Guestro policies

Privacy, cookies and platform terms.

These policies explain how Guestro Limited operates its platform, handles personal information, uses cookies and similar technologies, and provides services to business customers.

Privacy Notice

Guestro Limited · Company number 17392688 · Last updated: August 2026

This Privacy Notice explains how Guestro Limited ("Guestro", "we", "us" or "our") collects, uses, stores and shares personal information in connection with the Guestro platform, websites, booking services, management and staff applications, customer support, communications, integrations and related services.

Who we are

Guestro Limited is a UK hospitality software company providing technology for pubs, restaurants and other hospitality businesses. Depending on the activity, Guestro may act as a data controller or as a processor acting on the instructions of a hospitality business.

Guestro Limited, company number 17392688. Privacy contact: privacy@guestro.co.uk.

Where a venue uses Guestro to manage its own customers, employees or operations, that venue may be the controller of some or all of the relevant personal information. Its own privacy notice may apply alongside this notice.

When this notice applies

  • When you make, amend or manage a booking using Guestro.
  • When you receive booking confirmations, reminders or service communications sent using Guestro.
  • When you use a Guestro staff, management or authorised-user account.
  • When you work for, manage or represent a Guestro client.
  • When you contact Guestro for support, sales or another enquiry.
  • When you visit a Guestro website or use another Guestro service.
  • When you interact with a third-party service that a venue has connected to Guestro.

Information we may process

Booking and customer dataName, email address, phone number, booking date and time, party size, booking type, pre-orders, special requests, preferences and booking history.
Allergy and dietary dataOptional allergy or dietary information supplied for a booking or pre-order. This may reveal health, religious or other special-category information.
Account and identity dataName, email, phone number, account identifiers, organisation or venue memberships, role, permissions, account status and authentication information.
Workforce dataEmployee details, venue memberships, rotas, shifts, availability, leave, attendance or timesheet information and operational notes where those features are used.
Business and operational dataOpening times, table or room configuration, menus, stock, sales, reports, supplier or operational records and venue configuration.
Transaction and integration dataOrders, items purchased, transaction values, payment status, till or EPOS identifiers and related operational information received from Guestro modules or enabled integrations.
Security and technical dataLogin and security events, MFA status, audit records, IP address, device and browser information, timestamps, diagnostic information, application activity and service logs.
CommunicationsSupport enquiries, correspondence, feedback, booking messages and information provided when contacting Guestro or communicating through supported Guestro features.

Where information comes from

  • Directly from you, for example when you make a booking, create an account or contact support.
  • From a Guestro client such as a restaurant, pub, hotel or other hospitality business.
  • Automatically when you use Guestro services, including security, device, browser, IP address, usage and diagnostic information.
  • From enabled integrations and third-party services, such as EPOS/till systems, payment providers, email or SMS providers, or other operational systems.
  • From another person where they legitimately provide information relating to you, for example where a person makes a booking for a group.

Required and optional information

Some information is necessary to provide a service. For example, a venue may need a name and a means of contact to create and administer a booking, and an authorised user may need account information to access Guestro. Allergy, dietary, accessibility and special-request information is optional and should only be provided where relevant.

Why we use personal information

We process personal information only where there is an appropriate purpose and lawful basis. The exact basis depends on the activity and on whether Guestro or a client venue is acting as controller. Typical lawful bases include contract, legitimate interests, legal obligation, consent where specifically required, and processing on a client's documented instructions.

Allergy, dietary and other sensitive information

Allergy and dietary fields are optional. Information entered into them may reveal health information, religious beliefs or other special-category information. Where explicit consent is the appropriate condition for processing special-category information, the relevant interface should obtain that consent before submission. We do not use allergy or dietary information for advertising.

Electronic communications

Guestro and Guestro clients may use the platform to send operational communications by email, SMS, push notification or other supported channels, including booking confirmations, reminders, cancellation notices, account invitations, password or security messages, rota or shift updates, receipts and support communications. Operational messages are different from marketing communications.

Guestro does not currently use booking information for its own direct marketing. If this changes, this notice and the relevant interfaces will be updated and any required consent, preference or opt-out controls will be implemented.

Integrations, EPOS and transaction information

A Guestro client may connect Guestro to third-party systems such as EPOS, payment, accounting, messaging or other hospitality systems. Where enabled, Guestro may exchange information reasonably necessary to provide that integration. Third-party providers may also act as independent controllers and their own privacy notices may apply.

Who we share information with

We may share personal information with the hospitality business to which a booking or account relates; authorised users within the relevant organisation; hosting, cloud, email, SMS, security, monitoring, support, payment and integration providers; professional advisers; regulators or public authorities where required; and a buyer or successor in connection with a legitimate corporate transaction. We do not sell personal information to advertisers.

Retention and anonymisation

Booking identity/contact information and special requestsConfigured to be scrubbed or anonymised from completed historical bookings after approximately one month, subject to the applicable venue configuration and lawful requirements.
Allergy/dietary informationConfigured for shorter retention and, where operationally appropriate, deletion or scrubbing approximately one week after it is no longer needed for the booking.
Anonymised operational statisticsMay be retained for reporting where they no longer identify an individual.
Account/workforce informationRetained while required to provide the service and thereafter only as necessary for operational, security, legal or contractual purposes.
Security/audit recordsRetained for a proportionate period based on security, investigation and accountability needs.
BackupsRetained according to Guestro's backup retention schedule and deleted when they expire.

