PRIVACY POLICY
Last Updated: July 16, 2026
Reslify LLC (“Reslify”, “we”, “us”, “our”) is committed to safeguarding your privacy. This Privacy Policy (“Policy”) describes how Reslify collects, uses, discloses, and otherwise processes information in connection with (i) our websites and marketing pages (the “Site”), (ii) our business-to-business software-as-a-service platform for hospitality operators and similar venues (the “Platform”), including related features and functionality made available through the Platform from time to time, as well as any reservation/booking widget we provide for embedding on a client’s website and any Reslify-hosted booking page link a client may share (collectively, the “Widget”), and (iii) related products and services, features, and integrations (together, the “Services”).
For the supported PAYTR marketplace payment flow, Reslify LLC provides payment facilitation through Reslify Bilişim Pazarlama Limited Şirketi, its authorized Turkish reseller and PAYTR marketplace operator (the “Turkish Payment Operator”). References to the “Reslify entities” mean Reslify LLC and the Turkish Payment Operator together; each entity’s role is limited to the processing described in this Policy.
This Policy applies to: (a) visitors to our Site; (b) our current and prospective business customers, such as restaurants, hospitality operators, and other venues (each, a “Client” or “Venue”); (c) individuals who use the Services on behalf of a Client, including account owners, administrators, other authorized users, and the Client’s contracted agents or representatives (“Authorized Users”); (d) individuals who interact with a Client via the Widget or other booking flows (e.g., to make reservations, purchase experiences, buy tickets for events, purchase or receive gift cards, redeem gift cards, or otherwise book services), or otherwise interact with the Services, including where their information is provided to us by a Client (e.g., when a Venue creates a booking for a walk-in or phone reservation) (“Guests”); (e) individuals who contact us (including via email for support or inquiries); and (f) individuals who apply for jobs with us, where applicable.
Policy status; no third-party beneficiaries. This Policy is provided for transparency and does not create contractual rights or obligations for Guests or other third parties. It is a privacy notice and is not a contractual incorporated policy under the Agreement Documents. Nothing in this Policy is intended to limit or waive any rights or remedies that individuals may have under applicable law (including, where applicable, rights as third-party beneficiaries under the SCCs).
ROLES & GUESTS SUMMARY (B2B SERVICES)
Reslify provides the Services to hospitality businesses and similar venues (“Clients”). Depending on the context, Reslify processes personal data either (A) as a Processor on behalf of a Client (and, where applicable under U.S. law, as a Service Provider/Contractor) for data processed within a Client account (“Client Personal Data”), and/or (B) as an independent Controller for limited purposes that Reslify determines itself, such as operating our Site, managing the direct contractual and account relationship with Clients outside a Client tenant, billing, protecting the security and integrity of the Services, preventing fraud and abuse, complying with law, and establishing or defending legal claims. Reslify uses data for product analytics and general service improvement in its independent Controller capacity only where the data has been aggregated or anonymized so that it is no longer Personal Data under applicable law.
PAYTR marketplace roles. Where the supported PAYTR marketplace flow is enabled, Reslify LLC and the Turkish Payment Operator process the transaction, beneficiary, settlement, refund, and reconciliation metadata necessary to facilitate the Client’s Guest payments. To the extent this information is processed on the Client’s instructions to provide the payment-enabled feature, the applicable Reslify entity acts as a Processor or Subprocessor for the Client. The Turkish Payment Operator separately acts as an independent Controller for the limited marketplace-account, commission, reconciliation, fraud-prevention, accounting, tax, legal-compliance, and legal-claims records for which it determines the purposes and means.
Guests (diners). When you book with a Client (via the Widget, a Reslify-hosted booking page, an integration such as “Reserve with Google,” or when venue staff creates a booking for you), the Client is typically the Controller of your booking and guest profile data, and Reslify processes that data as a Processor/service provider to provide and support the Services.
Your rights. To exercise rights relating to your booking or venue guest profile (e.g., access, correction, deletion, or marketing preferences), please contact the applicable Client directly. If Reslify receives a request relating to Client-controlled Guest data, we will generally route it to the Client and, where appropriate, assist the Client as required by contract and applicable law.
Policy scope. This Policy describes Reslify’s processing where Reslify acts as a Controller and provides transparency regarding processing Reslify performs on behalf of Clients as a Processor. In Processor contexts, the Client is typically responsible for its own notices, lawful bases/consents, and privacy practices for Guest data.
Analytics note. Identifiable usage events, diagnostics, performance information, and other telemetry generated within a Client account to provide, maintain, troubleshoot, or report on the Services are processed on behalf of the Client as Client Personal Data. Reslify may process only the minimum identifiable telemetry necessary as an independent Controller for platform-wide security, fraud and abuse prevention, legal compliance, billing or contract administration, and the establishment or defense of legal claims. Product analytics and general service improvement in Reslify’s independent Controller capacity use only aggregated or anonymized data that is no longer Personal Data under applicable law. Reslify does not use Client booking data that it processes as a Processor to independently market to that Client’s Guests. (See Section 3.4.)
In Processor contexts (Client Personal Data), the DPA governs. If there is any inconsistency between this Policy and the DPA regarding Processor processing, the DPA controls.
1. SERVICES OVERVIEW (B2B PLATFORM)
The Platform interacts with a Venue to identify available reservations, to secure, change, or cancel bookings, and to confirm that reservations were honored. The Platform helps Clients (i) manage reservations and bookings, (ii) reduce no-shows through deposits, prepayments, card guarantees using saved payment methods and possible later cancellation/no-show charges, and, where separately enabled, authorization holds, (iii) sell and fulfill ticketed events and experiences, (iv) offer, deliver, and redeem Venue-issued gift cards, (v) import and manage menu content, including through an optional AI-assisted menu import feature, and (vi) manage guest communications and operational workflows, including via the Widget, Reslify-hosted booking pages, and supported integrations such as “Reserve with Google.” When bookings or purchases are made—whether placed directly with a Venue, through other third-party reservation services that a Venue may use, through supported integrations, via the Widget or Reslify-hosted links, or entered into the Platform by Venue staff (e.g., for walk-ins or phone reservations)—information about Guests, purchasers, and recipients is recorded in (or transferred to) the Platform on behalf of the applicable Venue to help the Venue manage the booking, purchase, delivery, redemption, or related service.
Payment processing for deposits, prepayments, gift-card purchases, saved payment method setup/card guarantees, possible later cancellation/no-show charges, and, where separately enabled, authorization holds is performed by third-party payment processors such as Stripe or PayTR. Sensitive card input is collected in processor-controlled fields, pages, or iframes and is sent directly to the applicable processor. In the supported PAYTR marketplace flow, the Turkish Payment Operator administers the marketplace account and submits allocation, settlement, reconciliation, refund, and adjustment instructions; PAYTR transfers the Client/Venue’s seller net amount directly to the Client/Venue’s designated IBAN and transfers only the applicable platform commission to the Turkish Payment Operator. The Reslify entities do not store full payment card numbers or card security codes and do not receive or hold the Client/Venue’s seller net proceeds as principal in their own bank accounts.
2. INFORMATION WE COLLECT
The categories of information we collect depend on how you interact with the Services.
2.1 Information you provide to us (Controller contexts)
Business Contact Details. Name, email address, phone number, company name, job title, and country/region.
Business Communications. The content of messages you send us (for example, via web forms, email, or chat) and related details needed to respond (such as timestamps and contact identifiers). This may include communications related to support, sales inquiries, partnerships, or employment opportunities.
Account Registration and Administration (Client-level; outside the Client tenant). Business contact details for the Client’s representatives (for example, the account owner/primary administrator and other Authorized Users), such as name, business email, phone number, role/job title, and account settings necessary to provision and manage access. Only Authorized Users (representatives of a Client/Venue) may create or administer Accounts.
Authentication Data. Login credentials and related authentication information (for example, username and password, single sign-on (SSO) identifiers, or similar access credentials), as applicable.
