Privacy Policy
This document is provided in English. If you need it in another language, contact us at hi@rizzrv.com and we will arrange a translation. If a translated version ever conflicts with the English version, the English version prevails.
1. Overview
Rizzrv (“we”, “us”) is an online booking platform for restaurants, salons and studios. This policy explains what personal data we process, why, where it is stored and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR). You can reach us about anything in this policy at hi@rizzrv.com.
We process personal data in two distinct roles:
- As a controller — for visitors to this website and for the businesses that hold a Rizzrv account (sections 2, 4–5).
- As a processor — for the booking data that guests submit on a business’s booking page. There, the business you book with is the controller and we act on its behalf (section 3).
2. Data we collect as a controller
Business accounts
- Account data: your name, email address and password (stored only as a cryptographic hash), and your role within the business.
- Business profile: business name, description, logo and images, brand colours, address, contact email and phone, opening hours, services and the names of staff members you add.
- Billing data: your plan, subscription status and Stripe customer reference. Card details are entered directly with Stripe and never touch our servers.
- Security data: when you sign in we record session data including IP address and browser user-agent, used to secure your account.
- Correspondence: emails you send to hi@rizzrv.com.
Website visitors
This marketing website sets no cookies and runs no third-party analytics or advertising trackers. Our infrastructure providers process technical request data (such as IP addresses) in server logs for security and delivery; see section 7.
3. Booking data — when you book with a business
When you book a table or appointment on a Rizzrv booking page, the data you enter goes to the business you are booking with. That business is the data controller; Rizzrv stores and processes the data on its behalf under a Data Processing Agreement. This data includes:
- your name, email address and, optionally, phone number;
- booking details: date, time, service, party size and your language preference;
- any notes you choose to add and, where the business requests it, allergen information. Because allergen details can reveal health information, they are collected only with your explicit consent (Art. 9(2)(a) GDPR), given via a separate tick box on the booking form, and are shared only with the business so it can prepare for your visit.
We use this data solely to operate the booking: to show it in the business’s calendar and to send you a confirmation, a reminder before your appointment, a short “starting soon” notice and cancellation messages. Every confirmation email contains a secure link you can use to review or cancel the booking yourself. We never use guest data for advertising and never sell it.
The same secure link gives you direct control over your data: you can download a copy of everything stored with the booking in a machine-readable JSON file at any time, and once the booking is over or cancelled you can permanently erase your personal details yourself — no email required. Erasure removes your name, contact details, notes and allergen information; only the anonymous booking record (date, time, service, status) remains for the business’s statistics.
To exercise your data protection rights over a booking, you can also contact the business you booked with — its dashboard includes tools to look up, export and erase everything stored about your email address. If you contact us instead, we will forward your request to the business and assist it in responding.
4. Purposes and legal bases
- Providing the Service (accounts, booking pages, notifications, billing) — performance of a contract, Art. 6(1)(b) GDPR.
- Security (session logs, abuse prevention) — our legitimate interest in keeping the platform safe, Art. 6(1)(f) GDPR.
- Legal obligations (invoicing, tax and accounting records) — Art. 6(1)(c) GDPR.
- Anything based on consent (for example a future newsletter) — Art. 6(1)(a) GDPR; consent can be withdrawn at any time.
5. Emails
The platform sends transactional email only: booking confirmations, reminders, cancellations, and account and billing messages. We do not send marketing email without prior consent. Emails are delivered through Resend (see section 7).
6. Cookies and tracking
- dine.rizzrv.com (this website): no cookies, no analytics scripts.
- app.rizzrv.com (business dashboard): strictly necessary session cookies to keep you signed in. No advertising or analytics cookies.
- Booking pages: no advertising or analytics cookies; the booking flow works without tracking.
- Reserve with Google: when a business enables this integration, Google attaches a referral token to visits arriving from Google Search or Maps. The token is linked to the business, not to you, is kept for at most 30 days, and the conversion reports we send to Google contain no guest personal data.
7. Where your data lives
Our application — the APIs and the database holding all account and booking data — runs on servers operated by Hetzner in Nuremberg and Falkenstein, Germany. Your data is stored in the EU and handled in line with the GDPR. We use a small number of carefully chosen providers:
| Provider | What for | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of our APIs and database — where all application data is stored | Nuremberg & Falkenstein, Germany (EU) |
| Cloudflare, Inc. | Delivery of our static websites (this site, the dashboard and booking-page assets) | Global edge network (US company) |
| Stripe Payments Europe, Ltd. | Subscription payment processing for business accounts | Dublin, Ireland (EU) |
| Resend | Delivery of transactional email (confirmations, reminders, cancellations) | United States |
| Google Ireland Limited | Reserve with Google — only for businesses that enable it | Ireland (EU) / global |
8. International transfers
Application data is stored in Germany. Where a provider processes data outside the European Economic Area — for example Cloudflare’s edge network or Resend’s email infrastructure in the United States — the transfer is protected by the EU Standard Contractual Clauses or an EU adequacy decision such as the EU–US Data Privacy Framework.
9. How long we keep data
- Account and business data: for the life of the account, then deleted within 90 days of closure.
- Booking data: kept while the business’s account is active so guests and businesses can refer back to bookings, or until the business instructs us to delete it; deleted within 90 days of account closure. Businesses can additionally enable automatic erasure, which anonymizes guest personal data a set number of days after the visit, and guests can erase their own data via their booking link (section 3).
- Invoices and billing records: retained as long as tax and accounting law requires.
- Server and security logs: kept for a short period, then rotated.
10. Your rights
Under the GDPR you can ask us (or, for booking data, the business you booked with) for:
- access to the personal data held about you, and a copy in a portable format;
- correction of inaccurate data;
- deletion, or restriction of processing;
- objection to processing based on legitimate interests;
- withdrawal of any consent you gave, without affecting prior processing.
For booking data, the fastest route is self-service: the secure link in your booking emails lets you download a portable copy of your data and erase it once the booking is over. For everything else, write to hi@rizzrv.com and we will respond within one month. You also have the right to complain to your local data protection supervisory authority.
11. Security
All traffic to and from the platform is encrypted with TLS. Passwords are stored only as cryptographic hashes. Each business’s data is isolated per account, access is limited to what is needed to run the Service, and we keep regular backups within the EU.
12. Children
The Service is aimed at businesses and their guests; it is not directed at children, and we do not knowingly collect data from children under 16. Contact us if you believe a child has provided us personal data.
13. Changes to this policy
We will update this policy as the Service evolves and change the date at the top when we do. For material changes we will notify account holders by email or in the dashboard.