Skip to content
Rreservory® home
Product⌄
Explore all product ↗BKBookingsThe phone-legible bookings screen your front desk actually wants.CPCapacity & demandKnow when you’re full, when you’re empty, and what to charge.PYPaymentsHonest fees, full payouts, and receipts that show every dollar.CRGuest CRMCohorts, RFM segments, and win-backs that grow repeat visits.POPoint of saleWalk-ins, retail, cash drawers and shifts — on any tablet.WVWaivers & check-inPre-arrival digital waivers and a 10-second check-in flow.INIntegrationsStripe, Twilio, QuickBooks, Zapier and more — passed through at cost.
TAKE A LOOK INSIDE
Today’s arrivals 11121314
Garcia · 4 guestsReady
Vault Heist · 12:00↗

A better Saturday
starts here.

Explore the live demo ↗
Solutions⌄
Explore all solutions ↗EREscape roomsRoom timers, sequenced bookings, and waivers built for the genre.AXAxe throwingLane scheduling, coaches, and league nights without the spreadsheet.MGMini golfTee-time pacing, group flow, and weather-proof rebooking.TPTrampoline parksTimed jump sessions, capacity caps, and grip-sock add-ons.LTLaser tagArena rotations, team sizes, and back-to-back game pacing.VRVR & arcadesStation-level capacity, timed play, and prepaid game cards.CLClimbing gymsDay passes, intro classes, memberships, and belay waivers.FECFamily entertainmentMulti-attraction venues with one capacity model and one cart.
TAKE A LOOK INSIDE
Today’s arrivals 11121314
Garcia · 4 guestsReady
Vault Heist · 12:00↗

A better Saturday
starts here.

Explore the live demo ↗
PricingCustomersDocs ↗
Sign inStart free ↗
☰
Product↗Solutions↗Pricing↗Customers↗Documentation↗About Reservory↗See the demo↗Sign in↗
SECURITY

Isolation by design. Not by policy.

Reservory is a multi-tenant platform. We treat tenant data isolation as a structural guarantee enforced at the database, not just an application-layer convention.

TENANT ISOLATION

Every tenant is a hard boundary.

Row-level security policies on every tenant-scoped Postgres table mean that even a bug in application code cannot return one tenant's data to another. Policies enforce two independent checks: the row's tenant_id must match the caller's tenant, and the caller must be an active member of that tenant. An automated cross-tenant isolation test runs on every pull request.

WHAT WE PROTECT

A full security checklist.

Per-tenant Postgres row-level security — every query is double-gated by tenant_id and tenant membership
Card payments handled entirely by Stripe — Reservory never touches raw card numbers
Stripe Connect Standard keeps each operator’s money in their own account
Integration credentials (OAuth tokens, API keys) encrypted at rest with AES-256-GCM
HMAC-signed, expiring tokens gate customer payment and waiver flows
HTTP idempotency middleware prevents double-charges on browser retries
Append-only audit log records every operator action with identity and timestamp
Outbound webhook URLs validated at registration and re-validated at every delivery (SSRF defense)
SHA-256-hashed API keys for automation — plaintext shown once, never stored
Concurrency-safe refund pre-allocation prevents concurrent operators from over-issuing refunds
Automatic Supabase database backups with point-in-time recovery
GDPR right-to-be-forgotten queue with 30-day cooling-off and full PII scrubbing
KEY PRACTICES

How the hard parts work.

PAYMENTS

Stripe handles PCI scope

Reservory uses Stripe Connect Standard. Card data is collected by Stripe Elements and never touches our servers. Each operator keeps their own Stripe account — payouts go directly to them.

SECRETS

AES-256-GCM encrypted config

OAuth tokens and API keys for integrations (Mailchimp, Klaviyo, HubSpot, QuickBooks) are stored encrypted at rest. The encryption key never lives in the database — only in environment secrets.

TOKENS

HMAC-signed access tokens

Customer payment and waiver flows use short-lived HMAC tokens with domain separators. A waiver token cannot be substituted for a payment token. Booking UUIDs are never exposed in URLs or referrer headers.

IDEMPOTENCY

Safe retries everywhere

Every mutating POST is wrapped in HTTP idempotency middleware. Browser retries and network blips don't create duplicate bookings or double charges. Transient failures are not cached — retries re-run cleanly.

AUDIT LOG

Append-only operator ledger

Every operator action — refund, cancellation, bulk re-book, gift card anomaly — is logged with the operator's identity, timestamp, and the action taken. The log is append-only: no UPDATE or DELETE policies exist on it.

WEBHOOKS

SSRF defense at every step

Outbound webhook URLs are validated against an allowlist at registration. The URL is re-resolved immediately before each delivery to defend against DNS rebinding attacks. Internal and private IP ranges are blocked.

COMPLIANCE POSTURE

Where we stand today.

PCI DSS

Stripe handles card scope

Reservory is not a card processor. Stripe, our payment provider, maintains PCI DSS compliance. Our scope is limited to transmitting tokenized payment intents — we never store, process, or transmit raw card data.

SOC 2

Available to Scale customers

A SOC 2 audit is on our compliance roadmap. Security evidence packages — architecture documentation, access control policies, and penetration test results — are available to Scale-tier customers on request.

GDPR

Right-to-be-forgotten queue

Guest deletion requests are processed within 30 days. The anonymizer scrubs PII from customer records, cancels pending email and SMS queues, and marks the record as anonymized. Operators submit requests from the dashboard.

RESPONSIBLE DISCLOSURE

Report a vulnerability

Report security vulnerabilities to security@reservory.com. Researchers are acknowledged publicly unless they prefer anonymity. Reporting guidelines at Security Policy →

Questions about our security posture?

Email our security team directly or review the full responsible disclosure policy, including scope and testing restrictions.

Contact security teamRead disclosure policy
PGP key at /.well-known/pgp-key.txt · machine-readable policy at /.well-known/security.txt
Rreservory

For the people
who make people’s day.

Let’s make yours better ↗

PRODUCT

  • Bookings
  • Capacity & demand
  • Payments
  • Guest CRM
  • Point of sale
  • Waivers

SOLUTIONS

  • Escape rooms
  • Axe throwing
  • Mini golf
  • Trampoline parks
  • All verticals

RESOURCES

  • Live demo
  • Documentation
  • SDKs
  • API reference
  • Webhooks
  • GraphQL
  • Integrations

COMPANY

  • About
  • Customers
  • Pricing
  • Changelog
  • Careers
  • Security
  • Acknowledgments
reservory®
© 2026 Reservory, Inc.
PrivacyTermsDisclosure
EN · A$ AUD Product updates ↗