PRIVACY POLICY
Reservai Booking Platform
Effective Date: 4 September 2026
Last Updated: 4 September 2026
This Privacy Policy explains how Reservai handles personal data across its websites, dashboards, public booking pages, embedded booking experiences, AI-assisted booking chats, payment-related features, communications, and related services. Reservai does not collect or hold Customer payments and does not receive payment-card details — Customers pay Service Providers directly through the Service Provider's own payment gateway or at the service location. This Policy should be read together with our Terms and Conditions.
Contents
- Introduction and scope
- Personal data we collect
- Where data comes from
- How and why we use data
- Reservai and Service Provider roles
- How we share data
- Payments and gateways
- AI-assisted features
- Identity and business verification
- Cookies and embedded services
- Retention
- Security
- International transfers
- Your rights
- Communications and marketing
- Children and minors
- Third-party sites and services
- Changes to this Policy
- Contact us
1. INTRODUCTION AND SCOPE
1.1 Who We Are
Digiteon Technologies L.L.C-FZ, trading as Reservai ("Reservai," "we," "us," or "our"), operates the Reservai booking and business-management platform.
Our registration number is 2306345.01. Our contact details are in Section 19.
1.2 Applicable Framework
We handle personal data in accordance with applicable privacy and data-protection requirements, including UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data (the "UAE PDPL"), where it applies.
1.3 Who and What This Policy Covers
This Policy applies when you visit or use Reservai as a:
- Service Provider, account owner, administrator, or staff member;
- Customer, booking guest, payer, attendee, or recipient of a service;
- visitor to a Reservai website, public booking page, or supported embedded experience; or
- person who contacts support, submits a request, receives a communication, or otherwise interacts with the Platform.
A Service Provider may publish its own privacy notice for the services it offers, and its payment gateway provider will have its own notice for payment data. Those notices also apply and should be reviewed before you provide information or make a Booking.
1.4 Terms Used in This Policy
Capitalised terms such as Booking, Service Provider, Provider-Owned Gateway, Payment Processor, Legacy Managed Payments, and Withdrawal Date have the meanings given in our Terms and Conditions. In particular, "Legacy Managed Payments" refers to payments Reservai facilitated the collection of before the Withdrawal Date under a payment mode that has since been discontinued.
2. PERSONAL DATA WE COLLECT
2.1 Account, Contact, and Profile Data
- name, email address, telephone number, username, and protected authentication credentials;
- profile image, preferred language, time zone, location settings, and communication preferences;
- optional profile details, such as date of birth or gender, where you choose to provide them; and
- account type, permissions, team membership, access history, and security events.
2.2 Service Provider and Business Data
- business name, description, category, contact details, address, service areas, websites, branding, and social links;
- services, prices, resources, locations, staff, schedules, availability, policies, images, listings, and other Provider Content;
- licence, registration, tax, ownership, authorised representative, and identity-verification information;
- plan, billing, Commission, usage, invoice, and account-status information, together with any remaining Legacy Managed Payments balance; and
- support requests, complaints, reviews, dispute evidence, and communications with Reservai.
2.3 Booking and Customer Data
- Customer and attendee names, email addresses, telephone numbers, addresses, and verification information;
- selected service, date, time, location, assigned staff or resource, quantity, duration, recurrence, price, discount, deposit, tax, and status;
- answers to intake questions, preferences, notes, special requests, accessibility information, and files submitted for a Booking;
- amendments, rescheduling, cancellations, no-shows, attendance, check-in, completion, and service history;
- booking messages, confirmations, reminders, feedback, reviews, complaints, and support history; and
- records needed to identify linked, recurring, team, rental, asset, or multi-resource Bookings.
Service Providers choose many intake fields. Please do not provide sensitive or unnecessary information unless it is genuinely required and you understand how the Service Provider will use it.
