OpenTable keeps the rights to the diner data it sends you
Exports close 30 days after you leave. An exported phone number isn't permission to text, and a court struck down NYC's delivery-data law.

Every platform a restaurant uses tells it the same thing about guest data: it's yours. Reservation systems, delivery apps and POS vendors all say some version of it. The contracts are more specific, and they don't all say the same thing.
Three questions decide whether a guest list is actually yours. Can you export it? What are you allowed to do with it? And when does the export window close? The answers differ a lot by platform, and the time to find out is before you need the list, not the week you switch systems.
What you can export, platform by platform
From each platform's help center, terms or developer documentation, checked in September 2026:
| Platform | What you can export | Limits on marketing use |
|---|---|---|
| OpenTable | Guest CSV with name, phone, email, opt-in status, birthday, anniversary | Email only guests who opted in; OpenTable's SMS tools can't be used for marketing; export only during the contract and 30 days after |
| Resy | Guestbook download, filterable by visits, tags and opt-in | Email only guests marked as marketable |
| Tock | Opted-in guest CSV, plus a full directory download | Opted-in list is the one meant for marketing |
| SevenRooms | Says restaurants own first-party guest data | Guests who booked through DoorDash Reservations need their own opt-in |
| Toast | Guestbook CSV; the download link expires after 72 hours | Profiles carry email and SMS subscription status |
| Square | Customer directory import and export | Only subscribed customers; receipt emails can't be marketed to without separate consent |
| Clover | Customer records with email, phone and a marketingAllowed flag, via API | Use the flag |
| Uber Eats | Customers who share with you: name, email, order history (phone not listed) | Promotional email to customers who share |
| DoorDash marketplace | No routine contact details; shared when a customer joins your loyalty program | Loyalty members who consented |
| Grubhub | Marketplace: no individual diner data. Grubhub Direct: full customer download | Direct customers, for your own marketing |
I couldn't verify export steps for Yelp Guest Manager or ezCater from their own documentation. A competitor's migration guide says Yelp data comes by request, and that some rows have only date, time and party size, because Yelp lets guests withhold contact details.
OpenTable, read closely
OpenTable's marketing says restaurants own their data. Its client agreement, updated in July 2026, divides the data in two:
- "Client Data" is what you put in, such as walk-ins you entered and notes you wrote. You keep the rights to it.
- "Online Reservation Data" is the diner information OpenTable provides. Section 15 says OpenTable "and its licensors retain all intellectual property and other rights in" it.
Both can be exported, but only during the contract and for 30 days after it ends. After that, the list is gone.
Two 2026 changes are worth knowing if you're signing or renewing. From April 16, new partners must use OpenTable as their primary table management system. And a "Global Guestbook" links walk-in and phone guests to those diners' OpenTable accounts. Guests who never booked through OpenTable can end up in its system through your host stand. Contracts also moved to 12-month auto-renewal.
None of this is unusual for a marketplace; it's what a network does. It does mean "we own our guest list" is true only for the part you entered, and only if you export it while you can.
Delivery apps share less than you'd expect
The marketplaces keep the customer. DoorDash doesn't routinely share contact details; they reach you when a customer joins your loyalty program through the app. Uber Eats lets customers share their name, email and order history with a restaurant. Grubhub's marketplace gives you no individual diner data, while its Grubhub Direct ordering sites let you download everything.
New York City tried to change this. A 2021 law required delivery apps to hand restaurants each customer's name, email, phone number and order details on request. A federal judge struck it down under the First Amendment in September 2024, and the federal appeals court affirmed in August 2026, according to reporting on the decision. One judge called the list it would have created "a marketing list that no customer asked to join."
The practical answer is the one from the delivery post in June: customers who order on your own site are the ones whose details you actually get.
An export is not permission
This is where exported lists get restaurants into trouble. Having a guest's contact details and being allowed to market to them are two different things.
- Email is the forgiving channel. Federal law doesn't require opt-in before a commercial email, but every message needs a working unsubscribe and a postal address, and opt-outs must be honored within 10 business days. Penalties reach $53,088 per email. Platforms add their own rules on top: OpenTable and Resy limit marketing to guests who opted in.
- Texts are not forgiving. Marketing texts need prior express written consent. A phone number exported from a reservation system was given to confirm a booking, not to receive promotions. Import it into an SMS tool and text it, and you've created a Telephone Consumer Protection Act problem, which carries per-message damages.
The full consent rules are in the email and SMS marketing post. The short version: keep the opt-in column when you export, and don't merge lists in a way that loses it.
What I'm not going to give you
Export steps for Yelp, ezCater and SevenRooms. Their documentation was behind logins or unavailable to me. Ask each vendor, in writing, what an export contains and in what format.
A count of state privacy laws. It changes often enough that any number I gave would be stale. Most independent restaurants fall below California's threshold of $26.6 million in revenue in any case.
A ruling on who owns what in your contract. Read the data section of each agreement you've signed. The OpenTable split above is a good guide to what to look for.
What to do
- Export every guest list now, and then monthly. Don't wait until you're switching; windows close.
- Keep the consent fields with each record: email opt-in, SMS opt-in, and the source.
- Keep one master list in a system you control, fed from each platform's export.
- Read the data section before signing or renewing, especially the part that says who holds rights to the data the platform provides.
- Never text an imported phone list without written consent collected for marketing.
- Move repeat delivery customers to your own ordering channel, where their contact details come to you directly.
Disclosure: I work at Katalyst, which sells a POS with guest profiles and data exports, so I benefit when restaurants keep their guest list in their own system. The advice in step 1 applies to us as much as to anyone. Export from your POS on a schedule too.
Related Katalyst products
See how Katalyst handles your service style
A 30-minute walkthrough of the platform, tuned to how your restaurant actually runs.



