Privacy Policy

Last updated: May 20, 2026

Summary

This notice explains how SlotAgent ("we," "us," or "our") handles personal information when you use our reservation and resource-management platform, the operator dashboard, optional public booking pages, billing, and related services (collectively, the "Services").

Venue guests: If you book through a venue's public page, that venue receives the details you submit. We process information to run the Services for operators and, where applicable, as described below. You should also read the venue's own privacy notice.

Questions? Use the contact options in Section 17. If you disagree with this notice, please discontinue use of the Services.

1. What information we collect

You provide to us

We collect information you voluntarily submit, such as when you register, manage a subscription, update settings, contact support, or complete forms. This may include names, email addresses, phone numbers, business or venue details (including optional address), account credentials (stored using industry-standard practices), preferences, and messages you send us.

Payments. Paid plans are processed by our payment processor, Stripe, Inc. Card and payment instrument details are handled according to Stripe's practices. See Stripe's privacy information. We store only billing-related identifiers (customer ID, subscription ID, payment method metadata such as last-four digits, card brand, and expiry) — never raw card numbers.

Guest bookings. When someone books through a venue's public flow, we collect the information the form requests (for example name, contact details, party size, notes, and optionally UTM/campaign parameters) so the venue can fulfill the reservation.

Push notification tokens. If you install a SlotAgent mobile app and enable push notifications, we store a Firebase Cloud Messaging (FCM) device token to deliver reservation alerts. These tokens are distinct identifiers tied to your device, not to you personally.

Sensitive categories. We do not intentionally collect sensitive or special-category data unless you choose to include it in free-text fields; please avoid sending health or other sensitive data unless the Service explicitly requires it.

Collected automatically — web application

When you use our web application, we automatically receive technical data such as IP address, browser type, general location derived from IP, referring URLs, and usage diagnostics (e.g. timestamps, pages or screens viewed, errors). We use this to secure the Services, troubleshoot, and understand aggregate usage. We may use cookies and similar technologies as described in Section 6.

Collected automatically — mobile application

The SlotAgent mobile app collects only what is necessary to provide its functionality: your account data (the same profile and subscription information you manage via the web dashboard), a push notification token (FCM) if you enable notifications, and basic error diagnostics used solely to fix crashes and improve stability. The mobile app does not use analytics SDKs, advertising identifiers (IDFA/GAID), or any technology that tracks your activity across other apps or websites. Because no cross-app or cross-site tracking occurs, the mobile app does not present Apple's App Tracking Transparency (ATT) permission prompt and does not appear under the "Data Used to Track You" category in App Store privacy labels.

Google. If you connect Google services, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.

2. How we use your information

We process personal information to:

  • Create and maintain accounts, authenticate users, and operate the Services.
  • Provide scheduling, reservations, resources, team collaboration, and public booking as configured.
  • Process subscriptions, invoices, and payment-related communications.
  • Respond to inquiries, provide support, and send service-related notices (including policy updates).
  • Deliver SMS, email, and push notifications related to reservations, as configured.
  • Power the AI Phone Receptionist feature, including routing calls and storing call logs.
  • Secure the platform, monitor for fraud and abuse, and comply with legal obligations.
  • Improve reliability, fix bugs, and analyze aggregated or de-identified usage trends.
  • Send marketing only where permitted and consistent with your choices; you may opt out as described in Section 12.

3. Legal bases (EEA, UK, Canada, and similar jurisdictions)

Where GDPR, UK GDPR, or comparable laws apply, we rely on appropriate bases such as: contract (providing the Services you request), legitimate interests (security, product improvement, and communications that align with your expectations), consent (where we ask for it, e.g. certain cookies or marketing), and legal obligation. Canadian users may withdraw consent where processing is consent-based, subject to legal exceptions.

