Skip to content
OpenReserve

Privacy Policy

Effective 2026-10-07 · Last updated 2026-10-08

OpenReserve is online booking, payments and client management for barbershops, salons and tattoo studios. This policy explains what we collect, why, who sees it, how long we keep it, and the choices and rights you have. If anything here is unclear, email hello@openreserve.app and we will explain it plainly.

In plain English: We collect what we need to run OpenReserve. We do not sell your information, we do not show ads, and you can see, export, correct and delete your data.

1. Who we are, and who is responsible for your data

In plain English: MemoryMaps, LLC runs OpenReserve. When you book with a business, that business decides what happens to its records about you, and we handle them on its behalf.

MemoryMaps, LLC d/b/a OpenReserve ("OpenReserve," "we," "us," "our") operates openreserve.app and the OpenReserve for Business and OpenReserve mobile apps (together, the "Service").

The Service is used by businesses (and their staff), the clients who book with or buy from them, and people who create their own OpenReserve account. Who is responsible for your information depends on how you use the Service:

  • We are the controller of the information about people who use the Service directly: business owners and staff, people with their own OpenReserve account, and visitors to our website. "Controller" means we decide why and how that information is used, and this policy describes it.
  • The business is the controller of the records it keeps about its clients: appointments, contact details, notes, forms and payment history. We process those records on the business's behalf and on its instructions, as its service provider (or "processor"), under our Data Processing Addendum. The business's own privacy notice also applies to them. To access, correct or delete those records, contact the business; if you contact us instead, we will pass your request to the business and help it respond.

2. What we collect

In plain English: The details you give us, the records needed to provide the Service, and a small amount of technical data to keep it secure and working.

Account details

Your name, email address and, if you add one, phone number, and how you sign in. If you sign in with Apple or Google, we receive only the identifier and email address they share with us.

Account acceptance evidence

The account reference, the identifier and version of the terms or consent accepted, the acceptance time, and the IP address and user-agent details (browser or app information) recorded with that acceptance.

Business information

Details about a business that uses the service: its name, address, opening hours, services and prices, staff names and roles, branding, and subscription and payout status.

Information about a business's clients

When you book with or buy from a business: your name, email address and phone number, your appointments and purchases, your preferences, and notes the business keeps about your visits.

Payment information

Card details go directly from your device to Stripe and never reach our servers. We keep Stripe's payment reference, the amount, currency and status, and the card brand and last four digits that Stripe returns, so receipts, refunds and disputes work.

Photos and files you upload

Images you choose to upload, such as a profile picture, portfolio or gallery photos, or reference images. We remove location and camera details embedded in photos before storing them.

Device information

If you allow notifications, a push token issued by Apple or Google, plus your device type, operating system and app version.

Logs and security data

Technical records our servers create when you use the service: IP address, browser or app details, the requests made, and timestamps.

Messages you send us

What you write when you contact us for support or with a request, and our replies.

3. What we do not collect or do

In plain English: No selling, no ads, no tracking across other companies' apps and websites.

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • There is no advertising in the Service. We do not use advertising identifiers and we do not track you across other companies' apps or websites.
  • Card numbers, security codes and bank account numbers never reach our servers.
  • We do not ask for your location.
  • We do not read your contacts, calendar or microphone.
  • We do not use your information to make automated decisions that have legal or similarly significant effects on you.
  • We do not use the records a business keeps about its clients to market to them, and we do not combine one business's client records with another's.

4. How we use it

In plain English: To run the Service, keep it secure, and talk to you about it.

  • Account details: to create and secure your account, sign you in, and contact you about your account.
  • Account acceptance evidence: to record which terms or consent you accepted and when.
  • Business information: to set up and run the business's workspace, bill its subscription, and show its public pages.
  • Information about a business's clients: to let you book, to let the business provide its service and contact you, and to send the confirmations and reminders you expect.
  • Payment information: to take deposits and payments, issue refunds, and handle disputes.
  • Photos and files you upload: to show them where you put them and to the people you share them with.
  • Device information: to deliver notifications to the right device and support the app versions in use.
  • Logs and security data: to keep the service secure and reliable, prevent abuse and fraud, and enforce rate limits.
  • Messages you send us: to answer you and keep a record of what was agreed.