2.4 Payment, Refund, and Transaction Records
Because payment is made to the Service Provider rather than to Reservai, we hold payment records rather than payment funds. These may include:
- amount, currency, payment method, payment status, the Service Provider's processor, and transaction or payment-intent identifiers;
- limited funding-source details returned by that processor, such as card brand and last four digits;
- refund, reversal, chargeback, dispute, and reconciliation information relating to the Booking;
- the Service Provider's own billing details, invoices, receipts, tax information, gateway connection status, and processor webhook records; and
- for transactions predating the Withdrawal Date only: Legacy Managed Payments ledger entries, historical Wallet credits and debits, settlement and payout records, and related balances retained for reconciliation, dispute, accounting, and legal purposes.
Reservai does not store complete payment-card numbers and does not receive Customer funds. Card and funding credentials are collected and processed by the Service Provider's Payment Processor, as explained in Section 7.
2.5 AI Chat and Interaction Data
- messages, prompts, responses, chat transcripts, language, and feedback;
- service, availability, pricing, location, staff, resource, recurrence, and booking context presented to or generated during a chat;
- contact details, one-time-password verification events, selections, confirmations, and requested actions;
- structured outputs used to create or manage a Booking, together with validation results and error logs; and
- usage, metering, safety, security, and diagnostic information associated with AI Features.
2.6 Device, Log, Usage, and Location Data
- IP address, browser, device, operating system, language, and approximate location inferred from technical data;
- pages, screens, links, actions, timestamps, referring URL, session, error, and performance information;
- cookie, local-storage, analytics, and similar identifiers; and
- more precise location only where a feature requests it, your device permits it, and it is needed for that feature.
2.7 Data from Integrations and Third Parties
We may receive data from a Service Provider's Payment Processor, banks, social sign-in services, identity and business-verification providers, messaging and email providers, analytics and security tools, embedded-site operators, or other integrations that you or a Service Provider enables. The information depends on the integration, its settings, and your permissions.
3. WHERE PERSONAL DATA COMES FROM
We collect personal data:
- directly from you when you register, book, pay, chat, upload content, configure the Platform, or contact us;
- from a Service Provider, staff member, booking organiser, payer, or another authorised User;
- automatically from devices, browsers, cookies, Platform events, security systems, and server logs; and
- from processors, integrations, verification services, and other third parties as described above.
If you provide another person's personal data, you must be authorised to do so and must give that person any notice required by law.
4. HOW AND WHY WE USE PERSONAL DATA
4.1 Purposes
We use personal data to:
- create, authenticate, secure, administer, and support Accounts;
- publish Provider Pages and enable availability, quotations, Bookings, amendments, cancellations, reminders, and communications;
- initiate a payment through the Service Provider's own gateway and record the resulting payment status, refunds, and reconciliation data against the Booking;
- calculate and administer Reservai's own plan fees, Commission, usage metering, invoices, and billing;
- administer and settle any remaining Legacy Managed Payments balance, including related refunds, chargebacks, and reconciliation;
- provide AI-assisted discovery, question answering, booking, and booking-management features;
- verify identity, business eligibility, and compliance information where required;
- prevent fraud, abuse, unauthorised access, security incidents, and violations of our Terms;
- provide support, investigate complaints, preserve evidence, and resolve operational or payment-record issues;
- measure usage, maintain service reliability, troubleshoot, test, analyse, and improve Platform features;
- send transactional, security, legal, support, and permitted marketing communications; and
- comply with law, regulatory requests, accounting and tax duties, legal claims, and enforcement obligations.
4.2 Legal Grounds
Depending on the activity and applicable law, we process personal data:
- with consent, where consent is required;
- to enter into or perform a contract requested by the data subject;
- to comply with legal, regulatory, accounting, tax, or court obligations;
- to establish, exercise, or defend legal claims;
- to protect Users, the public, the Platform, or important interests, including fraud and security prevention; or
- under another ground or exception permitted by applicable law.
Where processing depends on consent, you may withdraw that consent. Withdrawal does not affect processing already carried out lawfully and may prevent us from providing a feature that requires the data.
5. RESERVAI AND SERVICE PROVIDER DATA ROLES
The legal role of each party depends on the processing activity:
- Reservai-controlled activities: Reservai generally determines the purposes and means for operating Accounts, Platform security, its own billing, usage metering, support, compliance, and improvement of its services.
