Privacy Policy

Last updated: July 2, 2026

Sneaker Pack LLC (“we,” “our,” or “us”), a Delaware limited liability company operating as Mise, is committed to protecting your privacy. Mise is an automated restaurant reservation booking service that monitors reservation platforms for availability and executes millisecond-precise burst booking on your behalf when tables become available. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website, and related services (collectively, the “Service”).

By creating an account or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with these practices, please do not use the Service.

Notice at Collection

At the point of collection, Mise gathers personal information directly from you when you create an account, link a reservation platform, subscribe to Mise Reserve, enroll as a Mise Market seller, submit a support request, or otherwise interact with the Service. The categories of personal information we collect and the business or commercial purpose for each category are described in detail in the “Information We Collect” section below. This notice is provided pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

1. Information We Collect

Account Information

When you create an account, we collect the following information to authenticate you and manage your profile:

  • Email address (optional for phone-only signups)
  • Phone number (used for one-time password authentication via SMS)
  • First name and last name
  • Referral attribution data (the user who referred you, if any)

Platform Credentials

To monitor availability and book reservations on your behalf, we collect your login credentials for third-party reservation platforms, which may include Resy, OpenTable, SevenRooms, Wisely, DoorDash, and Beli. These credentials are encrypted using AES-256-GCM encryption before storage and are never stored in plain text. You may unlink a platform account at any time, which deletes the encrypted credentials associated with that account.

Payment Information

We use Stripe to process subscription payments and marketplace transactions. Your payment card details are collected and stored directly by Stripe, which is certified as a PCI-DSS Level 1 Service Provider, and are never transmitted to or stored on our servers. We only receive and store:

  • Stripe customer ID and payment method ID for subscription billing
  • Subscription status and Stripe price identifier

For Mise Market sellers, we additionally collect Stripe Connect KYC (Know Your Customer) data required for payouts and tax reporting, which may include your legal name, date of birth, last four digits of your Social Security Number, and bank account information for payouts. This data is collected and verified by Stripe; we retain only the references necessary to manage your marketplace account.

For ambassadors, Stripe collects legal name, date of birth, address, and SSN/EIN for tax reporting (1099-NEC) during Stripe Connect onboarding. This data is collected and verified by Stripe; we retain only the references necessary to manage ambassador payouts and tax reporting.

SevenRooms vaults payment cards with AES-256-GCM encryption for prepaid reservations. When you authorize a SevenRooms prepaid booking, your card details may be stored in an encrypted vault to facilitate the transaction.

Reservation & Hunt Data

  • Venue names, identifiers, and platform you are searching
  • Desired reservation dates, time windows, and party sizes
  • Hunt configuration including Magic Mode, group hunts, and priority settings
  • Booking confirmation details when reservations are successful
  • Cancellation policies and prepaid authorization status
  • Synced reservation history from linked platform accounts

Device & Notification Information

  • Apple Push Notification service (APNs) device tokens for delivering push notifications
  • Device model, operating system version, and app version
  • IP address (used for session management and proxy routing)
  • Locale and timezone settings for displaying reservation times correctly

Log Data

We maintain logs to operate, debug, and secure the Service. These may include:

  • Hunt logs recording monitoring events, slot detection, booking attempts, and outcomes
  • Server logs including timestamps, request metadata, and HTTP status codes
  • Error logs capturing exceptions, stack traces, and diagnostic context
  • Antibot detection events (e.g., HTTP 403 responses from platforms)

Marketplace Data

If you participate in Mise Market as a buyer or seller, we collect:

  • Listing details including venue, date, party size, and asking price
  • Transfer records and reservation details shared between users for fulfillment
  • No-show reports and dispute information
  • Seller ratings and transaction history
  • Payout and tax identification data for 1099-K reporting

Automatically Collected Information

When you interact with the Service, we automatically collect certain information:

  • Session data stored in your device's local storage, including your authentication token and UI preferences
  • Usage data such as features accessed and actions taken within the app
  • Network information necessary for proxy routing and platform API communication
  • Referral attribution signals: when you open an invite link, we record the associated referral code alongside a one-way hashed fingerprint derived from your IP address and browser language. We cannot reverse this hash to your IP address, and we retain it only briefly (24 hours) to connect your invite to your first app launch, after which it is automatically deleted

We do not use third-party analytics or advertising cookies in the mobile application.

Ambassador & Affiliate Program Data

If you apply to or participate in the Mise Ambassador (affiliate) Program, we collect:

  • Ambassador application data: platform (Instagram, TikTok, YouTube, etc.), handle, follower count, city, pitch, and proposed referral code
  • Ambassador profile data: display name, platform, avatar URL, and title used on public creator pages
  • Referral code and curated collection (Creator's List) associated with your ambassador account
  • Conversion tracking data: for each successful referral, we track the conversion amount, status, payout amount, and payout date
  • Stripe Connect account ID for processing commission payouts and issuing tax forms (1099-NEC)

2. How We Use Your Information

We use your personal information for the following purposes:

