Privacy Policy
Last updated July 28, 2026
1. Data we collect
We keep what we need to run the booking service for you:
- Account identity. When you sign in with Google (through Supabase Auth) or with email and password, we receive your email address (and, with Google, your name) to identify your account.
- Your Resy connection. The Resy token you provide so we can book on your behalf, plus a short-lived access token we cache from Resy. Both are encrypted at rest (see below).
- Your OpenTable connection. If you connect OpenTable, the sign-in tokens OpenTable issues after you enter the code it emails you, plus your OpenTable account identifier and the phone number saved on your OpenTable profile (OpenTable requires it to place a booking). The tokens are encrypted at rest like the Resy token.
- Booking configuration & history. The venues, dates, party sizes, time windows, and release times you set up, and a log of the booking attempts (“races”) we run for you.
- SevenRooms guest details. If you set up bookings at restaurants that use SevenRooms, the name and phone number you save for guest checkout there.
- Text-alert opt-in. If you opt in to SMS alerts, your consent and the time you gave it; alerts go to the phone number you saved.
- AI assistant connections (beta). If you connect an AI assistant through our connector, a record of that agent’s authorized access and the hashed credentials it uses. You can revoke an assistant from the dashboard at any time.
- Payment reference. A Stripe customer identifier and a reference to the card you saved. We do not store your card number — see “Payments” below.
2. Encryption of your platform tokens
Your Resy refresh token and cached access token, and your OpenTable tokens if you connect OpenTable, are encrypted at rest using AES-256-GCM, with the encryption bound to your account. These tokens are used only on our servers to talk to the reservation platforms; they are never sent to your browser and never written to logs.
3. The browser extension
You connect your Resy account through the SeatSwiper browser extension — it links your account in one click, and it is the only way to connect:
- When you click it, the extension reads your resy.com login cookie (the production_refresh_token) locally in your browser — only at that moment, and only on that site.
- It hands that token to your own signed-in SeatSwiper dashboard tab over a validated same-origin message; the dashboard stores it encrypted at rest as described above. Nothing else about how your data is handled changes.
- The extension itself stores nothing and logs nothing, and it never sends your token to any third party or to any server other than your SeatSwiper dashboard.
4. Payments — Stripe holds your card, not us
We use Stripe as our payment processor. When you save a card, it is collected and stored by Stripe (a PCI-compliant processor) — we never see or store your full card number. We keep only a Stripe customer id and a reference to the saved card so we can charge our service fees (the $5 fee when a booking succeeds, and the $1 fee to start a cancellation watch). Stripe’s handling of your card data is governed by Stripe’s own privacy policy.
5. Third parties we share data with
We rely on a small set of service providers to operate SeatSwiper. We share only what each needs to do its job:
- Supabase — authentication (Google or email/password sign-in) and the database where your account and booking data are stored.
- Stripe — payment processing and storage of your saved card for the service fee.
- Resy — the reservation platform we connect to on your behalf using the token you provide.
- SevenRooms — a second reservation platform. When we book an SR restaurant for you, SevenRooms receives your name, phone number, and email address to place the reservation as your guest checkout.
- OpenTable — a third reservation platform. When you connect it and we book an OpenTable restaurant for you, OpenTable sees the booking made on your own account using the tokens you authorized.
- Resend — delivers our transactional email (booking confirmations and updates, and messages you send to support), so it processes your email address and the reservation details in those messages.
- Twilio — delivers the optional SMS alerts you opt in to, so it processes your phone number and the alert text.
- PostHog — product analytics and session replay on our own site (served through our own domain), so we can see how the product is used and fix what is broken. It receives usage events tied to your account identifier, never your platform tokens or card details.
- Vercel — hosting for the web application.
- Railway — hosting for the background worker that runs your booking races.
We do not sell your personal data.
6. How long we keep it (retention)
We keep your account, platform connections, booking configuration, and race history for as long as your account is active so the service can function. You can remove a stored platform token at any time by disconnecting that platform, and you can delete your entire account and the data we hold at any time (see below). Some records may be retained by our processors (for example, Stripe’s record of a charge) as required for their legal, accounting, or fraud-prevention purposes.
7. Deleting your account & data
You can delete your account from within the app: open your account menu and choose Delete account. When you do, we:
- best-effort delete your customer record at Stripe, which removes the card you saved with them; and
- delete the data we hold — your encrypted platform tokens (Resy and OpenTable) and cached access tokens, your saved guest details, your booking configurations, your race history, and any AI assistant connections.
8. Security
We encrypt sensitive credentials at rest, keep secret tokens server-side, and restrict database access. No system is perfectly secure, but we aim to limit what we store and to protect what we do.
9. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above.
10. Contact
Questions about your privacy or a deletion request? Email support@seatswiper.com.
See also our Terms of Service.