Reservics collects only the diner data needed to run a reservation: name, email, phone, party size, date, time, and any custom form fields the merchant adds. That data lives inside your Shopify ecosystem, not a separate third-party booking network. Reservics also handles Shopify’s data-request and data-erasure (redaction) webhooks, and it never logs personal information.
Before you start #
Privacy obligations belong to the merchant, who is the data controller for diners. Reservics processes that data on your behalf. This article explains how the app handles it. It is not legal advice, and Reservics does not claim any formal certification (such as ISO or SOC 2).
What diner data Reservics collects and why #
Reservics asks for the minimum needed to confirm and manage a booking.
| Data collected | Why it is needed |
|---|---|
| Name | Identify the booking and greet the diner |
| Send the confirmation and the manage/cancel link | |
| Phone | Optional contact; used for WhatsApp reminders if enabled (Pro+) |
| Party size, date, time | Reserve the right capacity in the right slot |
| Custom form fields | Any extra questions the merchant adds in the Form Builder |
| Deposit payment | Handled by Shopify Checkout, not stored in Reservics (Pro+) |
Diners book without creating an account. Deposits, when required, are paid through Shopify Checkout, so card details never touch Reservics.
Where the data lives #
Diner data stays within your Shopify ecosystem rather than a separate reservation marketplace.
- Reservation records are stored for your store inside the Reservics app database, tied to your shop.
- After a booking, Reservics tries to link the diner to a Shopify customer record by matching email, so you can re-engage them later. This is best-effort.
- Deposit payments and refunds run through Shopify Checkout and Shopify’s billing flow.
- Because the diner is mirrored into your Shopify customer list, you keep the relationship instead of handing it to a third-party booking network.
How GDPR data requests and erasure are handled #
Shopify sends mandatory privacy webhooks to apps, and Reservics acts on them automatically.
- When a customer asks for their data, Shopify sends a data-request webhook. Reservics receives it and surfaces the relevant reservation data for that customer so you can fulfill the request.
- When a customer asks to be deleted, Shopify sends a customer-redaction webhook. Reservics removes that diner’s personal data.
- When a store uninstalls and is closed, Shopify sends a shop-redaction webhook, and Reservics removes that shop’s data.
- Redaction jobs run on Shopify’s grace window before final deletion, matching Shopify’s required timing.
Because these requests come through Shopify, the diner does not need a Reservics login to exercise their rights. You handle them from the same Shopify privacy tools you already use.
How personal data is protected #
- Personal information (such as customer email and phone) is never written to application logs. Reservics logs only IDs and short status reasons.
- The manage/cancel link in a diner’s email uses a 32-character token, so a diner can manage their booking without an account and without exposing other diners’ data.
- Deposit and refund handling stays inside Shopify Checkout, so payment details are not stored in Reservics.
- Shopify access tokens for your store are encrypted at rest.
Frequently asked questions #
What diner data does Reservics store? #
Reservics stores the booking essentials: name, email, phone, party size, date, time, and any custom fields you add in the Form Builder. It does not store card details, because deposits are paid through Shopify Checkout. The data is tied to your shop and used only to run and manage reservations.
Is Reservics GDPR compliant? #
Reservics is built to support your GDPR obligations. It handles Shopify’s mandatory data-request and data-erasure webhooks, keeps personal data minimal, and never logs personal information. The merchant remains the data controller for diners, and Reservics processes that data on your behalf. Reservics does not claim a formal certification such as ISO or SOC 2.
How does a diner request deletion of their data? #
A diner submits the request through your store using Shopify’s standard privacy tools. Shopify then sends Reservics a customer-redaction webhook, and Reservics removes that diner’s personal data automatically. You do not need to delete records by hand inside the app.
Does diner data get shared with a third-party booking network? #
No. Diner data stays within your Shopify ecosystem. Reservations live in the app tied to your shop, and diners are linked to your Shopify customer list. Reservics does not sell or pool diner data into a shared reservation marketplace.
Does Reservics store payment or card details? #
No. When a deposit is required, the diner pays through Shopify Checkout, and refunds are issued back through Shopify. Card and payment details are handled by Shopify, not stored in Reservics.