Reservai
Features Solutions

Use Cases

Padel & Courts Med Spa & Clinics Driving Schools Pet Grooming & Boarding Fitness & Studios Equipment Rental Pricing Blogs

PRIVACY POLICY

Reservai Booking Platform — International

Effective Date: 4 September 2026
Last Updated: 4 September 2026

This Privacy Policy explains how Reservai handles personal data across its international websites, dashboards, public booking pages, embedded booking experiences, AI-assisted booking chats, payment features, communications, and related services at getreservai.com. It should be read together with our Terms and Conditions.

Reservai does not collect or hold booking payments on this platform. Card payments are processed by the Service Provider's own payment account, and other payments are taken directly by the Service Provider. See Section 7.

Contents

  1. Introduction and scope
  2. Personal data we collect
  3. Where data comes from
  4. How and why we use data
  5. Reservai and Service Provider roles
  6. How we share data
  7. Payments and gateways
  8. AI-assisted features
  9. Verification and billing
  10. Cookies and embedded services
  11. Retention
  12. Security
  13. International transfers
  14. Your rights
  15. Communications and marketing
  16. Children and minors
  17. Third-party sites and services
  18. Changes to this Policy
  19. Contact us

1. INTRODUCTION AND SCOPE

1.1 Who We Are

Digiteon Technologies L.L.C-FZ, trading as Reservai ("Reservai," "we," "us," or "our"), operates the Reservai booking and business-management platform from the United Arab Emirates.

Our registration number is 2306345.01. Our contact details are in Section 19.

1.2 Which Platform This Policy Covers

This Policy applies to the Reservai international platform at getreservai.com. Reservai operates a separate platform for the United Arab Emirates at reservai.ae, which has its own privacy policy. Both platforms now work the same way — the Service Provider is paid directly and Reservai does not hold booking funds — but the UAE platform also retains historical records from a payment mode it operated in the past, which its own policy explains. If you use both, the policy for the platform you are using at the time applies to that activity.

1.3 Applicable Framework

We handle personal data in accordance with applicable privacy and data-protection requirements. As a company established in the United Arab Emirates, we apply UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data (the "UAE PDPL"). Where another data-protection law applies to our processing of your personal data — for example the EU General Data Protection Regulation, the UK GDPR, or the law of your own country — we handle that data in accordance with the requirements of that law.

1.4 Who and What This Policy Covers

This Policy applies when you visit or use Reservai as a:

  • Service Provider, account owner, administrator, or staff member;
  • Customer, booking guest, payer, attendee, or recipient of a service;
  • visitor to a Reservai website, public booking page, or supported embedded experience; or
  • person who contacts support, submits a request, receives a communication, or otherwise interacts with the Platform.

A Service Provider publishes and is responsible for its own privacy notice for the services it offers. That notice also applies to the Service Provider's handling of your data and should be reviewed before you provide information or make a Booking.

2. PERSONAL DATA WE COLLECT

2.1 Account, Contact, and Profile Data

  • name, email address, telephone number, username, and protected authentication credentials;
  • profile image, preferred language, country, currency, time zone, location settings, and communication preferences;
  • optional profile details, such as date of birth or gender, where you choose to provide them; and
  • account type, permissions, team membership, access history, and security events.

2.2 Service Provider and Business Data

  • business name, description, category, contact details, address, country of operation, service areas, websites, branding, and social links;
  • services, prices, resources, locations, staff, schedules, availability, policies, images, listings, and other Provider Content;
  • licence, registration, tax, ownership, and authorised-representative information where we request it;
  • plan, billing, Commission, usage, invoice, statement, and account-status information; and
  • support requests, complaints, reviews, dispute evidence, and communications with Reservai.

2.3 Booking and Customer Data

  • Customer and attendee names, email addresses, telephone numbers, addresses, and verification information;
  • selected service, date, time, time zone, location, assigned staff or resource, quantity, duration, recurrence, price, currency, discount, deposit, tax, and status;
  • answers to intake questions, preferences, notes, special requests, accessibility information, and files submitted for a Booking;
  • amendments, rescheduling, cancellations, no-shows, attendance, check-in, completion, and service history;
  • booking messages, confirmations, reminders, feedback, reviews, complaints, and support history; and
  • records needed to identify linked, recurring, team, rental, asset, or multi-resource Bookings.

