Tablfy Last updated: 17 September 2026
GETBOOKINGS PTY LTD (“we”, “us”, “our”) is a marketing and technology company for hospitality venues. We operate Tablfy, our marketing and booking platform, available at tablfy.com, through our mobile apps, and through websites and booking pages we build and host on venues' own domains. Tablfy is built for venue owners and managers to consolidate their marketing and booking data into a single platform, helping them understand the real ROI of their advertising spend against actual reservations.
This Privacy Policy explains what personal and business information we collect, how we use it, who we share it with, and what rights you have. It applies to venue owners, managers and staff who use the Tablfy service, to guests who book, enquire, or otherwise interact with a Tablfy-hosted booking page, widget, enquiry form or venue website, and to visitors to our own marketing website at tablfy.com.
We are committed to handling all information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Questions? Contact us at privacy@tablfy.com.
We collect and process booking data in two ways: when you connect your booking management software via email forwarding or direct integration, and when guests book directly through Tablfy-hosted booking pages, widgets, waitlists, or enquiry forms. This may include:
This data belongs to your venue and we process it on your behalf. We retain it to operate your booking widget and the platform, and we analyse it alongside data from the other venues we serve to improve how Tablfy performs. Your data is never shown to another venue or shared outside Tablfy.
When you connect your Google account via OAuth, we pull website sessions, traffic sources, conversion events, and geographic and device breakdowns from your GA4 property. We access only the GA4 properties you explicitly authorise.
When you connect your Meta Business account via OAuth, we pull ad spend, impressions, clicks, ROAS, and conversion events linked to your Meta Pixel.
When you connect a third-party tool like NowBookIt or Meta Ads, we store whatever access that platform requires for the connection to work. That differs by platform: some issue an authorisation token, some need a login, some need an invite to your account. We use whichever method that platform currently offers, and only the access needed to run your service.
Access is stored server-side, never exposed to the browser, and removed when you disconnect or revoke it. You can revoke it at any time from within that platform.
We use HTTP-only secure cookies to manage authenticated sessions. These cookies are not accessible to JavaScript and are used only for authentication purposes.
When guests use Tablfy-hosted booking pages and enquiry forms we collect standard technical information: IP address, device and browser details, and the marketing source that led to the visit. We use it to attribute bookings to your marketing and to improve the booking experience.
| Purpose | Lawful Basis |
|---|---|
| Providing and operating the Tablfy service | Performance of contract |
| Connecting to Google GA4 and Meta Ads via OAuth | Your explicit consent (granted during OAuth flow) |
| Parsing booking confirmation emails to populate the platform | Your explicit consent |
| Generating ROI and marketing performance reports | Performance of contract |
| Displaying booking, financial, and ad data in the platform | Performance of contract |
| Operating Tablfy-hosted booking widgets and enquiry forms for your venue | Performance of contract |
| Attributing bookings to marketing activity and reporting conversions to your connected advertising platforms | Performance of contract |
| Enhancing the guest experience across Tablfy-powered widgets (e.g. recognising returning guests) | Legitimate interest |
| Sending transactional emails (account setup, alerts) | Performance of contract |
| Troubleshooting, debugging, and service support | Legitimate interest |
| Improving the service and fixing bugs | Legitimate interest |
| Complying with legal obligations | Legal obligation |
We don't sell your data or your customers' data, and we don't use it for our own advertising. We use it to run and improve Tablfy for the venues we work with. Conversion reporting to advertising platforms happens only on your behalf, for your own venue's advertising, as described in Section 4. The analytics we run on our own marketing website at tablfy.com are separate and never draw on venue or guest data; they are described in Section 12.6.
All Tablfy data is stored in a secure database hosted by an enterprise cloud provider based in the United States. All database tables are protected by Row-Level Security (RLS), ensuring each venue account can only access its own data. Our hosting provider does not use your data for its own purposes.
We integrate with Google's services using OAuth 2.0. You grant Tablfy access to specific Google resources during the authorisation flow. Our use of Google API data is subject to the Google API Services User Data Policy, including the Limited Use requirements. See Section 5.
We integrate with the Meta Marketing API using OAuth 2.0 to retrieve ad performance data from your Meta Business Manager account. We access only the ad accounts you explicitly authorise. See Section 6.
Your venue's Meta Pixel is owned and controlled by you. We configure it and report conversions through it. We don't run a shared pixel or use pixel data across accounts.
Where you've connected your advertising account, we also send booking and enquiry conversions to that platform on your behalf so you can measure your advertising. Guest identifiers like email and phone are hashed before they're sent, as the platform requires.
Our own pixel on tablfy.com runs only on our marketing pages. It never touches a venue's widget, form or website. It is described in Section 12.6.
Where your venue uses a Tablfy-hosted booking widget, guest booking details are transmitted to your venue's reservation platform to create and manage the booking, exactly as if the guest had booked with your venue directly. Where a booking requires a card pre-authorisation, card details are collected directly by a secure payment provider; Tablfy never receives or stores card numbers. Where your venue connects its payment provider for revenue reporting, we store aggregated transaction summaries only, not individual customer payment details.