We also use information when the law requires it, to enforce our Terms of Service, and to protect the rights, safety and property of our users, the public and ourselves. We may create aggregated or de-identified statistics that cannot reasonably be used to identify anyone, and use them to understand and improve the Service.

5. Who we share it with

In plain English: Only with the people and providers who need it to deliver the Service, and with authorities when the law requires.

WhoWhyWhat they receive
The business you book with or buy fromTo provide its service and contact you about itYour booking, contact details, and the forms, requests and messages you send it
Our service providers (list)Hosting, payments, push notifications, email and securityOnly what each needs to do its job for us, under contracts that require them to protect it
StripeTo process payments on the business's own Stripe accountThe payment details you enter directly with Stripe, and the amount and a reference for the payment
Apple and GoogleSign-in, if you choose Sign in with Apple or Google, and delivering push notificationsNotification content and your device's push token
Courts, regulators and law enforcementWhen the law requires it, or to protect someone's safetyOnly what the request lawfully requires
A company that acquires usIf we are involved in a merger, acquisition or sale of assetsThe information covered by this policy, which would stay protected by it; we will tell you before it becomes subject to a different policy

Our service providers are: Amazon Web Services, Stripe, Vercel, Expo, Cloudflare, Microsoft 365, and Neon. Stripe handles payment details under its own privacy policy. We also share information when you ask us to.

6. Payments

In plain English: Stripe handles your card. We never see the number.

Payments are processed by Stripe, a certified PCI Level 1 payment processor. Your card details go directly from your device to Stripe and never reach our servers. We keep only Stripe's reference for the payment, the amount and currency, its status, and the card brand and last four digits that Stripe returns, so that receipts, refunds and disputes work. When you pay a business, the payment is made to that business's own Stripe account, and the business is the seller.

7. How long we keep it

In plain English: As long as needed to provide the Service and meet our legal obligations, then we delete it.

InformationHow long we keep it
Account detailsUntil you delete your account
Account acceptance evidenceAccount acceptance evidence is preserved after account deletion, including the accepted document or consent identifier and version, acceptance time and retained account reference. IP address and user-agent details are removed when the account is purged. No automatic expiry is currently configured for the remaining account acceptance evidence.
Business informationUntil you delete your account
Information about a business's clientsWhile the business uses the service, through the 30-day closure grace period, and until unresolved payment or refund obligations are resolved and the tenant purge can complete
Payment informationLocal tenant payment and refund records are kept while the business uses the service. They are deleted with tenant-owned data after the 30-day closure grace period, once unresolved payment or refund obligations are resolved and the purge can complete.
Photos and files you uploadUntil you delete your account
Device informationUntil you delete your account
Logs and security data7 days in development and 30 days in production
Messages you send us3 years

When you delete your account, we hide your profile right away and delete or scrub personal account details after a grace period of 30 days; records retained after deletion are described above; until then, you can change your mind. Database recovery history is configured for six hours. Tenant media storage does not keep object versions. This recovery-history setting does not specify when every backup copy held by a provider is physically erased. A business can export its data during the 30-day period after it closes its workspace. After that closure grace period, tenant-owned data is deleted once unresolved payment or refund obligations are resolved and the purge can complete. A scrubbed workspace record and a minimal purge audit record remain. This local deletion does not delete records held separately by Stripe or close the business's Stripe account.

8. Your rights and choices

In plain English: See, export, correct and delete your data, and opt out of messages, from the app or by emailing us.

Wherever you live, you can ask us to:

  • Access and export the personal information we hold about you, in a portable format.
  • Correct information that is wrong or incomplete. Most details can be edited in your account settings.
  • Delete your information. See Delete your account for how to do it in the app or on the web.
  • Object to or restrict how we use it, and withdraw consent you gave us.

You also control messages directly: turn off push notifications in your device settings; and use the unsubscribe link in any non-essential email.

To make a request, email hello@openreserve.app from the address on your account. We may need to confirm it is you before we act, and we will respond within 30 days. If we cannot do what you ask, we will explain why, and you can appeal by replying to our decision; if your appeal is denied, you can contact your state attorney general. We will not treat you differently for exercising your rights. For records a business keeps about you as its client, the business decides: contact it directly, or ask us and we will forward your request.

