Skip to content

Privacy

Privacy Policy.
In plain English.

Effective October 3, 2026

Vespar, LLC (“Vespar”, “we”, “us”) provides an AI host that helps restaurants answer messages, quote catering, and book private events. Handling your messages means handling your personal data, so here is exactly what we collect, why, who processes it, how long we keep it, and how to get it exported or deleted.

What we collect, and where it comes from

  • Conversations: messages you exchange with a venue’s assistant on Facebook Messenger, Instagram or WhatsApp where enabled, or through the chat widget on this site or a venue’s site.
  • Voice in the website chat: if you talk to a venue’s host instead of typing, the text of what you say and of the host’s replies, kept as ordinary chat messages. The audio itself is not recorded.
  • How you found the venue: when you start a chat or send an event request, the first page you visited, the site that sent you there, the campaign tags in that link (utm_source, utm_medium, utm_campaign, utm_term and utm_content), whether the link carried an advertising click marker (we note which kind, never the marker itself), and when this was noted. We keep web addresses without the rest of their query.
  • WhatsApp messaging: your phone number, messages, consent and opt-out records, delivery receipts, and any advertising referral identifiers WhatsApp includes with your enquiry.
  • Phone calls: if you call a venue’s phone line and its host answers, the number you call from (unless you withhold it), a recording, transcript and short summary of the call, when it happened and how long it lasted, and the details you give the host. See Phone calls and recordings below.
  • Booking details: name, email address, phone number, event date, guest count, menu selections, and similar details you provide while planning an event or filling an order form.
  • Guest text messages: your mobile number, requested text or booking updates, the consent notice you received, your written response, consent and opt-out records, message content, and delivery status.
  • Business inquiries: name, email, venue details, and your message when you submit our quote or contact forms.
  • Survey responses: post-event ratings and feedback comments, if you choose to give them.

We do not collect payment card numbers. Payments are made directly to the venue through Stripe’s secure checkout, and card data never touches our systems.

How we use it

  • Answering your messages, calls, and questions about the venue, its menu, and its spaces.
  • Preparing quotes, deposit invoices, and final invoices for events you book.
  • Adding confirmed bookings to the venue’s calendar.
  • Sending booking-related email (invoices, confirmations) and, after your event, a feedback survey.
  • Sending a requested menu or booking link, or booking confirmations and reminders, by text when you separately agree to that purpose.
  • Alerting the venue’s human team when a conversation needs their attention.
  • Showing the venue which pages, links and campaigns its enquiries arrived from.
  • Keeping a record of each phone call for the venue, so its team can check what was asked and agreed, and see which of its ads, if any, led to the call.

Conversations are processed by large-language-model AI services to generate replies. Your messages are used to answer you. We do not sell personal data, and we do not use your conversations to train AI models.

Who processes data on our behalf

We use a small set of service providers, each bound by their own data-processing terms:

  • Meta: delivers Messenger, Instagram and WhatsApp conversations for the channels a restaurant has connected.
  • Twilio and mobile carriers: connect calls to a venue’s phone line, deliver guest text messages, and process replies, delivery receipts, and opt-out requests.
  • Stripe: invoicing and payments (the venue is the merchant of record).
  • Google: venue calendar entries for confirmed bookings, and Google Analytics to count visits to our own pages according to the choice and region rules described below. Our Analytics tag never runs on a venue’s site or inside the chat widget. Separately, a venue can choose to connect its own Google Analytics and Search Console to Vespar; see If your venue connects Google below.
  • Microsoft: venue calendar entries for confirmed bookings, when the venue has connected its Outlook calendar.
  • Mailchimp: post-event survey email.
  • Resend: transactional email (alerts, confirmations).
  • OpenRouter: routes conversation text to AI models to generate replies and, when a venue’s team asks its dashboard a question, that venue’s own report figures to generate the answer.
  • ElevenLabs: runs the voice of a venue’s phone line, and of the website chat when you talk to a restaurant’s host by voice instead of typing. It turns your speech into text and the host’s replies into speech. On the phone it also records and summarizes the call, and keeps its own copy of the recording and transcript, which we delete when you ask us to. In the chat, your audio is not recorded and ElevenLabs keeps nothing once the call ends; the conversation stays in the chat as text, like any typed message.
  • Vercel, Supabase, Upstash: hosting, database, and queue infrastructure.
  • Sentry: error monitoring; error reports are automatically scrubbed of emails, phone numbers, and credentials before they leave our servers.

Guest texts and your permission

Vespar Guest Texts is operated by Vespar, LLC for participating restaurants. We use your number and messaging records to deliver the specific texts you request, keep the restaurant’s conversation and booking records together, and honor your messaging choices. Consent to one link does not subscribe you to reminders, texts for another restaurant, or marketing.

We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes.

The restaurant handling your enquiry and the service providers needed to operate and deliver these texts process the relevant information for those purposes. Your opt-in is not permission for them to market to you. We keep a record of consent and opt-out requests so that we can apply your preferences.

Read the guest text messaging guide for the opt-in steps and the SMS Terms for message frequency, charges, and help. Reply STOP to the number that texted you to unsubscribe, or HELP for assistance.

Phone calls and recordings

Some venues have their host answer the phone. When it does, your conversation with the host is recorded.