Billing and Subscription Information. Subscription plan, invoices, billing contact details, billing address (if applicable), tax or business identifiers (if applicable), payment status, and transaction references/identifiers. Payment processing is handled by third-party providers; see Section 4.2.
Venue and Business Profile Information. Venue or business name, address, geographic coordinates, place identifiers, time zone, locale, contact details, website, and other operational profile information submitted during onboarding or administration of a Client account.
Marketing Preferences and Engagement (if applicable). If you opt in to receive marketing communications from us, we may collect your marketing preferences (such as preferred channels and topics of interest) and information about your engagement with our communications (for example, whether you open emails or click links). You can opt out of marketing communications as described in Section 14.5 (Marketing communications) and, where applicable, Section 15 (United States – State Privacy Rights).
Survey and Feedback Data. If you participate in a survey, product feedback session, or research conducted by Reslify, we may collect your responses and any profile information you provide to help us improve our Services.
Employment Application Data (if applicable). Information you submit in connection with job applications (e.g., CV/resume, work history, contact details, and communications) and related recruiting notes.
Other Information You Choose to Provide. We may collect other information that you choose to provide to us or that is not specifically listed above, and we will use it only as described in this Policy or as otherwise disclosed at the time of collection.
Authorized User data may be processed in different contexts: (i) account-level administration data Reslify processes as a Controller (e.g., billing owner contact, master account settings), and (ii) in-tenant activity/audit data Reslify processes on behalf of the Client as a Processor.
2.2 Information processed on behalf of Clients (Processor contexts)
Guest Booking and Contact Details. Guest name, email address and/or phone number (whether submitted directly by the Guest or entered by Venue staff).
Reservation Details. Date/time, party size, venue/location/area/table preferences, and booking history/status.
Events and Experiences. Selections, quantities, session/time slot, and attendance/check-in status.
Gift Cards. Where a Venue enables gift cards, Reslify may process purchaser and recipient names and contact details; purchaser and recipient language preferences; gift-card product, amount, currency, delivery choice, delivery timing, and expiry information; an optional personal message; gift-card code or token and status; purchase, delivery, redemption, balance, and adjustment history; and related non-card payment and transaction metadata. The Venue is the issuer and typically determines the purposes and means of this processing.
Menu Content and AI-Assisted Menu Import. Client-provided menu files and images, file names, file types, menu text, product and category information, prices, descriptions, dietary or source labels, and the structured draft generated from an import. A source file may contain names, contact details, or other personal data if the Client includes that information in the uploaded material. Clients should upload only information necessary to create or update their menus and should not include unnecessary personal data or Sensitive Data.
Venue Profile and Media Content. Venue names, descriptions, addresses, contact details, website and review links, geographic coordinates, opening and service information, logos, profile images, experience images, gift-card images, menu images, and related file and asset metadata uploaded or configured by a Client. Client-provided media may contain personal data if identifiable individuals appear in it, and Clients are responsible for having the rights and lawful basis required to upload and publish that content.
Guest Notes and Client-Configured Fields. Content entered by Guests in the default “Special Notes” / “Special Requests” free-text field that is included in the booking flow for all Venues by default (and may be left blank). In addition, Clients may choose to add or enable additional custom fields or forms; the content of those fields and whether they are optional or required is determined by the Client.
Client Tenant User Data. Client staff / Authorized User identity, roles/permissions, and in-product action and audit trails visible to the Client.
Transaction and Payment Metadata. Where a booking involves a deposit, prepayment, gift-card purchase, card guarantee/saved payment method setup, possible later cancellation/no-show charge, or, where separately enabled, authorization hold, Reslify may process payment processor customer identifiers, tokenized payment-method identifiers, setup/payment intent identifiers, transaction identifiers, timestamps, gross amount, seller net amount, platform commission, refund and adjustment amounts, currency, paid/refunded/failed/authorized and settlement status, Client/Venue beneficiary name and IBAN, and masked card descriptors such as brand, last four digits, and expiry month/year where available. Full card numbers and card security codes are processed by third-party payment processors and are not stored by the Reslify entities; see Section 4.2.
Client-Enabled Integrations. If a Client enables integrations (for example, “Reserve with Google” or other supported partners), Reslify may receive and process the reservation and related booking data necessary to fulfill the booking and to synchronize availability, bookings, and status updates, as configured by the Client.
Client Configuration and Sensitive Data Notice. Clients may choose to add or enable additional custom fields or forms through the Services (including whether such fields are optional or required), and Clients are responsible for providing appropriate notices and obtaining any required consents under applicable law. The default “Special Notes” / “Special Requests” field is a free-text field provided as part of the booking flow, and Reslify does not control what a Guest chooses to submit in free-text inputs; as a result, Guests may include sensitive information (for example, allergy or dietary information). Reslify does not require special category / sensitive data to use standard reservation functionality. Where a Client chooses to add fields that request such information, or where a Guest submits such information in free-text inputs, the Client is responsible for establishing a valid legal basis and providing any required notices and obtaining any required consents or other lawful authorizations under applicable law. Reslify processes such information only as necessary to provide the Services and in accordance with the Client’s configuration and instructions.
2.3 Information collected automatically (Controller and Processor contexts)
Device and Network Data. IP address, device type, device identifiers (including cookie identifiers and similar online identifiers), browser type, operating system, language settings, and approximate location (e.g., city/region).
Usage and Activity Data. Pages or screens viewed, features used, clicks and navigation paths, access times and duration, referring URLs, and, where applicable, interactions with our communications (e.g., whether you open emails or click links).
Logs, Diagnostics, and Security Telemetry. Timestamps, log files, error and crash reports, performance data, and security-related signals used to protect the Site and Services and prevent fraud and abuse.
Cookies and Similar Technologies. For more information, see Section 6 (Cookies and Similar Technologies).
Bot Detection / reCAPTCHA (if used). We may use security and anti-abuse tools. If we use reCAPTCHA or similar services, they may collect device/browser information and interaction signals (e.g., mouse movements or clicks) and process such information in accordance with the provider’s policies.
Mobile App and Push Notification Data. If an Authorized User uses a Reslify mobile application and enables push notifications, we may collect and store the user and Client/merchant identifiers associated with the device; an installation identifier; device platform and push provider; an AWS SNS platform-endpoint identifier and the last four characters of the native push token; notification-permission status; app name and version; device model, operating-system information, locale, time zone, and related registration and last-seen timestamps. The complete native token is received through the authenticated registration request and handled transiently to establish or refresh the AWS endpoint, but is not retained in Reslify's application database. We use this information to register the device, route operational notifications, maintain device registrations, and protect the Services. Reslify does not need precise device location to provide the currently implemented push-notification functionality.
Do Not Track. We do not respond to ‘Do Not Track’ browser signals.
Opt-out preference signals. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC). For more information, see Sections 6 and 15.
2.4 Information from third parties
Clients/Venues and their authorized agents. Clients may input booking-related data into the Platform (including information entered by Venue staff or authorized agents) and may connect integrations or booking channels that transmit booking-related data as configured by the Client (for example, “Reserve with Google” or other third-party booking partners).
Third-party services you use in connection with the Services (if applicable). If you choose to use third-party services in connection with, or otherwise link to, the Site or Services (for example, single sign-on providers), we may receive information such as identifiers or profile information made available to us based on your settings with that third party.
Service Providers. Our service providers (including AWS) may provide operational, security, or diagnostic information to support hosting, reliability, monitoring, and incident response. Where such providers process Client Personal Data on our behalf in Processor contexts, they are treated as subprocessors as described in Section 4.1 and are listed in Schedule 2 of the DPA.
Public sources (B2B). Where permitted by law, we may obtain business contact information from public sources (for example, public records or publicly available professional information).
Private sources (B2B) (if applicable). Where permitted by law, we may obtain business contact information from third-party data providers or licensors.
Marketing partners (if any). If we run joint marketing activities or co-sponsored events, we may receive information from marketing partners in connection with those activities.
