BelioReservations
Legal

Privacy Policy

Last updated: 30 July 2026

This Privacy Policy explains how Belio Reservations ("Belio", "we", "us") collects, uses, stores, and protects personal data when you use our website, application, and related services. It is designed to meet the EU General Data Protection Regulation (GDPR), Spain's Organic Law 3/2018 (LOPDGDD), and applicable ePrivacy rules.

1. Data controller

The data controller for the Belio Reservations platform and marketing website is Belio Studio, operating the service at reservations.belio.studio.

Contact for privacy matters: info@belio.studio.

If you are in the European Economic Area or Spain, you may also lodge a complaint with your supervisory authority. In Spain, that is the Agencia Española de Protección de Datos (AEPD) — www.aepd.es.

2. Information we collect

Depending on how you use Belio, we may process:

  • Account data — name, email, password hash, phone, preferred language, and restaurant profile details.
  • Reservation & guest data — guest identity and contact details, booking date/time, party size, notes, allergies, special requests, visit history, and status changes entered by the restaurant or the guest.
  • Operational content — floor plans, tables, opening hours, menus (including PDF menus), gallery images, and settings.
  • Billing data — plan, subscription status, and Stripe customer/subscription identifiers. Full card numbers are processed by Stripe, not stored on Belio servers.
  • Technical data — IP address, browser/device information, approximate location derived from headers where used for phone-country defaults, timestamps, and security/rate-limit signals.
  • Communications — transactional emails (confirmations, reminders, password resets, invites) and support messages.
  • Cookies & similar tech — as described in our Cookie Policy. Analytics cookies run only with your prior consent.

3. Purposes and legal bases

  • Contract — providing the SaaS platform, accounts, bookings, billing, and support you request.
  • Legitimate interests — securing the service, preventing abuse, improving reliability, and basic product analytics that do not require non-essential cookies.
  • Legal obligation — accounting, tax, and responding to lawful requests.
  • Consent — non-essential analytics cookies (Google Tag Manager / measurement tags) and any optional communications that require consent. You may withdraw consent at any time via the cookie banner or our Cookie Policy, without affecting the lawfulness of prior processing.

4. Restaurant guest data (controller / processor)

When a restaurant uses Belio to manage guests and reservations, that restaurant typically acts as controller of guest personal data. Belio acts as a processor on the restaurant's documented instructions, to host and operate the booking tools.

Guests should contact the restaurant first to exercise rights over reservation data. Belio can assist restaurants and, where we are controller (e.g. our own marketing site or account data), will handle requests sent to info@belio.studio.

5. Recipients and subprocessors

We use specialised providers under contracts that require appropriate safeguards:

  • Neon — PostgreSQL database hosting (EU region where configured).
  • Netlify — application hosting and delivery.
  • Stripe — payments and subscriptions.
  • Resend — transactional email delivery.
  • Cloudflare — Turnstile bot protection on selected public forms.
  • Upstash — Redis-backed rate limiting.
  • Google — Tag Manager and analytics/measurement tags only when you have consented to analytics cookies.

We do not sell personal data. We may disclose data to professional advisers or authorities when required by law or to protect rights and security.

6. International transfers

Some providers may process data outside the EEA. Where that happens, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses, as required by the GDPR.

7. Retention

We keep data only as long as needed for the purposes above: while your account is active, for the lifetime of restaurant workspaces you manage, and thereafter for limited periods required for legal, security, or dispute-resolution reasons. Guest reservation retention may also follow the restaurant's instructions as controller.

8. Security

We apply technical and organisational measures appropriate to the risk (access controls, encryption in transit, hashed passwords, rate limiting, and bot protection on sensitive forms). No online service is perfectly secure; please use a strong unique password.

9. Your rights

Under the GDPR / LOPDGDD you may have the right to access, rectify, erase, restrict, object, and data portability, and not to be subject to solely automated decisions with legal effects (Belio does not make such decisions about you).

To exercise these rights regarding Belio as controller, email info@belio.studio. You may also complain to the AEPD or your local authority.

10. Cookies

Strictly necessary cookies and similar storage keep the service secure and usable. Analytics technologies load only after you opt in through our cookie banner. You can reject them with equal ease, customise categories, and change or withdraw your choice later via the cookie banner or our Cookie Policy.

11. Children

Belio is aimed at restaurants and adult guests making reservations. We do not knowingly collect personal data directly from children for our own purposes.

12. Changes

We may update this policy. The "Last updated" date will change when we do. Material changes affecting cookies will also be reflected in the consent banner version so you can review choices again if needed.

13. Contact

Privacy questions: info@belio.studio. Studio site: belio.studio.

Privacy Policy | Belio