us)A live saved-card mandate is voided when the guest is erased, and is never charged after the booking is resolved. A charged deposit or no-show fee reference is retained as an anonymised financial record for the life of the venue’s account (see “Guest payment records” above)
Stranded payment recovery records (a guest was charged but the booking, order, event ticket or gift card could not be completed — the payment references plus the payer’s contact details, kept so we can refund automatically and send an apology)The payer’s contact details are removed automatically as soon as the recovery completes (the money is refunded, or the purchase turns out to have succeeded after all). If a refund needs manual attention, the contact details are kept only until it is resolved — we keep them for that period so the money can be returned (our contract and legal-claims bases). The anonymised payment facts are then retained as financial records for the life of the venue’s account (see “Guest payment records” above)
Order drafts (an order-and-pay checkout that was started but never paid for — the items chosen plus any contact details entered)Deleted as soon as the order is placed. An abandoned checkout expires after 48 hours and is then automatically deleted
Routine audit logs (administrative actions, settings changes, logins)24 months on every plan (how far back they can be viewed in-app varies by plan)
Billing-related audit entries (refunds, plan changes, subscription cancels)7 years (UK HMRC requirement; copied to a tamper-resistant retained billing log)
Analytics aggregates (daily and monthly KPI snapshots, usage history)24 months rolling
SMS delivery logs (may contain templated guest details, e.g. a name in a booking confirmation)24 months rolling
Email delivery logs (the sent-email queue record — may contain templated guest details, e.g. a name in a booking confirmation)90 days, then deleted. Sends that failed permanently are kept for up to 12 months so we can investigate delivery problems, then deleted
Erasure records (one-way hashed identifiers only, no readable personal data; used so deletions survive backup restores)60 days
Tenant data export ZIPs (downloadable copy of your data)Until the secure download link expires (24 hours)
Scheduled analytics report PDFs (higher-tier plans)Until the secure download link expires (30 days)
Sentry error reportsA short rolling period set by our error-tracking provider (Sentry)
Tenant support threads (in-app chat + emails to support@/billing@/policies@)Open conversations: indefinite while active. Resolved: 24 months, then archived. Archived: 6 months, then permanently deleted.
External (non-tenant) support threadsResolved threads are archived, then permanently deleted after a further retention period.
Support attachments (image uploads on a thread)Stored alongside the parent thread; deleted when the thread is hard-deleted.
Cookie consent records6 months
Marketing consentUntil withdrawn
Marketing consent evidence (when a marketing choice was made, on which page, the exact wording shown, and the choice)Kept for as long as the marketing preference it evidences is relied on, and deleted with the guest’s profile (or on an erasure request). We keep the most recent evidence entries — a newer choice supersedes older ones
Backup snapshotsDaily backups retained 31 days, plus 7-day point-in-time recovery (managed by Google Cloud)
Deleted or terminated tenant accounts30-day window (during which you can request a final data export — see the Terms, section 13), then permanent deletion. Cancelling a paid subscription alone downgrades you to the free tier: the account stays open and this window does not start
Abandoned / incomplete signupsPermanently deleted 7 days after signup if onboarding is not completed
Venue setup codes (prospective customers — the venue’s own contact details, the owner’s name and email address, the proposed venue configuration, and any logo or cover image supplied)Up to 30 days; unused codes and everything held against them, including images, are automatically deleted when they expire. Used codes become part of the venue’s account records
Call bookings (prospective customers — name, email address, phone number, topic, notes and the chosen time slot from our book-a-call page)90 days after the call date, then automatically deleted
Launch / industry-interest waitlist signups (email address, chosen industry or your short business description, consent wording, anti-abuse identifiers)Kept while your registration waits for the launch you asked to hear about; deleted whenever you ask us to remove you — use the removal link in your confirmation email, or contact us any time

9. How we keep your information safe

In short: We use industry-standard technical and organisational measures, but no system is 100% secure. We acknowledge that risk transparently.

  • Encryption in transit and at rest.
  • Multi-factor authentication available on every account.
  • Audit logging of administrative actions.
  • Role-based access controls following least-privilege defaults.
  • Continuous Sentry monitoring and BetterStack uptime checks.

Despite these measures, no system can be guaranteed 100% secure. If you suspect unauthorised access to your account, contact [email protected] immediately.

10. Information from minors

In short: Account holders must be 18 or over. Guests booking a table should be 16 or over. We do not knowingly collect data directly from younger children.

Account holders and their staff must be aged 18 or over. Guests booking a table or buying a ticket should be aged 16 or over; the venue is the controller of guest data and is responsible for handling any younger guest’s data appropriately. A guest may also record family details about their party — for example, the number of children dining, whether a highchair is needed, or whether a children’s menu was requested. Where this information relates to a child, it is provided by the adult guest on behalf of their party; we do not collect information directly from young children or invite them to use the Services themselves.

If you believe we have inadvertently collected information directly from a minor, contact [email protected] and we will delete it promptly.

11. Your privacy rights

In short: Under the UK GDPR you have the right to access, correct, erase, restrict, port, and object to processing of your personal data. You can also lodge a complaint with the ICO.

If you are a guest, the venue you booked with — or bought from, ordered from, or whose scheme you joined — is the controller of your information — exercise your rights with them in the first instance (we assist them as their processor). The rights below describe how we handle requests where we are the controller (tenant account holders and people who contact us directly).

Under Articles 15 to 22 of the UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data erased ("right to be forgotten").
  • Restrict our processing of your data.
  • Receive your data in a portable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time.
  • Not be subject to fully automated decisions that have a legal or similarly significant effect.

Automated decisions. We do not make decisions about you using solely automated means that produce legal or similarly significant effects, such as profiling. A no-show fee is charged when a venue’s staff mark a booking as a no-show, or — where the venue enables it — automatically when you cancel after the free-cancellation deadline you agreed to at booking; either way the fee and that window are set by the venue and shown to you before you confirm. Loyalty earning and redemption are mechanical consequences of your own actions (a qualifying visit earns; a redemption you or staff trigger redeems) — any manual balance adjustment is made by a named member of the venue’s staff with a recorded reason, never automatically. Our AI support assistant only drafts replies for human handling — it does not make decisions about your account.

We respond to verified requests within 7 working days. To exercise your rights:

  • Tenants: email [email protected] from your account email to request a copy of your data (we produce the export and send a secure download link) or to delete your account.
  • Guests: contact the venue first. If they cannot help, email [email protected] and we will forward the request.
  • External (non-tenant) senders who have emailed support@, billing@ or policies@ can request access or deletion of their support correspondence by emailing [email protected] from the same address.

You also have the right to complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

12. Do-Not-Track signals

In short: Analytics only run with your explicit consent, so a Do-Not-Track browser is covered by default. We do not use your data for advertising.

ResoFlow does not run advertising campaigns or build profiles for ad targeting. Analytics and optional tracking cookies never run without your explicit consent through our cookie banner, so a Do-Not-Track browser is covered by default — nothing runs unless you opt in. See our Cookie Policy.

13. Updates to this policy

In short: We will give 14 days advance notice in-app and by email before any material change takes effect.

For non-material changes (typo fixes, formatting, clarifications) we will update the "Last updated" date at the top of this page without separate notice.

14. How to contact us

For privacy and data protection matters, email [email protected].

By post:
Caleonix LTD (Company No. 17162652)
71-75 Shelton Street
London
England, WC2H 9JQ
United Kingdom

Related documents

Please also refer to our main Terms of Service and our Cookie Policy.