Privacy Policy
Last updated: July 5, 2026
ReserveFlow is a business operating platform operated by Two Square Root (“ReserveFlow”, “we”, “us”). It lets restaurants and other businesses manage reservations, messaging, invoicing, inventory, and promotions — including through connected messaging channels (WhatsApp Business, Instagram, and Facebook Messenger). This policy explains what we collect, how we use it, and the choices you have.
1. Who this policy covers
- Business users — owners, managers, and staff who use the dashboard.
- Customers — people who message a connected business or book through it.
2. Information we collect
- Account & contact: business name, staff names, phone numbers, email, role.
- Messaging content: the messages exchanged with a business over WhatsApp, Instagram, or Messenger, plus sender identifiers provided by Meta (e.g. a page-scoped ID or phone number), timestamps, and delivery status — used only to operate the conversation.
- Reservations & operations: booking details (date, party size, notes), waitlist entries, table assignments.
- Invoicing: invoice/receipt images a business forwards or uploads, and the data extracted from them (supplier, amounts, VAT, dates).
- Technical: device/browser data, IP address, and log data for security and reliability.
3. How we use information
- To deliver the service — routing messages, managing bookings, and answering with our AI assistant.
- To send transactional notifications (e.g. booking confirmations, one-time verification codes).
- To provide analytics and reporting to the business that owns the data.
- To secure the platform, prevent abuse, and comply with legal obligations.
We do not sell personal data, and we do not use messaging content to build advertising profiles.
4. Platform data (Meta / WhatsApp, Instagram, Messenger)
When a business connects a Meta channel, we access only the data needed to send and receive that business’s messages, in accordance with the Meta Platform Terms and Developer Policies. Message content and identifiers are used solely to operate the conversation for that business and are retained per Section 6. We do not transfer this data to unauthorized third parties.
5. How we share information
We share data only with:
- The business that owns the conversation or record.
- Service providers under contract (cloud hosting, database, message delivery, and AI processing) who act on our instructions — including Meta (message delivery), our cloud infrastructure providers, and AI model providers used to read invoices and draft replies.
- Authorities when required by law.
6. Data retention
We keep data for as long as the business account is active and as needed to provide the service. Conversation data is retained to maintain history for the business; invoicing records may be kept to meet the business’s bookkeeping and tax-retention obligations. When data is no longer needed, or on a valid deletion request, we delete or anonymize it.
7. Your rights & deleting your data
You may request access to, correction of, or deletion of your personal data. To delete data associated with your messaging account, see our Data Deletion instructions, or email us at support@twosquareroot.com. Business customers can also have their entire workspace deleted on request.
8. Security
We protect data with encryption in transit, access controls, tenant isolation, and signed-request verification on all inbound platform webhooks. No system is perfectly secure, but we work to keep your data safe and to notify you of material incidents as required by law.
9. Children
The service is for businesses and their adult customers and is not directed to children under 16.
10. Changes & contact
We may update this policy; we’ll revise the date above and, for material changes, notify account owners. Questions or requests: support@twosquareroot.com.