Privacy Policy

Tablfy   Last updated: 17 September 2026

1. Introduction / Who We Are

GETBOOKINGS PTY LTD (“we”, “us”, “our”) is a marketing and technology company for hospitality venues. We operate Tablfy, our marketing and booking platform, available at tablfy.com, through our mobile apps, and through websites and booking pages we build and host on venues' own domains. Tablfy is built for venue owners and managers to consolidate their marketing and booking data into a single platform, helping them understand the real ROI of their advertising spend against actual reservations.

This Privacy Policy explains what personal and business information we collect, how we use it, who we share it with, and what rights you have. It applies to venue owners, managers and staff who use the Tablfy service, to guests who book, enquire, or otherwise interact with a Tablfy-hosted booking page, widget, enquiry form or venue website, and to visitors to our own marketing website at tablfy.com.

We are committed to handling all information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Questions? Contact us at privacy@tablfy.com.


2. What Information We Collect

2.1 Account Information

  • Full name
  • Email address
  • Password (stored as a hashed value; we never store plaintext passwords)
  • Role within your organisation (owner, admin, manager, or staff)

2.2 Venue Data

  • Venue name and location details
  • Timezone settings
  • Revenue configuration and cover settings
  • Branding preferences

2.3 Booking Data

We collect and process booking data in two ways: when you connect your booking management software via email forwarding or direct integration, and when guests book directly through Tablfy-hosted booking pages, widgets, waitlists, or enquiry forms. This may include:

  • Customer names, email addresses, and phone numbers
  • Booking history, dates, party sizes, and statuses
  • Any additional details a guest chooses to provide during booking, such as special requests, occasions, marketing preferences, or optional profile details requested by your venue

This data belongs to your venue and we process it on your behalf. We retain it to operate your booking widget and the platform, and we analyse it alongside data from the other venues we serve to improve how Tablfy performs. Your data is never shown to another venue or shared outside Tablfy.

2.4 Financial & Sales Data

  • Daily sales figures
  • Payment method breakdowns (e.g. cash, card, split)
  • Revenue per cover metrics

2.5 Google Analytics 4 (GA4) Data

When you connect your Google account via OAuth, we pull website sessions, traffic sources, conversion events, and geographic and device breakdowns from your GA4 property. We access only the GA4 properties you explicitly authorise.

2.6 Meta Ads Data

When you connect your Meta Business account via OAuth, we pull ad spend, impressions, clicks, ROAS, and conversion events linked to your Meta Pixel.

2.7 Credentials & Access

When you connect a third-party tool like NowBookIt or Meta Ads, we store whatever access that platform requires for the connection to work. That differs by platform: some issue an authorisation token, some need a login, some need an invite to your account. We use whichever method that platform currently offers, and only the access needed to run your service.

Access is stored server-side, never exposed to the browser, and removed when you disconnect or revoke it. You can revoke it at any time from within that platform.

2.8 Session Data

We use HTTP-only secure cookies to manage authenticated sessions. These cookies are not accessible to JavaScript and are used only for authentication purposes.

2.9 Technical & Attribution Data

When guests use Tablfy-hosted booking pages and enquiry forms we collect standard technical information: IP address, device and browser details, and the marketing source that led to the visit. We use it to attribute bookings to your marketing and to improve the booking experience.


3. How We Use Your Information

PurposeLawful Basis
Providing and operating the Tablfy servicePerformance of contract
Connecting to Google GA4 and Meta Ads via OAuthYour explicit consent (granted during OAuth flow)
Parsing booking confirmation emails to populate the platformYour explicit consent
Generating ROI and marketing performance reportsPerformance of contract
Displaying booking, financial, and ad data in the platformPerformance of contract
Operating Tablfy-hosted booking widgets and enquiry forms for your venuePerformance of contract
Attributing bookings to marketing activity and reporting conversions to your connected advertising platformsPerformance of contract
Enhancing the guest experience across Tablfy-powered widgets (e.g. recognising returning guests)Legitimate interest
Sending transactional emails (account setup, alerts)Performance of contract
Troubleshooting, debugging, and service supportLegitimate interest
Improving the service and fixing bugsLegitimate interest
Complying with legal obligationsLegal obligation

We don't sell your data or your customers' data, and we don't use it for our own advertising. We use it to run and improve Tablfy for the venues we work with. Conversion reporting to advertising platforms happens only on your behalf, for your own venue's advertising, as described in Section 4. The analytics we run on our own marketing website at tablfy.com are separate and never draw on venue or guest data; they are described in Section 12.6.


4. Third-Party Integrations

4.1 Data Hosting

All Tablfy data is stored in a secure database hosted by an enterprise cloud provider based in the United States. All database tables are protected by Row-Level Security (RLS), ensuring each venue account can only access its own data. Our hosting provider does not use your data for its own purposes.