3. HOW WE USE INFORMATION
How we use information depends on the context and whether Reslify acts as a Controller or a Processor, as described above.
3.1 Provide and operate the Services (Processor and Controller contexts)
We use information to provide, operate, maintain, and support the Services (including the Site, Platform, and Widget), including to:
- Provision and administer access. Set up, administer, and secure Client accounts and Authorized User access (e.g., identity, authentication, roles/permissions, tenant administration, and account settings).
- Authenticate and enable use of the Services. Identify you and authenticate you as an Authorized User, including handling login, SSO (if available), and access control.
- Process bookings, purchases, and operational workflows. Process reservations, bookings, ticketed events/experiences, Venue-issued gift-card purchases, delivery and redemption, and related operational workflows on the Client’s instructions, including changes, cancellations, confirmations, and balance adjustments.
- Import and manage menu content. Receive Client-uploaded menu files and images, extract and structure menu information, generate a draft for Client review, and create or update menu content only after the applicable Client action or confirmation.
- Facilitate Client-configured communications. Deliver service communications sent by or on behalf of Clients/Venues (e.g., confirmations, reminders, updates, cancellations, and check-in/attendance flows), as configured through the Services.
- Provide operational mobile notifications. Register Authorized Users' devices and send push notifications about reservation and reservation-request events to permitted Client users, where notifications are enabled.
- Support deposits, prepayments, card guarantees, later cancellation/no-show charges, and holds if enabled. Process and display limited payment status, saved-payment-method status, transaction metadata, and masked card descriptors where needed to provide the Services, without storing full card numbers or card security codes; see Section 4.2.
- Provide customer support and continuity. Troubleshoot issues, respond to support requests, maintain service continuity, and perform operational communications necessary to provide the Services.
- Personalize in-product experience (where applicable). Remember preferences and provide in-product guidance or configuration support for Authorized Users, where applicable.
3.2 Client billing and commercial relationship management (Controller)
We use information to manage our commercial relationship with Clients (and prospective Clients), including to:
- Subscriptions and billing administration. Set up and administer subscriptions, plan selections, renewals, and account-level billing settings (generally outside the Client tenant).
- Invoicing and payment management (Reslify billing). Issue invoices for Reslify subscription fees and other Reslify charges, reconcile payments, manage payment status, and (where applicable) process refunds, billing disputes, and chargebacks relating to Reslify’s own invoices/fees.
- Accounting, tax, and compliance recordkeeping. Maintain accounting, tax, audit, and compliance records and documentation as required or permitted by law.
- Billing and contract communications. Communicate with Clients (and, where applicable, designated billing contacts) about billing and contractual matters (e.g., invoicing notices, payment status, renewals, and plan changes).
- Disputes and enforcement. Maintain internal customer records for dispute resolution, collections (where applicable), and enforcing our agreements.
For clarity, this Section 3.2 covers Reslify–Client billing (e.g., Reslify subscription fees). Guest payments or payment arrangements made to or for a Client/Venue through the Services (including deposits, prepayments, gift-card purchases, card guarantees/saved payment methods, later cancellation/no-show charges, and, where separately enabled, authorization holds) are handled by the Client/Venue and the payment processor under the applicable terms, policies, and payment processor rules. For service operation, support, and account access within the Services, see Section 3.1.
3.3 Security, fraud/abuse prevention, and reliability (Controller and Processor contexts)
We use information to protect the Site and Services and to maintain reliability, including to:
- Security monitoring and incident response. Monitor for, detect, and respond to security events, vulnerabilities, and incidents; investigate suspicious activity; and take steps to protect the integrity of the Site and Services.
- Fraud, abuse, and misuse prevention. Detect, prevent, investigate, and respond to harmful, unauthorized, illegal, or abusive activity (e.g., attempted account compromise, spam, abuse, cyberattacks, and identity theft).
- Access controls and auditability. Enforce access controls, permissions, and authentication measures, and maintain auditability within the Platform (including tenant-level action/audit trails visible to Clients), to help protect accounts and data.
- Service reliability and performance. Monitor, debug, and improve performance and reliability (e.g., error logs, crash reports, diagnostics, and uptime monitoring), including troubleshooting and remediation.
- Safety and integrity. Protect Reslify, our Clients, Guests, and others from security threats and other harmful activity, consistent with applicable law and contractual obligations.
3.4 Platform Analytics, Diagnostics, and Service Improvement
(a) Client reporting and analytics (Processor). As part of providing the Services, Reslify may generate reports, dashboards, and analytics within a Client account (for example, reservation volume, cancellations/no-shows, seating utilization, ticketing/prepayment performance, and operational trends). In these cases, Reslify processes Client Personal Data as a Processor/service provider on behalf of the Client, and the Client determines how such reporting is used.
(b) Service telemetry and limited Controller purposes. Identifiable technical, usage, diagnostic, performance, and operational data generated within a Client account to provide, maintain, troubleshoot, or report on the Services is processed on behalf of the Client as Client Personal Data. This includes in-tenant feature-usage events, configuration indicators, user-action and audit trails, request metadata, and diagnostics used to provide or support the Client’s Services.
Reslify processes identifiable telemetry as an independent Controller only to the minimum extent necessary for purposes Reslify determines independently: platform-wide security monitoring and incident response; fraud and abuse prevention; compliance with law and legal process; billing and direct contract or account administration outside the Client tenant; and establishing, exercising, or defending legal claims (“Limited Controller Telemetry”). Limited Controller Telemetry may include device, browser, network and IP information, timestamps, security events, fraud and abuse signals, authentication events, and limited request, error, or diagnostic metadata necessary for those purposes. It does not include Client Content or the substantive content of Guest booking records except where access is strictly necessary for a specific security incident, fraud or abuse investigation, legal obligation, or legal claim.
Reslify does not use identifiable Client Personal Data, including Client booking data, for its own general product analytics or service-improvement purposes. Reslify may use aggregated or anonymized usage and performance information for product analytics and service improvement only where that information is no longer Personal Data under applicable law. Reslify does not attempt to re-identify such information and does not use Client booking data processed as a Processor to independently market to that Client’s Guests.
For clarity, troubleshooting, capacity planning, reliability monitoring, product analytics, and service improvement involving identifiable Client Personal Data remain Processor activities unless the Processing is strictly necessary for one of the limited independent Controller purposes stated above.
We do not disclose Limited Controller Telemetry in a manner that identifies a particular Client or Data Subject except (i) to Reslify’s service providers acting under Reslify’s instructions and confidentiality obligations, (ii) where required by applicable law or legal process, or (iii) as necessary to establish, exercise, or defend legal claims.
We apply access controls and least-privilege principles to Limited Controller Telemetry and limit internal access on a need-to-know basis.
(c) No Guest marketing or cross-client profiling. Reslify does not use Client booking data that Reslify processes as a Processor to independently market to that Client’s Guests, build Reslify marketing profiles of Guests, or combine identifiable Client Personal Data across Clients for product analytics or service improvement.
(d) Legal bases (where applicable). Where European data protection law applies and Reslify acts as Controller for Limited Controller Telemetry, Reslify generally relies on legitimate interests for security, fraud and abuse prevention, direct contract and account administration, and legal claims; contractual necessity for direct billing and contract administration where applicable; and compliance with legal obligations where Processing is required by law.
3.5 Marketing (B2B) and promotional communications (Controller)
Where permitted by applicable law, we (and our service providers) may collect and use business contact information and communications engagement data (e.g., whether emails are opened or links are clicked) for marketing and promotional purposes, including to:
- Direct marketing. Send you B2B marketing communications (e.g., product updates, newsletters, webinars, events, and offers). Where permitted, we may personalize these messages based on your expressed preferences, interactions with our communications, and your relationship with us. You can opt out as described in Section 14.5 (Marketing communications).
- Marketing partnerships (if any). Administer joint webinars/events or co-sponsored campaigns with partners (where applicable), and measure the effectiveness of such campaigns.