- Provider-controlled activities: A Service Provider determines why it collects Customer information for its Provider Services, which intake fields it requests, how it takes and refunds payment, how it communicates with Customers, and how it uses booking records for its own business.
- Processing for a Provider: For some booking, intake, communication, and business-management functions, Reservai processes data on the Service Provider's instructions.
- Payment data: For a payment taken through a Provider-Owned Gateway, the Service Provider and its Payment Processor determine how payment credentials and related data are handled. Reservai holds only the transaction record described in Section 2.4.
- Separate responsibilities: Reservai and a Service Provider may each act as an independent controller for different purposes involving the same Booking.
Service Providers must provide appropriate privacy notices, collect only necessary information, establish a lawful basis, protect Customer data, honour applicable rights, and configure Platform access for their staff responsibly.
6. HOW WE SHARE PERSONAL DATA
We may disclose personal data as reasonably necessary to:
- Service Providers and their authorised staff: to request, confirm, deliver, manage, support, or dispute a Provider Service;
- Customers, attendees, organisers, and payers: to provide booking, payment, service, and status information relevant to their transaction;
- The Service Provider's payment providers: including Stripe, PayPal, banks, card networks, and fraud or dispute services connected by that Service Provider, to initiate or reconcile a transaction;
- Providers used for remaining legacy balances: banks and processors involved in settling a Legacy Managed Payments balance or a related dispute;
- Technology and operations vendors: such as hosting, database, storage, security, analytics, identity, communications, support, document-processing, and AI service providers;
- Professional advisers and transaction parties: including auditors, insurers, accountants, lawyers, investors, buyers, and counterparties under appropriate confidentiality arrangements;
- Authorities and other parties: where required or permitted by law, legal process, regulatory request, safety needs, fraud prevention, rights protection, or enforcement of our Terms; and
- A successor organisation: in connection with a merger, acquisition, financing, restructuring, insolvency, or sale of all or part of the business, subject to applicable safeguards.
Reservai does not sell personal data for money. We also do not disclose Customer data to unrelated third parties for their own direct marketing except where you have directed or validly consented to that disclosure or it is otherwise lawful.
7. PAYMENTS AND GATEWAYS
7.1 Provider-Owned Gateways
Online payments are taken through the Service Provider's own supported gateway account, such as a Stripe or PayPal account it controls. In that setup:
- the Service Provider and its Payment Processor have their own direct merchant and privacy relationship;
- the processor collects payment credentials and may collect identity, fraud, device, and compliance data under its own privacy notice;
- Reservai may send Customer, Booking, amount, currency, and reference data required to initiate or manage the transaction;
- Reservai receives transaction identifiers, statuses, limited funding-source details, webhooks, refunds, disputes, fees, and reconciliation data needed to operate the Platform; and
- the money itself is received by the Service Provider and never passes through Reservai.
The Service Provider is responsible for lawfully configuring and using its gateway and for giving Customers any gateway-specific notices required by law. Where a Booking is paid in cash or by another method at the service location, Reservai holds only the payment record entered against that Booking.
7.2 Legacy Managed Payments
Before the Withdrawal Date, Reservai offered a payment mode in which it facilitated collection through its own configured Payment Processors. That mode has been discontinued and no new payments are collected under it. Reservai continues to hold the transaction, ledger, settlement, refund, dispute, and balance records created under that mode, and processes them only to complete outstanding settlements, handle refunds and chargebacks, reconcile accounts, respond to enquiries and claims, and meet accounting, tax, and legal-retention obligations.
7.3 Processor Policies
Payment Processors act under their own privacy terms for the activities they control. Please review the applicable processor's notice, including the Stripe Privacy Policy or PayPal Privacy Statement, where relevant. For a payment taken through a Provider-Owned Gateway, the relevant notice is that of the processor connected by your Service Provider.
