Politique de confidentialité

Last updated: August 16, 2026

This Privacy Policy explains how UPSALT, a French simplified joint-stock company (SAS) ("Upsalt", "we", "us") collects, uses, and protects personal data when you use the Upsalt booking and reservation-management platform — including app.upsalt.io (guest booking), admin.upsalt.io (business backoffice), and our public API and AI-agent (MCP) endpoints.

Upsalt is registered at 50 Boulevard Stalingrad, 06300 Nice, France, SIRET 994 024 362 00018 (RCS Nice). For any question about this policy, contact info@upsalt.io.

1. Who this policy applies to

Upsalt serves two kinds of users, and we collect different data for each:

  • Businesses — restaurants and other venues that create an account on our backoffice to manage reservations, floorplans, staff, and payments.
  • Guests — people who book a table, order via Click & Collect, or otherwise interact with a business through Upsalt, without holding an Upsalt account themselves.

2. What we collect

2.1 Business accounts

  • Name, email, phone number, and password (stored as a salted hash, never in plain text).
  • Two-factor authentication secrets and recovery codes, if enabled.
  • Business details: name, address, business type, opening hours, floorplan, uploaded images/logos.
  • Stripe Connect account identifiers, used to route payments and payouts to the business (we do not store card details — see §4).

2.2 Guests

  • First name, last name, email address, phone number.
  • Booking details: date, time, party size and composition (adults, children, babies, pets), any special requests you leave for the business.
  • Dietary and allergy information (vegan, vegetarian, gluten-free, nut allergy) — provided voluntarily so the business can accommodate your needs. Under GDPR this can qualify as special-category data; we only collect it with your explicit action of entering it, and only use it to fulfil your reservation.
  • Approximate location (latitude/longitude), city and country, and IP address — used for fraud prevention and to pre-fill the venue search; IP addresses are resolved to a general location via a third-party IP-lookup service (see §5).
  • Marketing opt-in preference, if you choose to provide it.
  • Loyalty/visit history maintained by the business you book with: number of visits, no-shows, VIP status.
  • Click & Collect: order history, promo code usage, and loyalty credit balance, tied to your email/phone.

2.3 Payments

Card and bank details are entered directly into Stripe's own hosted forms or embedded components and never pass through or are stored on Upsalt's servers. We only receive and store payment metadata: amount, status, and Stripe's own reference identifiers.

3. AI agent bookings

Upsalt operates a public Model Context Protocol (MCP) server that lets AI assistants (e.g. Claude, ChatGPT) search for a venue and create a booking on a guest's behalf, using the same booking flow and data fields as our website. If you (or someone booking for you) uses an AI agent to make a reservation through Upsalt, the information you give that agent — name, contact details, party details, dietary needs — is submitted to us and processed exactly as described in this policy. We recommend reviewing what an AI agent sends before it confirms a booking on your behalf. See our MCP server documentation for technical details.

4. Why we process this data

PurposeLegal basis
Creating, confirming, and managing a reservation or orderPerformance of a contract
Processing payments and deposits via StripePerformance of a contract
Accommodating dietary/allergy needsExplicit consent (you providing the information)
Sending booking confirmations, reminders, and service messages (email/WhatsApp)Performance of a contract / legitimate interest
Marketing communicationsConsent (opt-in)
Fraud prevention, spam and abuse protection (reCAPTCHA, IP checks, upload scanning)Legitimate interest
Maintaining loyalty history and business analyticsLegitimate interest of the business you book with
Complying with legal and tax obligationsLegal obligation

5. Who we share data with

We use the following processors to operate the service. None of them are permitted to use your data for their own purposes.

ProviderPurpose
StripePayment processing and payouts to businesses (Stripe Connect)
Meta (WhatsApp Business Cloud API)Sending booking notifications via WhatsApp, where enabled
BrevoSending transactional emails (confirmations, resets, notifications)
Cloudflare (R2 storage)Storing uploaded images, logos, and floorplan files
Google reCAPTCHADistinguishing human visitors from bots on public forms
OVHWeb application hosting

The business you book with also sees your reservation and guest details in its own backoffice — it acts as an independent data controller for the way it uses that information (e.g. its own marketing lists), and you may need to contact that business directly for requests specific to their use of your data.

6. International data transfers

Some of the providers listed in §5 may process data outside the European Economic Area (e.g. Stripe, Meta, Google). Where this happens, we rely on the provider's Standard Contractual Clauses or an equivalent safeguard recognized under GDPR.

7. How long we keep your data

  • Guest booking data is retained for as long as needed to service the reservation and for a reasonable period afterward for support, dispute, and legal/tax purposes, then deleted or anonymized.
  • Business account data is retained for the life of the account and for the period required by applicable accounting/tax law after closure.
  • You can ask us or the business you booked with to delete your data sooner, subject to §8 below.

8. Your rights

Under GDPR (and equivalent laws where applicable), you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request erasure ("right to be forgotten"), subject to legal retention requirements.
  • Object to or restrict certain processing, including marketing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your national data protection authority (in France, the CNIL).

To exercise any of these rights, contact info@upsalt.io.

9. Security

We use encryption in transit (HTTPS), hashed passwords, and access controls scoped per business account. No system is completely secure; if we become aware of a data breach affecting your personal data, we will notify affected users and the relevant authority as required by law.

10. Cookies

We use only the cookies strictly necessary to operate the service: a session cookie to keep you signed in, and a CSRF-protection token. We do not use third-party advertising or analytics cookies.

11. Children

Upsalt is not directed at children, and we do not knowingly collect personal data from children under 16.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

13. Contact

Questions or requests regarding this policy: info@upsalt.io.

See also our Terms of Service.