Venview

← Back to sign up

Privacy Policy

Last updated: 9 June 2026  ·  Effective: 9 June 2026

1. Who We Are

Venview (“we”, “us”, “our”) operates a reservation management and AI workflow platform for restaurant businesses. This Privacy Policy explains how we collect, use, store, and share personal data in connection with the Service.

For the purposes of the GDPR, we act as a data controller for account and billing data (the restaurant operator’s own details), and as a data processor for the guest data a restaurant uploads to or generates within the Service — for that data the restaurant is the controller and we process it on their instructions.

2. Data We Collect

Account data: name, email address, Google account identifier, restaurant name, timezone, and subscription details provided during sign-up.

Guest data: reservation details, guest names, contact details, and any notes you store in the Service about your guests.

Email content: when you connect a Gmail account, we access inbound emails in order to process reservation requests. We store message content only as required to operate the AI workflow features.

Usage data: log data including IP addresses, browser type, pages visited, and actions taken within the Service, for security and performance purposes.

Payment data: billing information is processed by our payment provider (Stripe). We do not store full card numbers.

3. How We Use Your Data

4. Legal Basis for Processing (GDPR)

5. Sub-processors and Data Sharing

We do not sell your personal data. We share it only with the sub-processors we engage to operate the Service, and with legal authorities when required by applicable law or court order. Our current sub-processors are:

Sub-processors are contractually bound to protect personal data. Under our API agreements with Google and Anthropic, your data is not used to train their models. We maintain an up-to-date sub-processor list and will give notice of changes.

Google API Services Limited Use

When you connect a Gmail mailbox, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we use Gmail data only to provide and improve the user-facing reservation features you have enabled (reading inbound reservation emails and drafting and sending replies from your mailbox). We do not transfer or sell Gmail data for advertising, we do not use it to train or improve generalised AI/ML models, and we do not allow humans to read it except where you direct us to, where you give specific consent, where required for security or to comply with applicable law, or on data that has been aggregated and anonymised for internal operations.

6. Data Retention

We retain account data for the duration of your subscription and for up to 12 months thereafter for audit and legal purposes. Guest and reservation data is retained for 24 months from the date of the reservation, or for the duration of your subscription, whichever is longer. Email content is retained for 12 months. You may request earlier deletion at any time.

7. International Transfers

Our core infrastructure is hosted within the European Economic Area. Some sub-processors — including Anthropic, Stripe, Meta, Sentry, and Cloudflare — process data in the United States. Our AI features that read inbound email content or the public booking form's comment (either of which can include dietary/allergy information) run on Google Vertex AI within the European Economic Area; only our internal operations assistant may surface limited data to Anthropic in the United States. Where data is transferred outside the EEA, we rely on appropriate safeguards, including the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You can request details of the safeguards in place for a specific transfer.

8. Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (TLS), encrypted storage, access controls, and regular security reviews.

9. Your Rights

Under the GDPR and applicable privacy law, you have the right to:

To exercise any of these rights, contact us at privacy@venview.app. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

10. Cookies and Tracking

We use a session cookie to keep you signed in. The operator dashboard does not use third-party advertising cookies. On a restaurant’s public booking page, a visitor who picks a language from the on-page switcher gets one first-party preference cookie (pb_lang) so the pages they visit next stay in that language; it stores only the language code, identifies no one, and is set only when the visitor chooses a language themselves. Where the restaurant has enabled a conversion-tracking or analytics tag (Meta Pixel, TikTok Pixel, Google Ads, or Google Analytics), that tag loads only after the visitor accepts it via the on-page consent banner; visitors who decline get no tag. That tracking is controlled by the restaurant as data controller.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before they take effect.

12. Contact

For privacy enquiries, contact our data protection contact at privacy@venview.app.