  • Authentication: Verifying your identity and managing your account session
  • Monitoring: Polling reservation platforms for availability on your behalf
  • Booking: Executing automated burst booking using your linked platform credentials
  • Payments: Processing subscription charges via Stripe and managing Mise Reserve billing
  • Marketplace: Facilitating Mise Market listings, transfers, payouts, and dispute resolution
  • Ambassador Program: Managing ambassador applications, referral tracking, commission payouts, and tax reporting
  • Notifications: Delivering push notifications and emails when reservations are booked or availability is found
  • Support: Responding to customer support inquiries and resolving issues
  • Fraud Prevention: Detecting and preventing fraudulent activity, abuse, and violations of our terms
  • Legal Compliance: Fulfilling legal obligations including tax reporting and responding to legal process
  • Service Improvement: Analyzing usage patterns to improve features, performance, and reliability

3. How We Share Your Information

We share your personal information with the following categories of third parties as necessary to operate the Service:

Reservation Platforms

We transmit your platform credentials and booking requests to Resy, OpenTable, SevenRooms, Wisely, DoorDash, and Beli to search for availability and book reservations on your behalf. These platforms receive your account credentials, reservation preferences, and booking instructions as if you were using their services directly.

Payment Processor (Stripe)

We share payment-related data with Stripe for subscription billing, Mise Market seller payouts and KYC verification, and ambassador commission payout distribution via Stripe Connect. For ambassadors and marketplace sellers, Stripe collects and verifies KYC data (legal name, date of birth, address, SSN/EIN) required for tax reporting. Stripe's privacy policy: stripe.com/privacy

Email Service (SendGrid)

We use SendGrid to deliver transactional and service-related emails, such as booking confirmations and account notifications. SendGrid may process your email address and email content.

Push Notification Service (Apple APNs)

We use Apple Push Notification service (APNs) to deliver push notifications to your iOS device. APNs receives your device token and notification payload.

SMS Service (Twilio)

We use Twilio to deliver one-time passwords (OTPs) via SMS for phone-based authentication. Twilio receives your phone number and the OTP message content.

Cloud Hosting (Railway, PostgreSQL)

We host our application and databases on Railway, which provides PostgreSQL database instances. Your data is stored and processed on Railway's infrastructure, subject to Railway's security and privacy practices.

Proxy Network Providers

To access reservation platform APIs from IP addresses not blocked by those platforms, we route certain requests through proxy network providers. These providers may see the destination URL, request headers, and your platform credentials in transit, but do not retain your data beyond what is necessary to provide the proxy service.

Tax Authorities

For Mise Market sellers who exceed applicable thresholds, we report earnings via Form 1099-K to the Internal Revenue Service and applicable state tax authorities. For ambassadors who earn $600 or more in a calendar year, we report commission payments via Form 1099-NEC. This may include your legal name, address, taxpayer identification number, and gross transaction amounts.

Law Enforcement

We may disclose your information to law enforcement or government authorities in response to a valid subpoena, court order, or other legal process, or when we believe in good faith that disclosure is necessary to comply with applicable law, protect our rights, or ensure the safety of others.

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of substantially all of our assets, your information may be transferred as part of that transaction. We will notify you via email or in-app notice before your information is transferred under different ownership.

4. Proxy Usage and IP Address Disclosure

To access reservation platform APIs reliably, Mise routes platform interactions through proxy servers located in various regions. As a result:

  • Your platform account may show activity from IP addresses that are not your own
  • Platform login and booking requests may originate from proxy IPs rather than your device
  • This activity may trigger platform fraud detection or account security alerts
  • Platforms may flag, suspend, or ban your account due to perceived automated or suspicious activity

You acknowledge and accept these risks as a condition of using the Service. Mise is not responsible for any actions taken by reservation platforms against your account, including suspension or termination, arising from proxy-routed activity.

5. Automated Booking Disclosure

Mise performs reservation booking via automated software using your linked platform credentials. This includes monitoring for availability, executing burst booking attempts at release time, and auto-booking the first available slot when Magic Mode is enabled. You pre-authorize this automated activity when you create a hunt or enable Magic Mode.

Important: Automated booking may violate the Terms of Service of one or more reservation platforms. Platforms may detect and take action against your account, including warning, suspending, or permanently banning your account. By using Mise, you acknowledge and assume all risk of such platform actions. Mise is not liable for any consequences arising from platform enforcement against your account.

6. Data Security

We implement industry-standard security measures to protect your information:

  • Platform credentials are encrypted using AES-256-GCM encryption at rest
  • All data transmission between your device and our servers uses HTTPS/TLS encryption
  • Passwords are hashed using bcrypt; we never store passwords in plain text
  • Payment card data is handled exclusively by Stripe, which is PCI-DSS Level 1 certified
  • Database and server access is restricted to authorized personnel and monitored
  • SevenRooms prepaid cards are vaulted with AES-256-GCM encryption

Despite these measures, no method of transmission or storage is fully secure. We cannot guarantee absolute security of your information, and you acknowledge that you provide your personal information at your own risk.

