Privacy Policy
1. Definitions
“We,” “us,” “our,” “reservie,” “my.reservie.net,” and “reservie.net” refer to Reservie Ltd, a limited liability company (registration: 14747690) with registered offices at Exchange House, St Cross Lane, Newport, Isle of Wight, PO30 5BZ.
The organisation provides online platforms called “Services” for selling and managing events. A “Member” is a registered person or entity using the Service. “You” or “your” refers to a Member.
An “event” encompasses classes, workshops, holidays, retreats, appointments, or similar time-based intervals where clients enrol. A “Client” or “Participant” is someone purchasing or enrolling in Member-created events, identified by name, email, and telephone.
The “Site” refers to www.reservie.net or reservie.net, promoting the Service and presenting public information. A “Visitor” is anyone visiting the Site regardless of membership status.
“Checkout” is a publicly accessible system for clients to purchase Member events. For GDPR purposes, reservie assumes the “Processor” role while Members assume the “Controller” role.
2. Variation
Reservie may change this Privacy Policy at any time. The most recent version is reflected by the date at the policy’s bottom. Updates are effective immediately upon notice, which may be provided through posting revised versions or other means. Continued website use signifies acceptance of changes. Electronically stored copies represent the authentic version effective on respective visit dates.
3. Scope
This Privacy Policy applies to all data collected about or from users according to the Terms of Use.
4. Questions and Concerns
For questions, updates, deletions, modifications of personal information, or privacy concerns, contact via the contact form or:
Attn. Privacy Officer Reservie Ltd C/o Exchange House, St Cross Lane Newport Isle of Wight, PO30 5BZ
5. Members (Providers) Personal Information
5.1 Data Collection
Upon registration, reservie collects:
- Name
- Email address
- Telephone number
- Website address
- Payment processor identification
Login monitoring captures:
- IP address
- Browser identification records
- Date/time information
5.2 Data Uses
Member data is used to:
- Maintain service accounts
- Contact regarding sold events
- Update on service changes
- Process payments via preferred processors
5.3 Cookies
When Members sign in to the Service, reservie uses cookies to keep them signed in. These are set by Amazon Cognito, the sign-in service reservie uses, and are named CognitoIdentityServiceProvider followed by identifiers for the Member’s account:
- LastAuthUser — Records which account last signed in on the device.
- accessToken, idToken and refreshToken — Keep the Member signed in securely. They contain the account’s sign-in details, including its email address, which also forms part of the cookie names.
- signInDetails and clockDrift — Record how the Member signed in, and correct for differences between the device’s clock and the server’s.
These cookies are necessary for sign-in to work. They last for up to 12 months, or until the Member signs out.
The Service also stores a small number of display preferences in the browser, such as which menu is open. These are not cookies and contain no personal information.
5.4 Data Sharing, Data Usage, and Sub-processors
Reservie performs most data processing internally but uses specialised third-party sub-processors for specific tasks.
Payment Processors
Members choose from PayPal Standard, Stripe, or both. Members register directly with selected processors. Reservie identifies members via:
- PayPal: Member’s PayPal identifier
- Stripe: A shared key provided during Stripe account association
All payment processing and PCI compliance are handled by chosen processors.
Email Notification Processors
Mailgun (Privacy Policy) and Postmark (EU Privacy) send notifications to members and their clients. Shared information includes:
- Email address
- Email notifications
Service updates, privacy notices, and marketing communications (including our newsletter) use Loops (Privacy), located in the US. Newsletter emails are sent only to people who have subscribed, and every email includes an unsubscribe link.
Servers
Servers, storage, and backups are provided by Amazon Web Services (GDPR) and DigitalOcean (Legal), in their London, UK regions.
Cloudflare (Privacy) sits in front of the Service for delivery and security. No personal data is stored on Cloudflare; the only information held there is event data, which contains nothing that identifies a person.
Accountancy
Xero (Privacy) manages company accounting and tracks member fees.
Direct Debit Processing
For monthly plans via direct debit, information is shared with GoCardless and Directli.
GoCardless (Privacy) — Located in the UK, requires explicit signup with name, postal address, email, and bank details. GoCardless shares member information with Reservie Ltd, and Reservie shares payment details with GoCardless.
Directli (Privacy) — Located in the UK, interfaces between Xero and GoCardless, sharing payment details and tracking received payments.