7.4 Wallet and Historical Financial Records
Wallet records arose from Legacy Managed Payments. Wallets are no longer funded and cannot be used to pay for new Bookings. Reservai retains historical Wallet and related ledger entries to administer any remaining credit, support reconciliation and dispute handling, prevent misuse, and comply with legal or accounting obligations. This data is a Platform ledger record and may remain linked to the underlying transaction.
8. AI-ASSISTED FEATURES
8.1 How AI Data Is Used
Reservai may use AI models and related services to understand messages, answer questions, present Provider information, collect booking choices, create structured booking instructions, assist with amendments or cancellations, translate or format content, detect misuse, and support Platform operations.
8.2 Information Sent for Processing
Relevant prompts, messages, Provider Content, service and availability context, booking state, and limited technical data may be sent to contracted AI or infrastructure providers. Payment credentials are not part of an AI conversation. We seek to limit the information to what is reasonably needed for the feature, and you should not enter passwords, payment-card details, government identifiers, medical details, or other sensitive information unless the feature expressly requests it and you are authorised to provide it.
8.3 AI Limitations and Safeguards
AI output may be incomplete or incorrect. Reservai uses authoritative Platform records and validation rules for availability, pricing, identity verification, payment status, and final booking actions. An AI response does not independently override those records. Users may be asked to review or confirm important details before an action is completed.
Reservai may review AI interactions using automated tools or authorised personnel for support, safety, fraud prevention, quality, and troubleshooting. Where applicable law gives you rights concerning automated processing, you may contact us as described in Section 14.
9. IDENTITY AND BUSINESS VERIFICATION
To protect Users, meet legal or country-policy requirements, and settle any remaining Legacy Managed Payments balance, Reservai or a verification provider may request:
- government-issued identity documents and identity details;
- business licences, incorporation, ownership, tax, and authorised-representative documents;
- bank or other supported account information needed to release a remaining legacy balance; and
- verification status, risk indicators, source-of-funds or supporting information where required.
A Service Provider that connects its own gateway will separately undergo the onboarding and verification checks required by its Payment Processor, which processes that information under its own privacy notice. We may restrict an Account, gateway connection, feature, or the release of a remaining legacy balance while verification is incomplete, invalid, expired, or under review.
10. COOKIES AND EMBEDDED SERVICES
Reservai and its service providers may use cookies, local storage, pixels, and similar technologies to:
- keep sessions secure, remember preferences, and provide requested features;
- prevent fraud, balance traffic, diagnose errors, and measure performance; and
- understand Platform use and, where lawful and permitted, support communications or marketing.
You can manage cookies through available consent controls and browser settings. Blocking essential storage may prevent login, checkout, embedded booking, or other features from working correctly.
When a Service Provider embeds Reservai on its own website, both that website and Reservai may receive technical information needed to load and secure the embed. A card payment started from an embed is completed with the Service Provider's Payment Processor, and card details are not passed to or stored by Reservai. The Service Provider is responsible for its website's cookie notice, consent controls, domain configuration, and surrounding third-party technologies.
11. DATA RETENTION
We retain personal data only for as long as reasonably needed for the purpose for which it was collected and for applicable legal, regulatory, accounting, security, dispute, and enforcement requirements. Retention depends on factors such as:
- whether an Account, Booking, recurring series, payment record, legacy balance, dispute, or support matter remains active;
- the nature and sensitivity of the data and the risk associated with continued storage;
- contractual commitments and instructions from a Service Provider;
- processor, tax, accounting, anti-fraud, identity-verification, and legal-record requirements;
- limitation periods, legal holds, investigations, complaints, chargebacks, and claims; and
- security, audit, backup, recovery, and business-continuity needs.
Different categories therefore have different retention periods. Booking and financial records, including Legacy Managed Payments ledgers, may need to be kept after an Account closes, while optional marketing data may be deleted or suppressed when consent is withdrawn. Verification, transaction, and dispute information may be kept for the period required by law, a processor, or an unresolved matter.
When data is no longer needed, we take reasonable steps to delete, anonymise, aggregate, or otherwise place it beyond ordinary use. Residual copies may remain temporarily in backups or restricted archives until they are overwritten or safely deleted.