4. When we share information

We may disclose personal information to:

  • Service providers (sub-processors) who assist us in delivering the Services, bound by contractual confidentiality and security obligations. Our current principal sub-processors include:
    • — Supabase, Inc. Authentication, user session management, and database hosting.
    • — Stripe, Inc. Payment processing, subscription management, and invoicing.
    • — ElevenLabs, Inc. AI voice synthesis, conversational AI agent (AI Phone Receptionist), and post-call transcription and analysis. Call audio and transcripts may be processed and temporarily retained by ElevenLabs under our data-processing agreement.
    • — Telnyx LLC SMS delivery for reservation notifications.
    • — Google LLC (Firebase / FCM) Push notification delivery to mobile devices.
    • — Resend, Inc. Transactional and notification email delivery.
    • — Inngest, Inc. Background job orchestration (e.g. reservation emails, account deletion workflows).
    • — Cloudflare, Inc. Bot protection (Turnstile) on specific sensitive actions.
    • — Google LLC (Tag Manager / Analytics) Website analytics and tag management, loaded only after your explicit cookie consent.
  • Venue operators you interact with — for example, guest data submitted through a venue's booking experience is available to that venue.
  • Professional advisers, regulators, or authorities when required for legal, audit, or compliance reasons.
  • Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

We do not sell your personal information as that term is commonly defined in US state privacy laws. We may allow limited analytics technology as described in Section 6 where you have given consent.

5. Third-party websites

The Services may link to third-party sites or embed third-party content. We do not control those sites and are not responsible for their privacy practices. Review their policies before sharing information.

6. Cookies and similar technologies

We use cookies, local storage, and similar technologies for session management, preferences, security, and — with your consent — analytics. You can control these through our cookie consent banner (shown on first visit) and through your browser settings. For a full list of every cookie and local-storage item we set, see our Cookie Policy.

Essential & functional

These are required for the platform to work: authentication session cookies (Supabase), sidebar state preference, UI theme preference, language preference, and your cookie consent choice. We do not require additional consent for these.

Analytics (consent required — web application only)

We use Google Tag Manager to load Google Analytics on the web application only. The SlotAgent mobile app does not load Google Tag Manager, Google Analytics, or any other analytics or advertising SDK. These cookies are set only after you give explicit consent via the banner. If you choose "Essential only," no analytics cookies are loaded. You can withdraw consent at any time by clearing the sa_cookie_consent key in your browser's local storage (developer tools → Application → Local Storage). The Google Analytics opt-out add-on is also available.

Mobile application

The SlotAgent mobile app does not use cookies, web storage for tracking, or any technology that identifies you across apps or websites. The only local storage used by the mobile app is for authentication session management and user preferences required to operate the app. No consent banner is shown in the mobile app because no analytics or tracking technologies are loaded.

7. Artificial intelligence & voice features

AI language models

Some capabilities use AI or machine learning. Where we use third-party model providers, inputs and outputs may be processed by those vendors under agreements that restrict use of your data for model training except as disclosed. Do not submit secrets or highly sensitive data into AI features.

AI Phone Receptionist

SlotAgent's AI Phone Receptionist is powered by ElevenLabs Conversational AI. When a call is handled by the AI receptionist:

  • The call is processed in real time by ElevenLabs servers for speech-to-text (transcription) and text-to-speech (voice synthesis).
  • After the call ends, ElevenLabs sends us a post-call webhook containing a full transcript, a machine-generated call summary and evaluation, call metadata (duration, disconnection reason, cost units), and latency metrics. We store all of this in our database linked to the reservation or call log.
  • ElevenLabs processes this data under a data-processing agreement that prohibits them from using your call data to train their models without disclosure. See ElevenLabs' privacy policy.

Operator responsibility. Venue operators who enable the AI Phone Receptionist are responsible for ensuring that callers (guests) are notified that their call may be recorded and transcribed, in compliance with applicable recording-consent and wiretapping laws in their jurisdiction (for example, two-party consent states in the US, or equivalent local law). SlotAgent provides the infrastructure; compliance with local recording-notice requirements is the operator's obligation.

You may limit AI processing through account settings or by contacting us. Operators can disable the AI receptionist at any time in the Receptionist settings.