Zoom
Connecting Reservie to Zoom accounts stores basic identifiers and tokens enabling:
- Zoom meeting setup requests
- Sharing Zoom invites with clients
Client information is not shared with Zoom or accessed from Zoom.
5.5 Data Security and Management
Reservie maintains technical and physical safeguards protecting personal data integrity against unauthorised access, use, alteration, or disclosure. Measures include device encryption, firewalls, and virus checking. Security systems are regularly reviewed.
5.6 Data Access, Modification, and Removal
Members have rights to:
- Update and correct account information
- Request all held personal information
- Request processing restrictions
- Request data deletion
- Object to continued processing
- Data portability (where applicable)
Administrative charges may apply for data copies; appropriate identification may be required. Complaints may be filed with the Information Commissioner (www.ico.gov.uk). Contact reservie using provided information or manage basic changes via account settings.
5.7 Data Access, Modification, and Removal of Third-Party Data
Reservie stores only minimum data necessary for third-party service interoperability. Full records may require contacting third-party vendors directly. Disconnecting integrations removes associated data.
6. End Client Personal Information
End client information is gathered and processed on behalf of providers. Reservie never contacts clients except upon provider request. Providers retain client data rights.
Client registration minimally requires:
- Name
- Contact number
Credit card information is not captured by Reservie; payment partner Stripe handles this.
Providers may request additional information facilitating business operations.
6.1 Data Collection
When providers create public events for purchase, client checkout collects:
- Information tracking checkout progression
Additionally, depending on the elected payment processor:
Stripe:
- Participant names, emails, contact numbers
- Payee credit card details and registered address
PayPal:
- No additional information; PayPal provides payee name, address, and telephone upon successful purchase
6.2 Data Uses
Checkout Progression Information
This manages client sessions during checkout without retaining personally identifiable information.
Participant Names, Emails, Contact Numbers
Upon purchase, participants enrol in events with created accounts. For PayPal purchases, only buyer name, email, and telephone are stored and enrolled.
Payee Credit Card Details and Registered Address
For Stripe only, this information transmits directly to Stripe for validation, with success or failure notification.
If members authorise, notification emails are sent for:
- Client initial registration
- Event purchase
- Event cancellation
6.3 Cookies
When clients sign in to a provider’s booking pages, reservie sets one cookie:
- auth_token — Keeps the client signed in. It cannot be read by other scripts on the page, is only sent over a secure connection, and lasts 4 hours.
Payments are handled by Stripe. When a booking page loads Stripe’s payment tools, Stripe sets its own cookies to help prevent fraud:
- __stripe_mid — Lasts up to 1 year.
- __stripe_sid — Lasts 30 minutes.
- m — Set on Stripe’s own domain (m.stripe.com). Lasts up to about 13 months.
These are third-party cookies controlled by Stripe. Stripe’s Cookie Policy explains how it uses them.
The booking pages also keep a small amount of temporary information in the browser while in use, which is cleared when the tab is closed.
6.4 Data Sharing and Sub-processors
Reservie performs most processing internally but uses specialised third-party sub-processors.
Payment Processors
When clients make payments, event details are shared along with processor-specific information:
PayPal
No additional information is shared; clients are referred to PayPal for payment completion. Successful payments result in PayPal sharing client name, email, and telephone with Reservie.
Stripe
Additional information enables payment processing and verification:
- Credit/debit card information
- Card name
- Card registered address
6.5 Data Security
Reservie maintains technical and physical safeguards protecting personal data integrity against unauthorised access, use, alteration, or disclosure. Measures include device encryption, firewalls, and virus checking. Security systems are regularly reviewed.
6.6 Data Access, Modification, and Removal
End-clients have rights to:
- Update and correct account information
- Request removal or processing restrictions of held information
- Object to continued processing
- Data portability
Administrative charges may apply for data copies; appropriate identification may be required. Complaints may be filed with the Information Commissioner (www.ico.gov.uk).
Members bear responsibility for providing client data access and facilitating modifications upon client request. Assistance contact: [email protected].
Clients who want their account deleted can use Delete your account.
6.7 Questionnaire and Waiver Answers
Providers may ask clients to complete questionnaires or waivers. Clients’ answers are kept for a period chosen by the provider, up to a maximum of 10 years. Each provider sets this period to meet the laws that apply to it and its insurer’s requirements. Most periods are shorter: new questionnaires are set to 3 years unless the provider changes this.
Because each provider sets its own period, clients who want to know how long their answers will be kept should ask the provider directly.