- Interest-based advertising (not currently enabled). We do not currently engage in interest-based advertising or “cross-context behavioral advertising” using third-party advertising cookies, pixels, or similar technologies on the Site. If we enable interest-based advertising in the future, we may work with advertising partners to deliver, measure, and improve ads and may share limited information such as online identifiers (e.g., cookie or device identifiers) and information about interactions with the Site and our marketing communications. Where required by law, we will provide any required notices and choices (including cookie consent and opt-out mechanisms) and will update this Policy and our Cookie Notice accordingly.
- Your choices. Where required, we will obtain your consent for non-essential cookies and similar technologies. We will also provide opt-out choices as required by applicable law. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC). For more information, see Section 6 (Cookies and Similar Technologies) and our Cookie Notice, and (where applicable) Section 15 (United States – State Privacy Rights).
- No Guest marketing using Client booking data. For clarity, we do not use Guest booking data that we process on behalf of a Client as a Processor to send Reslify’s own marketing communications to that Client’s Guests. See Sections 1 and 3.4.
3.6 Legal, compliance, and enforcement (Controller)
We use information as necessary to:
- Comply with applicable law and legal process. Comply with applicable laws, regulations, and lawful requests (including from law enforcement, regulators, or courts, where applicable).
- Enforce our agreements and policies. Enforce our Terms/agreements, this Policy, and other policies, and investigate potential violations.
- Protect rights and safety. Protect the rights, privacy, safety, and property of Reslify, our Clients, Guests, and others, including by establishing, exercising, or defending legal claims.
- Maintain records and meet compliance obligations. Maintain appropriate records for legal, accounting, tax, and compliance purposes, and perform internal audits and compliance monitoring where appropriate.
- Recruiting and hiring (if applicable). Process employment application data to review applications, communicate with candidates, conduct interviews, evaluate qualifications, manage recruiting operations, and comply with applicable legal obligations.
- For fraud/abuse prevention and security monitoring, see Section 3.3.
3.7 AI Booking Assistant, AI-Assisted Menu Import, and other AI Features
AI Booking Assistant. Where enabled by a Client, Reslify provides an AI-powered booking assistant on certain guest-facing booking experiences. The AI Booking Assistant may respond to Guest questions and propose booking-flow actions or draft changes. The booking flow remains the source of truth: the AI Booking Assistant does not independently confirm a reservation, create a hold, make a payment, or make a final decision on behalf of a Venue.
Information processed. To provide the AI Booking Assistant, Reslify processes Guest messages and any personal data included in those messages, relevant booking-journey information (such as requested date, time, party size, availability, and selected booking options), prior conversation context, and Client-configured venue information, offers, policies, and other booking content. Guests should not submit unnecessary Sensitive Data through the AI Booking Assistant, including health or allergy information; important allergy, accessibility, safety, payment, cancellation, and special-requirement questions should be directed to the Venue.
AI-Assisted Menu Import. Where enabled by a Client, Reslify may use an AI model to extract and structure menu information from files or images uploaded by an Authorized User. The information sent for this purpose may include the uploaded file or image, its file name and type, extracted menu text, menu names, categories, item names, descriptions, prices, and dietary or source labels. The generated result is a draft for Client review and may be edited or rejected before it is used as menu content. Clients should not upload files containing unnecessary personal data or Sensitive Data.
Retention. Reslify stores an AI Booking Assistant session in Reslify’s systems for up to 24 hours to maintain the conversation and booking journey. The stored conversation history is limited to the most recent messages and is designed to redact email addresses and telephone numbers before storage. AI-assisted menu-import source files and associated import-job records stored by Reslify are scheduled to expire after up to seven (7) days. These Reslify retention periods are separate from the AI provider’s retention. Under OpenAI’s standard API data controls, API inputs and outputs may be retained in abuse-monitoring logs for up to thirty (30) days, unless a shorter approved retention control applies, and may be retained longer where OpenAI is legally required to do so. Menu content that a Client reviews and saves to the Services becomes part of the Client’s menu data and is retained in accordance with the Client’s instructions and the DPA.
AI model provider. Reslify uses OpenAI OpCo, LLC to process AI Booking Assistant requests and AI-assisted menu imports on Reslify’s behalf. Where that processing involves Client Personal Data, OpenAI acts as a subprocessor and is identified in Schedule 2 of the DPA. Processing occurs in the United States.
No training of general-purpose models using Client data (unless solely for Client’s use). Unless otherwise expressly agreed in writing with the Client, Reslify does not use or share Client Personal Data or Client Content processed on behalf of a Client to train, fine-tune, or improve any generalized artificial intelligence model that is not deployed solely for that Client’s use. OpenAI states that data submitted through its business/API services is not used to train or improve its generalized models by default unless the customer affirmatively opts in.
Service improvement using aggregated/de-identified data. Reslify may use aggregated, anonymized, and/or de-identified usage and performance data (and other data that is no longer Personal Data under applicable law) to develop, maintain, and improve the Services, including AI Features, consistent with applicable law. Reslify does not attempt to re-identify de-identified data except where permitted by law.
Transparency and required notices. The Reslify-controlled guest interface identifies the AI Booking Assistant as an AI system through a clear, visible, and non-configurable notice before a Guest can send it a message. Clients must not remove, obscure, or misrepresent that notice and remain responsible for any additional notices required by their configuration or applicable law, including, where applicable, the EU AI Act.
3.8 With Your Consent. Where required by applicable law, or where we otherwise ask for your consent, we will process personal data for the purposes described at the time you provide consent. You may withdraw your consent at any time, subject to legal or contractual restrictions.
4. HOW WE DISCLOSE INFORMATION
We may disclose your personal data as described below and as described elsewhere in this Policy.
4.1 Service providers and subprocessors
We use service providers to help us operate, provide, and secure the Services. Our primary infrastructure provider is Amazon Web Services (“AWS”), which supports core hosting and infrastructure for the Platform. The contracting and invoice-issuing entity for Reslify’s current production AWS account is AWS Turkey Pazarlama Teknoloji ve Danışmanlık Hizmetleri Limited Şirketi. AWS’s data-processing terms also apply with Amazon Web Services, Inc. and the applicable AWS contracting party, as described in Schedule 2 of the DPA.
Where enabled, Reslify uses OpenAI OpCo, LLC to generate AI Booking Assistant responses and to extract and structure information from Client-uploaded menu files or images. OpenAI processes the necessary request information and uploaded menu material in the United States only on Reslify’s instructions and subject to contractual confidentiality, security, and data protection obligations. OpenAI and its processing location are identified in Schedule 2 of the DPA.
For operational push notifications in the Reslify Host mobile application, Reslify uses Amazon Simple Notification Service (“AWS SNS”) to establish an endpoint for the device's native Apple Push Notification service (“APNs”) token and to deliver a minimized notification to Apple. AWS SNS and Apple may process the native token and a neutral localized title and party-size body together with a versioned data payload containing the event type, Client/merchant identifier, pseudonymous reservation or request identifier, event timestamp, and party size. The payload excludes the Guest’s name and contact details, reservation time and status, notes, free text, and application routes. The authenticated application constructs the route locally and retrieves any detailed Guest or reservation information directly from Reslify. Expo is used for EAS Build and EAS Update only and does not receive device push tokens or operational notification payloads through this delivery path. AWS, Expo, and the independent APNs service are identified in Schedule 2 of the DPA.
Reslify also uses Google Analytics 4 (“GA4”) for server-side product, operational, conversion, and service-usage analytics. The implemented server-side integration sends allow-listed event names and properties, a generated or pseudonymous client/session identifier, timestamps, application/surface information, and product or transaction event metadata. It is designed not to send raw names, email addresses, telephone numbers, payment-card details, free-text Guest notes, or full page URLs. Google may process this information under the applicable Google service terms. Browser-based GA4 collection is not enabled unless the relevant external analytics setting is enabled and any consent required by applicable law has been obtained.
