Privacy policy
Version
1. Who we are
Bookado provides reservation, table-management and host-stand software for restaurants. This policy explains how personal data is handled by the Bookado website (this site), the Bookado Backoffice (the web application used by restaurant teams) and the Bookado host stand application (the tablet used at the door).
For questions about this policy or your data, write to support@bookado.app.
2. Two roles: controller and processor
- Restaurant teams (our customers). When you create an organisation, sign in, invite colleagues or pay a subscription, Bookado is the controller of that account data.
- Guests of restaurants. Names, contact details, party sizes, booking times, deposits and check-in records that a restaurant enters into Bookado belong to that restaurant. For that data Bookado acts as a processor on the restaurant’s instructions. Guests who want to exercise their rights should contact the restaurant they booked with; we support the restaurant in responding.
3. What we collect on this website
- No account is created on this site. Sign-up, login and billing happen in the Backoffice application.
- Demo requests. If you ask for a demonstration we collect your name, work email, phone number, company and venue count to contact you about Bookado. We keep this for as long as needed to follow up and then for our legitimate interest in sales records.
- Plan catalogue. The pricing page loads plans from our public API without cookies or authentication. No personal data is sent with that request.
- Measurement. We only load analytics after you consent, and never send personal data or full URLs to third parties. Server logs record IP address, request identifier and user agent for security and abuse prevention, and are retained for a limited period.
4. What we process in the applications
- Account data: name, email, role, organisation and venue details, invitation and session records, audit trail of administrative actions.
- Booking data (as processor): guest name and contact details, party size, date and time, table, notes, deposit status, check-in events (including NFC/QR check-in resolution) and no-show or cancellation history.
- Payments: subscription payments are handled by Stripe; deposits from guests are paid to the restaurant’s own Stripe account. Bookado never stores card numbers.
- Emails: reminder and cancellation emails to guests are sent on the restaurant’s behalf only when the restaurant enables that feature.
5. Legal bases
Performance of a contract (providing the service), legitimate interests (security, abuse prevention, product improvement without profiling), consent (marketing measurement and optional communications) and legal obligations (accounting and tax records).
6. Sharing
We use infrastructure and service providers to run Bookado — hosting, database, email delivery, payment processing and error monitoring — bound by data-processing agreements. We do not sell personal data.
7. International transfers
Where data leaves the region in which it was collected we rely on adequacy decisions or standard contractual clauses, and we document those transfers on request.
8. Retention
Account data is kept while the organisation is active and for a limited period after cancellation to allow reactivation and to meet legal obligations. Booking data is retained according to the restaurant’s settings; restaurants can anonymise a guest at any time, which removes identifying fields while keeping aggregate statistics.
9. Your rights
Depending on your jurisdiction you may have the right to access, rectify, erase, restrict or object to processing, to data portability and to lodge a complaint with a supervisory authority. Restaurant team members can exercise these rights through the Backoffice or by email; guests should contact their restaurant, and we will assist it.
10. Security
Access is authenticated and scoped per organisation and venue, administrative actions are audited, data is encrypted in transit, and public endpoints are rate-limited.
11. Changes
We publish each version of this policy with its date. Material changes are announced to account owners before they take effect.