HENDRA ONE PRIVACY

Privacy policy

This website

Hendra One is the trading name of Hendra Group Limited, registered in England & Wales. This site is an information site: it sets no marketing or analytics cookies and collects no personal data while you browse. If you email us to book a demo, we use your details only to reply, and delete them if things go no further.

If you're a guest of a venue that runs on Hendra One

Each venue is the data controller for its guests; Hendra One processes bookings on the venue's behalf under a Data Processing & Service Level Agreement. Every booking page links its venue's privacy policy. Where a venue hasn't published its own, the standard policy below applies, it is the same text shown on their booking pages.

If you work for one of our client venues

Your employer is the controller of your staff account, rota, holiday and compliance records; Hendra One processes them on your employer's instructions. Ask your Head Office for their staff privacy notice.


THE STANDARD GUEST POLICY

The venue is the data controller for personal information collected through this booking page. This policy explains what is collected, why, and your rights. It applies unless the venue has published its own policy.

What we collect

  • Booking details: your name, phone number, email address, party size, date and time, and any special requests you add.
  • Waitlist details: name, phone number and (optionally) email, if you join a waitlist.
  • Pre-order details: names and menu choices (and optionally email/phone) for each member of your party, if the venue sends you a pre-order link.
  • Feedback and reviews: a rating and any comments you choose to leave after a visit.
  • Marketing preference: whether you ticked the box to receive news and offers. It is never ticked for you.
  • Card details for no-show protection: only if the venue asks you to secure a booking with a card. Card numbers are entered on and stored by Stripe, our payment provider; they never touch this site's servers. Any cancellation or no-show fee is disclosed before you add a card.

Why we use it

  • To provide your booking (contract): confirmations, reminders, waitlist and pre-order emails about a booking you made.
  • To run the venue well (legitimate interests): visit history, follow-up "how was your visit?" and review-request emails after you dine. Every such email contains an unsubscribe link, and one click stops them all.
  • Marketing (consent): news and offers are sent only if you opted in, and every email has an unsubscribe link. We measure whether marketing emails are delivered and opened so the venue can tell what's working.

Who processes it for us

  • Google Cloud / Firebase: secure hosting and database for the booking system.
  • Resend: delivers our emails and reports delivery, open and click events back to us.
  • Stripe: payments, deposits and card storage for no-show protection.
  • Google reCAPTCHA: protects the booking page from bots and abuse; Google's privacy policy applies.

These providers act only on our instructions. We never sell your data.

Where your data is held

Our booking database and the servers that run it are operated by Google Cloud in the United States, and the email and payment providers above also process data there. That means your details are transferred outside the UK. Those transfers are covered by the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise by the UK International Data Transfer Agreement or Addendum, which are the safeguards UK law recognises for keeping your rights with the data. Card details themselves are held by Stripe, not by us.

Cookies and similar technologies

This booking page sets no advertising or analytics cookies, and nothing that tracks you across other sites, which is why you won't see a cookie banner. The only storage used is strictly necessary: keeping your booking session working, and Google reCAPTCHA's anti-abuse checks (which may set a cookie governed by Google's privacy policy) to protect the page from bots.

How long we keep it

Only as long as needed. Waitlist entries are removed once the date has passed, and booking records are anonymised after the venue's retention period. Stored cards are removed shortly after your visit.

Your rights

You can ask for a copy of the personal data held about you, ask for it to be corrected, or ask for it to be erased, contact the venue directly and they can action all three. You can stop marketing and follow-up emails at any time with the unsubscribe link in any email. If you're unhappy with how your data has been handled, you can complain to the Information Commissioner's Office (ICO).


Venues: a client-ready Word version of this policy (with placeholders for your company details) is available to download, Guest Privacy Policy template (.docx).