nice work

Privacy Policy — Nice Work Reservations

Last updated: 5 September 2026
Operator: Shinsora Pte. Ltd. (UEN 201841129Z), 261 Waterloo Street #03-11, Waterloo Centre, Singapore 180261 ("Nice Work", "we", "us")
Data protection contact: hello@nicework.sg

1. What this policy covers

Nice Work Reservations is a restaurant reservations service. Restaurants and other venues ("venues") use it to take bookings. Diners use it to book a table at a venue, through the venue's booking page at book.nicework.sg, a booking widget embedded on the venue's own website, or through partner channels the venue has switched on.

This policy explains what personal data we collect, why, who we share it with, and what choices you have. It applies to diners, to venue staff who use the service, and to visitors of our websites.

2. Our role: two different relationships

If you are a diner. The venue you book with decides what information to collect and how to use it. Under Singapore's Personal Data Protection Act (PDPA) the venue is the organisation responsible for your data, and Nice Work processes it on the venue's behalf as a data intermediary. When you contact us about your booking data, we will help, but the venue is the party that decides.

If you work at a venue. Nice Work is the organisation responsible for your account data (your name, work email, role and login activity) and for the data we need to run, secure and bill the service.

Where a venue also uses Nice Work POS, the venue's guest records are shared between its Nice Work products. They are never shared with other venues.

3. Data we collect

From diners

  • Booking details. Name, phone number, email address, party size, date and time, and any occasion, seating preference, dietary or special-request notes you type in.
  • Booking history. Visits, cancellations and no-shows at that venue, which the venue can see against your guest profile. Venues may also see spend from a linked Nice Work POS bill.
  • Card details, when the venue requires them. Some venues ask for a card to hold a booking or take a deposit. Your card number goes directly to Stripe and never reaches our servers. We keep only a Stripe reference, the card brand and last four digits, and the outcome of any charge.
  • Messaging preferences. Whether you agreed to receive reminders or marketing by email or WhatsApp, when you agreed, and where you agreed.
  • Technical data. IP address, browser type and a bot-protection token from Cloudflare Turnstile. If the venue has connected Meta advertising, Meta's cookies (_fbp, _fbc) may be read on the venue's booking page. See section 6.

From venue staff

  • Account data. Name, work email, phone number, role, and the venue you belong to.
  • Activity records. Bookings you create or change, settings you edit, and sign-in events, kept in an audit log for security and dispute resolution.
  • Integration credentials. If your venue connects Stripe, WhatsApp Business or Meta, we store the account identifiers and access tokens needed to operate those connections. Tokens are stored encrypted.

From website visitors

  • Standard server logs from our hosting provider, including IP address and pages requested, kept for security and troubleshooting.

We do not collect data from anyone under 13 knowingly. Bookings should be made by an adult.

4. How we use data

  • To create, confirm, remind, change and cancel bookings.
  • To send booking emails and, if the venue has enabled it and you have agreed, WhatsApp messages.
  • To let the venue recognise returning guests, keep notes, and manage waitlists and seating.
  • To place card holds or take deposits that the venue has set, and to charge no-show or late-cancellation fees according to the policy shown to you at booking time.
  • To send marketing from the venue, only where you opted in, and always with a one-click unsubscribe.
  • To keep the service secure, prevent abuse and bots, and investigate problems.
  • To operate, bill and improve the service, including aggregate statistics that do not identify anyone.
  • To meet legal obligations.

We do not sell personal data. We do not use diner data to advertise to diners on our own behalf.

5. Who we share data with

The venue you book with. Everything you submit in a booking goes to that venue.

Service providers who process data for us. We use a small number of providers, each bound by contract to handle data only on our instructions:

Provider Purpose Location
Supabase Database and authentication Singapore
Vercel Hosting and application delivery Singapore
Resend Sending transactional and marketing email United States
Stripe Card holds, deposits and charges Global
Cloudflare Bot protection (Turnstile) Global

Providers the venue chooses to connect. These are optional and only apply when the venue has switched them on. The venue, not Nice Work, holds the account with the provider:

  • Meta (WhatsApp Business). Reminders and confirmations sent over WhatsApp go through Meta's WhatsApp Cloud API using the venue's own WhatsApp Business account.
  • Meta (advertising). If the venue connects its Meta ad account, a Meta Pixel runs on that venue's booking page and we send booking and dine-in events to Meta's Conversions API. Contact details in those events are hashed before they leave our servers.
  • Google (Reserve with Google). If the venue enables it, we publish the venue's availability to Google, and bookings made on Google are delivered to the venue through our service.
  • Google Analytics. If the venue has added its own tag to its booking page.

Legal and safety. We disclose data when the law requires it, to enforce our terms, or to protect the rights and safety of diners, venues or the public.

Business transfers. If Nice Work is acquired or merges, data may transfer to the new owner under this policy.

6. Cookies

We use strictly necessary cookies to keep venue staff signed in and to protect forms against bots. We do not run advertising or analytics cookies of our own on booking pages.

A venue may add its own Meta Pixel or Google tag to its booking page, in which case those providers set cookies under their own policies. Where the law requires, the venue is responsible for obtaining consent for those cookies.

7. International transfers

Our servers are in Singapore. Some providers listed above process data outside Singapore. Where that happens we rely on contractual commitments that meet the PDPA's transfer requirements, and on the providers' own security certifications.

8. How long we keep data

  • Bookings and guest profiles. Kept for as long as the venue keeps its Nice Work account, so the venue can recognise returning guests and keep records.
  • Card references. Kept until the hold is released or the charge is settled, plus the period Stripe requires for disputes.
  • Marketing consent records. Kept for as long as the guest profile exists, including the date consent was given and withdrawn, as evidence.
  • When a venue closes its account. Its data is held for 30 days in case the closure was a mistake, then permanently deleted from our systems. Stripe and Meta retain what their own policies require.
  • Logs and backups. Server logs are kept for 30 days. Database backups are kept for 7 days and are overwritten in the normal cycle.

9. Your rights and choices

Access and correction. You can ask for a copy of the personal data we hold about you, and ask us to correct it. Diners should ask the venue first, because the venue controls the data. If you contact us instead, we will pass the request to the venue and help them respond.

Withdrawing consent. Every marketing email has a one-click unsubscribe link. Reply STOP to any WhatsApp message to stop WhatsApp messages. You can withdraw other consent by contacting the venue or us, and we will explain any consequences, such as being unable to send booking reminders.

Deletion. Ask the venue to delete your guest profile. Venue staff can delete their own account from inside the service, subject to the 30-day grace period in section 8.

Complaints. Contact us first at hello@nicework.sg. You may also complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg. If you are outside Singapore, you may have additional rights under your local law and may contact your local regulator.

We respond to requests within 30 days.

10. Security

We protect data with encryption in transit and at rest, role-based access controls that restrict each venue to its own data, encrypted storage of integration tokens, audit logging of sensitive actions, and bot protection on public forms. No system is perfectly secure. If we discover a breach that is likely to cause significant harm, we will notify affected venues and, where required, the PDPC and the individuals concerned.

11. Changes to this policy

We will post any changes here and update the date at the top. For material changes we will notify venues by email at least 14 days before they take effect.

12. Contact

Shinsora Pte. Ltd.
261 Waterloo Street #03-11, Waterloo Centre, Singapore 180261
hello@nicework.sg

© 2026 Nice Work · Shinsora Pte. Ltd.Terms of ServiceContact