SevenRooms
United States · sevenrooms.com · 40 vendors
Resilience scores
- Digital Sovereignty: 75
- Digital Resilience: 7
- Financial Resilience: 8
Technology vendors
- Anthropic, PBC — Technology — United States
- Curator Hotel & Resort Collection — United States
- Stripe, Inc. — Financial Services — United States
- and 39 more
Services catalogue
1 service in catalogue across 1 category; runs on 40 sub-vendors.
- SevenRooms
Insights
Last updated 2026-08-14 · revision 2
40 direct vendors, 285 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- Australia: 1
- Netherlands: 2
Subvendors by controlling owner country (sample)
- Germany: 8
- Israel: 2
- Serbia: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SevenRooms exhibits a high degree of migration readiness, largely attributable to its deeply integrated cloud-native architecture on Google Cloud Platform (GCP). The extensive use of GCP services, coupled with a modern internal tech stack (Python, TypeScript, ReactJS, Redux, Django), signifies a flexible and modular system that is well-positioned for further cloud optimization or potential migration within a cloud ecosystem. The explicit mention of 'API & Integrations' with over 100 pre-built integrations highlights an API-first approach, which greatly facilitates data portability and interoperability, key aspects of successful migrations. Despite these strengths, certain unknowns introduce potential complexities. The 'Vendor Lock-in Risk' is unspecified; while vendor geographic diversity is present (8 countries for 57 services), the sheer number of services and integrations could imply complex dependencies that might complicate a full migration away from their current ecosystem. The absence of data on specific regulatory environments and data residency requirements means potential compliance hurdles are unknown. Additionally, the lack of financial stability data makes it impossible to assess the company's capacity to fund a large-scale migration project. However, the strong cloud-native foundation and API strategy are significant advantages, indicating high readiness for evolving their digital infrastructure.
Compliance
9 in-scope frameworks identified; showing 3.
Singapore PDPA — Assessment Required
SevenRooms has confirmed Singapore operations — a press release about Singapore dining habits is listed on the Our Story page, and the Brotzeit case study (12 locations, $2M revenue generated) appears to be a Singapore-based restaurant group. Risk is Medium because: (1) Singapore operations are confirmed; (2) PDPA applies to organizations collecting, using, or disclosing personal data of Singapore residents; (3) PDPA was significantly amended in 2021 with enhanced obligations including mandatory data breach notification, increased financial penalties (up to 10% of annual Singapore turnover or SGD $1M), and data portability obligations; (4) cross-border transfer restrictions apply under PDPA.
Evidence: https://sevenrooms.com/our-story/, https://sevenrooms.com/, https://sevenrooms.com/privacy-policy/
CPRA — Compliant
SevenRooms explicitly lists CCPA as a compliance item on its Trust Portal and dedicates a detailed section of its Privacy Policy to California residents' rights under CCPA and CPRA. The company has implemented required disclosures, opt-out mechanisms, and data subject rights procedures. Risk is Low because active compliance measures are documented and publicly disclosed. Ongoing risk relates to CPRA amendments and enforcement by the California Privacy Protection Agency (CPPA).
Evidence: https://trust.sevenrooms.com/?itemUid=4064ac33-7b48-407b-aed7-ce02971d1ec1&source=click, https://sevenrooms.com/privacy-policy/, https://trust.sevenrooms.com/
SOC 2 (source) — Compliant
SevenRooms has confirmed SOC 2 compliance, which is listed as an active compliance item on its Trust Portal. As a cloud-based SaaS platform processing personal data for 15,000+ restaurant clients globally, SOC 2 is highly relevant and expected by enterprise clients (confirmed enterprise clients include MGM Resorts International, Bloomin' Brands, Live Nation). The risk level is Low because the company has demonstrated active compliance with this framework, maintains a SecurityScorecard Grade A rating, and has a comprehensive security program evidenced by its Trust Portal. Ongoing risk relates to maintaining annual SOC 2 audit cycles and ensuring continued compliance as the platform scales.
Evidence: https://trust.sevenrooms.com/, https://trust.sevenrooms.com/?itemUid=7bfa66da-33ab-49de-8391-e329738a1ae9&source=click, https://trust.sevenrooms.com/?itemUid=e4e84d80-25cf-4c34-b518-d3e093f54f28&source=click
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 8/10
SevenRooms demonstrates strong financial resilience, particularly following its acquisition by DoorDash in May 2025. As a private, venture-backed company prior to the acquisition, it exhibited robust growth of 417% over three years (2020-2023) per the Inc. 5000 list, indicating a strong recurring SaaS revenue model with sticky CRM data creating high switching costs. The company had raised approximately US$71M+ in publicly known funding including a US$50M PSG Equity round in 2020, supported by blue-chip investors like Amazon and Comcast Ventures. The acquisition by DoorDash (a US$60+ billion market-cap public parent) effectively removes solvency risk, embedding SevenRooms within a well-capitalized public company. Its enterprise customer base includes premier brands like Marriott, MGM Resorts, Mandarin Oriental, Wynn Resorts, and Jumeirah, implying enterprise-tier ARR and multi-venue contracts. Venue count growth from ~10,000 (2024) to 15,000+ (2026) demonstrates consistent double-digit customer expansion. However, standalone profitability remains unconfirmed, and the business faces cyclicality risk given hospitality end-markets are highly sensitive to consumer discretionary spending and macro shocks (as evidenced by COVID-19 impact). Competitive intensity is significant with Toast, OpenTable, Resy, Tock, and TheFork all vying for market share. Integration risk with DoorDash also poses near-term challenges.
Key strengths: Acquisition by DoorDash (~US$1.2B) removes solvency risk, 417% three-year revenue growth (2020-2023) per Inc. 5000, Blue-chip enterprise customer base (Marriott, MGM, Mandarin Oriental), Strong VC backing including Amazon, Comcast Ventures, PSG Equity, Recurring SaaS model with high switching costs via embedded CRM data, 15,000+ venues globally, consistent double-digit customer growth, Three consecutive years on Inc. 5000 list (2022, 2023, 2024)
Risk factors: End-market cyclicality in restaurants and hospitality, Intense competition from Toast, OpenTable, Resy, Tock, TheFork, Post-acquisition integration risk with DoorDash, Standalone EBIT profitability not confirmed, Potential channel conflict with OpenTable partnerships and DoorDash marketplace, Sensitivity to consumer discretionary spending and labor availability
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.