Riserva Back to site
Legal

Privacy policy

Last updated 14 August 2026. This policy covers the Riserva app for Shopify and the riservahq.com website.

Who we are

Riserva™ is a reservation and hospitality app for Shopify merchants, operated by Whatever DTC LLC, 1030 Topsail Drive, Vallejo, CA 94591, United States. For anything in this policy, write to privacy@riservahq.com.

When a winery installs Riserva, the winery is the controller of its guests' personal information and Riserva is its processor: we handle that information to provide the service, on the winery's instructions.

What we collect

From Shopify's APIs, once a merchant installs the app. Store details and settings; staff name and user id, so actions in the app can be attributed to the person who took them; products and variants the app itself creates for each bookable experience; and orders, line items and refunds relating to those reservations, so the app knows what has been paid.

Customer information, where the merchant has enabled it. Guest name, email address, phone number and the customer tags used to recognise club members. We do not request customer addresses.

From guests, when they book. The details they enter in the booking window: name, email, phone, party size, date and time, special requests, and answers to any questions the merchant chose to ask.

From the merchant directly. Account and contact details, venue and experience configuration, images they upload, and any keys they paste in to connect another service.

Riserva never sees or stores payment card numbers. Payments run through Shopify's checkout and point of sale.

How we use it

To take and manage reservations; to show staff the day's list and check guests in; to apply the merchant's cancellation and refund policies; to send guests the confirmation, reminder and cancellation emails the merchant has switched on; to recognise members; to produce the merchant's own reports; and to support and secure the service.

We do not sell personal information, and we do not use a merchant's guest data to advertise to those guests or to train models.

Who it is shared with

Only the providers needed to run the service:

Shopify — the platform the app runs on and where orders and customers live.
Fly.io — application hosting and the managed database, in San Jose, California (United States).
Resend — delivery of the transactional emails sent to guests and staff.
Klaviyo and Awtomic — only if the merchant connects them. Reservation events are then sent to the account the merchant nominates, under that provider's own privacy terms.

We may also disclose information where the law requires it, or to protect the service against fraud and abuse.

Where it is processed

Riserva stores and processes data in the United States (San Jose, California). If a merchant or their guests are in a region with transfer restrictions, that information is transferred under the safeguards those rules require.

How long it is kept, and how it is deleted

Reservation records are kept while the app is installed, because they are the merchant's own operating history and reporting.

When a winery uninstalls Riserva, we delete their data — reservations, guests, settings and activity records — within 30 days. Shorter-lived working records go sooner: unconverted booking holds are cleared within 24 hours of expiring, and the receipts we keep to stop duplicate order processing are removed once they can no longer serve that purpose. We do not keep guest details for any period beyond the merchant relationship they belong to.

Riserva implements the privacy requests Shopify forwards. When a merchant erases a customer, we remove that guest's name, email, phone, special requests and question answers from their reservations, and scrub those details from the associated activity records — the reservation itself remains as an anonymous entry so the merchant's counts and revenue history stay intact. When a store is erased or uninstalls, we delete that store's data from our systems.

Backups are overwritten on a rolling basis, so deleted records can persist in backups for a short period after removal.

Rights and requests

Depending on where they live, guests may have the right to access, correct, delete or port their information, or to object to its use. Because the winery is the controller of its guest data, guests should contact the winery they booked with, which can raise the request through Shopify. If a request reaches us directly, we will pass it to the merchant and help them answer it.

Merchants can reach us at privacy@riservahq.com.

Cookies

The Riserva admin uses the session cookies needed to keep a merchant signed in inside Shopify. The booking window stores a short-lived reference so a guest's selection survives the trip to checkout. This website uses no analytics or advertising cookies; it does load fonts from Google Fonts, which means Google receives the request for those files.

Changes

If this policy changes we will update the date at the top of this page, and tell merchants directly when the change is material.