9. California privacy rights

In plain English: California law gives you specific rights and requires specific disclosures. We do not sell or share your information.

This section applies to California residents and supplements the rest of this policy. In the last 12 months we collected the following categories of personal information, from the sources listed, for the purposes described in "How we use it":

CategoryExamplesSources
Identifiers (such as name, email address, phone number, account ID, IP address, device identifiers)Account details, account acceptance evidence, business information, information about a business's clients, device information, logs and security data, and messages you send usYou, Apple or Google, if you sign in with them, the business and its staff, your device, and our servers
Personal information in customer records (Cal. Civ. Code § 1798.80(e)), such as contact detailsAccount details, account acceptance evidence, information about a business's clients, payment information, and messages you send usYou, Apple or Google, if you sign in with them, the business and its staff, Stripe, and our servers
Commercial information (such as appointments, purchases and payment history)Business information, information about a business's clients, and payment informationYou, the business and its staff, and Stripe
Internet or other electronic network activity (such as logs and app interactions)Account acceptance evidence, device information, and logs and security dataYou, your device, and our servers
Audio, electronic, visual or similar information (such as photos you upload)Photos and files you uploadYou
Professional or employment-related information (such as a staff member's role)Business informationThe business and its staff
  • Disclosures for a business purpose. We disclosed each category above to our service providers, for the purposes described in this policy, and booking, contact and form information to the business you booked with.
  • No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the last 12 months. We do not knowingly sell or share the personal information of consumers under 16.
  • Sensitive personal information. We do not collect sensitive personal information as defined by California law.
  • Retention. We keep each category for the periods in "How long we keep it."
  • Your rights. You have the right to know what personal information we collect, use and disclose; to access it; to delete it; to correct it; to opt out of its sale or sharing (which we do not do); to limit the use of sensitive personal information (which we use only as permitted); and not to be discriminated against for using these rights.
  • How to exercise them. Email hello@openreserve.app. We verify requests by confirming control of the email address on the account. You can use an authorized agent; we will ask for proof that you gave the agent signed permission, and may ask you to confirm your identity directly.
  • Global Privacy Control. We treat a Global Privacy Control signal from your browser as a request to opt out of sale and sharing.
  • Shine the Light. We do not disclose personal information to third parties for their own direct marketing.
  • Information we process for a business. For records we hold as a business's service provider, please make your request to the business. If you send it to us, we will pass it on.

Residents of other US states with comprehensive privacy laws have similar rights, and we honor those requests in the same way.

10. Security

In plain English: Encrypted connections, encrypted storage, strict separation between businesses, and access only for those who need it.

We protect information with encryption in transit (HTTPS/TLS) and at rest, separation of each business's data enforced in the database itself, short-lived sign-in tokens, least-privilege access for our team, and audit logs. No system is perfectly secure; if we learn of a breach that affects your personal information, we will notify you and the authorities as the law requires. Details, and how to report a vulnerability, are on our Security page.

11. Children

In plain English: OpenReserve is not for children under 13.

The Service is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us personal information, email hello@openreserve.app and we will delete it. People under 18 should use the Service only with the involvement of a parent or guardian. Some businesses require their clients to be 18 or older for certain services; that is the business's policy.

12. Where your information is processed

In plain English: In the United States.

We are based in the United States, and we and our service providers store and process information there. If you use the Service from outside the United States, your information is transferred to the United States, where data protection laws may differ from those where you live.

13. Cookies and similar technology

In plain English: The website uses only what it needs to work. No advertising cookies.

We use cookies and browser storage to keep you signed in, to protect the Service, and to remember your preferences. There are no advertising cookies and no third-party tracking pixels. See our Cookie Policy for the details.

14. Changes to this policy

In plain English: We announce material changes at least 7 days before they take effect.

We may update this policy from time to time. For material changes, we will notify you by email or in the app at least seven (7) days before the change takes effect. The "Last updated" date at the top of this page shows the latest revision. Clarifications and corrections that do not reduce your rights may be made without notice.

15. Contact us

In plain English: Email us with any privacy question or request.

  • Company: MemoryMaps, LLC d/b/a OpenReserve
  • Address: 11750 W 135th St #1551, Overland Park, KS 66221-9395, United States
  • Privacy questions and requests: hello@openreserve.app