Trust & policies
Privacy Policy
Last updated: 4 October 2026 · Version 2.0 (draft).
Draft, pending legal review (4 October 2026). This policy has not yet been reviewed by a solicitor and may change before it takes effect.
1. About this policy
Reservory provides booking, payment, waiver and point-of-sale software to venues such as escape rooms, trampoline parks and family entertainment centres. This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We handle personal information in two roles:
- Venues and their staff. When a venue signs up, we collect information about the business and the people who use its account. We decide how that information is used.
- Guests of venues. When you book, buy or sign a waiver with a venue that uses Reservory, the venue collects your information and is responsible for it. We store and process it for the venue, under our agreement with the venue. For questions about how a venue uses your information, contact the venue first. We will help venues respond.
2. What we collect
- Venue accounts: names, email addresses, phone numbers, business details and billing details of the venue and its staff.
- Bookings and orders: name, email, phone (if given), party size, booking times, purchases, notes and answers to any questions the venue asks.
- Waivers: the signer's name, signature, the waiver text agreed to, the time of signing, IP address and browser details. For children, see section 5.
- Payments: payment details are entered with our payment provider, Stripe. We receive payment status and limited card details (such as brand and last four digits), never full card numbers.
- Marketing preferences: whether you have agreed to receive marketing from a venue, and any unsubscribe or SMS opt-out.
- Technical information: IP address (used for security and rate limiting), error reports and product-usage events. Request bodies, headers, cookies and user details are removed from error reports and named fields such as email addresses are redacted, though an error message can still contain personal information. Session replay is turned off.
We collect this from you directly, from the venue you deal with, from Stripe, and automatically when you use our pages. If you don't provide the details a booking needs, the venue may not be able to take it.
3. How we use it
- To take and manage bookings, payments, waivers and orders for venues.
- To send booking messages such as confirmations, reminders, waiver links and receipts by email or SMS.
- To keep the service secure, prevent fraud and abuse, and fix faults.
- To support venues and improve our software.
- To meet legal, tax and accounting obligations.
Marketing is opt-in. A venue only sends you news and offers if you tick the box to agree. Every marketing email has an unsubscribe link, and you can reply STOP to SMS messages. We may send venue account holders information about Reservory; they can unsubscribe at any time.
We do not sell personal information, and we do not use guest information to advertise to guests.
4. Who we share it with
- The venue you booked with, and the staff it authorises.
- Service providers that help us run Reservory (listed in section 6).
- Tools a venue chooses to connect, such as Mailchimp, Klaviyo, HubSpot, QuickBooks, Zapier or its own webhooks. The venue decides what is sent to these tools.
- Authorities, where the law requires or allows it.
5. Children
Some venues ask a parent or guardian to sign a waiver for a child. In that case we collect the child's name and date of birth, and the parent or guardian's name, relationship to the child and signature. We collect this from the parent or guardian, not from the child. It is used to record consent and to check the child's age on arrival. It is not used for marketing or advertising.
When a venue deletes a guest's record, the child's name and date of birth are removed from its booking records. The signed consent record, including the child's details, is kept as evidence for the venue's waiver retention period, which is at least seven years. Waivers under a legal hold are kept until the hold ends.
6. Where information is stored, and overseas disclosure
Our database and application servers are in Sydney, Australia (Supabase and Vercel). Some of our service providers store or access information outside Australia:
- Stripe (payments): United States and other countries where Stripe operates.
- Resend (email delivery): United States.
- Twilio (SMS): United States.
- Sentry (error monitoring): United States.
- PostHog (product analytics): United States.
- Upstash (rate limiting, using IP addresses): may be outside Australia.
- Vercel's content network may serve pages from locations near you.
Tools a venue connects (section 4) may also be overseas; their locations depend on the provider. We use contracts and these providers' security controls to protect information they handle.
7. Security
Information is encrypted in transit. Each venue's data is separated by database row-level security, staff access is limited by role, and connected-tool credentials are encrypted. No system is completely secure. If a data breach is likely to cause serious harm, we will notify affected venues and, where required, the people affected and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
8. How long we keep it
We keep booking and payment records for as long as needed for tax and accounting, usually seven years. A venue can delete a guest; their name, email and phone are then removed from the venue's records after a 30-day period in which the venue can cancel the request. Signed waivers and financial records are kept for their retention period, with personal details removed where we can. When a venue closes its account, we delete or de-identify its data once it no longer needs to be kept.
9. Access, correction and complaints
You can ask to access or correct personal information about you. Guests should contact the venue first; you can also email privacy@reservory.com. We will respond within 30 days and won't charge you to make a request.
If you have a privacy complaint, email privacy@reservory.com. We will respond within 30 days. If you are not satisfied, you can complain to the OAIC at oaic.gov.au or on 1300 363 992.
10. Changes and contact
We will post changes to this policy on this page and update the date above. Contact us about privacy at privacy@reservory.com.