Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
UMAI is a restaurant reservation, guest management and marketing platform operated from Malaysia. Its booking widget is embedded on a restaurant website so diners can check availability and reserve a table, collecting personal data such as name, contact details, party size and reservation history. The widget stores booking details in first party cookies and localStorage and, through connected marketing and analytics tools, sets non essential cookies. The booking itself can rely on contract, but those marketing and analytics cookies may only be set after the diner has given consent.
UMAI is a restaurant reservation, guest management and marketing platform operated by UMAI Restaurant Software from Kuala Lumpur, Malaysia. It gives restaurants a booking widget that is embedded on their website, along with table management, a guest CRM and marketing automation. A diner uses the embedded widget to check real time availability, choose a date, time and party size and confirm a reservation without leaving the restaurant website.
When a diner makes a reservation, the widget collects personal data such as name, email address, telephone number, party size, special requests and, over time, a history of past reservations, preferences and no shows that builds a guest profile in the UMAI CRM. To operate the booking flow, UMAI stores booking details in first party cookies and browser localStorage. Through connected marketing and analytics integrations such as Google Tag Manager, Google Analytics and the Meta Pixel, the widget can also set non essential cookies that measure widget performance and support remarketing to diners.
The diner details and the identifiers UMAI processes are personal data under the GDPR, because they relate to identifiable individuals. Storing and reading identifiers on the diner device also falls within Article 5(3) of the ePrivacy Directive. The strictly necessary booking session is exempt from prior consent, but the marketing and analytics cookies are not, and the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all enforce a strict prior consent obligation for such non essential trackers.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The booking transaction itself can rest on the performance of a contract or on steps taken at the request of the diner under Article 6(1)(b) GDPR, so the strictly necessary booking session may run without prior consent. The non essential marketing and analytics cookies set through the widget are different: they require prior, freely given, specific, informed and unambiguous consent under Article 6(1)(a) GDPR, and it must be as easy to refuse as to accept. Until the diner accepts, those marketing and analytics cookies should not be set.
UMAI is operated from Malaysia and hosts its platform in the Asia Pacific region, so diner data is transferred outside the European Economic Area. Malaysia is not covered by a European Commission adequacy decision, so the transfer requires the EU Standard Contractual Clauses 2021/914 within the UMAI data processing agreement and a documented Transfer Impact Assessment, in line with the Schrems II ruling and the guidance of the European Data Protection Board. Where the widget also loads Google and Meta tools, data may additionally reach the United States under the same clauses.
Gate the non essential UMAI cookies behind your consent management platform so that Google, Meta and other marketing and analytics tags fire only after the relevant category is accepted, while keeping the booking session available so diners can always reserve. Provide clear information about UMAI in your cookie policy, including the booking and marketing cookies it sets and their lifetime. Sign the UMAI data processing agreement, complete a Transfer Impact Assessment and apply the shortest workable retention on guest records. Collect only the diner data you need to manage the reservation.
Websites using UMAI must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is advisable when the UMAI booking widget is used at scale or combined with marketing profiling of diners. Document the diner data collected by the widget, meaning name, contact details, party size, special requests and reservation history, the booking cookies and localStorage entries, the non essential marketing and analytics cookies set through the Google and Meta integrations, the transfer of data to Malaysia and potentially the United States, and the retention period applied to guest records. Configure the widget so that non essential cookies load only after consent and keep the booking session limited to what is necessary to complete the reservation.
Sample consent text
We use UMAI, a restaurant reservation and guest management service operated by UMAI Restaurant Software (Malaysia), to take your booking. The reservation itself is processed to fulfil your request. UMAI and connected tools also use marketing and analytics cookies that are not necessary for the booking, and your data may be transferred outside the European Economic Area under the EU Standard Contractual Clauses. These non essential cookies will only be set if you click Accept.
Third-party domains contacted
umai.ioreservation.umai.ioletsumai.comgoogletagmanager.comconnect.facebook.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| umai_booking_session | HTTP cookie (first party) | Session | Maintains the reservation session in the UMAI booking widget so the diner steps, selected date, time and party size and submitted details are grouped together during a single booking. Strictly necessary for the booking to work. |
| umai_widget_storage | localStorage | Persistent (until cleared) | Stores booking widget state and the diner details entered in the reservation form, such as name and contact information, so the form is convenient to reuse and can resume where the diner left off. |
| _ga | HTTP cookie (first party) | 13 months | Set through the UMAI Google Analytics and Google Tag Manager integration to distinguish diners and measure how the booking widget and pages are used. Non essential analytics cookie that requires consent. |
| _fbp | HTTP cookie (first party) | 3 months | Set through the UMAI Meta Pixel integration to identify browsers for advertising measurement and remarketing to diners on Meta platforms. Non essential marketing cookie that requires consent. |
UMAI collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The UMAI booking widget stores booking details in a first party session cookie and in browser localStorage so the reservation form and guest information persist during a visit. Through its marketing and analytics integrations it can also set non essential cookies, such as the Google Analytics identifiers and the Meta Pixel cookie, for measurement and remarketing.
You do not need consent for the strictly necessary booking session, which is exempt because it is required to deliver the reservation the diner requested. You do need prior consent before the non essential marketing and analytics cookies set through UMAI, so those should stay blocked until the diner accepts.
Two bases apply. Managing the reservation rests on contract under Article 6(1)(b) GDPR, so the booking session can run without consent. The non essential marketing and analytics cookies rely on consent under Article 6(1)(a) GDPR combined with Article 5(3) of the ePrivacy Directive. Legitimate interest cannot cover those trackers.
Yes. UMAI is operated from Malaysia and hosts data in the Asia Pacific region, and Malaysia has no EU adequacy decision, so diner data leaves the European Economic Area. Where the widget loads Google and Meta tools, data may also reach the United States. You need the EU Standard Contractual Clauses and a Transfer Impact Assessment to cover both.
A Data Protection Impact Assessment is recommended when UMAI is used at scale or when guest data is combined with marketing profiling. Assess the diner data collected, the booking and marketing cookies, the guest CRM enrichment and the transfer to Malaysia and potentially the United States.
Keep the booking session running so diners can always reserve, but load the non essential marketing and analytics cookies only through your consent management platform after the relevant category is accepted. Describe UMAI in your cookie policy, sign the data processing agreement, complete a Transfer Impact Assessment and apply a short retention period on guest records.
Alternatives include TheFork, OpenTable, SevenRooms, Resy, Formitable and Zenchef. They raise similar consent, cookie and transfer questions, so evaluate each provider's hosting location and data processing terms before assuming any of them is lighter on privacy.
Add a dedicated entry that names UMAI as the provider, separates the strictly necessary booking cookies from the non essential marketing and analytics cookies, lists each cookie with its lifetime, explains the diner data collected, and discloses the transfer to Malaysia and potentially the United States and its safeguard. Keep the entry in step with your consent categories.