  • What is kept: the recording, a written transcript and a short summary of the conversation, the number you called from (unless you withheld it), when you called and for how long, and the details you gave the host.
  • Calls from ads: if the venue connects its Google Ads account, Google’s report of a call from one of its ads (its time and length, and the caller’s country and area code, never the full number) is matched to the recorded call when the two line up, so the venue can see which ad led to it.
  • Where it is kept: in private storage that is never public, and with ElevenLabs, which runs the line’s voice and keeps its own copy.
  • How long: there is no automatic expiry. A call is the venue’s record of what was asked and agreed, and of which ad led to it, so it is kept until you ask us to delete it.
  • Who can hear it: members of the venue’s team who have access to its guest records, inside the venue’s signed-in dashboard, and our own team when helping that venue. Recordings are never published and never shared with another venue.

To have your calls deleted, see Your rights below. We delete the recording and transcript from our storage and from ElevenLabs, and remove your number and details. The venue keeps only what identifies no one: that a call happened, when, for how long, and which ad it came from.

If your venue connects Google

This part is for venue owners, and connecting is optional. If you connect your venue’s Google Analytics or Search Console to Vespar, you either sign in with Google and choose the property to share, or add Vespar’s reporting account to that property as a viewer. Either way the access is read-only: we cannot change anything in your Google accounts.

  • What we read: aggregated figures only. From Analytics: visits, visitors, top traffic sources and top landing pages. From Search Console: clicks, impressions, average position and top search queries. We do not request data about individual visitors.
  • What we use it for: showing your venue its own marketing report inside Vespar, and nothing else.
  • What we store: an encrypted access credential, if you signed in with Google, and the ID of the property you chose. We do not store the reports. They are held in a short-lived cache for at most one hour and then discarded.
  • Who else receives it: when someone on your team types a question into the “Ask about your marketing” box, the figures on that page, including these, are sent to our AI model provider to write the answer shown to that person. That happens only when a question is asked. We do not use these figures to train AI models.
  • Who at Vespar sees it: our staff do not review these figures. A member of our team who opens your dashboard to help with a support request you raised will see your report as you do.

We never sell this data, never use it for advertising, and never share it with another venue. If you signed in with Google, you can disconnect at any time in Setup, Connections. That deletes our stored credential and the property you chose with it straight away, and any copy of the credential still held in a running server’s memory expires within five minutes. You can also remove Vespar’s access on Google’s side at myaccount.google.com/permissions. If you added Vespar’s reporting account instead, remove it from the property in Google Analytics or Search Console, or ask us to.

Vespar’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How long we keep it

Identifying data has an automatic expiry: if you have no upcoming event and have been inactive for 90 days, a daily job strips your name, email, phone, and messaging identity from our records, scrubs your conversation text, and removes campaign search terms and the full address of the page that referred you. Anonymous business records (that an event happened, its date and amount, the site or campaign it arrived from, the page you first arrived on and when, aggregate ratings) are retained for accounting and statistics.

Phone calls are the exception. A call’s recording, transcript and summary, the number it came from, and the details you gave the host are not part of that expiry. They are kept until you ask us to delete them; see Phone calls and recordings.

Paid invoices are retained by the venue in Stripe as financial records, as required by tax and accounting law.

Your rights (GDPR & CCPA)

Wherever you are, we honor the core rights of the EU GDPR and the California CCPA/CPRA:

  • Access / export: request a machine-readable copy of everything we hold about you.
  • Deletion: request erasure; we remove your identity and conversations, including call recordings, keeping only what the law requires (e.g. invoices) or fully anonymized statistics.
  • Correction: ask us to fix inaccurate details.

To exercise access or deletion, request it here. We email a link to confirm it’s really you (nothing happens until you open it), and then answer within 30 days. Every request is logged for accountability.

If you called a venue and never gave its host an email address, email info@vespar.ai instead, with the number you called from. We may ask you to confirm that the number is yours.

For corrections, or to reach a person about anything on this page, email info@vespar.ai from the address your booking used.

Security

  • All traffic is encrypted in transit (TLS).
  • Venue credentials and integration secrets are encrypted at rest with AES-256-GCM.
  • Access to operational data is restricted to the Vespar team and the venue’s own staff.
  • Every inbound webhook is cryptographically verified before it is processed.

Cookies & local storage

We use Google Analytics to see which pages are useful. That is the only thing here we ask about, and the notice on your first visit lets you refuse it. We run no advertising trackers, nothing that follows you to other sites, and no cookie that sells or shares what you did.

In regions where we require prior consent, analytics waits for you to accept. Elsewhere it may start while the notice offers a choice. Choosing “Reject optional” prevents future analytics collection, including when the tag has already loaded. Cookies already set may remain until they expire or you clear them. We remember your choice when browser storage is available.

The rest is essential or stays with you. A login cookie if you sign in to the venue dashboard. An anonymous session token in local storage, kept for 30 days, that lets the chat widget remember your conversation. A draft of a form you started, and the page you first arrived on, both held in this tab’s session storage so a form can survive a mistake and we can tell which page brought you here. On a venue’s own website that has installed our chat script, the script makes its note as the page loads, even where the chat button does not appear: the first time a tab arrives from another site or through a tagged link, it keeps the page you arrived on, the address of the page that referred you, that link’s campaign tags, which kind of advertising click marker it carried (never the marker itself), and the time, in that tab’s session storage. The guided intake saves your answers when you submit, restores them if submission fails, and clears them after success or a fresh start. Session storage stays in this tab and is cleared when the tab closes. When you send a chat message or an event request, the arrival details go with it and are saved on that venue’s record of your enquiry, kept as described under “How long we keep it”. They are shared only with that venue. Nothing else here is shared with anyone.

Children

Our services are for booking event venues and are not directed at children under 16. We do not knowingly collect children’s data.

Changes & contact

If this policy changes, we’ll update this page and its effective date. Questions about privacy (or anything else) reach us at info@vespar.ai or via the contact form.