Data processing addendum

How HostyFlow handles the personal information your restaurant puts into HostyFlow. Version 2026-09-29.

Last updated September 29, 2026

The parties

This addendum sets out how HostyFlow handles the personal information your restaurant puts into HostyFlow.

You are the controller

Your restaurant decides what information about your guests and your team goes into HostyFlow, and what it is used for.

HostyFlow is the processor

HostyFlow handles that information only to run HostyFlow for you, and only as your settings and your team's actions in the Workstation direct. Those settings and actions are your instructions.

The information and why

What HostyFlow handles for you, and the only reasons it does.

About your guests

Names, phone numbers, email addresses, bookings, party sizes, notes, allergies, occasions, visits, texts, emails, call recordings and transcripts, voicemails, faxes and payment records. Never card numbers.

About your team

Names, email addresses, phone numbers, roles, schedules, sign-ins and the changes each person makes.

Purpose

To take and manage bookings, run your waitlist and floor, answer your calls and messages, send the texts and emails you set up, take payments into your account and keep your records. HostyFlow does not sell this information or use it to advertise.

Kept to your restaurant

Your guests' details stay with your restaurant. They reach another restaurant only when a guest signs in to HostyFlow and chooses to share them.

Subprocessors

The companies HostyFlow uses to run the service.

The list

Every company that handles your restaurant's information for HostyFlow is named at hostyflow.com/trust/subprocessors, with what it does, what it touches and where. The page shows the date it last changed.

Security

The measures in place today.

Your own storage

Each restaurant's bookings, guests and floor live in storage of its own. No other restaurant can open them.

Encrypted connections

Every page, screen and connection to HostyFlow uses HTTPS.

Sign-in

Each person signs in with a one-time code sent to their own email or mobile number. Their role decides what they can open, and HostyFlow checks the role on its servers.

Activity log

Every change in the Workstation is recorded with the person's name and the time.

Cards

Guests type card numbers only on the payment company's page. HostyFlow never receives them.

HostyFlow's own team

HostyFlow's team opens your account only through a support session that lasts at most an hour, needs a written reason and is recorded.

Breaches, requests and removal

What HostyFlow does when something goes wrong or someone asks.

Breach notice

If HostyFlow learns that someone reached your restaurant's information without permission, HostyFlow emails your account owner within 72 hours with what happened, what information was involved and what HostyFlow is doing about it.

Guest requests

If a guest asks you to remove their details, use Remove on their guest card in the Workstation, or send them to hostyflow.com/privacy. Either way their details are removed from use right away. If a guest asks to see their details, forward it to privacy@hostyflow.com.

Removal

Removed details leave every screen, list and message at once, and no more texts or emails go to that guest. A sealed copy is kept for at least three years for legal and dispute needs, and it is never used for anything else. hostyflow.com/trust/retention shows how long each kind of record is kept.

Standard terms

How this addendum fits with the rest of your agreement.

Part of the Terms

This addendum is part of your agreement with HostyFlow under the Terms at hostyflow.com/terms. Where they differ about personal information, this addendum applies.

Versions

Each version has a date. Settings in the Workstation shows the version your restaurant accepted, who accepted it and when.

Contact

privacy@hostyflow.com for this addendum. security@hostyflow.com for security questions.

Accept the addendum

Your restaurant’s owner accepts it in Settings, under Data processing. HostyFlow records who accepted, when and which version.

Open Settings