Processor contexts (Client Personal Data). Where we process Client Personal Data on behalf of a Client/Venue as a Processor (or as a service provider/contractor, where applicable), our service providers that process such Client Personal Data on our behalf act as “subprocessors” and are engaged under written agreements that include confidentiality, security, and data protection obligations as required by applicable law. Our current list of subprocessors for Client Personal Data is set out in Schedule 2 of the DPA.
Clients. If you are a Client/Venue, our Data Processing Addendum (DPA) governs Reslify’s processing of Client Personal Data as a processor.
Controller contexts (Reslify-controlled data). Where we process personal data as an independent Controller (for example, Site operations, direct account and contract administration outside a Client tenant, billing, platform-wide security, fraud and abuse prevention, legal compliance, legal claims, and Limited Controller Telemetry), we may use service providers to support those activities. Such providers process personal data only under our instructions and subject to confidentiality and security obligations.
We do not disclose Client Personal Data or Limited Controller Telemetry to third parties for their own independent purposes, except as described in this Policy. If we add or replace subprocessors for Client Personal Data, we will provide notice to Clients as described in the DPA and update the DPA subprocessor list accordingly.
4.2 Payment processing
We use third-party payment processors such as Stripe or PAYTR to process deposits, prepayments, gift-card purchases, saved payment method setup/card guarantees, possible later cancellation/no-show charges, and, where separately enabled, authorization holds made or arranged through the Services. Stripe uses provider-controlled payment elements or checkout pages, and the supported PAYTR marketplace flow uses a provider-hosted iframe operated under the Turkish Payment Operator’s marketplace account. In the current Stripe Connect card-guarantee flow, the payment method may be saved on the Client/Venue’s connected Stripe account through a SetupIntent for possible future off-session use; saving a payment method is not, by itself, an authorization hold or completed charge. Sensitive card input is collected by the applicable processor and is processed under that processor’s own terms and privacy policy. The Reslify entities do not store full payment card numbers or card security codes (CVV).
Reslify may receive and process the payment and settlement metadata described in Section 2.2. In the PAYTR marketplace flow, the Turkish Payment Operator submits the gross amount, seller net amount, platform commission, beneficiary name and IBAN, and related transaction, refund, and adjustment instructions to PAYTR. PAYTR transfers the Client/Venue’s seller net amount directly to its designated IBAN and transfers only the applicable platform commission to the Turkish Payment Operator’s account. These records support payment facilitation, reconciliation, reporting, fraud prevention, accounting, tax, legal compliance, and legal claims, but do not include full card numbers or card security codes. Reslify does not independently adjudicate Guest refunds, disputes, or chargebacks; these are handled by the Client/Venue and the payment processor under the applicable terms and rules.
4.3 Client-directed sharing and integrations
If a Client enables integrations or connects third-party services (for example, “Reserve with Google” or other supported partners), booking-related data may be exchanged with those third parties as configured by the Client and as necessary to fulfill bookings and synchronize availability, reservations, and status updates.
During Client onboarding and venue configuration, Reslify uses Google Maps location services, including Places/geocoding and time-zone functionality, to search for and validate a Venue location and determine its time zone. Search text, address or place information, geographic coordinates, place identifiers, locale, and related device/network information may be sent to Google as necessary to provide this functionality. Google processes this information under its own terms and privacy policy.
Clients are responsible for configuring integrations and providing any notices and obtaining any consents required for such Client-enabled sharing under applicable law. Third parties that receive data through Client-enabled integrations process that data under their own terms and privacy policies, and Clients and Guests should review those third-party policies where applicable.
4.4 Disclosure to Clients (Guest and booking contexts)
When a Guest makes a reservation or purchase through a Client/Venue’s booking flow (including via the Widget, Reslify-hosted booking pages, and supported integrations as configured by the Client), the information the Guest provides (such as name and, if provided, email address and/or phone number) is made available to the applicable Client/Venue and its Authorized Users so it can administer the booking (for example, confirmations, changes, cancellations, check-in/attendance, and service delivery). If a Guest submits notes, preferences, or other information (including in free-text fields), those details will also be shared with the applicable Client/Venue to the extent necessary to provide the booking and related services.
The Client/Venue processes Guest information in accordance with its own privacy practices and policies. Access to Guest booking information within the Platform is generally limited to the Client/Venue with which the Guest interacted and its Authorized Users, subject to that Client/Venue’s configuration and access controls. Venues cannot use the Services to access Guest booking information associated with other Venues, except where a Client with multiple venues under common ownership elects to share information within its corporate group for multi-venue management, subject to the Client’s settings and applicable law.
Privacy requests. If a Guest submits a privacy request relating to a Client/Venue (for example, access, correction, or deletion of booking-related data), please see Section 14.1. Reslify may, where appropriate, support the Client/Venue in responding, consistent with applicable law and our contractual obligations.
Reslify is not responsible for personal data that a Client/Venue collects independently on its own websites, systems, or other services that are not provided through the Services.
If a Client operates multiple Venues and enables cross-venue sharing, the Client remains the Controller. Guests should contact the Venue where the booking was made (or the Client entity identified in the booking confirmation) for rights requests.
4.5 Professional advisors; authorities; legal compliance; and protection of rights
We may disclose personal data to our professional advisors (such as auditors, lawyers, accountants, and insurers) where necessary for our legitimate business purposes, including to obtain advice, perform audits, and manage risk.
We may also disclose personal data to law enforcement, courts, regulators, government authorities, or other third parties where we reasonably believe in good faith that disclosure is required by applicable law, legal process, or a lawful request, or where disclosure is necessary to protect the rights, privacy, safety, and security of Reslify, our Clients, Guests, or others (including to prevent, detect, investigate, or respond to fraud, abuse, security incidents, or other harmful or unlawful activity).
To the extent any disclosure in this Section includes Client Personal Data that Reslify processes as a Processor, Reslify will make such disclosure only as permitted under the DPA and applicable law (including, where required, to competent authorities), and where the recipient is a service provider/subprocessor, under written terms consistent with the DPA. Where Reslify acts as a Controller for the relevant data, Reslify will disclose such data only as described in this Policy and consistent with applicable law.
4.6 Corporate transactions
We may disclose information in connection with an actual or contemplated merger, acquisition, reorganization, financing, bankruptcy/insolvency, or sale or transfer of some or all of our business or assets, including as part of due diligence or negotiations. In such cases, we may take commercially reasonable steps to help ensure appropriate confidentiality and security protections apply to the information involved. If a transaction results in another organization acquiring all or a portion of our business or assets, that organization may process the information as described in this Policy (or as otherwise disclosed to you).
For clarity, where information is Client Personal Data that Reslify processes as a Processor, Reslify will disclose or make such information available in connection with a corporate transaction only as permitted under the applicable agreements (including the DPA) and applicable law, and subject to appropriate confidentiality and security measures.
4.7 Marketing partners (co-marketing), if any
If you choose to provide your business contact information in connection with a co-marketing initiative we run with another company (for example, registering for a joint webinar or downloading content co-produced with a partner), we may share your information with that partner, as disclosed at the time of collection and in compliance with applicable law. The partner will be identified on the relevant landing page or materials so you understand that it is a co-marketing initiative. The partner’s processing of your information is subject to its own privacy practices and policies.
4.8 Advertising partners (interest-based advertising)
We do not currently share personal data with third-party advertising partners for interest-based advertising. If we engage in interest-based advertising in the future, we may share limited information (such as online identifiers, device/cookie identifiers, and information about interactions with the Site and our marketing communications) with advertising partners to deliver, measure, and improve advertising, as described in Section 3.5 and our Cookie Notice. Where required by law, we will obtain consent for non-essential cookies/technologies and provide opt-out choices. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC).