8. Social sign-in

If you register or sign in with Google, Apple, or another provider, we receive profile details that provider chooses to share (often name, email, and profile image). Their use of your information is governed by their policies; please review them and your privacy controls on those platforms.

9. Retention

We retain personal information only as long as needed for the purposes above, including legal, accounting, and reporting requirements. When data is no longer required, we delete or anonymize it, except where backup or archival copies persist for a limited period under technical safeguards.

Voice call logs (transcripts, analysis, metadata) are retained as part of your subscription data. They are deleted as part of the account-deletion workflow when you request deletion of your account.

Guest reservation data is retained for the duration of your subscription and deleted or anonymized upon account deletion, subject to any legal retention obligations (e.g. financial records).

10. Security

We implement organizational and technical measures designed to protect personal information, including encrypted data transmission (TLS), managed authentication via Supabase, and access-controlled database environments. However, no method of transmission or storage is completely secure; use the Services only on trusted networks and protect your credentials.

11. Children

The Services are not directed to children under the age required in your jurisdiction (typically 16–18). We do not knowingly collect personal information from children. If you believe we have, contact us and we will take appropriate steps to delete it.

12. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing or automated decision-making. You may withdraw consent where processing is based on consent. To exercise rights, contact us as in Section 17. We will verify requests as permitted by law. EEA/UK users may lodge a complaint with a supervisory authority.

Marketing opt-out: use unsubscribe links in emails, adjust in-app notification preferences (Account → Preferences), or email us. We may still send non-promotional messages about your account or the Services.

Account self-service. You can delete your account from the Account settings page. This triggers a data-deletion workflow that removes your profile, subscription, reservations, resources, and related data from our systems. See Section 18 for details.

13. Do-not-track

There is no consistent industry standard for browser DNT signals. We do not respond to DNT signals today; if that changes, we will update this notice. You may opt out of analytics cookies via the cookie consent banner as described in Section 6.

14. United States residents

Residents of certain US states may have additional rights (including to know, access, correct, delete, opt out of targeted advertising or "sales"/"sharing" as defined locally, and appeal denials). To submit a request, contact us with sufficient detail to identify your account. Authorized agents must provide documentation of authority. We will not discriminate for exercising rights.

Categories collected (illustrative). In the preceding twelve months we may have collected: identifiers (name, email, phone, account ID); commercial information (transactions processed by our payment partner); internet or network activity (logs, diagnostics); audio/call data (voice call transcripts via AI receptionist, where applicable); geolocation data inferred from IP; and inferences drawn from usage data.

California "Shine the Light" requests regarding marketing disclosures may be sent using the contact in Section 17.

15. Other regions

Australia & New Zealand: This notice is intended to meet transparency expectations under local privacy laws. You may request access or correction via Section 17 or 18.

South Africa & others: If local law grants you complaint rights, you may contact your regulator after first allowing us to address your concern.

16. Updates to this notice

We may revise this Privacy Policy from time to time. The "Last updated" date will change, and we may provide additional notice for material changes (for example by email or in-app message). Continued use after the effective date constitutes acceptance of the revised notice where permitted by law.

17. Contact

For privacy questions or requests, contact us using the support or privacy contact published on our website, in the application, or in subscription communications. If no dedicated address is shown, reach out through the same channel you use for product support.

18. Access, correction, and deletion

You may review or update certain information directly in your account. To request access, correction, export, or deletion of personal information we hold, contact us as described in Section 17. We will respond within timelines required by applicable law. Some requests may be limited (for example where we must retain data for legal compliance or dispute resolution).

Account deletion. You can initiate account deletion from Account settings → Delete account. This triggers an automated workflow that deletes your reservations, resources, operating hours, AI agent configuration, team memberships, subscription, profile record, and authentication credentials. Voice call logs and SMS records associated with your subscription are also deleted. The process is typically completed within a few minutes; some anonymized analytics data and financial records required for legal compliance may be retained longer.

HomeTerms of UseCookie Policy