Privacy Policy
Last updated September 2026. Questions? [email protected]
1. Scope of this policy
This Privacy Policy explains what data Reservify ("we", "us") processes when a Business uses the Service, including through a connected Instagram professional account and/or Facebook Page (together, "Meta Channels"), and what we do with it. It applies to Business Owners, their staff, and the Customers who message a connected Meta Channel.
Reservify is a third-party application built on Meta's Instagram Messaging and Messenger Platform APIs. Nothing here overrides Meta's own privacy terms for the account you use to connect your Meta Channel(s) — this policy covers only what Reservify itself does with the data it receives.
2. Controller and processor roles
For a Business's account data (owner email, dashboard activity, billing) we are the controller. For the Customer data a Business collects through its connected Meta Channel — messages, names, phone numbers, booking history — the Business is the controller and we act only as its processor, following the Business's instructions, this policy, and the Data Processing Addendum in our Terms of Service. A Customer with a question about how their data is used by a specific Business should contact that Business directly; we assist the Business in responding.
3. Meta Platform data we receive
When a Business connects a Meta Channel, we request only the permissions required to receive messages sent to it and to send replies on the Business's behalf. Through that connection we receive:
- the content of messages a Customer sends to the connected Instagram account or Facebook Page;
- the Customer's platform-scoped sender identifier (Instagram-scoped ID or Messenger PSID) — not their public username or profile, unless the Customer shares it in the conversation;
- the connected account's own Instagram/Facebook business identifiers, used to route messages to the correct Business;
- button taps on any interactive message we send (e.g. "Confirm booking").
4. What we do not do with Meta Platform data
We do not use Meta Platform data for advertising, do not sell it, do not share it with data brokers, and do not use it to build profiles beyond what is needed to operate the booking assistant for the connected Business. We do not post to a Business's feed or Page, read its stories, or access its follower or friend lists — the permissions we request do not extend that far.
5. Other data we collect
Beyond Meta Platform data, we collect:
- Account data — the Business Owner's and any invited staff member's name, email, password/session credentials, and locale preference;
- Business configuration — services, staff, locations, hours, and policies the Business enters into the dashboard;
- Customer records the Business or Bot creates — name, phone, and email captured over DM with the Customer's consent, plus booking history and any staff notes;
- Payment data — handled entirely by our payment processor, Paddle; we receive only plan/subscription status, never card or bank details;
- Usage and diagnostic data — request logs, error reports, and aggregate usage metrics. Message bodies, prompt/response text, customer names and phone numbers, and access tokens are never written to logs at any level, by design.
6. SMS and email outreach
A Business may enable booking reminders or follow-up messages to a Customer over SMS or email in addition to DM. We send those only to a contact whose phone number or email carries a consent timestamp captured through the DM conversation itself — a number or address a staff member types into the dashboard by hand is never used for outreach. Every marketing or reminder email includes an unsubscribe link that stops all future email to that address immediately; SMS messages follow standard carrier opt-out (replying STOP).
7. How we use data
We use the data above to: operate the Bot and generate replies; create, reschedule, and cancel bookings; enforce plan and usage limits; send transactional email and in-app notifications; provide analytics to the Business Owner; secure the Service and investigate abuse; and bill for subscriptions. We do not use Customer message content to train any AI model, ours or a third party's.
8. Legal basis for processing
Where GDPR or an equivalent law applies, we process Business account data under contract (to provide the Service you signed up for) and legitimate interest (security, product improvement). We process Customer data as a processor acting on the Business's instructions and legal basis; the Business is responsible for having a lawful basis, such as consent, for the data it directs the Bot to collect.
9. AI processing
The Bot tells a Customer it is an automated assistant at the start of every new conversation, and this instruction is a fixed platform rule that no Business can turn off or override — required under the EU AI Act's transparency rules and Meta's own platform policy.
To generate replies, the Agent sends the relevant conversation context to a third-party AI model provider (currently one or more of Groq, OpenAI, Google Gemini, DeepSeek, or Moonshot/Kimi, selected at the platform level). These providers process the request to generate a response and are bound by their own data-processing terms; we do not control their infrastructure. We select and can change providers to manage cost, quality, and reliability.