7. Data Retention

We retain your personal information for the following periods:

  • Account data: Retained until you delete your account, plus 30 days for processing, after which it is permanently deleted
  • Encrypted platform credentials: Retained until you unlink the platform account, then deleted immediately
  • Hunt logs: Retained for 12 months for debugging and service improvement, then deleted
  • Booking records: Retained for 7 years for tax and legal compliance purposes
  • Marketplace records: Retained for 7 years for tax compliance, including 1099-K reporting obligations
  • Ambassador conversion records: Retained for 7 years for tax compliance, including 1099-NEC reporting obligations
  • Device tokens: Retained until you uninstall the app or the token is invalidated by Apple
  • OTP codes: Retained for 10 minutes, then permanently deleted

Database backups are retained according to our hosting provider's standard retention schedule. Information deleted from the primary database may persist in backups for up to 30 days before being overwritten. We do not restore deleted data from backups except to recover from system failure.

8. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to Know: Request the categories and specific pieces of personal information we have collected about you, the source, the purpose, and the third parties to whom it was disclosed
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions (e.g., legal retention obligations)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale or Sharing: Opt out of the sale or sharing of your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: Limit the use of your sensitive personal information to what is necessary to perform the services or maintain the functionality requested
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights

You may submit a request by emailing privacy@bookmise.com or through the in-app Settings > Help & Support menu. You may also designate an authorized agent to submit requests on your behalf by providing written authorization. We will verify your identity before processing your request and respond within 45 days of receipt, as required by California law.

“Do Not Sell or Share My Personal Information”

Mise does not sell your personal information to third parties, nor do we share your personal information for cross-context behavioral advertising purposes as those terms are defined by California law. We have not sold or shared personal information in the preceding 12 months and will not do so in the future without providing you with notice and an opportunity to opt out.

Note: Mise Market enables user-to-user transfers of reservations. When you participate in a transfer, certain reservation details (such as venue, date, party size, and guest name) are shared between the buyer and seller for fulfillment purposes only. This sharing is necessary to complete the transaction you initiated and is not for advertising or commercial purposes unrelated to the Service.

9. Sensitive Personal Information (CPRA)

Under the CPRA, certain categories of information are classified as “sensitive personal information.” We collect the following sensitive personal information:

  • Platform account credentials (Resy, OpenTable, SevenRooms, Wisely, DoorDash, Beli), which constitute account login information
  • Stripe Connect KYC data for Mise Market sellers and ambassadors, which may include government identification numbers (last 4 of SSN) and financial account information

You have the right to limit our use of your sensitive personal information to what is necessary to perform the services or maintain the functionality you requested. To exercise this right, contact us at privacy@bookmise.com or via in-app Settings > Help & Support. We will process your request within 45 days.

10. Your Privacy Rights (EEA, UK, Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and applicable national data protection laws:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data (“right to be forgotten”)
  • Right to Restriction of Processing: Request that we limit the processing of your personal data
  • Right to Data Portability: Receive your personal data in a structured, machine-readable format
  • Right to Object: Object to the processing of your personal data for certain purposes
  • Rights Regarding Automated Decision-Making: Request human intervention regarding decisions made solely by automated means

Lawful Basis for Processing: We process your personal data on the basis of performance of a contract (to monitor availability and book reservations on your behalf), legitimate interests (to operate and secure the Service), and consent (for marketing communications, which you may withdraw at any time).

You have the right to lodge a complaint with your local data protection supervisory authority. For international data transfers, we rely on Standard Contractual Clauses approved by the European Commission and, where applicable, the EU-U.S. Data Privacy Framework and the UK Extension to the Data Privacy Framework.

11. Automated Decision-Making and Profiling

Mise performs automated booking using software that operates your linked platform credentials without human intervention. Specifically:

  • Reservations are booked automatically by software using your credentials when availability is detected
  • Magic Mode auto-books the first available slot that meets your criteria without additional confirmation
  • You pre-authorize this automated activity when you create a hunt or enable Magic Mode

Under Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. You may request human intervention by contacting privacy@bookmise.com. We will review your request and provide a response within 30 days.

12. Cookies and Tracking Technologies

Our website uses local storage to store your authentication token and UI preferences (such as theme selection). We do not use third-party analytics or advertising cookies. The Mise iOS application does not use cookies and is subject to Apple's App Tracking Transparency framework. We do not track your activity across other companies' apps or websites for advertising purposes.

13. Children's Privacy

Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected personal information from a minor, please contact us at privacy@bookmise.com and we will promptly delete such information.

14. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users and applicable regulators without undue delay, and in any case within the timeframes required by applicable law (including within 72 hours where required by the GDPR). Notifications will describe the nature of the breach, the likely consequences, and the measures we are taking to address it and mitigate its effects.

15. International Data Transfers

Your personal information is processed and stored on servers located in the United States. If you are accessing the Service from outside the United States, you should be aware that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework (and UK Extension) as applicable legal transfer mechanisms.

16. Third-Party Links

The Service may contain links to third-party websites or services, including reservation platforms and payment processors. We are not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the features of the Service. When we make material changes, we will notify you by email, in-app notice, or by posting the updated policy on this page and updating the “Last updated” date. We encourage you to review this policy periodically. Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.

18. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us using either of the following methods:

Sneaker Pack LLC

Operating as Mise

Email: privacy@bookmise.com

In-app: Settings > Help & Support