Service Providers choose many intake fields. Please do not provide sensitive or unnecessary information unless it is genuinely required and you understand how the Service Provider will use it.

2.4 Payment, Refund, and Transaction Data

Because payment is made to the Service Provider rather than to Reservai, we hold payment records rather than payment funds. These may include:

  • amount, currency, payment method, payment status, processor, transaction and payment-intent identifiers;
  • limited card or funding-source details returned by a processor, such as brand and last four digits;
  • records of payments taken offline by a Service Provider, including the amount, method, date, and any proof it uploads;
  • refund, reversal, chargeback, dispute, fraud-screening, and reconciliation information reported to us; and
  • your Reservai billing details, invoices, statements, receipts, tax information, gateway connection status, and processor webhook records.

Reservai does not store complete payment-card numbers, and does not receive or hold Booking funds on this platform. Card or funding credentials are collected and processed by the relevant Payment Processor, as explained in Section 7.

2.5 AI Chat and Interaction Data

  • messages, prompts, responses, chat transcripts, language, and feedback;
  • service, availability, pricing, location, staff, resource, recurrence, and booking context presented to or generated during a chat;
  • contact details, one-time-password verification events, selections, confirmations, and requested actions;
  • structured outputs used to create or manage a Booking, together with validation results and error logs; and
  • usage, metering, safety, security, and diagnostic information associated with AI Features.

2.6 Device, Log, Usage, and Location Data

  • IP address, browser, device, operating system, language, and approximate location inferred from technical data;
  • pages, screens, links, actions, timestamps, referring URL, session, error, and performance information;
  • cookie, local-storage, analytics, and similar identifiers; and
  • more precise location only where a feature requests it, your device permits it, and it is needed for that feature.

2.7 Data from Integrations and Third Parties

We may receive data from Payment Processors, social sign-in services, identity and business-verification providers, messaging and email providers, analytics and security tools, embedded-site operators, or other integrations that you or a Service Provider enables. The information depends on the integration, its settings, and your permissions.

3. WHERE PERSONAL DATA COMES FROM

We collect personal data:

  • directly from you when you register, book, pay, chat, upload content, configure the Platform, or contact us;
  • from a Service Provider, staff member, booking organiser, payer, or another authorised User;
  • automatically from devices, browsers, cookies, Platform events, security systems, and server logs; and
  • from processors, integrations, verification services, and other third parties as described above.

If you provide another person's personal data, you must be authorised to do so and must give that person any notice required by law.

4. HOW AND WHY WE USE PERSONAL DATA

4.1 Purposes

We use personal data to:

  • create, authenticate, secure, administer, and support Accounts;
  • publish Provider Pages and enable availability, quotations, Bookings, amendments, cancellations, reminders, and communications;
  • initiate payments through a Service Provider's connected gateway and record payment, refund, Commission, chargeback, dispute, and reconciliation events;
  • bill Service Providers for plan fees, Commission, overages, and AI usage, and collect amounts owed to Reservai;
  • provide AI-assisted discovery, question answering, booking, and booking-management features;
  • verify business eligibility and compliance information, and support a Service Provider's onboarding with its own Payment Processor;
  • prevent fraud, abuse, unauthorised access, security incidents, sanctions breaches, and violations of our Terms;
  • provide support, investigate complaints, preserve evidence, and resolve operational or payment issues;
  • measure usage, maintain service reliability, troubleshoot, test, analyse, and improve Platform features;
  • send transactional, security, legal, support, and permitted marketing communications; and
  • comply with law, regulatory requests, accounting and tax duties, legal claims, and enforcement obligations.

4.2 Legal Grounds

Depending on the activity and the law that applies to it, we process personal data:

  • to enter into or perform a contract requested by the data subject;
  • with consent, where consent is required;
  • to comply with legal, regulatory, accounting, tax, or court obligations;
  • for our legitimate interests, or an equivalent lawful basis, in operating, securing, and improving the Platform, preventing fraud and abuse, and pursuing or defending legal claims, where those interests are not overridden by your rights;
  • to protect Users, the public, the Platform, or other important interests; or
  • under another ground or exception permitted by applicable law.

