1. Who We Are
Resvly ("we", "us", "our") is a SaaS booking and queue management platform operated from Australia. We act as the data controller for personal information collected from visitors, customers, and service providers who use the Platform at https://resvly.com.
Contact: [email protected]
2. What Data We Collect
Account Registration
- Name, email address, and (optionally) mobile phone number
- Password stored as a one-way bcrypt hash — never in plain text
- Country and timezone preference
- Profile images (if uploaded)
Bookings & Queue Entries
- Service selected, date, time, and any booking notes
- Walk-in queue entries: name, email, phone, service, staff preference, and any custom fields the provider configured
- Payment status and Stripe references (not card details — those stay with Stripe)
Provider Business Data
- Business name, description, address, and contact details you publish on your profile
- Service definitions, staff schedules, and operating hours
- Stripe Connect account identifiers (not bank details — those stay with Stripe)
Technical Data
- Session cookies required for authentication and CSRF protection (see Section 7)
- IP address and user-agent string logged for security and fraud prevention
- reCAPTCHA Enterprise signals collected on registration and contact forms to detect bots (processed by Google)
3. Why We Collect It & Legal Basis
| Purpose |
Legal Basis (GDPR) |
| Creating and managing your account | Contract |
| Processing bookings and queue entries | Contract |
| Sending booking confirmations, reminders, and queue updates | Contract |
| Facilitating payments via Stripe Connect | Contract / Legal obligation |
| Fraud prevention and security logging | Legitimate interest |
| reCAPTCHA bot protection | Legitimate interest |
| Sending marketing/feature update emails | Consent (opt-out available anytime) |
| Complying with tax and legal obligations | Legal obligation |
4. Third-Party Processors
We use the following sub-processors. Each has its own privacy policy and is bound by data processing agreements where required by law:
-
Stripe — Payment processing and Stripe Connect for provider payouts. Card details are handled entirely by Stripe and never transmitted to our servers. stripe.com/privacy
-
Mailjet — Transactional and marketing email delivery. Your email address is shared with Mailjet solely for the purpose of sending emails on our behalf. mailjet.com/privacy-policy
-
Google reCAPTCHA Enterprise — Bot and spam protection on registration and contact forms. Google processes certain browser and interaction signals to assess risk. No personal data is stored by us from reCAPTCHA. policies.google.com/privacy
-
Jitsi Meet (meet.jit.si) — Free video conferencing for remote service bookings. Unique room links are auto-generated per booking. We do not record or store video sessions. Jitsi Meet is an open-source service operated by 8x8, Inc. jitsi.org/meet-jit-si-privacy
-
Cloudflare — CDN and image delivery. Images are served via Cloudflare's network. Cloudflare may log request metadata for performance and security purposes. cloudflare.com/privacypolicy
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
5. Data Retention
- Active account data is retained for as long as your account exists.
- Booking and queue records are retained for 12 months after the service date for audit and dispute-resolution purposes, then deleted or anonymised.
- Deleted accounts have personal data removed within 30 days. Some anonymised aggregate records may be retained for statistical purposes.
- Security logs (IP addresses) are retained for 90 days.
- Marketing email suppression records (bounces, unsubscribes) are retained indefinitely to honour your preferences.
6. Your Rights
All Users
- Access — request a copy of personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request erasure of your data (subject to legal retention obligations)
- Objection to marketing — opt out of marketing emails at any time via account settings or the unsubscribe link in any email
EU / UK Users (GDPR)
- Portability — receive your data in a machine-readable format
- Restriction — request that we limit processing of your data in certain circumstances
- Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior processing
- Lodge a complaint — with your local supervisory authority (e.g. the ICO in the UK or your national DPA in the EU)
California Users (CCPA)
- Know — what categories of personal data we collect and why
- Delete — request deletion of personal data, subject to exceptions
- Non-discrimination — we will not discriminate against you for exercising your CCPA rights
- We do not sell personal information as defined by the CCPA
To exercise any of these rights, contact us via the contact page or email [email protected]. We will respond within 30 days.
7. Cookies
We use the following cookies:
-
Resvly_session — Session cookie required for authentication and CSRF protection. Essential — cannot be disabled.
-
XSRF-TOKEN — Cross-site request forgery protection. Essential — cannot be disabled.
-
app_theme, app_language, app_country, app_timezone — Stores your display preferences (dark/light mode, language, country, timezone). Functional — can be cleared via browser settings.
-
Google reCAPTCHA cookies — Set by Google on pages with bot-protection forms. These are third-party cookies governed by Google's privacy policy.
-
Google AdSense cookies (if enabled) — Set by Google for advertising purposes. You can opt out via google.com/settings/ads.
We do not use tracking or analytics cookies beyond what is listed above. You can manage cookies through your browser settings; disabling essential cookies will prevent you from logging in.
8. Walk-In Queue Kiosk
When you use a walk-in queue kiosk at a participating business, we collect your name, email address, and phone number to create your queue entry and send you position updates. If no Resvly account exists for your email address, one is created automatically. The lawful basis for this processing is the performance of the service you requested (joining the queue).
Your queue entry data is shared with the business whose kiosk you used (provider). It is not shared with other businesses or third parties. You may contact us to delete your account and associated queue history at any time.
9. Security
We implement industry-standard security measures including HTTPS encryption in transit, bcrypt password hashing, CSRF protection on all forms, and rate limiting on authentication endpoints. Access to production data is restricted to authorised personnel.
No system is completely secure. If you believe your account has been compromised, please contact us immediately.
10. Children's Privacy
The Platform is intended for users aged 16 and over (or 13 with parental consent). We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or via a notice on the Platform. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the Platform after changes are published constitutes acceptance of the updated policy.
12. Contact & Complaints
For privacy-related questions, data requests, or complaints, contact us at: [email protected]
or via our contact page.
If you are an EU resident and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your national Data Protection Authority. If you are based in Australia, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Effective Date:
This Privacy Policy is effective as of July 28, 2026.