Skip to content
Policies

Sub-processors

Last updated: 22 September 2026

About this list

In short: Sub-processors are third-party services we use to deliver ResoFlow. We give 30 days notice before adding one that affects your existing use; sub-processors that only power an optional feature are authorised when you switch that feature on.

A sub-processor is a third-party company that processes personal data on our behalf so we can deliver the Services. Each is bound by a Data Processing Agreement and provides assurances on UK GDPR compliance.

We give at least 30 days advance notice before adding a new sub-processor that processes data as part of your existing use of ResoFlow. New sub-processors that only power an optional feature you choose to switch on are listed here and authorised when you enable that feature. Tenants who want to be added to an email list for these notifications can email privacy@resoflow.co.uk with the subject "Subscribe to subprocessor updates".

For the legal basis on which we use these sub-processors, see our Data Processing Agreement and Privacy Policy.

Current sub-processors

NameRoleLocationDPA
Google LLC (Firebase / Google Cloud Platform)Database, authentication, hosting and Cloud Functions; Vertex AI (Gemini) generative AI for Rezo, our AI support assistant, which answers first-line support questions in the support inbox and the public contact widget (the model also reads any picture a user attaches in a support conversation, and each reply is given a short summary of the venue’s own settings, plan and usage so Rezo can answer about that venue’s setup — never customer personal data), for reading a menu (a photo, PDF or menu web page) or a picture of a floor plan that a venue chooses to import (the file is sent to the model, read once, and deleted as soon as it has been read, whether or not the read succeeded; it is never used to train a model), and for the optional ‘Check my wording’ tool in a venue’s policy settings (the policy text the venue has written is sent for an advisory read when they click it, and is never used to train a model), and for the optional AI marketing assistant in the campaign composer (drafting campaign text and, where enabled, images from the brief a venue types — the model receives the venue’s own facts and brief only, never customer personal data, and nothing sent is used to train a model), and for the optional AI promotion drafter on the Promotions page (suggesting the shape of one offer from the goal a venue types — the model receives the venue’s name, that goal, the promo codes it already uses and which features are switched on, never customer personal data, and nothing sent is used to train a model); and Vertex AI text embeddings — a non-generative model that writes no text — for the Help Centre’s smart search, which converts the words searched for into a list of numbers so they can be matched by meaning against our own help guides (the search text is never used to train a model). All AI processing stays inside the European Union (Google’s EU-only multi-region); the database and functions run in europe-west1. Firebase Cloud Messaging delivers push alerts to the staff devices that have turned alerts on (an optional feature — authorised when a venue switches it on for a device; no notice period): it receives the device’s push token and the alert text (a first name and initial, a party size and a time — never a phone number, email address, allergies or notes) and hands the encrypted message to the push service of the device’s own browser or operating system.European Union (database & functions in europe-west1, Belgium; AI in Google’s EU-only multi-region) + global CDNGoogle Cloud DPA
Cloudflare, Inc.CDN, DDoS protection, web application firewall (WAF), bot management (Super Bot Fight Mode), cookieless Web Analytics on our public pages (page-view totals — no cookies, no cross-site tracking), DNS hosting, and Turnstile bot challenge — used both for per-submission protection on the public booking page and as the app-wide attestation provider for Firebase App Check. Cloudflare receives request metadata (IP address, user-agent, request path, geo-location) at the edge for security analysis. For venues who enable the optional Your domain product, Cloudflare additionally serves the venue’s own connected domain: it issues and renews the domain’s security certificate, terminates TLS and routes the traffic to ResoFlow (Cloudflare for SaaS custom hostnames), and hosts the per-venue Turnstile bot-check configuration for that domain. Enabling the product is the venue’s authorisation for this processing.Global edge network (US-headquartered; processing in any Cloudflare PoP including UK + EU)Cloudflare DPA
Stripe Inc.Subscription payments, and Stripe Connect payments taken on the venue’s own connected account — deposits and no-show protection (saving a customer’s card and charging any no-show fee), event tickets, online gift card sales, Order & Pay table orders, pre-order payments and payment links.United States / IrelandStripe DPA