4.9 No sale or sharing of personal information (as defined by applicable law)
Processor contexts (Client Personal Data). Where Reslify processes Client Personal Data on behalf of a Client/Venue as a Processor (or as a Service Provider/Contractor, where applicable), Reslify does not sell or share personal information (as those terms may be defined under applicable law) and processes such information only to provide the Services in accordance with the applicable agreement(s) (including the DPA) and the Client/Venue’s documented instructions.
Controller contexts. Reslify does not sell personal information for monetary consideration, and we do not currently share personal information for cross-context behavioral advertising or targeted advertising as those terms may be defined under applicable law. If our practices change, we will provide any required notices and opt-out choices. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC).
5. DATA RETENTION
We retain personal data for as long as reasonably necessary to fulfill the purposes described in this Policy, including to provide, maintain, and secure the Services, comply with applicable legal, accounting, and reporting requirements, resolve disputes, establish or defend legal claims, and enforce our agreements.
Processor contexts (Client Personal Data). Where we process Client Personal Data on behalf of a Client/Venue as a Processor (or as a Service Provider/Contractor, where applicable), retention, deletion, and return are governed by our agreement(s) with the Client/Venue (including the DPA) and the Client/Venue’s documented instructions. Upon expiration or termination of the applicable agreement, we will delete or return Client Personal Data at Client’s written election. If Client does not specify its election within thirty (30) days following expiration or termination, we will delete the Client Personal Data, unless retention is required by applicable law. To the extent of any inconsistency regarding deletion/return timelines and procedures for Client Personal Data, the DPA controls.
Feature-specific operational retention. AI Booking Assistant session data and AI-assisted menu-import source files and import-job records stored in Reslify’s systems are retained as described in Section 3.7. The separate OpenAI API retention described in Section 3.7 applies to information transmitted to OpenAI. Mobile push-device registrations are scheduled to expire 90 days after their most recent registration or refresh and may be deleted earlier when the user unregisters the device or when Reslify receives an invalid-token response. Gift-card purchase, delivery, balance, and redemption records and saved menu data remain part of the applicable Client’s operational records and are retained in accordance with the Client’s instructions, the DPA, and applicable law.
Operational logs. Ordinary production application, API, request, error, AI, import, and session diagnostics are retained in access-controlled primary logging systems for up to 30 days and may be deleted earlier. Only selected, explicitly classified, and minimized security, payment, and dispute evidence events are copied to an access-controlled archive for up to 400 days. Archived evidence excludes request bodies, headers, authentication material, network identifiers, contact details, free-text provider errors, and stack traces; it contains only stable event classifications and identifiers necessary to investigate security or payment events. Relevant evidence may be preserved for longer only under a documented, case-specific legal hold or where necessary to comply with law or establish, exercise, or defend legal claims, and such holds are reviewed periodically.
Controller contexts only. In determining appropriate retention periods in Reslify Controller contexts, we consider the amount, nature, and sensitivity of the data; the potential risk of harm from unauthorized use or disclosure; the purposes for which we process the data and whether those purposes can be achieved through other means; and applicable legal requirements.
We may retain aggregated, anonymized, and/or de-identified information for longer periods as permitted by law. We do not attempt to re-identify de-identified information except as permitted by law.
6. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies, pixel tags, SDKs, and similar technologies to operate and secure our Site and Services, remember preferences, and understand usage. For more information about the types of cookies and similar technologies we use and your choices, please see our Cookie Notice. Where required by law, we obtain your consent before using non-essential cookies, and you can manage your preferences through your browser settings and, where provided, our cookie settings tools. Some features may not function properly without certain cookies. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC), for certain online tracking activities that may be considered “sale,” “sharing,” or targeted advertising. Opt-out preference signals are generally browser- and device-specific, and you may need to renew your preference if you use a different browser/device or clear cookies.
7. SECURITY
Reslify uses reasonable administrative, technical, organizational, and physical safeguards designed to protect the personal data we process, whether we act as a Controller or a Processor in the applicable context. However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of personal data.
8. COMMUNICATIONS AND DISCLOSURES
Service communications (Guests). Guests may receive automated service messages by email and/or text message relating to a booking, such as confirmations, reminders, updates, changes, cancellations, check-in/attendance status, or requests for feedback (“Service Communications”). These messages are sent by or on behalf of the applicable Client/Venue and delivered through the Services (powered by Reslify), as configured by the Client/Venue. Depending on the configuration, the sender name may reference the Client/Venue, and Reslify may appear as the delivery facilitator or service provider. You may not be able to opt out of essential Service Communications, because they are necessary to administer your booking and provide core functions of the Services. Message and data rates may apply.
Service communications (Authorized Users). Authorized Users may receive administrative and account-related messages (for example, security notices, password resets, support communications, billing messages, and service updates). Authorized Users may not be able to opt out of essential administrative messages.
Marketing communications (Reslify – B2B). Where permitted by law and if applicable, Reslify may send marketing communications to business contacts (for example, product updates, webinars, and events). You can opt out as described in Section 14.5 (Your Privacy Rights and Choices). For more information about Reslify marketing and our use of Guest booking data, see Section 3.5.
From Clients/Venues. Clients/Venues may use the Services to send Guests Service Communications and, where permitted by law and where a Guest has opted in (or another lawful basis applies), Marketing Communications. When a Client/Venue sends communications through the Services, Reslify processes the personal data involved as described in this Policy (including where Reslify acts as a Processor/service provider on behalf of the Client/Venue). The Client/Venue remains responsible as the Controller for determining the purposes and means of processing, providing required notices, and obtaining any required consents or other lawful basis under applicable law. Communications that a Client/Venue sends outside of the Services are governed by the Client/Venue’s own privacy policy and practices. You may opt out of Client/Venue Marketing Communications using the mechanisms provided by the Client/Venue (for example, unsubscribe links in emails or “STOP” instructions in texts), where applicable.
9. ACCOUNTS (AUTHORIZED USERS)
Authorized Users can access, review, and update certain account information (such as business contact details, login credentials, and account settings) through the Services, subject to the Client’s access controls and administrator settings.
Authorized Users may contact us to request deactivation of their Authorized User access. We may need to verify identity and authority (including confirming the request with the applicable Client administrator, where appropriate). We will process deactivation requests and any associated Client Personal Data in accordance with the applicable agreement (including the DPA), the Client’s instructions, our retention practices, and applicable law. For information about privacy rights and choices, see Section 14 (Your Privacy Rights and Choices). See also Section 17 (Contact Us).
If you are a Guest, please contact the relevant Client/Venue to exercise rights or manage marketing preferences related to your booking. Reslify does not use Client booking data processed on behalf of Clients/Venues to market to Guests. See Sections 1 and 3.4.
10. CHILDREN
The Services are intended for use by businesses (Clients/Venues) and are not directed to children. Reslify does not knowingly collect personal data from children in connection with the Site or in Reslify’s independent Controller contexts. In connection with reservations and bookings made through a Client/Venue, information may be submitted by Guests or entered by venue staff in the course of providing the requested service; Reslify processes such information on behalf of the applicable Client/Venue in accordance with the Client/Venue’s instructions and applicable agreements. If we become aware that personal data from a child has been collected in our independent Controller contexts, we will take steps to delete it as soon as reasonably practicable, subject to applicable law. If you believe we may have collected personal data from someone under 18, please contact us at support@reslify.com.
11. CHANGES TO THIS POLICY
We may update this Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Any updates will be posted on this page, and we will update the “Last Updated” date at the top of this Policy (which is the effective date of the updated version). We encourage you to review this page periodically to stay informed about any changes.
We will update this Policy as needed to reflect changes in our practices and to comply with applicable privacy laws. If we make material changes, we will provide notice as required by applicable law, which may include sending an email to Clients or their Authorized Users and/or posting a prominent notice on our Site and/or within the Platform.
For updates that affect Client Personal Data processed by Reslify as a Processor under the DPA, notice will be provided as set out in the DPA.
12. LANGUAGE
This Policy is written in English. Any translation is provided for convenience only. In the event of any inconsistency, the English version will prevail, except to the extent mandatory law requires otherwise.