Where processing depends on consent, you may withdraw that consent. Withdrawal does not affect processing already carried out lawfully and may prevent us from providing a feature that requires the data.

5. RESERVAI AND SERVICE PROVIDER DATA ROLES

The legal role of each party depends on the processing activity:

  • Reservai-controlled activities: Reservai generally determines the purposes and means for operating Accounts, Platform security, billing, usage metering, support, compliance, and improvement of its own services.
  • Provider-controlled activities: A Service Provider determines why it collects Customer information for its Provider Services, which intake fields it requests, how it takes and refunds payment, how it communicates with Customers, and how it uses booking records for its own business.
  • Processing for a Provider: For some booking, intake, communication, and business-management functions, Reservai processes data on the Service Provider's instructions.
  • Payment data: For a card payment taken through the Service Provider's connected account, the Service Provider and its Payment Processor determine how payment credentials and related data are handled. Reservai holds only the transaction record described in Section 2.4.
  • Separate responsibilities: Reservai and a Service Provider may each act as an independent controller for different purposes involving the same Booking.

Service Providers must provide appropriate privacy notices, collect only necessary information, establish a lawful basis, protect Customer data, honour applicable rights in the markets they serve, enter into any additional data-processing terms their own law requires, and configure Platform access for their staff responsibly.

6. HOW WE SHARE PERSONAL DATA

We may disclose personal data as reasonably necessary to:

  • Service Providers and their authorised staff: to request, confirm, deliver, manage, support, or dispute a Provider Service;
  • Customers, attendees, organisers, and payers: to provide booking, payment, service, and status information relevant to their transaction;
  • Payment providers: including a Service Provider's connected Stripe or other supported account, card networks, and fraud or dispute services, to initiate and reconcile transactions;
  • Technology and operations vendors: such as hosting, database, storage, security, analytics, identity, communications, support, document-processing, and AI service providers;
  • Professional advisers and transaction parties: including auditors, insurers, accountants, lawyers, investors, buyers, and counterparties under appropriate confidentiality arrangements;
  • Authorities and other parties: where required or permitted by law, legal process, regulatory request, safety needs, fraud prevention, sanctions compliance, rights protection, or enforcement of our Terms; and
  • A successor organisation: in connection with a merger, acquisition, financing, restructuring, insolvency, or sale of all or part of the business, subject to applicable safeguards.

Reservai does not sell personal data. We also do not disclose Customer data to unrelated third parties for their own direct marketing except where you have directed or validly consented to that disclosure or it is otherwise lawful.

7. PAYMENTS AND GATEWAYS

7.1 Provider-Owned Gateways

On this platform, card payments for a Booking are processed through the Service Provider's own connected payment account, such as a supported Stripe account. In that setup:

  • the Service Provider and its Payment Processor have their own direct merchant and privacy relationship, and the Service Provider is the merchant of record;
  • the processor collects payment, identity, fraud, device, and compliance data under its own privacy notice;
  • Reservai sends the Customer, Booking, amount, currency, and reference data required to initiate or manage the transaction;
  • Reservai receives transaction identifiers, statuses, limited funding-source details, webhooks, refunds, disputes, fees, and reconciliation data needed to operate the Platform; and
  • the money itself is received by the Service Provider and never passes through Reservai.

The Service Provider is responsible for lawfully configuring and using its gateway and for giving Customers any gateway-specific notices required by law.

7.2 Offline Payments

Where a Service Provider takes payment in cash or by bank transfer at or around the time of service, that payment happens outside the Platform and outside any Reservai payment integration. Reservai records only what the Service Provider enters against the Booking, such as the amount, method, date, and any proof it uploads.

7.3 Reservai Billing Data

Separately from Booking payments, Reservai collects the billing information needed to charge a Service Provider its own plan fees, Commission, overages, and AI charges. A payment method saved for Reservai billing is held by our own Payment Processor, not by Reservai, and we retain only the transaction records, invoices, and statements needed for accounting and support.

7.4 Processor Policies

Payment Processors act under their own privacy terms for these activities. Please review the applicable processor's notice, including the Stripe Privacy Policy, where relevant. For a card payment on a Booking, the relevant notice is that of the processor connected by your Service Provider.

