Skip to main content
rectangle-6702-3

 

OPENTABLE SECURITY CENTER

OpenTable Trust & Security Center

For over 25 years, OpenTable has built a trusted, reliable platform for diners and restaurants. Whether you’re booking a table or managing a busy restaurant, we’re committed to protecting your privacy, ensuring fair treatment, and keeping our platform safe.

Certified security you can rely on

OpenTable is dedicated to compliance with the highest global standards to protect your information at every step. We’re proud to align our practices with the following frameworks.

SOC 2 Type II compliance logo.

SOC 2 Type II

System and Organization Controls 2

Our SOC 2 Type II compliance, validated by independent audits, demonstrates our commitment to robust controls across security, availability, processing integrity, confidentiality, and privacy.

PCI DSS compliance logo.

PCI DSS

Payment Card Industry Data Security Standard

We follow strict controls to protect your payment card information and keep every payment secure, in accordance with the latest PCI DSS standards.

GDPR compliance logo.

GDPR

General Data 
Protection Regulation

Trust is paramount. That’s why we rigorously uphold data privacy rights across Europe, giving you control over the use of your personal data.

CCPA Compliant logo.

CCPA

California Consumer Privacy Act

We empower California residents with control over their personal information in accordance with the California Consumer Privacy Act.

PIPEDA - Canada's privacy legislation logo.

PIPEDA

Personal Information Protection and Electronic Documents Act

We respect the privacy of our Canadian users and operate in compliance with Canada’s PIPEDA legislation.

Data Privacy Framework Program logo.

EU-U.S. DPF, Swiss-U.S. DPF, UK

Data Privacy Framework Extensions

OpenTable is committed to upholding international data transfer standards. We participate in and comply with the EU-U.S. DPF, the Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF for the transfer of personal data from the EU, Switzerland, and the UK.

Want to dive deeper?

OpenTable partners: Contact your Account Manager for access to specific compliance certificates.

Read our Privacy Policy

For guests: Book and dine with confidence

Our guests’ personal and financial information deserves the highest level of protection. That’s why we build privacy and security into everything we do—from encrypting your data during booking to storing it securely.

Secure data encryption

We encrypt your data in transit and at rest.

Proactive threat monitoring

We’re here 24/7, monitoring for threats and taking action to help protect your account and peace of mind.

Privacy-driven processes

We follow global privacy laws like GDPR and CCPA—giving you transparency and control.

Verified restaurant listings

Every restaurant on OpenTable is vetted to ensure real, high-quality dining experiences.

Clear booking policies

We display restaurants’ booking and cancellation policies clearly so you know before you book.

Respectful community standards

We expect—and enforce—respectful behavior from guests and staff alike.

For restaurants: Secure operations for trusted dining experiences

OpenTable enables restaurants to run secure operations and protect what matters most: their guests, data, and reputation. From fraud prevention to transparent policies, our platform is designed to earn and keep your trust.

shieldplus

Secure infrastructure

We safeguard your guest data with industry-standard security protocols and compliance.

faders

Access controls

User-friendly tools help you manage user permissions so you can protect sensitive data.

usercircle

Data ownership

We help you use your guest data responsibly to grow your business.

star

Verified reviews

Only verified guests can leave reviews—and we moderate for fairness and respect.

magnifyingglass

Fair visibility

Paid promotions never replace organic search results so guests only see honest availability.

currencydollarsimple

Transparent pricing

No hidden fees—our pricing and commissions are clear and easy to understand.

WHAT OUR LEADERS SAY

“Your Security and Trust matter—whether you’re managing your restaurant on OpenTable or a guest making a reservation. We’ve implemented strong safeguards to protect your data, creating a secure environment for every interaction. You can trust OpenTable to prioritize your peace of mind, ensuring a safe and seamless experience for all.”

Chris Kennedy

SVP – Technology Operations & CISO at OpenTable

Chris Kennedy, SVP of Technology Operations and CISO at OpenTable.

We prioritize transparency and reliability

We’re committed to keeping your restaurant running smoothly—and securely. That means being upfront about security practices and platform performance, while continually investing in our infrastructure to stay ahead of emerging threats.

We prioritize transparency and reliability

We’re committed to keeping your restaurant running smoothly—and securely. That means being upfront about security practices and platform performance, while continually investing in our infrastructure to stay ahead of emerging threats.

99.9% platform uptime.

 

System status

Check real-time updates on system availability—so you’re always in the know.

99.9% platform uptime.

 

System status

Check real-time updates on system availability—so you’re always in the know.

We prioritize transparency and reliability

We’re committed to keeping your restaurant running smoothly—and securely. That means being upfront about security practices and platform performance, while continually investing in our infrastructure to stay ahead of emerging threats.

99.9% platform uptime.

 

System status

Check real-time updates on system availability—so you’re always in the know.

For restaurants: Security tips for your team

Empower your front-of-house and management teams with these simple, effective practices to keep information safe and stop issues before they start.

Strengthen passwords and limit account access

Use unique, complex passwords—and update them often. Set role-based permissions and never share login credentials.

Secure your devices

Keep POS terminals and tablets secure by locking screens when unattended and keeping your operating systems up to date.

Handle guest data with care

Be discreet with printed or written guest information. Dispose of sensitive data securely and follow your restaurant’s privacy policy.

Spot phishing & social engineering

Watch out for suspicious emails or requests for sensitive information like login details. Verify requests through trusted channels.

Report suspicious activity right away

Establish a clear process for staff to report potential security concerns immediately.

Be careful what you download

Malware and shady browser extensions can steal your login info. Only install trusted tools and keep software up to date.

