GETBOOKINGS PTY LTD (Tablfy) Last updated: 12 July 2026
GETBOOKINGS PTY LTD (“we”, “us”, “our”) operates Tablfy, a B2B SaaS platform available at tablfy.com and through associated applications. Tablfy is built for restaurant owners and managers to consolidate their marketing and booking data into a single dashboard, helping them understand the real ROI of their advertising spend against actual reservations.
This Privacy Policy explains what personal and business information we collect, how we use it, who we share it with, and what rights you have. It applies to all users of the Tablfy platform and any restaurant staff accounts created within it.
We are committed to handling all information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Questions? Contact us at admin@getbookings.io.
We collect and process booking data in two ways: when you connect your booking management software via email forwarding or direct integration, and when guests book directly through Tablfy-hosted booking pages, widgets, waitlists, or enquiry forms. This may include:
This data belongs to your restaurant; we process it on your behalf. We also retain booking data to enhance the guest experience across Tablfy-powered booking widgets, for example recognising returning guests and streamlining repeat bookings.
When you connect your Google account via OAuth, we pull website sessions, traffic sources, conversion events, and geographic and device breakdowns from your GA4 property. We access only the GA4 properties you explicitly authorise.
When you connect your Meta Business account via OAuth, we pull ad spend, impressions, clicks, ROAS, and conversion events linked to your Meta Pixel.
We securely store OAuth tokens for your Google and Meta accounts to enable ongoing data synchronisation. These tokens are stored server-side and are never exposed to the browser.
We use HTTP-only secure cookies to manage authenticated sessions. These cookies are not accessible to JavaScript and are used only for authentication purposes.
When guests use Tablfy-hosted booking pages and enquiry forms, we automatically collect standard technical information, including IP address, device and browser details, and the marketing source that led to the visit (such as campaign and advertising parameters). We use this to attribute bookings and enquiries to the venue's marketing activity and to improve the booking experience.
| Purpose | Lawful Basis |
|---|---|
| Providing and operating the Tablfy platform | Performance of contract |
| Connecting to Google GA4 and Meta Ads via OAuth | Your explicit consent (granted during OAuth flow) |
| Parsing booking confirmation emails to populate your dashboard | Your explicit consent |
| Generating ROI and marketing performance reports | Performance of contract |
| Displaying booking, financial, and ad data in your dashboard | Performance of contract |
| Operating Tablfy-hosted booking widgets and enquiry forms for your venue | Performance of contract |
| Attributing bookings to marketing activity and reporting conversions to your connected advertising platforms | Performance of contract |
| Enhancing the guest experience across Tablfy-powered widgets (e.g. recognising returning guests) | Legitimate interest |
| Sending transactional emails (account setup, alerts) | Performance of contract |
| Troubleshooting, debugging, and platform support | Legitimate interest |
| Improving the platform and fixing bugs | Legitimate interest |
| Complying with legal obligations | Legal obligation |
We do not use your data, or your customers' data, for our own advertising, profiling, or any purpose unrelated to operating the Tablfy platform for your business. Conversion reporting to advertising platforms happens only on your behalf, for your own venue's advertising, as described in Section 4.
All Tablfy data is stored in a secure database hosted by an enterprise cloud provider based in the United States. All database tables are protected by Row-Level Security (RLS), ensuring each restaurant account can only access its own data. Our hosting provider does not use your data for its own purposes.
We integrate with Google's services using OAuth 2.0. You grant Tablfy access to specific Google resources during the authorisation flow. Our use of Google API data is subject to the Google API Services User Data Policy, including the Limited Use requirements. See Section 5.
We integrate with the Meta Marketing API using OAuth 2.0 to retrieve ad performance data from your Meta Business Manager account. We access only the ad accounts you explicitly authorise. See Section 6.
