Privacy Policy
How Modus Reservations collects, uses and protects personal data — written for both the venues that run on Modus and the guests who book with them.
Last updated: 6 August 2026
1. Who we are
Modus Reservations ("Modus", "we", "us") provides a reservation and hospitality management platform for bars and restaurants: online booking pages and an embeddable booking widget, table and floor-plan management, staff rotas and leave, payments and deposits, and integrations with services such as Google Calendar and Discord (together, the "Service").
This policy explains what personal data we collect, why we collect it, who we share it with and the choices you have. It applies to our website at modusreservations.com, our web and mobile applications, our booking widget, and our communications. If you have any questions, contact us at hello@modusreservations.com.
2. Our two roles
Modus handles personal data in two distinct capacities, and your rights run to different parties depending on which applies to you.
As a controller — venue accounts and our website
When you create a Modus account, manage a venue, visit our website or contact us, we decide how and why your data is processed. We are the data controller for that data, and this policy describes that processing in full.
As a processor — guest and staff data belonging to venues
When a guest books a table at a venue that uses Modus (through the venue's booking page, the embedded widget, or entered by the venue's staff), and when a venue records details about its own staff, the venue is the data controller and Modus processes that data on the venue's instructions as a data processor. The venue's own privacy policy governs that data. If you are a guest and want to access, correct or delete your booking details, the quickest route is to contact the venue you booked with; we support venues in meeting those requests and will redirect any request we receive directly to the relevant venue.
3. Information we collect
Account and profile information
When you sign up we collect your name, email address and password (or your Google account identifier if you sign in with Google). Authentication is operated by Clerk on our behalf. New accounts are reviewed and approved manually before gaining full access, and we process your signup details as part of that review.
Venue and business information
Venue names, addresses, contact details, opening hours, table layouts, shift and pricing configuration, and anything else you add to run your venue on Modus.
Booking and guest information
Guest names, email addresses, phone numbers, party sizes, dates and times, special requests, dietary or accessibility notes the guest or venue chooses to record, and the booking's status and payment state. We process this as a processor for the venue (see section 2).
Staff information
Where a venue uses rotas, leave or staff management, it may record staff names, contact details, roles, pay rates, working patterns and leave. Rota documents can be delivered to staff by email or Discord direct message at the venue's request.
Payment information
Payments and deposits are handled by Stripe. Card numbers are collected by Stripe directly and never touch our servers; we store only the resulting transaction records (amount, currency, status and a Stripe reference).
Usage and device information
Log data, approximate location derived from IP address, browser and device type, pages viewed and actions taken, collected through the analytics and error-monitoring tools described in section 9.
Communications
Messages you send us — support requests, sales enquiries, feedback — and our records of transactional email we send you.
4. How we use information
- To provide the Service — operating bookings, availability, table assignment, rotas, payments, notifications and the integrations you connect.
- To send transactional messages — booking confirmations, reminders, waitlist offers, rota deliveries, account and security notices. These are part of the Service, not marketing.
- To review new accounts — verifying signups before granting access, which protects our email-sending reputation and our customers.
- To secure and debug the platform — detecting abuse, enforcing rate limits, monitoring errors and diagnosing failures.
- To understand product usage — aggregate analytics that tell us which features are used and where the product needs work.
- To comply with law — keeping records we are legally required to keep and responding to lawful requests.
We do not sell personal data, and we do not use guest or venue data for third-party advertising.
5. Legal bases for processing
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases for the processing we carry out as a controller:
- Contract — providing the Service you signed up for, including account management and transactional messages.
- Legitimate interests — securing the platform, preventing abuse, reviewing new accounts, improving the product and running proportionate analytics.
- Legal obligation — tax, accounting and other records we must keep.
- Consent — where we ask for it specifically, such as optional marketing communications. You can withdraw consent at any time.
6. AI features
Some features use large language models to answer questions about your venue's data — for example, the Discord /ask command. When you use these features, the relevant question and the venue data needed to answer it are sent to our AI provider (currently OpenAI) for processing. We send only what the feature needs, our agreements with the provider prohibit the use of this data to train their models, and AI features only run when you invoke them.
8. Google user data
If a venue connects Google Calendar, we access the connected calendar to create, update and remove events for that venue's bookings and to read changes made on the calendar side. OAuth tokens are stored encrypted (AES-256-GCM) and are used only for this sync; disconnecting the integration revokes our access and deletes the stored tokens.
Modus' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
10. International transfers
We operate from the United Kingdom and several of our providers are in the United States. Where personal data leaves the UK or EEA, we rely on adequacy regulations (including the UK–US Data Bridge and the EU–US Data Privacy Framework where the provider is certified) or on standard contractual clauses with the relevant provider.
11. Data retention
- Account data is kept while your account is active and deleted or anonymised within a reasonable period after the account closes, except where law requires longer.
- Booking and guest data is kept for as long as the venue it belongs to remains a customer and instructs us to keep it; venues can delete bookings at any time.
- Payment records are kept as required for tax and accounting purposes.
- Logs, error reports and analytics are kept on the short rolling retention windows of the tools that hold them.
12. Security
All traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting providers. Third-party OAuth tokens are additionally encrypted at the application layer. Access to production data is limited to those who need it to operate the Service. Every venue's data is scoped to its owning account at the query layer, card details never touch our servers, and public endpoints are rate-limited. No system is perfectly secure — if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.
13. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on it. To exercise any of these rights, email hello@modusreservations.com. We will respond within the time the law allows (one month under UK and EU GDPR).
If you are in the UK you can complain to the Information Commissioner's Office (ico.org.uk); in the EEA, to your local supervisory authority. We would appreciate the chance to resolve your concern first.
If you are a guest whose data a venue holds in Modus, direct your request to the venue — it controls that data — and we will support the venue in fulfilling it (see section 2).
14. Children
The Service is a business tool and is not directed at children. Accounts may only be created by people aged 18 or over. Guests under 16 should only be included in a booking by an adult making the reservation.
15. Changes to this policy
We will update this policy as the Service and the law evolve. The date at the top reflects the latest revision. For material changes we will give account holders reasonable advance notice by email or in the product. Continued use of the Service after a change takes effect means the updated policy applies.
16. Contact us
Modus Reservations — hello@modusreservations.com. We aim to answer privacy queries within a few working days.