13. INTERNATIONAL DATA TRANSFERS AND DATA LOCATION
Where data is stored (EEA / Frankfurt). Our primary production hosting environment for the Platform is located in the EEA (currently Frankfurt, Germany), including our primary production database environment. For Clients/Venues established in the EEA, Platform production data is generally hosted in our EEA region by default, unless otherwise agreed. This statement concerns the Platform’s primary production environment; other systems (e.g., the Site, support tooling, communications systems) may be hosted in other regions, subject to appropriate safeguards. For clarity, for EEA Clients the Platform’s primary production environment (including the primary production database) is hosted in our EEA region by default, and any non-EEA access is limited and safeguarded as described in this Section 13 and, for Processor contexts, in the DPA.
Remote access and processing outside the EEA. Even where data is hosted in the EEA, personal data may be accessed from or processed in other jurisdictions as necessary to provide, maintain, secure, and support the Services (for example, for customer support, security monitoring, maintenance, and incident response). Depending on the circumstances, such access may be considered an international transfer under applicable European data protection law.
AI Features / United States. Where the AI Booking Assistant or AI-assisted menu import is enabled, the information necessary to generate a response or structure an uploaded menu may be processed by OpenAI OpCo, LLC in the United States. For menu import, this may include the uploaded menu file or image and extracted menu information. This processing may constitute an international transfer of personal data.
Mobile push notifications. Where an Authorized User enables push notifications, the native APNs token and minimized notification payload described in Section 4.1 may be processed by AWS SNS and Apple APNs in the locations applicable to those services. This processing may constitute an international transfer of personal data. Expo does not process push tokens or notification payloads in this delivery path.
Analytics. GA4 analytics information may be processed by the applicable Google entity in the EEA, the United States, or other locations where Google operates. This activity may constitute an international transfer of personal data and is subject to the safeguards described below where required.
PAYTR marketplace operations / Türkiye. Where the supported PAYTR marketplace flow is enabled, the payment and settlement metadata described in Sections 2.2 and 4.2 may be accessed and processed in Türkiye by the Turkish Payment Operator and PAYTR. PAYTR settles the Client/Venue’s seller net amount directly to the Client/Venue’s designated IBAN; only the applicable platform commission is transferred to the Turkish Payment Operator.
Safeguards for transfers from Europe. Where we transfer (or enable access to) personal data from the EEA, the UK, or Switzerland to a country that is not recognized as providing an adequate level of protection, we rely on appropriate safeguards, which may include: (i) the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914); (ii) the UK International Data Transfer Addendum to the EU SCCs; and/or (iii) a Swiss addendum/approach that recognizes the EU SCCs with necessary adaptations, together with supplementary measures where appropriate. In limited circumstances, we may rely on a lawful transfer derogation where permitted by applicable law.
More information. You may contact us at support@reslify.com to request additional information about the safeguards we use. For Client Personal Data processed on behalf of Clients/Venues as a Processor (or Service Provider/Contractor), the relevant transfer safeguards are set out in our agreements with the Client/Venue (including our DPA).
14. YOUR PRIVACY RIGHTS AND CHOICES
Your rights depend on where you live and the context in which Reslify processes your information (for example, whether Reslify acts as a Processor for a Client/Venue or as an independent Controller for Reslify’s own purposes).
14.1 Guests (data processed on behalf of Clients/Venues)
If you are a Guest using a Client/Venue’s booking flow, the Client/Venue is typically the Controller of your personal data used for reservations, guest profiles, and venue operations. To exercise your rights (such as access, correction, or deletion) regarding that booking or guest profile, please contact the relevant Client/Venue directly. If you are unsure which Client/Venue to contact, you may email us at support@reslify.com and we will try to help route your request to the appropriate Client/Venue. This Guest section applies to booking and venue-profile data that Reslify processes on behalf of a Client/Venue. For personal data that Reslify processes as an independent Controller (for example, Site cookies, direct account or billing records, or Limited Controller Telemetry described in this Policy), you may contact Reslify directly at support@reslify.com.
If Reslify receives a request from a Guest relating to data processed on behalf of a Client/Venue, Reslify will generally notify the relevant Client/Venue and direct the requester to the Client/Venue. Reslify will not take substantive action on such requests except on the Client/Venue’s documented instructions, and, where appropriate, Reslify will assist the Client/Venue as required by our contractual obligations and applicable law.
14.2 EEA / United Kingdom / Switzerland (Reslify Controller contexts)
If Reslify is the Controller of your personal data and the GDPR, UK GDPR, and/or applicable Swiss data protection law applies, you may have certain rights (such as access, correction, deletion, restriction, objection, portability, and withdrawal of consent) and the right to lodge a complaint with a supervisory authority. For additional information for European users (including legal bases and international transfer details), see Section 16 (Notice to European Users).
14.3 United States – privacy rights (Reslify Controller contexts)
If you are a U.S. resident, your rights and choices are described in Section 15 (United States – State Privacy Rights).
14.4 How to exercise your rights (and verification)
To submit a request in Reslify Controller contexts (including access/know, correction, deletion, or restriction/suspension of processing), you may contact us by email at support@reslify.com.
Please describe your request with sufficient detail so we can understand and evaluate it. We may need to verify your identity and/or your authority to submit a request (for example, if you are an authorized agent). If we cannot verify, we may request additional information or deny the request as permitted by law.
Where applicable, you may request that Reslify provide access to the personal data Reslify maintains about you, including information about the categories of personal data, the sources from which it was obtained, the purposes for which it is used, and the categories of recipients to whom it is disclosed. You may also request correction, deletion, or restriction/suspension of Reslify’s processing of your personal data, as permitted by applicable law.
Guest booking data requests should be directed to the relevant Client/Venue (Section 14.1).
14.5 Marketing communications
You can opt out of marketing emails by using the unsubscribe link in the message or by contacting us. Even if you opt out of marketing, you may still receive non-marketing communications (for example, security, billing, and administrative notices) where permitted by law.
15. UNITED STATES – STATE PRIVACY RIGHTS (Reslify Controller contexts)
Where this section applies. This section applies to individuals who reside in U.S. states that provide privacy rights under applicable state privacy laws (including CCPA/CPRA, VCDPA, and similar laws) (“State Privacy Laws”). “Personal Information” has the meaning given under the applicable State Privacy Laws. If you do not provide sufficient detail for us to understand and verify your request, we may not be able to process it and may deny the request as permitted by law.
Scope (Controller vs. Processor). This section applies only to Personal Information that Reslify collects and processes on its own behalf as a Controller (for example, Site visitors, B2B communications, direct account administration outside a Client tenant, billing, platform-wide security, fraud and abuse prevention, legal compliance, legal claims, and Limited Controller Telemetry). It does not apply to Guest booking data or identifiable in-tenant telemetry processed on behalf of a Client/Venue within the Platform/tenant. Requests relating to that Client Personal Data should be directed to the applicable Client/Venue.
Your rights (vary by state; not absolute). Depending on your state of residence and applicable law, you may have one or more of the following rights: (i) confirm/access (right to know), (ii) receive a copy/portability, (iii) correction, (iv) deletion (subject to exceptions), (v) opt out of certain processing (including targeted advertising and, where applicable, “sale” or “sharing”), (vi) appeal (in certain states), and (vii) non-discrimination.
Limit Sensitive Personal Information (California, where applicable): Request that we limit the use of sensitive personal information in circumstances where the CCPA/CPRA provides such a right. Where processed, ‘sensitive personal information’ (e.g., dietary/allergy notes provided by a Guest) is used only to provide the Services, ensure security, and comply with law, and not for inferring characteristics, targeted advertising, or other purposes that California residents have a right to limit under the CCPA/CPRA.
Information about our practices (lookback period). Where required, you may also request information for the applicable lookback period (for example, the past 12 months), such as the categories of Personal Information we collected, the categories of sources, our purposes for collecting/using it, the categories of third parties to whom we disclose it, and (if any) the categories of Personal Information we sold, shared, or disclosed for a business purpose and the categories of third parties to whom it was sold, shared, or disclosed.
