BookingNinja

Privacy Policy

This privacy policy applies to LetsBookFor, the consumer booking experience powered by BookingNinja. Here's exactly how we handle your data.

Last updated: 27 February 2026

We never sell your data

Your personal information is never sold, traded, or shared for advertising purposes.

Delete your data anytime

Use our self-service form to remove your data instantly.

Payments are secure

Card details are handled entirely by Stripe. We never see or store your card number.

LetsBookFor is the consumer-facing booking experience provided by BookingNinja, a trading name of Never Board Limited (“we”, “us”, “our”), trading as BookingNinja.io. When you make a booking through a LetsBookFor page, you are using the BookingNinja platform. We provide an online booking management platform used by restaurants, venues, and hospitality businesses (“Venues”) to accept and manage reservations from their customers (“you”, “your”).

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC013830.

Our Data Protection Officer is Mr Daniel Nethersole, who can be contacted at dan@bookingninja.io.

When you make a booking through our platform, the Venue acts as the data controller for your personal data, and BookingNinja acts as the data processor on their behalf. For platform-level data (such as account information), BookingNinja is the data controller.

If you have questions about how your data is used, contact the Venue directly or reach our Data Protection Officer at dan@bookingninja.io.

2.1 Information you provide

CategoryExamples
IdentityFull name
ContactEmail address, phone number, postal address
Booking detailsDate, time, party size, special requests/comments, accessibility requirements
Health & dietaryAllergy and dietary information, pre-order preferences
PaymentPayment card details (processed by Stripe — we do not store card numbers), deposit and transaction amounts
AccountEmail, password (hashed), membership details (if you create a membership account with a Venue)
FeedbackRatings, reviews, and survey responses submitted after a visit
Marketing preferencesWhether you consent to receive marketing communications from a Venue
Custom fieldsAny additional information a Venue configures on their booking form (e.g. occasion, vehicle registration)

2.2 Information collected automatically

CategoryDetails
Device & browserIP address, browser type, operating system, screen resolution
Usage dataPages visited, booking flow interactions, timestamps
Local storageSession tokens, booking state, and authentication tokens stored in your browser to maintain your session

2.3 Information from third parties

If a Venue enables analytics or advertising tools on their booking page, those services may collect data independently under their own privacy policies. See Section 6 for details.

PurposeLegal basis (GDPR Art. 6)
Process and manage your bookingPerformance of a contract (Art. 6(1)(b))
Send booking confirmations, reminders, and updates via email or SMSPerformance of a contract
Process payments and depositsPerformance of a contract
Manage your membership account (if created)Performance of a contract
Send marketing communications on behalf of a VenueConsent (Art. 6(1)(a))
Record allergy and dietary requirements to ensure your safetyVital interests (Art. 6(1)(d)) / Explicit consent for special category data (Art. 9(2)(a))
Send push notifications about your bookingConsent
Collect post-visit feedback and ratingsLegitimate interest (Art. 6(1)(f))
Maintain customer records for the Venue (CRM)Legitimate interest of the Venue
Detect fraud and prevent misuseLegitimate interest
Comply with legal obligationsLegal obligation (Art. 6(1)(c))

Allergy and dietary information may constitute health data under GDPR. We process this data only when you voluntarily provide it during the booking process, and solely for the purpose of communicating your requirements to the Venue. This data is processed on the basis of your explicit consent (Art. 9(2)(a)).

We share your personal data only with:

  • The Venue you are booking with — they are the data controller and receive your booking details to fulfil your reservation.
  • Stripe (payment processor) — to securely process payments. Stripe is PCI DSS Level 1 certified and handles card data directly. We never store your full card number.
  • Twilio — to deliver SMS and WhatsApp booking notifications. Your phone number and message content are shared.
  • Email delivery providers (e.g. SendGrid, Mailgun, Amazon SES) — to send transactional and marketing emails on behalf of Venues.
  • Push notification services (Firebase Cloud Messaging) — to deliver push notifications if you have opted in.

If a Venue enables analytics on their booking page, data may also be shared with:

  • Google Analytics — anonymised usage statistics
  • Meta Pixel — conversion tracking for the Venue's advertising
  • Plausible Analytics — privacy-friendly usage statistics

These third-party services process data under their own privacy policies. We do not sell your personal data to any third party.

Service improvement measurements

Participating venues use temporary measurements of the purchase journey, such as displayed steps, unavailable choices, validation categories and payment outcomes. We do not collect entered form values, card details or recordings for these reports. A temporary identifier relates actions within one attempt at one venue; it does not create a profile across venues.

Attempts have a 24-hour conversion window. In the live analytics database, temporary events and their links to purchases are deleted after aggregation and within 25 hours of the attempt starting. Restricted operational backup copies follow the existing backup retention cycle and are not used for analytics reporting. Combined statistics are retained for 13 months and shown to BookingNinja and the venue, with small breakdowns hidden.

We use browser local storage and session storage to maintain your booking session and authentication state. These are essential for the service to function and do not require consent.

Where a Venue has enabled third-party analytics (Google Analytics, Meta Pixel), those services may set their own cookies. These are governed by the Venue's cookie policy and the respective third-party privacy policies.

Some of our sub-processors (Stripe, Twilio, Google, Meta) may process data outside the European Economic Area (EEA). Where this occurs, transfers are protected by:

  • EU-U.S. Data Privacy Framework (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions of the European Commission

We retain your personal data for as long as necessary to fulfil the purposes described in this policy:

  • Booking data — retained for as long as the Venue requires for operational and legal purposes (typically up to 7 years for financial records).
  • CRM records — retained until you request erasure or the Venue deletes the record.
  • Membership accounts — retained until you or the Venue deletes the account.
  • Marketing data — retained until you withdraw consent (unsubscribe).

You can request erasure of your personal data at any time using the data removal tool below.

Under the GDPR and UK GDPR, you have the following rights:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — request correction of inaccurate data.
  • Right to erasure (Art. 17) — request deletion of your personal data. You can exercise this right directly using our self-service tool below.
  • Right to restrict processing (Art. 18) — request that we limit how your data is used.
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interest or for direct marketing.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time. For marketing, use the unsubscribe link in any email.

To exercise any of these rights, contact us at dan@bookingninja.io or use the data removal tool below for erasure requests.

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS)
  • Hashed passwords (never stored in plain text)
  • PCI DSS compliant payment processing via Stripe
  • Role-based access controls for Venue staff
  • Regular security reviews and monitoring

Our service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

We may update this privacy policy from time to time. The “Last updated” date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically.

If you are unsatisfied with how we handle your data, please contact our Data Protection Officer in the first instance. You also have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. Our ICO registration number is ZC013830.

For any privacy-related enquiries, contact our Data Protection Officer:

  • Data Protection Officer: Mr Daniel Nethersole
  • Company: Never Board Limited (trading as BookingNinja.io)
  • Email: dan@bookingninja.io
  • ICO Registration: ZC013830
Data Removal

Want to remove your data?

You can request the removal of your personal data from all venues using our self-service tool. It only takes a minute.

Powered by BookingNinja