10. Subprocessors and data sharing
We share data only with the subprocessors needed to run the Service, each strictly for that purpose:
- Meta (Instagram / Facebook Messenger) — to send and receive messages on a connected Meta Channel;
- AI model providers (see above) — to generate Bot replies;
- Paddle.com Market Limited — to process subscription payments as Merchant of Record;
- our email provider (Resend) — to send transactional and account email;
- Sentry — for error tracking, configured to never receive PII;
- PostHog — for product analytics, only once you accept analytics cookies (see "Cookies" below); never used to profile or track a Business's Customers;
- Railway — our infrastructure and database hosting provider.
11. International data transfers
Our subprocessors may process data outside your country, including in the United States. Where required, we rely on those providers' own compliance mechanisms (such as Standard Contractual Clauses) for cross-border transfer.
The GDPR applies to our processing of EU/EEA residents' personal data regardless of where we ourselves are established, because the Service is offered to businesses serving customers in the EU/EEA. Where the law requires it, we will designate an EU representative under GDPR Article 27 as a point of contact for EU supervisory authorities and data subjects.
12. Data retention
We keep Business and Customer data for as long as the Business account exists, so booking history and analytics remain accurate. Some derived or quoted data — such as mined conversation-topic highlights — ages out automatically after 180 days regardless of account status. Invoice records are kept indefinitely for accounting and legal purposes even after a subscription ends.
13. How to request deletion of your data
A Business Owner can disconnect a Meta Channel or delete their business at any time from the dashboard.
A Customer who wants their data removed can ask the connected Business directly, or use Meta's own "Remove App" / data-deletion request flow from their Instagram or Facebook account settings — Meta forwards that request to us automatically at a signed callback URL we operate. When we receive it, we revoke the connection, permanently clear the Customer's name, username, phone, and email, blank their message history, and delete any staff notes or extracted topic highlights tied to them across every Business that captured them; the booking and conversation records themselves are kept as anonymous shells so a Business's counts and history stay accurate. Meta requires we give a human a way to check the request's status: we do, at a page whose link and confirmation code we return in the same response Meta receives.
14. Data security
Access tokens for connected Meta Channels are encrypted at rest. Access to production data is limited to what operating the Service requires. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; we are not liable for unauthorized access that occurs despite reasonable safeguards, except as required by applicable law.
15. Your rights
If the EU/UK GDPR or the Serbian Law on the Protection of Personal Data applies to you, you have the right to access, rectify, erase, restrict, or port your data, to object to processing based on legitimate interest, and to lodge a complaint with your local data protection authority. We do not use automated decision-making that produces legal or similarly significant effects about a Customer.
If the California CCPA/CPRA or a similar US state privacy law applies to you, you have the right to know what personal data we hold, to request its deletion, and to opt out of its sale or sharing. We do not sell or share personal data for cross-context behavioral advertising, so there is nothing to opt out of.
A Business Owner can exercise most of these rights directly from the dashboard; anything else, or any request from a Customer that a Business cannot resolve directly, can be sent to the contact below. We will not discriminate against anyone for exercising a privacy right.
16. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us data, contact us and we will remove it.
17. Cookies
We use a small number of strictly necessary cookies — to keep you signed in, remember your language and the last business you viewed, and (staff only) support impersonation for support purposes. These require no consent under applicable law and the banner on this site never asks about them.
With your consent, given through the cookie banner shown on your first visit, we also set an analytics cookie via PostHog to understand how the product is used in aggregate. It is off by default: nothing is set until you accept, declining or dismissing the banner leaves it off, and you can withdraw consent at any time by clearing your browser's site data for this domain. We never use advertising or cross-site tracking cookies.
18. Changes to this policy
We may update this policy from time to time. We will post the revised policy with a new "last updated" date and, for material changes, notify Business Owners through the dashboard or by email.
19. Contact
Questions about this policy, or a data request, can be sent to [email protected]. The legal contact for this policy is Reservify d.o.o.