Privacy Policy
Last updated July 2, 2026
1. Data we collect
We keep what we need to run the booking service for you:
- Account identity. When you sign in with Google (through Supabase Auth), we receive your email address and name to identify your account.
- Your Resy connection. The Resy token you provide so we can book on your behalf, plus a short-lived access token we cache from Resy. Both are encrypted at rest (see below).
- Booking configuration & history. The venues, dates, party sizes, time windows, and release times you set up, and a log of the booking attempts (“races”) we run for you.
- SevenRooms guest details. If you set up bookings at restaurants that use SevenRooms, the name and phone number you save for guest checkout there.
- Payment reference. A Stripe customer identifier and a reference to the card you saved. We do not store your card number — see “Payments” below.
2. Encryption of your Resy token
Your Resy refresh token and the cached Resy access token are encrypted at rest using AES-256-GCM, with the encryption bound to your account. These tokens are used only on our servers to talk to Resy; they are never sent to your browser and never written to logs.
3. The browser extension
You connect your Resy account through the SeatSwiper browser extension — it links your account in one click, and it is the only way to connect:
- When you click it, the extension reads your resy.com login cookie (the production_refresh_token) locally in your browser — only at that moment, and only on that site.
- It hands that token to your own signed-in SeatSwiper dashboard tab over a validated same-origin message; the dashboard stores it encrypted at rest as described above. Nothing else about how your data is handled changes.
- The extension itself stores nothing and logs nothing, and it never sends your token to any third party or to any server other than your SeatSwiper dashboard.
4. Payments — Stripe holds your card, not us
We use Stripe as our payment processor. When you save a card, it is collected and stored by Stripe (a PCI-compliant processor) — we never see or store your full card number. We keep only a Stripe customer id and a reference to the saved card so we can charge our service fees (the $5 fee when a booking succeeds, and the $1 fee to start a cancellation watch). Stripe’s handling of your card data is governed by Stripe’s own privacy policy.
5. Third parties we share data with
We rely on a small set of service providers to operate SeatSwiper. We share only what each needs to do its job:
- Supabase — authentication (Google sign-in) and the database where your account and booking data are stored.
- Stripe — payment processing and storage of your saved card for the service fee.
- Resy — the reservation platform we connect to on your behalf using the token you provide.
- SevenRooms — a second reservation platform. When we book an SR restaurant for you, SevenRooms receives your name, phone number, and email address to place the reservation as your guest checkout.
- Resend — delivers our transactional email (booking confirmations and updates, and messages you send to support), so it processes your email address and the reservation details in those messages.
- Vercel — hosting for the web application.
- Railway — hosting for the background worker that runs your booking races.
We do not sell your personal data.
6. How long we keep it (retention)
We keep your account, Resy connection, booking configuration, and race history for as long as your account is active so the service can function. You can remove your stored Resy token at any time by disconnecting your Resy account, and you can delete your entire account and the data we hold at any time (see below). Some records may be retained by our processors (for example, Stripe’s record of a charge) as required for their legal, accounting, or fraud-prevention purposes.
7. Deleting your account & data
You can delete your account from within the app: open your account menu and choose Delete account. When you do, we:
- best-effort delete your customer record at Stripe, which removes the card you saved with them; and
- delete the data we hold — your encrypted Resy token and cached access token, your booking configurations, and your race history.
8. Security
We encrypt sensitive credentials at rest, keep secret tokens server-side, and restrict database access. No system is perfectly secure, but we aim to limit what we store and to protect what we do.
9. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above.
10. Contact
Questions about your privacy or a deletion request? Email support@seatswiper.com.
See also our Terms of Service.