Privacy and guest data
What Noctessa holds about your guests, how long it is kept, how to erase one guest's details when they ask, and what the privacy pages on your site are for.
This page explains how the product behaves. It is not legal advice — if you need to know exactly what your obligations are where you trade, ask a lawyer.
What is held about a guest
When somebody sends a reservation request from your site, you get:
- their name
- a phone number, an email address, or both — they must give at least one
- how many people are coming
- what they booked into, and the table they were given
- a note, if they wrote one
- whether they ticked the box agreeing to your privacy notice, and which version of that notice was showing at the time
If the guest's booking is confirmed and they gave an email address, they also get an e-ticket, and the ticket is recorded against their reservation so the door can check it.
If you take payment before arrival, the amount, the time it was taken and your payment processor's reference are recorded against the reservation too. The card itself never reaches Noctessa — it stays with your payment processor.
Nothing else about the guest is collected. There is no follower data, no browsing profile, no marketing list built in the background.
Where you can see it
- Reservations — the full list, with guest, party, contact and status.
- Floor plan — pick a table and you see who is on it.
- Activity log — a record of what your staff did in the panel, newest first.
Reservations also has an Export CSV button. Once a guest list is on somebody's laptop it is out of Noctessa and out of your control, so treat those files the way you would treat a printed guest list: keep them somewhere sensible and delete them when the service is over.
The privacy page on your site
Your public site has a privacy page. It is linked directly from the reservation form — the guest ticks a box that says they agree to your venue storing their details, and privacy notice in that sentence is the link.
The page tells guests what is collected, how long it is kept, and how to ask for it to be deleted. If no wording has been written for your venue, a sensible default is shown instead.
The version currently in force appears in Venue settings, in the Operational settings panel, as Privacy version. Every reservation stamps the version that was showing when the guest agreed, so if the wording changes later, older bookings still show what that guest actually agreed to.
The wording and the version are set up for you. To change either, ask the Noctessa team.
Noctessa's own privacy and deletion pages
Noctessa's own site carries two more pages, and they are a different document from yours:
- a privacy policy covering what the platform itself handles — your admin accounts, the reservations it processes on your behalf, and the social accounts you connect
- a data deletion page explaining how a venue or a guest asks for data to be erased
Those two describe Noctessa the service. Your page describes your venue. Both exist because guests and Facebook both need somewhere to look — you do not need to maintain the Noctessa ones.
How long guest details are kept
The default is 90 days afterwards. After that, the guest's name, phone, email and note on a past reservation are blanked out — the name is replaced with a placeholder, the rest is cleared.
The booking itself stays. Party size, which table, which date — those survive, so your history of how the room filled stays intact. Only the details that identify a person go.
The clearing period is agreed with the Noctessa team when your venue is set up. If you have a legal obligation to a specific retention period, confirm yours with them rather than assuming the default.
If a guest asks you to erase their details sooner, do not wait for the period to pass — use the erasure tool described below, which takes effect immediately.
Erasing one guest's details when they ask
A guest can ask you to delete their details at any time. Here is how.
- Open Venue settings.
- Scroll to Erase guest data.
- Type the guest's Guest email, their Guest phone, or both. You need at least one. Use whichever they actually booked with — a guest who only ever left a phone number will not be found by email.
- Press Anonymize data.
- Read the confirmation and confirm it.
You will see a message telling you how many reservations were cleared. If it says none were found, check the spelling, and check whether they booked with the other contact detail.
This cannot be undone. There is no restore button and no bin to fish it out of.
What it does
It clears that guest's name, phone, email and note from every reservation they ever made at your venue — past and upcoming, not just the one they complained about.
What it does not do
- It does not delete the booking. If they are coming this Friday, the table is still held; you just no longer have a name to call out. If you want the booking gone as well, delete it from Reservations using Delete reservation — that removes the reservation and frees its table.
- It does not reach any other venue. Erasing at your venue affects only your venue.
- It does not chase copies you made yourself. A CSV you exported, an email in your own inbox, a name written on a clipboard at the door — those are yours to deal with.
It is written down
The erasure is recorded in your Activity log: who did it, when, and how many reservations were affected. The guest's actual details are never written into that record — recording them would put back exactly what you just removed. So you have proof you acted on the request without keeping the data you erased.
Your staff's own data
Every person you invite in Staff has a name, an email address and a role. Passwords are never stored in a readable form, and nobody at Noctessa can read one back to you — a forgotten password is replaced with a fresh link, never recovered.
When somebody leaves, remove their account the same day. Open Staff, find the person and choose Remove. Access ends immediately, and the change is written to your audit log. You cannot remove yourself — ask another admin to do it for you.
If something looks wrong
- The privacy page on your site shows wording you did not write. No notice has been written for your venue yet, so the built-in default is showing. Ask the Noctessa team to put your own wording in.
- A guest says they asked to be deleted and their name is still there. Check you used the contact detail they actually booked with. If they booked with a phone and you searched by email, nothing matched.
- You erased the wrong guest. It cannot be reversed. If they book again, the new booking carries fresh details as normal.
- A guest wants a copy of what you hold, not a deletion. Everything you hold on them is on their reservation in Reservations. There is no automatic export for one guest — read it off the reservation and reply to them yourself.
- A guest asks Noctessa directly instead of you. They will be pointed back to you, because the guest list is yours. Their request still counts from the day they made it, so act on it.
Still stuck? Email info@noctessa.com and we will help.