4.2 Google (GA4)

We integrate with Google's services using OAuth 2.0. You grant Tablfy access to specific Google resources during the authorisation flow. Our use of Google API data is subject to the Google API Services User Data Policy, including the Limited Use requirements. See Section 5.

4.3 Meta (Facebook Ads Manager)

We integrate with the Meta Marketing API using OAuth 2.0 to retrieve ad performance data from your Meta Business Manager account. We access only the ad accounts you explicitly authorise. See Section 6.

4.4 Meta Pixel & Conversion Measurement

Your venue's Meta Pixel is owned and controlled by you. We configure it and report conversions through it. We don't run a shared pixel or use pixel data across accounts.

Where you've connected your advertising account, we also send booking and enquiry conversions to that platform on your behalf so you can measure your advertising. Guest identifiers like email and phone are hashed before they're sent, as the platform requires.

Our own pixel on tablfy.com runs only on our marketing pages. It never touches a venue's widget, form or website. It is described in Section 12.6.

4.5 Reservation & Payment Platforms

Where your venue uses a Tablfy-hosted booking widget, guest booking details are transmitted to your venue's reservation platform to create and manage the booking, exactly as if the guest had booked with your venue directly. Where a booking requires a card pre-authorisation, card details are collected directly by a secure payment provider; Tablfy never receives or stores card numbers. Where your venue connects its payment provider for revenue reporting, we store aggregated transaction summaries only, not individual customer payment details.


5. Google API Limited Use Disclosure

Tablfy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only request access to Google user data that is necessary for Tablfy to function.
  • We do not use Google user data to serve advertisements.
  • We do not allow humans to read your Google user data unless you have explicitly given us permission, it is necessary for security purposes, or we are required to do so by law.
  • We do not transfer or sell Google user data to third parties.
  • We do not use Google user data to build or augment user profiles for purposes unrelated to Tablfy's core functionality.

6. Meta Ads Integration Disclosure

  • We access only the ad accounts and campaigns you explicitly authorise during the OAuth flow.
  • Meta Ads data is used solely to populate the Tablfy platform for your venue.
  • We do not share, sell, or transfer your Meta Ads data to any third party.
  • We do not use Meta Ads data for our own advertising or marketing purposes.
  • OAuth tokens for Meta are stored securely server-side and are never exposed to the client browser.
  • You may revoke Tablfy's access to your Meta account at any time through Meta Business Manager settings, or by disconnecting the integration within Tablfy.

7. Data Storage & Security

  • Row-Level Security (RLS):Every database table enforces RLS policies; one venue account cannot access another's data.
  • HTTP-only secure cookies: Session tokens are stored in HTTP-only cookies inaccessible to JavaScript.
  • Server-side OAuth token handling: OAuth tokens for Google and Meta are stored and used server-side only.
  • HTTPS and HSTS: All communications are encrypted in transit using TLS with HTTP Strict Transport Security enforced.
  • Hashed passwords: User passwords are never stored in plaintext.

If something goes wrong. If personal information we hold is ever exposed, we will contain it, tell you what happened, and notify the Office of the Australian Information Commissioner where the law requires it.

If you believe your account has been compromised, contact us immediately at support@tablfy.com.


8. Data Retention

Data TypeRetention Period
Account and venue dataRetained while active. After termination we keep it 30 days so you can request an export, then delete it.
Booking and customer dataRetained while active. After termination we keep it 30 days so you can request an export, then delete it.
Google GA4 and Meta Ads dataRetained as cached snapshots; refreshed on a rolling basis
Booking notification emailsStored when received and retained while your account is active. The structured booking record is retained for the life of your account.
OAuth tokensRetained while integration is active; deleted immediately upon disconnection
Session cookiesExpire at end of session or within the defined authentication window
Widget & enquiry attribution eventsRetained while the venue's account is active; used for attribution, reporting, and guest experience

To request account deletion, contact privacy@tablfy.com. We will process it within 30 days.


9. Your Rights

9.1 Access

You have the right to request a copy of the personal information we hold about you. We will respond within 30 days.

9.2 Correction

Most account and venue data can be updated directly within Tablfy. For other corrections, contact privacy@tablfy.com.

9.3 Deletion

You may request deletion of your personal information. We will process requests within 30 days, subject to legal retention obligations.

9.4 Withdrawal of Consent

Where we rely on your consent (e.g. Google or Meta OAuth access), you may withdraw it at any time by disconnecting the integration within Tablfy or revoking access via Google's or Meta's security settings.

9.5 Complaints

Contact us first at privacy@tablfy.com so we can attempt to resolve the issue. If unsatisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

10. Australian Privacy Principles Compliance

GETBOOKINGS PTY LTD is committed to complying with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth):

  • APP 1: This Privacy Policy sets out clearly how we manage personal information.
  • APP 3: We only collect personal information that is reasonably necessary for operating Tablfy.
  • APP 5: Users are informed of what data is collected and why at the point of collection.
  • APP 6: We only use personal information for the primary purpose for which it was collected.
  • APP 7: We do not use personal information for direct marketing without consent.
  • APP 8: Where data is disclosed to overseas recipients, we take reasonable steps to ensure equivalent protection.
  • APP 11: Technical and organisational measures protect personal information from misuse and unauthorised access.
  • APP 12 & 13: Individuals may request access to and correction of their personal information (see Section 9).

