Privacy notice

Last updated:

This page explains which personal data we collect, why we collect it, who we share it with and what you can ask us for. It is written under articles 13 and 14 of the European Regulation 2016/679, the GDPR.

Who handles your data

The controller for the onebooking.club site and for accounts on the software is the company shown below. Write to it with any question about this notice and to exercise your rights.

Legal name
Investfood S.r.l.
Registered office
Via Riva di Trento 11/A, 20139 Milano (MI), Italy
VAT number
12925600962
Company register
REA MI 2692864
Certified email
investfood@legalmail.it

Three situations, three different roles

OneBooking is software that restaurants use to manage their own bookings. That means our role changes depending on who you are.

  • If you are visiting this site, we are the controller.
  • If you have an account because you work at a restaurant that uses OneBooking, we are the controller for your account data.
  • If you booked a table, the controller is the restaurant you booked with. We handle that data as a processor, on their behalf and on their instructions. Requests about your booking go to the venue, which can always bring us in.

What we collect and why

WhoDataPurposeLegal basis
Site visitorsIP address, browser type, page requested, date and time. These are the technical logs of the hosting service.Running the site, defending it from abuse and diagnosing faults.Legitimate interest, art. 6.1.f.
Account holdersName, email address, assigned role, venues they can reach, and a log of the actions they take on bookings.Giving access to the software, applying the right permissions and reconstructing who changed what.Performance of a contract, art. 6.1.b, and legitimate interest for the log, art. 6.1.f.
Guests who book a tableName, phone, email, party size, date and time, booking notes, and the history of visits to that restaurant.Handling the booking, sending confirmations and cancellations, recognising a returning guest.Performance of the contract with the restaurant, art. 6.1.b.
People who write to or call Booking AIPhone number, the content of the conversation, and a recording or transcript of the call where enabled.Taking the booking, answering questions about the venue and checking what was said if it is later disputed.Performance of a contract, art. 6.1.b, and legitimate interest, art. 6.1.f.
People who pay a depositAmount, payment outcome and transaction reference. Card details never pass through us and we never see them.Collecting the deposit and handling any refund.Performance of a contract, art. 6.1.b.

Allergies and notes about health

A booking can carry notes about allergies or intolerances. That is health data, which the GDPR protects specifically under article 9.

It is entered by the guest or by the restaurant staff for one precise reason: to put something safe on the table. The restaurant handles it on the basis of the explicit consent of the person providing it. We store it on the restaurant’s behalf and show it only to the staff of that venue.

If you would rather a health note were not kept, ask the restaurant to remove it: it disappears from the record and from the booking.

Where data we did not get from you comes from

Some bookings do not start with us. They arrive from TheFork, from the restaurant’s own website, from the till in the venue, or from a phone call typed in by staff. In those cases the data reaches us from the originating channel or is entered by the restaurant, and the categories are the same as those listed above for guests who book a table.

Who we share it with

We do not sell personal data and we do not pass it to third parties for their own purposes. We entrust it only to the suppliers we need in order to run the service, each one bound by a contract under article 28 of the GDPR.

SupplierWhat it does for usWhere it processes data
Google Cloud PlatformApplication hosting and databaseEuropean Union
Google FirebaseSite hosting and authenticationEuropean Union and United States
ResendTransactional email deliveryUnited States
TwilioWhatsApp messages and voice callsUnited States
TheForkConnected booking channelEuropean Union
StripeDeposit paymentsEuropean Union and United States

Transfers outside the European Union

The database and the application run on servers in the European Union. Some of the suppliers listed above are based in the United States: in those cases the transfer rests on the standard contractual clauses approved by the European Commission, or on the supplier’s certification under the European Union and United States Data Privacy Framework.

You can ask us for a copy of the safeguards in place by writing to the address at the foot of this page.

How long we keep it

DataRetention
Technical site logsUp to 12 months from the visit.
Software accountsFor the whole of the relationship, then up to 12 months.
Bookings and guest recordsFor the term of the contract with the restaurant. The restaurant can delete a record at any time.
Booking AI conversationsUp to 12 months, unless a dispute is still open.
Accounting records for paymentsTen years, as Italian law requires.
Cookie consentSix months from the choice, then the banner returns.

Automated decisions and Booking AI

Booking AI talks to the guest and offers the times that are free, but it does not take decisions producing legal effects on people. It works inside the rules the restaurant sets, and staff can always step in, correct or cancel what it did.

Automatic table assignment follows fixed criteria such as capacity and availability at that time. It does not profile people and it does not use the guest record to decide.

Your rights

The GDPR gives you rights you can exercise at any time, free of charge. We answer within one month.

  • Know whether we handle data about you and receive a copy, art. 15.
  • Have inaccurate or incomplete data corrected, art. 16.
  • Ask for erasure, art. 17.
  • Ask for the processing to be restricted, art. 18.
  • Receive your data in a machine readable format and have it moved elsewhere, art. 20.
  • Object to processing that rests on our legitimate interest, art. 21.
  • Withdraw a consent you had given, without affecting what was done before, art. 7.3.

If you think something is wrong

Write to us first: almost everything is settled before it becomes a complaint. If that is not enough, you can go to the Italian data protection authority, Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, or to the authority of the European country where you live or work.

How we protect the data

Traffic is encrypted in transit. The database is not reachable from the internet and accepts connections only from the application, over a private network. Credentials live in a secret manager, not in the source code. Every sign in goes through a personal account with a role, and operations on bookings land in a log that records who did what and when.

Calls between the software and connected systems, such as the till in the venue, are signed: a request without a valid signature is refused.

Children

The service is for restaurants and for adults booking a table. We do not knowingly collect data about children under fourteen. If you notice that it happened, write to us and we will remove it.

Changes to this notice

If we change something material we update the date at the top of the page, and where the change affects you directly we tell you by email or inside the software.