Privacy Policy

How we handle personal information, written to meet Australian Privacy Principle 1.4 under the Privacy Act 1988 (Cth).

Last updated: 10 August 2026

1. Who this covers

We handle personal information about two groups of people, and the difference between them runs through everything below.

  • Venue staff — the owners, managers and hosts who hold OneReserve accounts. They are our customers.
  • Diners — people who book a table at a venue that uses OneReserve. Diners are not our customers. Your booking is with the restaurant; we make the software the restaurant uses to take it.

For diner information, the venue decides what is collected and why. We hold it on the venue’s behalf and use it to run the service. Both we and the venue have obligations under the Privacy Act for that information.

2. What we collect

From diners, when a booking is made

InformationWhy we hold it
NameTo identify the booking to venue staff
Email addressConfirmation, reminder, and the link to change or cancel
Phone numberSo the venue can reach you about the booking
Date, time, party size, seating preferenceTo hold the right table
Occasion, and any special request you typeOptional. Passed to the venue
Dietary requirements and allergiesOptional. Passed to the venue so it can serve you safely
Your booking history at that venueSo the venue recognises a returning guest
Notes and labels staff add about youThe venue’s own record of its guests

Dietary requirements and allergies are health information, and health information is sensitive information under the Privacy Act. We collect it only where you or the venue supply it for your booking, we use it only for that booking, and you never have to provide it to make a reservation.

From venue staff

Name, email address, a hashed password, which venues you belong to and your role there, and your email preferences.

Payments

Where a venue requires a deposit, your card details go directly into a form hosted by Stripe and are never sent to or stored on our servers. We receive a payment identifier, the amount, the status, and the card’s brand and last four digits. We never see or hold a full card number.

Technical information

Our servers keep operational logs, and our error reporting tool records diagnostics when something breaks. We strip identifying fields from error reports before they are sent.

We use no analytics, no advertising, and no third-party tracking of any kind. This marketing site sets no cookies at all. The booking page sets only what is needed to complete your booking, and the staff console only a session cookie to keep you signed in.

3. How we use it

To take and manage bookings; to send confirmations, reminders and cancellation notices; to let a venue recognise a returning guest; to take a deposit where the venue requires one; to operate, secure and support the platform; and to meet our legal obligations.

We do not sell personal information, and we do not disclose it for advertising.

Marketing email. We send account and lifecycle email to venue staff, who can opt out at any time from the link in those messages. Transactional messages — booking confirmations, password changes, and the billing notices an owner must see to keep their page online — are not marketing and continue regardless, as the Spam Act 2003 (Cth) permits.

4. Who we disclose it to, and where it is stored

The venue you booked with. That is the point of the service.

Our service providers, each limited to what its function requires:

ProviderWhat it doesWhere
RailwayApplication and database hosting — this is where your information livesSingapore
StripeProcessing deposit paymentsUnited States, Ireland
ResendSending booking and account emailUnited States
SentryError reporting and diagnosticsUnited States

Our servers and database are hosted in Singapore, so your information is stored outside Australia. Sending it to any of the providers above is a disclosure to an overseas recipient under Australian Privacy Principle 8. We take reasonable steps to ensure each handles it consistently with the Australian Privacy Principles, but the laws of those countries are not the same as Australia’s, and the Office of the Australian Information Commissioner may not be able to help you enforce them there.

We may also disclose personal information where required or authorised by law.

5. How we protect it

Passwords are hashed and never stored in readable form. Access to a venue’s data is restricted to staff of that venue. Card details never reach our systems. Traffic is encrypted in transit. We keep the platform patched and monitored.

No system is completely secure, and we cannot guarantee absolute security.

If a data breach occurs that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner and the people affected, as Part IIIC of the Privacy Act 1988 (Cth) requires.

6. How long we keep it

A venue’s guest records are kept for as long as that venue’s account is open, because a restaurant needs its own booking history to recognise a returning guest. We do not delete them on a timer.

You can ask for your details to be erased at any time — see the next section. When we act on that, the booking record remains so the venue’s covers and revenue history stay accurate, but it no longer identifies you.

When a venue closes its account, we keep its data available for export for 30 days, then delete it.

7. Getting a copy, and correcting it

You can ask us for the personal information we hold about you, and ask us to correct it if it is wrong. Email [email protected]. We respond within a reasonable period — ordinarily 30 days — and we do not charge for a request.

If you are a diner, the venue you booked with is usually the better first contact, since the venue decides what it records about its guests. Ask us either way and we will help.

If we refuse access or a correction, we will tell you why in writing, and how to complain.

8. Complaints

If you think we have breached the Australian Privacy Principles, email [email protected] with “Privacy complaint” in the subject. We will acknowledge it within 5 business days and respond substantively within 30 days.

If our response does not satisfy you, you can complain to the Office of the Australian Information Commissioner:

9. Changes to this policy

We post any change here and update the date at the top. If a change materially affects how we use information we already hold, we will email account holders about it.

Our Terms of Service cover the subscription side of the relationship with a venue.

Contact

OneTable Technologies Pty Ltd
ABN 32 651 220 405
Adelaide, South Australia
[email protected]