Resend Inc.Transactional and support email delivery and inbound support email receiving. For venues who enable the optional Your domain product, Resend also verifies and sends from the venue’s own domain (customer-facing email only — booking confirmations and, with the venue’s explicit switch, marketing). Resend delivers through Amazon SES infrastructure in the EU (Ireland) region.European Union (Ireland)Resend DPA
Slack Technologies LLCInternal staff messaging bridge — outbound notifications when escalations occur, plus inbound replies routed back to customer conversations. Customer support correspondence (name, email, message text, image attachments) is shared.United States (ISO 27001 certified; SCC-based UK-EU data transfer mechanism)Slack DPA
Twilio Inc.SMS delivery (per-tenant subaccounts)United States / IrelandTwilio DPA
Functional Software Inc. (Sentry)Error tracking and performance monitoring, including a short, fully masked session replay around an error on signed-in screens only (see our Cookie Policy for the full detail).European UnionSentry DPA
BetterStackUptime monitoring and status pageEuropean UnionBetterStack DPA
Google LLC (Google Analytics 4)Aggregate web analyticsUnited StatesGoogle Ads Data Processing Terms
Apple Distribution International Ltd.Apple Wallet passes for event tickets, loyalty cards and gift cards — a ticket pass carries the ticket-holder name and event details; a loyalty-card pass carries the member’s name, balance and member code; a gift-card pass carries the card’s balance, code and expiry (no name). A pass is created only when a customer chooses to add it to their wallet (and, for loyalty, only where the venue has enabled its scheme).Ireland / European UnionApple Privacy Policy
Apple Inc. (Apple Push Notification service)Relays push alerts to iPhones, iPads and Macs whose staff member has turned alerts on in the ResoFlow app — Apple’s push service receives an encrypted message and a device token and shows the alert; it cannot read the alert’s content.United States / global (Apple’s push infrastructure)Apple Privacy Policy
Mozilla Corporation (Firefox push service)Relays push alerts to a computer whose staff member has turned alerts on in Firefox — Mozilla’s push service receives an encrypted message and a device token and shows the alert; it cannot read the alert’s content. (Android and Chrome/Edge alerts are relayed by Google’s push service under the Firebase / Google Cloud entry above.)United States / global (Mozilla’s push infrastructure)Mozilla Privacy Notice
Google LLC (Google Wallet)Google Wallet passes for event tickets, loyalty cards and gift cards — when a customer taps “Save to Google Wallet”, a ticket pass carries the ticket-holder name and event details; a loyalty-card pass carries the member’s name, balance and member code (and only exists where the venue has enabled its scheme); a gift-card pass carries the card’s balance, code and expiry (no name).United StatesGoogle Privacy Policy
OpenStreetMap Foundation (Nominatim)Geocoding a venue’s address to place its Apple/Google Wallet pass geofence. Receives the venue’s business address only — no customer personal data.United Kingdom / European UnionOSMF Privacy Policy
Google LLC (Google Maps Platform)Address autocomplete and geocoding for the venue address box in settings and onboarding (receives what an owner types into the address field — business address data only), and the static map image shown on a venue’s public pages: a customer’s browser fetches that image directly from Google, which therefore sees the customer’s IP address and browser details alongside the venue’s address. No customer name, booking or contact data is ever sent, and the map image sets no cookies. Where a venue enables delivery ordering (Order & Pay Pro), the delivery address a customer enters at checkout is also sent to Google Maps — from our servers, with no name or contact details attached — solely to measure its distance from the venue, so we can check it falls inside the venue’s delivery area and work out the delivery charge.United StatesGoogle Maps Platform DPT
rdap.org (RDAP registry lookup)Checking when a venue’s own connected domain is due to expire, so we can warn the venue before their website goes offline. Used only for venues with the optional Your domain product; receives the venue’s domain name only — never any personal data.Public registry infrastructure (queries routed to the domain’s own registry)About RDAP

Two further services are used only by ResoFlow’s own internal admin screens and by the status badge on our marketing site, and process no customer or venue data, so they are not sub-processors of your data: jsDelivr (cdn.jsdelivr.net, a content delivery network that serves the code editor used on ResoFlow’s internal admin screens to the browser of the member of our team using it) and BetterStack (resoflow.betteruptime.com, the public status feed our marketing site’s status badge reads — your browser fetches that feed directly, so BetterStack sees the ordinary details of that request, such as your IP address, but receives no personal data from ResoFlow).

Last updated

This list was last updated on 22 September 2026 (Cloudflare's entry now also names its cookieless Web Analytics, which runs on our public pages).