Privacy Policy
1. Controller
The controller responsible for the processing of personal data on this website is the operator named in the Legal Notice (Riservato, Rudolfstetten, Switzerland).
For any data-protection matter you can reach us at hello@riservato.ch.
2. Scope
This policy explains how we process personal data when you visit riservato.ch, create a restaurant account, or book a table through our booking widget. We process data in accordance with the Swiss Federal Act on Data Protection (revFADP / revDSG) and, where applicable, the EU General Data Protection Regulation (GDPR).
3. What data we process
Account data (restaurant owners/staff): name, email, password (hashed), phone, role and billing details.
Reservation data (guests): name, email, phone, party size, date/time, occasion, allergies/dietary notes and birthday, where provided.
Payment data: handled by our payment processor (Stripe). We do not store full card numbers; we receive only a customer/subscription reference and status.
Technical data: cookies strictly necessary for login sessions and language preference, plus standard server logs (IP address, timestamp, requested page).
4. Purposes
To provide the service: managing reservations, floor plans, guest profiles and communications.
To process subscriptions and payments and to issue invoices.
To send transactional and (where enabled by the restaurant) automated guest emails such as confirmations, reminders, review requests and birthday greetings.
To secure, operate, troubleshoot and improve the platform.
5. Cookies
We use only functional cookies that are necessary for the website to work — namely your login session and your chosen language. We do not use advertising or third-party tracking cookies, so no consent banner is required.
6. Sharing & processors
We do not sell personal data. We share it only with processors who help us run the service, under appropriate contracts:
Stripe (payment processing) · the restaurant's email/SMTP sender (Microsoft 365 or an email service, for guest mails) · our hosting provider (server infrastructure). Reservation data is, of course, made available to the restaurant you booked with.
7. International transfers
Our infrastructure is operated in Switzerland/the EU. Where a processor (e.g. Stripe) transfers data abroad, this is based on adequacy decisions or appropriate safeguards such as the EU Standard Contractual Clauses.
8. Retention
We keep personal data only as long as necessary for the purposes above or as required by law (e.g. accounting records for 10 years under Swiss law). Reservation data is retained for the restaurant's guest history; you may request deletion at any time.
9. Your rights
Subject to legal limits, you have the right to access, rectify, delete and restrict the processing of your personal data, to object to processing, and to data portability.
To exercise these rights, contact us at hello@riservato.ch. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
10. Changes
We may update this policy from time to time. The current version always applies and is published on this page.