International transfers

Some service providers may process information outside the UK. Where UK data-protection law requires safeguards, Guestro will use an applicable adequacy arrangement or appropriate contractual and supplementary safeguards. Details can be requested from privacy@guestro.co.uk.

Security

Guestro uses appropriate technical and organisational measures designed to protect personal information. Current measures include HTTPS, authentication controls, MFA for relevant access, role and permission controls, venue isolation, encrypted infrastructure and backups where configured, restricted AWS IAM permissions, secrets management, audit/security logging, retention/anonymisation jobs, backup controls, container hardening and monitoring.

Cookies, third-party links and children

Guestro may use cookies or similar technologies that are necessary for authentication, security, preferences and operation. Guestro services may link to third-party websites or services. Business management accounts are not intended to be created independently by children, although bookings may include children and some clients may lawfully employ young people.

Your rights and complaints

Depending on the circumstances and lawful basis, you may have rights to request access, correction, erasure, restriction, portability, to object to certain processing, and to withdraw consent where processing relies on consent. To exercise rights relating to Guestro-controlled processing, contact privacy@guestro.co.uk. You may also complain to the Information Commissioner's Office.

Automated decision-making and AI

Guestro does not currently make solely automated decisions about individuals that produce legal or similarly significant effects. If Guestro introduces AI or automated-decision features that materially affect personal information, we will assess the processing and provide required information, choices or safeguards.

Contact

Privacy: privacy@guestro.co.uk. Support: support@guestro.co.uk.

Platform Terms and Conditions

Guestro Limited · Company number 17392688 · Last updated: August 2026 · Draft for business clients

These Terms and Conditions govern a hospitality business's subscription to and use of the Guestro platform. They are intended primarily for business-to-business use. Venue-specific booking terms shown to consumers should be separate and should identify the venue as the contracting hospitality business where appropriate.

About Guestro and the agreement

Guestro Limited provides cloud-based hospitality software and related services. These terms, together with any order form, subscription confirmation, service schedule, data processing agreement and incorporated document, form the agreement between Guestro and the business customer. If an order form conflicts with these terms, the order form takes priority for the conflicting commercial term unless it states otherwise.

Services

The services may include booking and table management, management and staff portals, workforce and rota functionality, notifications, reporting, integrations and other modules made available by Guestro. Features may vary by subscription, venue and release.

Accounts and authorised users

  • Customers are responsible for accurate account information and authorised-user access.
  • Users must keep credentials confidential and must not share accounts unless Guestro expressly supports shared identities.
  • Multi-factor authentication or other security controls may be mandatory.
  • Customers must promptly remove or suspend access for people who no longer require it.
  • Customers are responsible for account activity except to the extent caused by Guestro's breach or security failure.

Acceptable use

Customers and users must not use Guestro unlawfully, infringe rights, bypass authentication or tenant isolation, probe or test security without permission, introduce malware, deliberately interfere with the service, reverse engineer or copy the service except where law permits it, store content they have no lawful right to process, or resell Guestro except as agreed in writing.

Customer responsibilities and booking terms

Customers remain responsible for hospitality operations and for the accuracy and lawfulness of information entered into Guestro, including opening hours, availability, capacity, tables or rooms, booking rules, menus, staff access and operational settings. Where Guestro provides a booking interface, the venue should maintain customer-facing booking terms covering deposits, cancellation and no-show rules, lateness, table duration, age restrictions, accessibility, pre-orders and venue-specific policies.

Fees, term, support and availability

Fees, billing frequency, modules, usage allowances and implementation charges will be stated in the applicable order form or subscription confirmation. Unless stated otherwise, fees are exclusive of VAT and applicable taxes. Subscription term, renewal, cancellation and notice periods are set out in the order form. Guestro aims to provide a reliable service but does not promise uninterrupted availability unless a specific service level is agreed in writing.

Integrations and third-party services

Guestro may integrate with EPOS, payment, email, SMS, cloud, accounting or other providers. Third-party services are governed by their own terms and may change, restrict or discontinue their APIs or services. Customers authorise Guestro to exchange information reasonably required to provide enabled integrations.

Data protection and security

Each party must comply with applicable data-protection law. The controller/processor roles depend on the processing activity. Where Guestro processes personal information on the Customer's documented instructions as processor, the parties should enter into or incorporate an appropriate Data Processing Agreement. Guestro will maintain appropriate technical and organisational security measures proportionate to the service and information processed.

Confidentiality and intellectual property

Each party must keep the other's confidential information confidential and use it only to perform or receive the services, except where disclosure is authorised or required by law. Guestro and its licensors retain ownership of Guestro software, branding, documentation, designs and platform intellectual property. Customers retain ownership of their own data, content, menus, branding and materials supplied to Guestro.

Suspension, warranties and liability

Guestro may suspend affected access where reasonably necessary to address a serious security risk, unlawful use, material breach, non-payment of undisputed fees, or a threat to the platform or other customers. Guestro will provide the services with reasonable care and skill. Neither party excludes liability where it would be unlawful to do so. Commercial liability caps and exclusions should be set in the signed order form or final lawyer-reviewed terms.

Other terms

Neither party is responsible for delay or failure caused by circumstances beyond its reasonable control. Guestro may update these terms to reflect legal, security, technical or product changes. Contract notices may be sent to the contact details specified in the order form or account. Unless an order form states otherwise, the agreement is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction.

Contact

Sales: sales@guestro.co.uk. Enquiries: enquiries@guestro.co.uk. Support: support@guestro.co.uk. Privacy: privacy@guestro.co.uk. Automated service emails may come from noreply@guestro.co.uk.