Skip to content

Privacy Policy

Last updated: June 2026

Riddlio ("we", "us", "our") operates the booking platform at https://www.riddlio.com and the application at https://app.riddlio.com. This policy explains how we handle your data.

Data We Collect

When you create an account, we collect your name, email address, and business information. When customers book through your booking pages, we collect booking details including name, email, phone number, and payment references processed securely by supported payment providers.

How We Use Data

We use collected data to provide the booking service, process payments, send booking confirmations and reminders, and improve our platform. We do not sell your data to third parties.

Data Storage

Data is stored on managed server infrastructure with restricted access. Raw card information is handled by payment providers and never stored on our servers. Browser and API traffic is protected in transit with TLS.

Consent Management

When a customer completes a booking through our widget, they must explicitly check a consent checkbox agreeing to this Privacy Policy before the booking can be submitted. This consent is recorded with a timestamp, IP address, and booking reference. Customers can view their consent history and withdraw consent at any time from their customer profile.

Your Rights - Data Export

Under GDPR Article 20 (Right to Data Portability), you can export all customer data as a structured JSON file at any time. This includes profile information, booking history, transactions, notes, badges, waiver signatures, and consent records. Escape room operators can initiate a data export from the customer detail page in the admin dashboard.

Your Rights - Right to be Forgotten

Under GDPR Article 17 (Right to Erasure), customers can request deletion of their personal data. Escape room operators can submit a deletion request from the customer detail page. When processed, all personally identifiable information (name, email, phone, address, date of birth) is anonymized. Booking records are retained for accounting purposes but are detached from the customer's personal identity. Auth tokens and consent records are permanently deleted.

Your Rights

In addition to the self-service features above, you can request export or deletion of your data by contacting us at [email protected]. Riddlio provides tools designed to help venues respond to GDPR, CCPA, and Australian Privacy Act requests.

Contact

For privacy questions or requests, email [email protected].

© 2026 Riddlio. All rights reserved.