12. DATA SECURITY
We use reasonable technical and organisational safeguards appropriate to the nature of the data and the risks involved. Measures may include encrypted network connections, protected credentials, access controls, role-based permissions, logging, monitoring, backups, vendor controls, and incident-response processes. Gateway credentials supplied by a Service Provider are stored encrypted.
No internet transmission or storage system is completely secure. Users must protect login credentials, use appropriate access permissions, keep contact information current, secure embedded websites and connected gateway accounts, and notify [email protected] promptly of suspected unauthorised access or disclosure.
13. INTERNATIONAL DATA TRANSFERS
Reservai serves Users through providers and infrastructure that may operate in the UAE and other countries. Personal data may therefore be stored, accessed, or processed outside the country in which it was collected, including by Payment Processors, cloud, communications, security, support, verification, and AI providers.
Where applicable law restricts a cross-border transfer, we use a permitted transfer mechanism and appropriate contractual, organisational, or technical safeguards, or rely on another lawful exception. Protection and government-access rules in another country may differ from those in the UAE.
14. YOUR DATA-PROTECTION RIGHTS
Subject to the UAE PDPL and other applicable law, you may have rights to:
- obtain information about the personal data being processed and access a copy;
- correct or update inaccurate or incomplete personal data;
- request deletion of personal data in applicable circumstances;
- restrict, stop, or object to certain processing;
- receive or transfer personal data in a machine-readable form where applicable;
- withdraw consent where processing is based on consent;
- object to or request review of certain automated processing decisions; and
- submit a complaint to the competent UAE data-protection authority or another authority available under applicable law.
Rights may be limited by legal exceptions, other persons' rights, identity-verification needs, security, privilege, legal claims, or mandatory recordkeeping. We may ask for information reasonably needed to confirm your identity and locate the relevant records.
To exercise a right, email [email protected]. If the request concerns information controlled by a Service Provider, we may direct the request to that Service Provider or assist it in responding. A request about payment-card or processor-held data should be directed to the relevant Payment Processor, and we will help you identify it. We will respond within the period required by applicable law.
15. COMMUNICATIONS AND MARKETING
We send transactional and service messages needed for registration, one-time-password verification, security, Bookings, reminders, amendments, cancellations, payment status, refunds, billing, support, and material policy or service updates.
We send marketing communications only where lawful and with consent where required. You may opt out using the unsubscribe method in a message or by contacting us. An opt-out does not stop essential transactional, security, legal, or service communications.
Service Providers are separately responsible for ensuring that their Customer marketing, imported contact lists, reminders, and campaigns comply with consent, notice, calling-time, suppression, and opt-out requirements.
16. CHILDREN AND MINORS
Reservai business Accounts are not intended for persons who lack legal capacity to enter the applicable agreement. A Service Provider may offer a lawful service for a child or minor, but the parent, guardian, and Service Provider are responsible for providing required notices and obtaining valid authorisation or consent.
If you believe a child has provided personal data without appropriate authorisation, contact us so we can review the circumstances and take action required by law.
17. THIRD-PARTY SITES AND SERVICES
The Platform may link to or integrate with third-party websites and services, including the payment pages of a Service Provider's Payment Processor. Their privacy practices are governed by their own notices. Reservai is not responsible for a third party's independent data handling, and a link does not mean that Reservai endorses that party's practices.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Policy to reflect legal, regulatory, security, operational, payment, AI, or product changes. We will display the updated date above and provide additional notice where required by law. Material changes take effect on the stated effective date.
19. CONTACT US
For privacy questions, rights requests, or concerns about how personal data is handled, contact:
Digiteon Technologies L.L.C-FZ
Trading as Reservai
Registration number: 2306345.01
Address:
Meydan Free Zone, Meydan Hotel, Ground Floor, Dubai, United Arab Emirates
Privacy and support enquiries: [email protected]
General enquiries: [email protected]
Phone: +971 50 335 7699
Website: https://reservai.ae