If a client’s account is deleted, their answers are kept for the rest of the provider’s chosen period, but the account record they are attached to no longer holds the client’s name or contact details.
6.8 The Reservie Studio Connect App
Clients can book with providers using the Reservie Studio Connect app for iOS and Android. The app uses the same account, and the same information, as the provider’s booking pages described in this section. In addition:
- Signing in. The app keeps your sign-in in your phone’s protected storage, so you stay signed in between visits.
- Camera. The app uses your camera only to scan your studio’s QR code when you first connect to it. It does not take, keep or upload photos.
- Calendar. If you choose to add a booking to your calendar, the app opens your phone’s calendar so you can save it. The app does not read your calendar.
- Information kept on your phone. The app keeps a temporary copy of some information from your account on your phone so it loads quickly.
- Payments and online classes. Checkout, online class links and on-demand videos open in a secure browser window. Payments there are handled by Stripe, and the cookies described in 6.3 apply.
The app does not use advertising, analytics or crash-reporting tools, and does not track you across other companies’ apps or websites.
To delete your account, go to Account, then Delete account in the app, or see Delete your account.
7. Visitors Personal Information
Visitors accessing the Site may be considered Members or Clients (refer to sections 5 and 6); this section addresses other Site visitors.
7.1 Data Collection
Visitor data collected includes:
- Non-personal information tracking visitor numbers and referral sources
- Email addresses for marketing list additions
7.2 Data Uses
Gathered data contacts visitors about Reservie systems and services.
7.3 Cookies
Cookies (small text files transferred to browsers) identify data traffic patterns, personalise content, and support security without disclosing specific identities, though they may identify computers, browsers, and internet settings. Browser settings allow disabling cookies at any time, though essential cookies are required for event purchases.
Google Cookies
Random unique numbers or letter-number strings identify browsers, interaction times, and dates. Information compilation produces reports improving site functionality. Cookies collect anonymous information including visitor numbers, referral sources, and visited pages.
- _ga — Duration: 2 years
- _gid — Duration: 2 days
- _gat — Duration: 2 minutes
7.4 Google Analytics
Google Analytics (provided by Google, Inc.) places cookies enabling activity reports. Google uses data solely for Site activity information without associating IP addresses with other Google data. IP address information transmits to and is stored by Google on US servers. Refusing these cookies is possible through browser settings or downloading the browser plug-in at https://tools.google.com/dlpage/gaoptout.
7.5 Data Sharing and Sub-processors
Reservie never sells or shares visitor data with third parties but uses specialised third-party sub-processors for specific tasks.
Loops
Loops (Privacy), located in the US, is used exclusively for email newsletters and campaign marketing. Your details are shared with Loops only if you choose to subscribe, and every email includes an unsubscribe link.
Postmark
Messages sent through our contact form are delivered to us by email using Postmark (EU Privacy). This includes the name, email address and message you enter on the form.
Cloudflare Turnstile
Our contact form is protected by Cloudflare Turnstile (Turnstile Privacy Policy), which checks that the form is being submitted by a person rather than a bot. Without it the form would be filled by automated spam.
When the check runs, Cloudflare processes:
- Your IP address
- Your browser’s TLS fingerprint
- Your browser’s User-Agent header
- The site key for our form, and the website it was loaded on
Cloudflare states that these signals are used only to tell humans and bots apart and to improve its bot detection, and not to identify, profile or advertise to individuals. Turnstile does not use this information to track you across other websites. Cloudflare is located in the US and acts as a sub-processor for this check only; the contents of your message are not sent to Cloudflare as part of it.
Turnstile may store a short-lived token in your browser to remember that the check has already passed. This is necessary for the contact form to work, so it is not covered by the cookie banner. If you would prefer not to use it, you can email us instead at [email protected].
7.6 Data Security
Reservie maintains technical and physical safeguards protecting personal data integrity against unauthorised access, use, alteration, or disclosure. Measures include device encryption, firewalls, and virus checking. Security systems are regularly reviewed.
7.7 Data Access, Modification, and Removal
Contact details of newsletter subscribers are stored in our Loops account. Subscribers may unsubscribe at any time using the link in any email we send. To see, correct or delete the details we hold, contact [email protected].
Last updated: 4 October 2026
Contact: [email protected] Phone: 0330 133 78 89 Address: Reservie Ltd, Exchange House, St Cross Lane, Newport, Isle of Wight, PO30 5BZ