Turn on two-factor authentication wherever you can

Two-factor authentication adds an extra layer of protection to your accounts—from OpenTable for Restaurants to email and banking.

Create individual logins for every team member

Avoid shared credentials by setting up separate accounts for each staff member. It keeps your data secure and makes tracking easier.

customizable-floor-plans

Frequently asked questions

Restaurants own their data, and guests own their data.

Guest data entered by a restaurant into its OpenTable system is owned by the restaurant, including any data collected when a guest makes a reservation over the phone or walks in.

Guests who come to OpenTable’s consumer-facing properties to make a reservation maintain ownership of their data. Since OpenTable is a consumer marketplace where millions of diners make reservations via OpenTable properties, we process a vast ecosystem of guests and guest-related information. We will securely share this information with restaurants to enhance your business – as long as the guest grants us permission to do so. Gaining and maintaining guests’ trust is critical for OpenTable to service our restaurant partners with guest demand, and ultimately keeps restaurants compliant with privacy laws as well.

As long as guests grant OpenTable permission to share their information, we securely share it. By agreeing to OpenTable’s Privacy Policy, the guest grants OpenTable certain rights to use their data – including the right to share their data with restaurants. Any restrictions on what OpenTable can share with restaurants is determined by what scope of data the guest agreed to in OpenTable’s Privacy Policy.

Guests who book through OpenTable may opt out of certain data-sharing activities through their account preferences. In cases where guests choose to opt-out, OpenTable is required by law to honor guest choice about how their information is used and shared. This is a requirement for OpenTable to stay compliant with privacy laws, as well as protect restaurants from risk.

OpenTable operates as a data processor, merely facilitating the reservation process and enabling guests to access restaurants for booking.

OpenTable’s use of a restaurant’s data is limited to the rights and permissions granted in the Client Agreement. That restaurant data is used for the limited purposes of promoting the restaurant on OpenTable properties, helping guests to make restaurant bookings, and enabling the restaurant reservation.

OpenTable also aggregates and anonymizes data to better service guests and restaurant partners.

All data received by the restaurant is handled in compliance with applicable data privacy laws and is processed and stored based on our robust, SOC 2 certified security program.

At OpenTable, we prioritize the security of your payment card information. When you enter your card details to make a reservation or payment, your information is encrypted using secure protocols during transmission. OpenTable does not store your payment card information. Instead, we partner with trusted, PCI-compliant payment processors who handle and store your data securely. We require these processors to keep your information secure and confidential.

At OpenTable, we prioritize privacy and are transparent about how we handle guests’ personal information. As permitted by applicable law, we share guest data with trusted partners—such as restaurants, service providers, and advertising partners—to enhance the dining experience and improve our services. 

For more information, view the “How We Share Your Information” section of our Privacy Policy.

OpenTable’s SOC 2 Type II compliance, validated by an independent auditor, proves that we rigorously safeguard your data with robust, consistently effective controls. This means you can trust us to protect your information and ensure the reliability of our services, giving you peace of mind. 

OpenTable employs a comprehensive array of security measures and controls to safeguard restaurant accounts, which include:

  • Multi-Factor Authentication (MFA): Restaurants have the option to enforce MFA for their staff accounts, enhancing security measures.
  • Granular Access Controls: Role-based access controls are implemented to ensure that employees have access only to the information needed to carry out their responsibilities.
  • Device Verification: To protect your most sensitive data and actions, our application enforces access controls that go beyond simple logins. Only devices that have been explicitly trusted by the user can access certain high-risk features.
  • Network Security: OpenTable ensures that all data exchanged between its restaurant clients and data centers is protected through encryption using secure transport protocols. Additionally, data stored within OpenTable databases is also encrypted, safeguarding it from unauthorized access.
  • Secure Data Centers: All OpenTable data centers are compliant with industry-standard security certifications, including SOC 2 Type II, PCI DSS, and ISO standards and international data security regulations. Data centers enforce stringent physical security standards and environmental protections.

To report a concern, please contact our customer support team.

  • We integrate artificial intelligence (“AI”), including generative AI, into our content, features, and Services (including OT4R).
  • This may involve partnerships with third-party entities or the use of their large language models.
  • We process your input and generate data to deliver and improve our Services, ensuring quality and troubleshooting, in accordance with our Terms and our Privacy Policy.
  • We have strict protocols to limit third parties from training their AI on your personal or sensitive data.
  • AI-generated content is provided “as-is” without guarantees of relevance, accuracy, or completeness, and we are not liable for its use.
  • Powering your experience: We leverage both established ML and cutting-edge LLM AI to enhance our Services for internal operations and direct restaurant/diner interactions.
  • Responsible AI: Our AI systems, classified as “limited risk” under the EU AI Act, are built with careful consideration for user safety.
  • Privacy-centric design: We deliberately exclude direct PII like names, emails, and phone numbers from our AI models.
  • Understanding your needs: While anonymized, insights into user behaviors and preferences help us personalize and improve your experience.
  • Innovation with safeguards: We are committed to utilizing the power of AI responsibly, prioritizing user privacy and adhering to regulatory standards.

OpenTable implements device verification to enhance data security. When a restaurant user logs in from an unfamiliar network, sensitive guest information, also known as Personally Identifiable Information (PII), such as email addresses or phone numbers, will be obscured. This measure helps protect PII from unauthorized access. Device verification is also required for critical guest-facing features like creating or editing Experiences, defining Booking Policies, and sending direct marketing communications among others, ensuring that only verified devices can manage these sensitive interactions.

Learn more about data security and privacy

Explore our related articles to learn more about data privacy, data protection best practices, OpenTable’s privacy policy, and how we safeguard restaurant and guest information every step of the way.