Privacy Policy
Last updated 28 September 2026
Tabivo ("Tabivo", "we", "us") provides reservation and front-of-house software to restaurants. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why, and the choices you have.
Two kinds of information
Restaurant customers. When a restaurant owner or staff member signs up for or uses Tabivo, we collect their name, email address, business details, and billing information. We are responsible for this information.
Diners. When a diner books with a restaurant that uses Tabivo, the restaurant collects the diner's name, contact details, party size, booking time and any notes. We store and process this on the restaurant's behalf, to provide the service to them. The restaurant decides how it uses this information, and diners should also read that restaurant's own privacy policy.
What we collect
- Account details: name, email address, role, and a securely hashed password
- Business details: restaurant name, address, phone, hours, logo and settings
- Booking details entered by diners or staff: name, phone, email, party size, date and time, and notes
- Ordering and payment records for dine-in tabs, if the restaurant uses those modules
- Billing details, handled by Stripe. We never see or store full card numbers.
- Technical information such as IP address, browser type and error logs, used to keep the service secure and working
- Messages you send us through support requests or email
How we use it
- To provide Tabivo: taking and managing bookings, sending confirmation emails, and running ordering and payments
- To bill restaurant customers and manage their subscriptions
- To provide support and respond to enquiries
- To protect the service against spam, abuse and unauthorised access
- To improve Tabivo and fix problems
- To keep in touch with restaurant customers about their account and, with their consent, about product news. You can unsubscribe at any time.
We do not sell personal information, and we never use diner information for our own marketing.
Who we share it with
We use trusted service providers to run Tabivo. They only process information as needed to provide their service to us:
- Cloudflare: hosting, storage, and spam protection on public forms
- Stripe: subscription billing and payments
- Resend: sending booking and account emails
- Zoho: our customer relationship and support systems (restaurant account details only, never diner or booking data)
- Sentry: error monitoring
- Square: only if a restaurant connects its Square account, for menu sync and card payments
- Google Maps: displaying a restaurant's location on its booking page
Some of these providers store or process information outside Australia, including in the United States and other countries. We take reasonable steps to make sure they protect it to a standard consistent with the Australian Privacy Principles. We may also disclose information where required by law.
Security
We protect information with encryption in transit, hashed passwords, rate limiting and lockout on logins, secure session cookies, and access controls that limit staff to their own restaurant. No system is perfectly secure, but we work to protect your information and will notify affected people of an eligible data breach as the law requires.
How long we keep it
We keep information while an account is active and for as long as needed to provide the service, meet legal and tax obligations, and resolve disputes. When a restaurant closes its account, we delete or de-identify its data within a reasonable period, except where we must keep it by law.
Cookies
The Tabivo dashboard uses essential cookies to keep you logged in. This website does not use advertising or tracking cookies.
Access, correction and complaints
You can ask to access or correct the personal information we hold about you by emailing [email protected]. Diners should usually contact the restaurant first, since the restaurant controls its booking records, but we're happy to help.
If you have a privacy complaint, email us and we'll respond within 30 days. If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
We may update this policy from time to time. We'll post the new version here and update the date at the top.