Privacy Policy
Last updated: September 29, 2026
This describes what Reservy (reservy.co) collects, why, and what you can do about it. It's written in plain language on purpose.
What we collect
From a business that creates an account: business name, email, a hashed password (we never store your actual password), phone, city, timezone, and business hours.
From a client who books an appointment: the name and phone number they enter on the public booking page, plus the service and time they picked.
From anyone browsing the site: basic analytics — page visited, referrer, device type, and an anonymous session identifier — collected by a shared tracking script also used by other sites we operate, so we can see which pages get used.
Cookies
A session cookie (rvid) keeps a business logged in — it's required for the app to work and isn't used for tracking. A second cookie (rvlang) remembers your preferred language across visits. Neither is sold or shared with advertisers; we don't run ad tracking.
How we use it
To run the schedule, booking page, and earnings tools; to send transactional emails (welcome, password reset, booking notifications) through Resend, our email delivery provider; and to understand which pages are actually useful so we can improve them.
Google Calendar (optional)
A business can connect its Google Calendar from Settings → Integrations. It is off by default, it is entirely optional, and Reservy works fully without it. Nothing described here happens unless you connect it yourself.
What we read. Only free/busy times from the calendar you connect — the start and end of the blocks you already have taken, so those hours stop being offered to your clients. We do not read event titles, descriptions, guests, locations, or attachments, and we do not read any other calendar. We also read the email address of the Google account you connect, so the app can show you which account is linked.
What we write. One event per Reservy appointment, in the calendar you chose. The event carries the client name, the service, the professional, the client phone and notes if they left any, and a link back to Reservy. When you move an appointment the event moves with it; when you cancel it the event is deleted. We never modify events that Reservy did not create.
Where it goes. Nowhere else. Google Calendar data stays on the server that runs Reservy and is used only to show you your own schedule and to calculate your availability. We do not sell it, do not share it with third parties, do not use it for advertising, do not use it to train artificial intelligence or machine learning models, and no person on our side reads it.
What we store. A token that lets Reservy keep the calendar in sync, the email address of the connected account, and the identifier of the event we created for each appointment. Free/busy times are held in memory for sixty seconds at a time and are never written to our database.
Turning it off. Settings → Integrations → Disconnect. That revokes our access with Google straight away and deletes the stored token. You can also revoke it from the permissions page of your Google account. Events already written to your calendar stay there — they are yours; delete them in Google if you would rather not keep them.
Reservy use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Payments
If you subscribe to the paid plan (Pro), the payment is handled by Lemon Squeezy, which acts as the merchant of record: they take the payment, issue the invoice and handle the sales tax or VAT of your country. We never see or store your card. It is typed on their checkout, not on ours.
What comes back to us is only what we need in order to know that your plan is active: the identifier of your subscription and of your customer record with them, its status, and the date it renews or ends. Your name and email reach them because an invoice cannot be issued without them.
If you cancel, we keep those identifiers while the paid period runs; after that the account is no longer active, or returns to its free plan if it already had one. Lemon Squeezy keeps the invoice for as long as their own accounting obligations require; that part is theirs, not ours.
Who we share it with
Resend, for sending email on our behalf. Lemon Squeezy, if you subscribe to Pro, to take the payment and issue your invoice. If you connect Google Calendar, the appointments you create in Reservy are written to the Google account you connected, as described above. We don't sell personal data, and we don't share it with advertisers or data brokers. We may disclose information if legally required to.
How long we keep it
For as long as the account is active. If you close your account, we delete the business's data; a client's appointment history tied to that account is deleted along with it.
Security
Passwords are hashed (scrypt), traffic runs over HTTPS, and session cookies are marked HttpOnly and Secure. No system is perfectly secure, but we treat account and client data as sensitive by default.
Your choices
You can review and correct your business information anytime in Settings. To request a copy of your data or full deletion, use the Need help? button on this page and we'll handle it directly — there's no self-service delete button yet.
Children
Reservy is meant for businesses, not children. We don't knowingly collect data from anyone under 16.
Changes
If this policy changes meaningfully, we'll update the date above.
Contact
Questions about your data: use the Need help? button on this page.