7.5 Financial Records

Reservai records booking payment events — amounts charged, refunded, outstanding, or disputed — to keep each Booking's payment status accurate, calculate Commission, support reconciliation and dispute handling, prevent misuse, and comply with legal and accounting obligations. These are ledger records of money that moved between the Customer and the Service Provider; Reservai holds no balance on behalf of either of them.

8. AI-ASSISTED FEATURES

8.1 How AI Data Is Used

Reservai may use AI models and related services to understand messages, answer questions, present Provider information, collect booking choices, create structured booking instructions, assist with amendments or cancellations, translate or format content, detect misuse, and support Platform operations. Where you interact with an AI Booking Assistant, you are interacting with automated software rather than a human agent.

8.2 Information Sent for Processing

Relevant prompts, messages, Provider Content, service and availability context, booking state, and limited technical data may be sent to contracted AI or infrastructure providers, which may be located outside your country. Payment credentials are not part of an AI conversation. We seek to limit the information to what is reasonably needed for the feature, but you should not enter passwords, payment-card details, government identifiers, medical details, or other sensitive information unless the feature expressly requests it and you are authorised to provide it.

8.3 AI Limitations and Safeguards

AI output may be incomplete or incorrect. Reservai uses authoritative Platform records and validation rules for availability, pricing, identity verification, payment status, and final booking actions. An AI response does not independently override those records. Users may be asked to review or confirm important details before an action is completed.

Reservai may review AI interactions using automated tools or authorised personnel for support, safety, fraud prevention, quality, and troubleshooting. Where applicable law gives you rights concerning automated processing, you may contact us as described in Section 14.

9. VERIFICATION AND BILLING CHECKS

Identity verification, beneficial-ownership checks, and merchant underwriting for card payments are carried out by the Service Provider's own Payment Processor under its agreement with that processor. Reservai does not perform that underwriting and does not receive the full verification file.

Separately, Reservai or a verification provider may request:

  • business name, registration, licence, tax, and authorised-representative details;
  • contact and address information for billing and invoicing;
  • billing payment-method details, held by our Payment Processor, for Platform charges; and
  • sanctions, risk, or fraud-screening information where required by law or by our own providers.

We may restrict an Account, gateway connection, feature, or transaction while verification is incomplete, invalid, expired, or under review, or where billing is overdue. Verification providers and Payment Processors may process this data under their own legal obligations and privacy notices.

10. COOKIES AND EMBEDDED SERVICES

Reservai and its service providers may use cookies, local storage, pixels, and similar technologies to:

  • keep sessions secure, remember preferences, and provide requested features;
  • prevent fraud, balance traffic, diagnose errors, and measure performance; and
  • understand Platform use and, where lawful and permitted, support communications or marketing.

Non-essential cookies are used only where your consent or another lawful basis permits it in your country. You can manage cookies through available consent controls and browser settings. Blocking essential storage may prevent login, checkout, embedded booking, or other features from working correctly.

When a Service Provider embeds Reservai on its own website, both that website and Reservai may receive technical information needed to load and secure the embed. A card payment started from an embed is completed with the Service Provider's Payment Processor, and card details are not passed to or stored by Reservai. The Service Provider is responsible for its website's cookie notice, consent controls, domain configuration, and surrounding third-party technologies.

11. DATA RETENTION

We retain personal data only for as long as reasonably needed for the purpose for which it was collected and for applicable legal, regulatory, accounting, security, dispute, and enforcement requirements. Retention depends on factors such as:

  • whether an Account, Booking, recurring series, payment, dispute, or support matter remains active;
  • the nature and sensitivity of the data and the risk associated with continued storage;
  • contractual commitments and instructions from a Service Provider;
  • processor, tax, accounting, anti-fraud, verification, and legal-record requirements in the relevant country;
  • limitation periods, legal holds, investigations, complaints, chargebacks, and claims; and
  • security, audit, backup, recovery, and business-continuity needs.

Different categories therefore have different retention periods. Booking and financial records may need to be kept after an Account closes, while optional marketing data may be deleted or suppressed when consent is withdrawn. Verification, transaction, and dispute information may be kept for the period required by law, a processor, or an unresolved matter.

When data is no longer needed, we take reasonable steps to delete, anonymise, aggregate, or otherwise place it beyond ordinary use. Residual copies may remain temporarily in backups or restricted archives until they are overwritten or safely deleted.