11. Cross-Border Data Transfers

Tablfy's data is stored in the United States with SOC 2 compliant providers. By using the Tablfy service you consent to that transfer.


12. Cookies & Tracking

12.1 Session Cookies

Tablfy uses HTTP-only secure session cookies to manage authenticated user sessions. These cookies are set server-side, inaccessible to JavaScript, and used solely for authentication, not for advertising or tracking.

12.2 Meta Pixel

If you have configured a Meta Pixel on your venue's website, that pixel is your own, operating under your Meta Business Manager account. As the operator, your venue is responsible for appropriate disclosure to your website visitors.

12.3 Advertising Cookies & Venue Data

We never use a venue's visitor or guest data for our own advertising, and we never share it across accounts or with advertising networks for our own purposes. Conversion events are shared with a venue's own connected advertising platforms only on that venue's behalf, as described in Section 4.4. Our own marketing website at tablfy.com is treated separately: those pages may use a Tablfy-owned Meta Pixel and server-side Conversions API events so we can measure and retarget our own advertising for Tablfy. That pixel only ever sees visitors to our marketing pages, and is described in Section 12.6.

12.4 Persistent Visitor Identifier

Tablfy-hosted booking widgets and events enquiry forms set a first-party browser storage value named tablfy_visitor_id (a random UUID containing no personally identifiable information). This identifier lets us recognise returning visitors across sessions on the same device so we can attribute repeat enquiries and bookings to the original marketing source. Visitors can clear this value at any time by clearing their browser's site data, or avoid setting it altogether by using private/incognito browsing.

12.5 Session Replay

We use a privacy-focused product analytics provider to record anonymised session replays of how visitors interact with our booking widget and events enquiry form. These recordings help us identify usability issues and improve conversion for the venues we serve.

  • All form input fields are masked by default. Recordings cannot capture passwords, contact details, payment information, or anything typed into a form field.
  • Recording only starts after a visitor has shown intent (selected a guest count in the booking widget, or begun typing in the events form). Visitors who land on a page and leave without engaging are not recorded.
  • Replays are linked to the anonymous tablfy_visitor_id only; no name, email, or phone number is sent to the provider.
  • Recordings are retained for a limited period (typically 30 days) and then automatically deleted.
  • Visitors can opt out by clearing their browser's site data, using private/incognito browsing, or enabling Do Not Track in supported browsers.

12.6 Analytics on the Tablfy Marketing Website

Our own marketing pages on tablfy.com (the homepage, /casestudy, /nowbookit, /breakeven, /integrations and /ios) use first-party analytics so we can understand how visitors find and use the site, and measure the performance of our own advertising for Tablfy. This applies to our marketing pages only. Tablfy-hosted booking widgets, enquiry forms and venue websites are unchanged and are covered by Sections 12.4 and 12.5.

On those pages we collect:

  • A first-party cookie named t_vid holding a randomly generated identifier that contains no personally identifiable information. It lasts up to 400 days so we can recognise a returning visitor on the same device. We also keep a small number of values for the current visit in your browser's local storage.
  • Page views, and clicks on links and buttons.
  • The referring website, and any campaign or advertising parameters carried in the URL (such as utm tags, fbclid and gclid).
  • An approximate location (city, region and country) derived from your IP address.
  • Device and browser details, and page load speed.

We also record session replays of these marketing pages using PostHog, which acts as our processor and hosts the data in the United States. All form inputs are masked, so a replay cannot capture anything you type into a field. These requests are proxied through tablfy.com so that content blockers do not silently break them.

Once we connect our own Meta advertising account, these marketing pages will also load a Tablfy-owned Meta Pixel and send matching server-side Conversions API page view events. We use this only to measure and retarget our own advertising for Tablfy. This pixel is ours, it is never placed on a venue's booking widget, enquiry form or website, and it never sees a venue's guests.

We keep this marketing website data only for as long as we need it for the purposes described above. We do not currently show a cookie consent banner on these pages. You can refuse or remove this collection through your browser's cookie and site-data settings, by browsing privately or in incognito mode, or by using a content blocker, which stops the analytics and pixel requests. You can also ask us to delete the data we hold about your visits by emailing privacy@tablfy.com.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and notify active users via email or a notice in Tablfy. Your continued use of Tablfy after any changes constitutes acceptance of the updated policy.


14. Contact Us

Tablfy

A product of GETBOOKINGS PTY LTD

Email: privacy@tablfy.com

Website: tablfy.com

This Privacy Policy reflects the data practices of the Tablfy service as at the date shown above. It does not constitute legal advice.