Your data, kept safe.
ResoFlow holds your guests’ details and your bookings. Here is how we protect them — where your data lives, who processes payments, and the controls you get.
Six plain answers.
Where your core data is stored, how payments work, and the controls available to your team.
Your bookings and guest records are stored in Google Cloud’s EU region, in Belgium.
Other services, including payments, email, edge hosting and support, may process limited data outside the UK/EU. Provider locations and the legal safeguards for those transfers are explained on the sub-processors page.
ResoFlow is a trading name of Caleonix LTD, company number 17162652, registered in England & Wales.
The company is registered with the Information Commissioner’s Office (ICO), registration ZC127147 — a public record you can look up without asking us.
Subscriptions, deposits, gift cards and event tickets are processed by Stripe. Card numbers go straight to Stripe — ResoFlow never stores your card details or your guests’.
Guest card payments go through your own Stripe account. Manage supported refunds in ResoFlow; a payment that needs further checking remains visible for follow-up.
Contact support to request a copy of your venue data. We prepare an export and email you a secure download link.
Deletion requests follow our retention policy, including records we must keep. On plans that carry the customer portal, your guests get the same GDPR self-service for their own records.
Your data is backed up every day, and every backup is checked, so a failed one gets spotted rather than discovered later.
How the platform is running is published openly at status.resoflow.co.uk — no sign-in needed.
Two-factor authentication is available to help protect accounts that can change things. On paid plans, staff sign in with their own PIN and carry only the permissions their role needs.
A full activity log records who did what and when, and your public pages carry bot protection so the booking form stays for real guests.
The controls, and where they apply.
Some of this is on every plan including the free one. Some of it needs a paid plan. Here is which is which.
| Control | On | What it does |
|---|---|---|
| Two-factor authentication | Every plan | A code from your phone on top of your password. |
| Bot protection on public pages | Every plan | Your booking page is screened, so the form stays for real guests. |
| A full copy of your data | Every plan | Ask, and we prepare it and email a secure download link. |
| Deletion on request | Every plan | Ask, and we delete. Your guests can ask you, and you can act on it. |
| Staff PINs | Paid plans | Everyone signs in as themselves — no password passed round the pass. |
| Roles and permissions | Paid plans | Owner, Admin, Manager and Host built in, plus five roles of your own. |
| Activity log | Paid plans | Who did what, and when. Filters and CSV export from Pro. |
| GDPR self-service for guests | Pro and up | Diners see, export and delete their own records in your customer portal. |
Tools to help you prepare and recover.
Most of what a venue fears isn’t a breach. It’s a Saturday at 19:00 with no idea who is coming in. So the answer to that is designed in.
Print the day sheet at the start of service — the full day’s bookings, tables, allergies and notes on paper. If the connection goes, service carries on from the sheet in your hand.
Reservations, kept safe.
Set up free in an afternoon on infrastructure built to look after your guests’ data — no card required.
No credit card required · Free plan available · 14-day money-back guarantee on paid plans