Privacy
Last updated 2 September 2026
Not ready to publish: the operator’s legal entity and a monitored contact address are still placeholders below. Both must be real before this page is linked from a consent screen shown to anybody outside the building.
Partynotes is software a restaurant uses to take private-event bookings — the enquiry, the room, the menu, the deposit and the correspondence, in one record. This page says what it stores, who can reach it, and what it deliberately never holds.
Who is responsible for what
A restaurant using Partynotes decides what it collects about its own customers and why; it is the controller of that information. [LEGAL ENTITY] operates the software and stores that information on the restaurant’s behalf, and processes it only to run the service.
If you are a customer of a restaurant that uses Partynotes and you want your details removed, ask the restaurant. They can delete them, and we will act on their instruction.
What is stored
For each person who enquires or books, a restaurant may record:
- A name, and a company if they gave one.
- A phone number, kept both as they said it and in a normalised form, so the same person is recognised however it was typed next time.
- An email address, if they gave one.
- The bookings themselves: date, time, room, guest count, what was ordered, what it came to, and any notes staff wrote.
- Email correspondence about a booking — subject and body, in both directions — where the restaurant has connected its mailbox.
For staff, an account holds a name, an email address and a role. Sign-in is through Google; no password is stored, because there is nowhere to store one.
What is deliberately never stored
No card number, security code or magnetic-stripe data exists anywhere in this system. There is no column for one. Deposits and payments are taken on the restaurant’s own card terminal, which Partynotes never sees and never talks to.
Where a booking shows an amount outstanding, that is arithmetic on what was quoted. It is not a record of a payment we processed, because we do not process payments.
Google account data, and how it is used
A restaurant may connect its own Gmail account so that confirmations come from its address and replies land against the right booking. Doing so is optional and can be undone at any time from the app’s settings, which also revokes our access at Google.
When connected, Partynotes requests three permissions and uses them narrowly:
- Read your email messages and settings (
gmail.readonly) — to find replies to bookings so the conversation appears in the app beside the booking it belongs to. Mail unrelated to a booking is not matched to one. - Send email on your behalf (
gmail.send) — to send a confirmation after a person at the restaurant has read it and pressed Send. Nothing is ever sent automatically. - See your primary email address (
userinfo.email) — to show which mailbox is connected.
A restaurant may also share one calendar with our service account so bookings appear on it. That grant reaches only the calendars deliberately shared, and no others.
Partynotes’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or sell this data, we do not use it for advertising, and we do not allow humans to read it except with the restaurant’s explicit permission, to resolve a fault they have reported, or where the law requires it. We do not use it to train generalised artificial-intelligence or machine-learning models.
One restaurant cannot see another
Every record belongs to a venue, and every query the software makes is bound to the venue of the person asking. This is enforced in one place in the code rather than remembered in many, and it is tested by giving two venues the same data and checking neither can reach the other’s.
A stored mailbox credential is encrypted at rest with a key held separately from the database, so a copy of the database on its own does not grant access to anyone’s mail.
Who else touches it
- Turso — the database, hosted in the United States.
- Vercel — runs the application and serves the pages.
- Google — only where a restaurant has connected Gmail or shared a calendar.
- Cloudflare — triggers the scheduled tasks that keep calendars and mail up to date.
Nobody else. Information is not sold, and is not shared for advertising or profiling by anyone.
How long it is kept
A booking and its correspondence are kept for as long as the restaurant wants them — bookings are records of what was promised to somebody, and a cancelled event still needs its history if a deposit is ever disputed. A restaurant can delete a contact, a booking or a conversation at any time, and deletion removes the record rather than hiding it.
When a restaurant stops using Partynotes, its data can be exported and is deleted on request.
Your rights
Depending on where you live you may have the right to ask what is held about you, to have it corrected or deleted, and to object to how it is used. If a restaurant holds your details, ask them first — they control that record. If you cannot reach them, write to us at [CONTACT ADDRESS] and we will help, subject to confirming who you are.
Contact
Questions about this policy: [CONTACT ADDRESS], operated by [LEGAL ENTITY].
Placeholder while the pilot is being set up: hello@partynotes.app.
Changes
If this policy changes in a way that affects what is collected or who it is shared with, the restaurants using Partynotes will be told directly rather than by a silent edit to this page.