Tablfy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If something goes wrong. If personal information we hold is ever exposed, we will contain it, tell you what happened, and notify the Office of the Australian Information Commissioner where the law requires it.
If you believe your account has been compromised, contact us immediately at support@tablfy.com.
| Data Type | Retention Period |
|---|---|
| Account and venue data | Retained while active. After termination we keep it 30 days so you can request an export, then delete it. |
| Booking and customer data | Retained while active. After termination we keep it 30 days so you can request an export, then delete it. |
| Google GA4 and Meta Ads data | Retained as cached snapshots; refreshed on a rolling basis |
| Booking notification emails | Stored when received and retained while your account is active. The structured booking record is retained for the life of your account. |
| OAuth tokens | Retained while integration is active; deleted immediately upon disconnection |
| Session cookies | Expire at end of session or within the defined authentication window |
| Widget & enquiry attribution events | Retained while the venue's account is active; used for attribution, reporting, and guest experience |
To request account deletion, contact privacy@tablfy.com. We will process it within 30 days.
You have the right to request a copy of the personal information we hold about you. We will respond within 30 days.
Most account and venue data can be updated directly within Tablfy. For other corrections, contact privacy@tablfy.com.
You may request deletion of your personal information. We will process requests within 30 days, subject to legal retention obligations.
Where we rely on your consent (e.g. Google or Meta OAuth access), you may withdraw it at any time by disconnecting the integration within Tablfy or revoking access via Google's or Meta's security settings.
Contact us first at privacy@tablfy.com so we can attempt to resolve the issue. If unsatisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
GETBOOKINGS PTY LTD is committed to complying with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth):
Tablfy's data is stored in the United States with SOC 2 compliant providers. By using the Tablfy service you consent to that transfer.
Tablfy uses HTTP-only secure session cookies to manage authenticated user sessions. These cookies are set server-side, inaccessible to JavaScript, and used solely for authentication, not for advertising or tracking.
If you have configured a Meta Pixel on your venue's website, that pixel is your own, operating under your Meta Business Manager account. As the operator, your venue is responsible for appropriate disclosure to your website visitors.
We never use a venue's visitor or guest data for our own advertising, and we never share it across accounts or with advertising networks for our own purposes. Conversion events are shared with a venue's own connected advertising platforms only on that venue's behalf, as described in Section 4.4. Our own marketing website at tablfy.com is treated separately: those pages may use a Tablfy-owned Meta Pixel and server-side Conversions API events so we can measure and retarget our own advertising for Tablfy. That pixel only ever sees visitors to our marketing pages, and is described in Section 12.6.
Tablfy-hosted booking widgets and events enquiry forms set a first-party browser storage value named tablfy_visitor_id (a random UUID containing no personally identifiable information). This identifier lets us recognise returning visitors across sessions on the same device so we can attribute repeat enquiries and bookings to the original marketing source. Visitors can clear this value at any time by clearing their browser's site data, or avoid setting it altogether by using private/incognito browsing.
We use a privacy-focused product analytics provider to record anonymised session replays of how visitors interact with our booking widget and events enquiry form. These recordings help us identify usability issues and improve conversion for the venues we serve.
tablfy_visitor_id only; no name, email, or phone number is sent to the provider.Our own marketing pages on tablfy.com (the homepage, /casestudy, /nowbookit, /breakeven, /integrations and /ios) use first-party analytics so we can understand how visitors find and use the site, and measure the performance of our own advertising for Tablfy. This applies to our marketing pages only. Tablfy-hosted booking widgets, enquiry forms and venue websites are unchanged and are covered by Sections 12.4 and 12.5.
On those pages we collect:
t_vid holding a randomly generated identifier that contains no personally identifiable information. It lasts up to 400 days so we can recognise a returning visitor on the same device. We also keep a small number of values for the current visit in your browser's local storage.We also record session replays of these marketing pages using PostHog, which acts as our processor and hosts the data in the United States. All form inputs are masked, so a replay cannot capture anything you type into a field. These requests are proxied through tablfy.com so that content blockers do not silently break them.
Once we connect our own Meta advertising account, these marketing pages will also load a Tablfy-owned Meta Pixel and send matching server-side Conversions API page view events. We use this only to measure and retarget our own advertising for Tablfy. This pixel is ours, it is never placed on a venue's booking widget, enquiry form or website, and it never sees a venue's guests.
We keep this marketing website data only for as long as we need it for the purposes described above. We do not currently show a cookie consent banner on these pages. You can refuse or remove this collection through your browser's cookie and site-data settings, by browsing privately or in incognito mode, or by using a content blocker, which stops the analytics and pixel requests. You can also ask us to delete the data we hold about your visits by emailing privacy@tablfy.com.
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and notify active users via email or a notice in Tablfy. Your continued use of Tablfy after any changes constitutes acceptance of the updated policy.
This Privacy Policy reflects the data practices of the Tablfy service as at the date shown above. It does not constitute legal advice.