How to exercise your rights; verification; authorized agents. To submit a request in Reslify Controller contexts, contact us at support@reslify.com. We may need to verify your identity (and, where applicable, your state residency) and may request additional information as permitted by law. Where permitted, you may designate an authorized agent; we may require proof of authority (for example, signed permission or power of attorney, as applicable) and may require you to verify your identity directly with us.
Opt-out of targeted advertising; sale/sharing (if applicable). Reslify does not sell Personal Information for money. Where required, we provide opt-out methods. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC). For details about cookies/online tracking controls and opt-out signals, see Section 6 (Cookies and Similar Technologies) and our Cookie Notice. In the past 12 months, we have not sold Personal Information for monetary consideration. We do not currently share Personal Information for cross-context behavioral advertising or targeted advertising purposes as those terms may be defined under State Privacy Laws. If we engage in such activities in the future, we may share online identifiers (such as cookie or device identifiers), device and online activity information, and communication interaction data for those purposes, and we will provide required notices and opt-out mechanisms.
Appeals. Where applicable, if we deny your request, you may appeal our decision by contacting us at support@reslify.com with the subject line “Privacy Appeal.”
California notice (where applicable). In the past 12 months, we have not sold Personal Information for monetary consideration, and we do not currently share Personal Information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use or disclose “sensitive personal information” for purposes that California residents have a right to limit under the CCPA/CPRA. Where we process such information (e.g., dietary/allergy notes provided by a Guest), we do so only to provide the Services, ensure security, and comply with law. We do not respond to browser “Do Not Track” signals. Where required by applicable law and where technically supported, we will honor legally recognized opt-out preference signals, such as Global Privacy Control (GPC); see Section 6. If our practices change, we will update this Policy and provide any required notices and opt-out mechanisms.
16. NOTICE TO EUROPEAN USERS (EEA, UNITED KINGDOM, AND SWITZERLAND)
16.1 Where this Notice applies
This Notice applies only to individuals in the European Economic Area (“EEA”), the United Kingdom (“UK”), and Switzerland (together, “Europe”).
16.2 Controller; contact details
Controller (Reslify Controller contexts). Reslify LLC (“Reslify”) is the controller for personal data processed in Reslify’s Controller contexts under this Policy (for example, Site visitors, B2B communications, account administration outside a Client tenant, billing, security, and platform usage analytics).
Contact. For our contact details (including our postal address), please see Section 17. You may also contact us at support@reslify.com.
16.3 Roles (Controller vs. Processor) for Guest booking data
Reslify as Processor. Where a Guest interacts with a Client/Venue booking flow and Reslify processes booking-related personal data within the Platform/tenant on behalf of that Client/Venue, the Client/Venue is typically the controller and Reslify acts as a processor under the GDPR/UK GDPR/Swiss data protection law. In those contexts, the Client/Venue determines the purposes and means of processing, and the Client/Venue’s privacy practices apply to its use of Guest data. Guests should contact the applicable Client/Venue to exercise rights relating to bookings or venue records.
16.4 EU/UK/Swiss representatives (where required)
EU Representative (Article 27 EU GDPR). Reslify has appointed the following EU representative:
Bilge Hicyilmam Thulestraße 37 13189 Berlin Germany Email: privacy@reslify.com
UK and Swiss representatives. Reslify has not currently appointed a UK representative under the UK GDPR or a Swiss representative under the Swiss Federal Act on Data Protection (FADP). If and to the extent such representatives are required for Reslify’s processing activities, Reslify will appoint and maintain the applicable representative(s) and will publish their contact details in this Section 16.4. Until then, you may contact Reslify at support@reslify.com.
16.5 Legal bases for processing (Reslify Controller contexts)
Where Reslify acts as controller and European data protection law applies, we rely on one or more of the following legal bases, as applicable:
(a) Contractual Necessity (to perform a contract with you or to take steps at your request before entering into a contract);
(b) Legitimate Interests (where our interests are not overridden by your rights and freedoms);
(c) Compliance with Law (to meet legal obligations); and/or
(d) Consent (where required, including for certain cookies/technologies or specific activities).
Where we rely on legitimate interests, you may have the right to object.
Typical purposes, data categories, and legal bases (Reslify Controller contexts only):
Legal bases for processing (Reslify Controller contexts)
- Service delivery & account operations: Business contact details; account/admin & authentication; billing/subscription; support communications; limited device/log data. Legal basis: Contractual Necessity; Legitimate Interests (operate/support services, reliability).
- Security, fraud/abuse prevention & reliability: Device/network; usage/activity; logs/diagnostics/security telemetry; account/access. Legal basis: Legitimate Interests (security/integrity); Compliance with Law (where applicable).
- Legal, compliance & enforcement: Contact/identity + audit/dispute/legal request records. Legal basis: Compliance with Law; Legitimate Interests (legal claims; protection).
- Limited Controller Telemetry: Minimum identifiable security, fraud/abuse, legal-compliance, billing/contract-administration, and legal-claims telemetry. Legal basis: Legitimate Interests; Contractual Necessity where applicable; Compliance with Law where required. Identifiable Client Personal Data used to provide, maintain, troubleshoot, or report on the Client’s Services remains Processor data.
- B2B marketing & promos: Business contact; preferences; engagement. Legal basis: Legitimate Interests or Consent (jurisdiction-dependent); opt-out/right to object. Where required by applicable e-privacy/marketing laws, we will obtain consent before sending electronic marketing messages, and we will provide opt-out mechanisms as required by law.
- Interest-based / targeted advertising (if enabled): Online activity; device identifiers; cookie/pixel data. Legal basis: Consent where required (especially EEA/UK).
- Aggregation / de-identification: Aggregated/anonymized/de-identified insights. Legal basis: Legitimate Interests and/or Contractual Necessity; no re-identification except as permitted.
- With your consent: Context-specific. Legal basis: Consent (withdraw anytime).
16.6 Data retention
Our retention practices are described in Section 5 (Data Retention).
16.7 No automated decision-making with legal or similarly significant effects
In Reslify’s controller contexts, we do not engage in automated decision-making and/or profiling that produces legal or similarly significant effects for individuals.
16.8 Your rights
Under the GDPR/UK GDPR and applicable Swiss law, you may have the right to: access; correct; delete (where applicable); restrict; object (including to direct marketing); data portability; and withdraw consent (where processing is based on consent). You also have the right to lodge a complaint with your competent supervisory authority.
How to exercise your rights. To submit a request in Reslify controller contexts, contact us at support@reslify.com and/or as listed in Section 17. We may request information to verify your identity and process your request. Where permitted by law, we may decline or limit a request (for example, where we cannot verify identity, where an exemption applies, or where the request is manifestly unfounded or excessive).
16.9 International data transfers (summary)
For international data transfers and safeguards, see Section 13.
16.10 Whether you must provide personal data
In Reslify’s Controller contexts, certain personal data is required to enter into and perform our contract with you and to provide core functionality (for example, creating and administering a Client account, authentication/SSO where available, security controls, and billing/subscription administration). If you choose not to provide required information, we may be unable to provide the Services (or certain features) to you. Other information is optional; where optional information is not provided, certain features, personalization, or support may be limited.
17. CONTACT US
If you have questions about this Policy or our privacy practices, please contact:
Reslify LLC
8 The Green, Suite B
Dover, DE 19901, USA
Email: support@reslify.com
For supported PAYTR marketplace operations:
Reslify Bilişim Pazarlama Limited Şirketi
Caferağa Mahallesi, Şifa Sokak No:19
Kadıköy, İstanbul, Türkiye
Email: support@reslify.com
Note for European users. If you are located in the EEA, the UK, or Switzerland and have questions about this Policy or your rights, you may contact us at support@reslify.com. Where required, representative contact details will be provided in Section 16.4.