BACK TO HOME
sevenrooms

sevenrooms

General Servicesevenrooms.com

Privacy Conclusion

"SevenRooms presents a high-risk privacy posture (68/100) comparable to Spotify/Netflix. The service collects extensive personal, payment, and behavioral data (+20 points for basic types: name, email, phone; sensitive location/contact context in reservations; payment information), shares it with at least 5 third-party analytics and payment processors without clear data broker restrictions (+16 points), and implements persistent behavioral tracking via Pendo without documented opt-out mechanisms (+11 points). Critical gaps in data retention disclosure (+12 points) and transparency regarding user rights, breach notification, and data portability (+9 points) prevent users from understanding or controlling their data lifecycle."

Risk Score
68
ELEVATED

sevenrooms Privacy Concerns & Scorecard

Privacy Risk Analysis
Transparency & RightsCRITICAL

The provided policy materials lack transparent disclosure of privacy rights, data portability options, breach notification commitments, and contact methods for privacy inquiries. Sensitive credentials (JWT tokens, RSA public keys) are embedded in client-side code without clear protection disclosure.

Data CollectionHIGH

SevenRooms collects comprehensive user data including identity information (name, email), payment information, reservation and booking details, guest profile information, activity logs, and technical/behavioral data through multiple tracking services.

Third-Party SharingHIGH

User data is shared with multiple third-party services including Pendo (product analytics), Sentry (error tracking), Stripe (payment processing), Zendesk (customer support), and FontAwesome. These integrations transmit personal and behavioral data to external servers.

Retention & ControlHIGH

The policy does not specify data retention periods, deletion mechanisms, or time limits for how long user data is retained. Retention policies are entirely vague or absent.

Tracking & AdsMEDIUM

Pendo.io is loaded for product analytics and user interaction tracking, enabling behavioral monitoring and targeting capabilities. No explicit opt-out mechanism for this tracking is documented.

Recommended Actions

No recommended actions at this time.

Automate your privacy

Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.

Data Collection & Tracking

Personal Information Collected

Identity Data

Account creation, authentication, and reservation management

Financial Data

Payment processing for reservations and bookings

Reservation & Booking Data

Core service functionality—managing restaurant reservations

Guest Profile Information

Personalization and guest experience optimization

User Interaction & Behavioral Data

Product analytics, feature optimization, and user experience improvement

Technical & Error Data

Error tracking, debugging, and platform stability monitoring

Activity Logs

Usage analytics, fraud detection, and user support

Cross-Platform Tracking

No explicit cross-platform or cross-device tracking mechanisms are described in the available policy segments. However, Pendo Analytics is initialized automatically and may correlate user behavior across multiple sessions or devices if users log in from different locations. No clear statement regarding whether SevenRooms correlates data across other websites or apps is provided.

Tracking Methods:

Pendo Analytics

JavaScript SDK (API key: 440b7c28-bcf7-40c2-4ff7-a446ac4315f9) loaded on all pages; tracks user interactions, behavioral patterns, and feature usage; initializes automatically without explicit opt-in notice

Sentry Error Tracking

Server-side and client-side error monitoring; transmits error context, stack traces, and diagnostic data to external Sentry servers; may include partial user data in error messages

LocalStorage & SessionStorage

Browser storage mechanisms enabled for data persistence; stores analytics identifiers, session tokens, and user preferences; persists across browser sessions

Third-Party Embeds & iFrames

Zendesk support widget and Stripe payment iframe embed third-party code that can track and collect data independently; enables cross-domain data sharing

Preconnect Headers

HTTP preconnect headers to multiple third-party domains establish early connections to analytics, CDN, and external service providers; suggests data routing to external servers

AI & Data Training

sevenrooms does not train AI on your content

Based on their public policy, your content is not used to train AI models.

How to Object

No opt-out available

This service does not currently provide a public way to opt out of AI training.

Why We Analyzed sevenrooms

TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.