12. DATA SECURITY

We use reasonable technical and organisational safeguards appropriate to the nature of the data and the risks involved. Measures may include encrypted network connections, protected credentials, access controls, role-based permissions, logging, monitoring, backups, vendor controls, and incident-response processes. Gateway credentials supplied by a Service Provider are stored encrypted.

No internet transmission or storage system is completely secure. Users must protect login credentials, use appropriate access permissions, keep contact information current, secure embedded websites and connected gateway accounts, and notify [email protected] promptly of suspected unauthorised access or disclosure.

13. INTERNATIONAL DATA TRANSFERS

Reservai is established in the United Arab Emirates and serves Users worldwide through providers and infrastructure that operate in several countries. Personal data will therefore be stored, accessed, or processed outside the country in which it was collected — including in the United Arab Emirates — by us and by Payment Processors, cloud, communications, security, support, verification, and AI providers.

Where applicable law restricts a cross-border transfer, we use a transfer mechanism permitted by that law — such as standard contractual clauses, an adequacy decision, or another lawful basis or exception — together with appropriate contractual, organisational, or technical safeguards. Data-protection standards and government-access rules in a destination country may differ from those in your own country.

14. YOUR DATA-PROTECTION RIGHTS

Subject to the law that applies to you, you may have rights to:

  • obtain information about the personal data being processed and access a copy;
  • correct or update inaccurate or incomplete personal data;
  • request deletion of personal data in applicable circumstances;
  • restrict, stop, or object to certain processing, including direct marketing;
  • receive or transfer personal data in a machine-readable form where applicable;
  • withdraw consent where processing is based on consent;
  • object to or request human review of certain automated processing decisions; and
  • submit a complaint to the competent data-protection authority in your country, or to the competent UAE authority.

Rights may be limited by legal exceptions, other persons' rights, identity-verification needs, security, privilege, legal claims, or mandatory recordkeeping. We may ask for information reasonably needed to confirm your identity and locate the relevant records.

To exercise a right, email [email protected]. If the request concerns information controlled by a Service Provider, we may direct the request to that Service Provider or assist it in responding. A request about payment-card or processor-held data should be directed to the relevant Payment Processor, and we will help you identify it. We will respond within the period required by applicable law.

15. COMMUNICATIONS AND MARKETING

We send transactional and service messages needed for registration, one-time-password verification, security, Bookings, reminders, amendments, cancellations, payments, refunds, billing, support, and material policy or service updates.

We send marketing communications only where lawful and with consent where the recipient's country requires it. You may opt out using the unsubscribe method in a message or by contacting us. An opt-out does not stop essential transactional, security, legal, or service communications.

Service Providers are separately responsible for ensuring that their Customer marketing, imported contact lists, reminders, and campaigns comply with the consent, notice, calling-time, suppression, and opt-out requirements of every market they contact.

16. CHILDREN AND MINORS

Reservai business Accounts are not intended for persons who lack legal capacity to enter the applicable agreement. A Service Provider may offer a lawful service for a child or minor, but the parent, guardian, and Service Provider are responsible for providing required notices and obtaining valid authorisation or consent under the law of their country.

If you believe a child has provided personal data without appropriate authorisation, contact us so we can review the circumstances and take action required by law.

17. THIRD-PARTY SITES AND SERVICES

The Platform may link to or integrate with third-party websites and services, including the payment pages of a Service Provider's Payment Processor. Their privacy practices are governed by their own notices. Reservai is not responsible for a third party's independent data handling, and a link does not mean that Reservai endorses that party's practices.

18. CHANGES TO THIS PRIVACY POLICY

We may update this Policy to reflect legal, regulatory, security, operational, payment, AI, or product changes. We will display the updated date above and provide additional notice where required by law. Material changes take effect on the stated effective date.

19. CONTACT US

For privacy questions, rights requests, or concerns about how personal data is handled, contact:

Digiteon Technologies L.L.C-FZ
Trading as Reservai
Registration number: 2306345.01

Address:
Meydan Free Zone, Meydan Hotel, Ground Floor, Dubai, United Arab Emirates

Privacy and rights requests: [email protected]
General enquiries: [email protected]
Phone: +971 50 335 7699
Website: https://getreservai.com