Tablfy supports use of your restaurant's own Meta Pixel for tracking booking conversion events. The pixel is owned and controlled by you. We facilitate configuration and reporting of conversion data but do not operate a shared pixel or use pixel data across accounts. Where your venue has connected its own advertising account, Tablfy may also transmit booking and enquiry conversion events to that platform on your behalf so your venue can measure its advertising. Where these events include guest identifiers (such as email or phone number), they are hashed before transmission in accordance with the platform's requirements, alongside standard technical information such as IP address, browser details, and campaign parameters.
Where your venue uses a Tablfy-hosted booking widget, guest booking details are transmitted to your venue's reservation platform to create and manage the booking, exactly as if the guest had booked with your venue directly. Where a booking requires a card pre-authorisation, card details are collected directly by a secure payment provider; Tablfy never receives or stores card numbers. Where your venue connects its payment provider for revenue reporting, we store aggregated transaction summaries only, not individual customer payment details.
Tablfy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you believe your account has been compromised, contact us immediately at admin@getbookings.io.
| Data Type | Retention Period |
|---|---|
| Account and restaurant data | Retained while active; deleted within 30 days of account closure upon request |
| Booking and customer data | Retained while active; deleted within 30 days of account closure upon request |
| Google GA4 and Meta Ads data | Retained as cached snapshots; refreshed on a rolling basis |
| Email-parsed booking data | Only structured booking records retained; raw email content is not stored |
| OAuth tokens | Retained while integration is active; deleted immediately upon disconnection |
| Session cookies | Expire at end of session or within the defined authentication window |
| Widget & enquiry attribution events | Retained while the venue's account is active; used for attribution, reporting, and guest experience |
To request account deletion, contact admin@getbookings.io. We will process it within 30 days.
You have the right to request a copy of the personal information we hold about you. We will respond within 30 days.
Most account and restaurant data can be updated directly within Tablfy. For other corrections, contact admin@getbookings.io.
You may request deletion of your personal information. We will process requests within 30 days, subject to legal retention obligations.
Where we rely on your consent (e.g. Google or Meta OAuth access), you may withdraw it at any time by disconnecting the integration within Tablfy or revoking access via Google's or Meta's security settings.
Contact us first at admin@getbookings.io so we can attempt to resolve the issue. If unsatisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
GETBOOKINGS PTY LTD is committed to complying with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth):
Tablfy stores data with a secure cloud hosting provider based in the United States. This means personal information may be transferred to and stored in the US. Our hosting provider maintains SOC 2 compliance and industry-standard data protection practices.
By using Tablfy and creating an account, you acknowledge that your data may be stored in the United States and consent to that transfer.
Tablfy uses HTTP-only secure session cookies to manage authenticated user sessions. These cookies are set server-side, inaccessible to JavaScript, and used solely for authentication, not for advertising or tracking.
If you have configured a Meta Pixel on your restaurant's website, that pixel is your own, operating under your Meta Business Manager account. As the operator, your restaurant is responsible for appropriate disclosure to your website visitors.
Tablfy does not use third-party advertising cookies on the Tablfy platform itself, and we do not share visitor data with advertising networks for our own purposes. Conversion events are shared with a venue's own connected advertising platforms only on that venue's behalf, as described in Section 4.4.
Tablfy-hosted booking widgets and events enquiry forms set a first-party browser storage value named tablfy_visitor_id(a random UUID containing no personally identifiable information). This identifier lets us recognise returning visitors across sessions on the same device so we can attribute repeat enquiries and bookings to the original marketing source. Visitors can clear this value at any time by clearing their browser's site data, or avoid setting it altogether by using private/incognito browsing.
We use a privacy-focused product analytics provider to record anonymised session replays of how visitors interact with our booking widget and events enquiry form. These recordings help us identify usability issues and improve conversion for the restaurants we serve.
tablfy_visitor_id only; no name, email, or phone number is sent to the provider.We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and notify active users via email or an in-app notification. Your continued use of Tablfy after any changes constitutes acceptance of the updated policy.
This Privacy Policy reflects the data practices of the Tablfy platform as at the date shown above. It does not constitute legal advice.