Privacy policy
Last updated 3 October 2026
Bordo is a service that lets restaurants take bookings and requests through a form on their own website. This page says what is stored, why, for how long, and what you can do about it.
If you book with a restaurant
When you book a table or send a request, the restaurant is responsible for your details. We store them on the restaurant’s behalf and use them for nothing else.
What is stored is your name, your email address, your phone number if you give one, the date, the time, the number of guests, your answers to the restaurant’s questions, and when the booking was made.
The details are used so that the restaurant can receive and handle your booking. They are not sold and not used for advertising.
You get an email with the booking and a link where you can cancel it. The restaurant gets an email about the booking if it has chosen to. If the restaurant has turned on reminders, you get one before your visit.
If you join a waitlist, your name, email, phone number if you give it, the date, party size and the times you can come are kept. You get an email if a table comes free, and can leave the list through the link in the email.
The restaurant sees your earlier bookings with it, whether you came or didn’t show up, and can write its own notes about you, such as allergies. The restaurant can delete everything about you at your request.
Your name, email, phone number and answers are erased automatically once the time the restaurant has chosen has passed after your visit, 24 months unless the restaurant has changed it, or sooner if the restaurant removes them. For a copy, a correction or a deletion, turn first to the restaurant you booked with.
If you have an account
Bordo is responsible for your account.
What is stored is your email address, your password (only as a one-way hash, never in plain text), when you last logged in, and the forms and settings you create.
The details are used so that you can log in and use the service. They are kept for as long as the account exists. You can download everything, and delete the account with everything in it, yourself under your account in the service.
Protection against abuse
To stop password guessing and junk bookings we count attempts to log in, sign up, reset a password, book and cancel. Each attempt is stored with a hash of your IP address and in some cases your email address, never the addresses themselves, and is deleted after a day.
Where the details are kept
The database is in Frankfurt with Neon, the service runs with Netlify, and emails are sent through Resend. These companies process the details on our behalf and may not use them for their own purposes.
If the restaurant has turned on text message reminders, the text is sent to your phone number through 46elks in Sweden.
If the restaurant asks for a card guarantee, a deposit or a prepayment, or you buy a gift card, you pay with Stripe. You give your card details straight to Stripe; neither we nor the restaurant see the card number. The payment is made to the restaurant’s own Stripe account, and the restaurant and Stripe are responsible for it.
If a restaurant has turned on notifications on its phone or browser, a notification about each new booking, with the guest’s name, party size and time, goes through the phone’s or browser’s own push service (Apple, Google, Mozilla or Microsoft). It is encrypted all the way to the restaurant’s device, so the push service can’t read it.
Your rights
You have the right to know which details are held about you, to have them corrected or deleted, and to object to how they are used. If you are not satisfied with the answer you can complain to the Swedish Authority for Privacy Protection, imy.se.
Contact
Bordo