Draft for review. This text will be reviewed before TableFlow Hotels launches.
Privacy policy · TableFlow Hotels
Last updated: October 7, 2026
Who we are
TableFlow Hotels is made by TableFlow Hospitality Management Systems, a Canadian company, part of Zook (which also makes TableFlow for restaurants). This policy explains what we do with personal information on this website and in TableFlow Hotels. Our Privacy Officer, Arlindo Codinha, is responsible for it: [email protected].
Two roles
For hotel staff accounts and for this website, we decide how information is used. For guests of the hotels that use TableFlow Hotels, each hotel decides, and we process the information on its behalf and only to run the service for that hotel.
What we collect
- On this website: the name, email, property name, city, province and room count you give to reserve a launch place, and the IP address the request came from, kept only to prevent abuse and deleted once you confirm or after 7 days.
- Hotel staff: name, email, role, sign-in and security records (sessions, devices, IP addresses, two-step sign-in), and what they change in the system.
- Guests, for the hotel: booking and contact details, preferences, messages with the hotel, bills, and access needs when the guest shares them. When the hotel uses online check-in: the registration card (address, phone, vehicle plate, other guests, signature) and the IP address and browser it was signed from. We never store card numbers.
- In your browser: this website and the booking page keep your language, display settings and booking progress on your device. Only if you say yes in the cookie banner, Google Analytics and Meta set cookies to tell us which of our ads bring visitors and launch-place sign-ups; without a yes, nothing of theirs loads. You can change your answer any time under “Cookie settings” at the bottom of each page. When you arrive through one of our ads or links, we keep which one (its campaign name) with your launch-place sign-up. On the card step, Stripe sets its own cookies to prevent fraud.
What we use it for
- To run the service: bookings, bills, messages, sign-in and security.
- To confirm your launch place and write to you about the launch. No newsletter, and we never sell personal information.
- To keep the service safe: preventing abuse, investigating problems, and keeping an audit record.
Consent
We collect information with your consent: when you fill in the launch-place form, or when you give it to a hotel that uses TableFlow Hotels. We collect only what we need for the purposes above. You can withdraw your consent at any time; some things may then no longer be possible, such as a booking.
Who else handles it
- Railway: hosting and the database.
- Cloudflare: delivers and protects this website and the app, so it sees your IP address, and stores our encrypted backups. Your approximate location from it only suggests a language and time zone.
- Stripe: payments. Stripe holds card numbers, so we never store them.
- Resend: email delivery. A hotel can instead send its guest emails through its own email server.
- Twilio: text messages, when a hotel turns texts on.
- Cloudinary: hotel and room photos.
- Google: the map on our hotel directory, and our own searches to add hotels to it.
- Adobe Fonts: this website’s headline font, so your browser’s request (including your IP address) reaches Adobe.
- Google (Analytics) and Meta (Facebook and Instagram ads): only with your yes to cookies, how you use this website and which ad brought you. When you confirm a launch place, we tell Meta that one of its ads led to a sign-up, with your email address scrambled (hashed) so it can match it to its own accounts.
- Have I Been Pwned: when staff choose a password, only the first 5 characters of its fingerprint are checked against known leaked passwords. The password itself never leaves.
- TableFlow, the restaurant system, when a hotel connects it: room number, first initial and last name, arrival and departure dates, and dietary needs if the hotel allows it. Never contact details or access notes.
Where it is stored
TableFlow Hotels and its database run in the United States (Railway, US East). Some of the providers above also store information outside Canada. Information stored in another country can be accessed by that country’s courts and authorities under its laws.
Access needs and sensitive information
Access needs a guest shares are shown only to the hotel staff whose job needs them, and every view of the private access note is recorded. They are never put in emails, texts or what the restaurant system receives.
How long we keep it
- While a hotel uses TableFlow Hotels, we keep its information so the service works. The hotel can download everything at any time, including what it must keep for taxes.
- When a hotel’s subscription ends, its information stays read-only for 90 days so it can be downloaded, and the owners are told by email at the start and two weeks before the end. Then all of it is deleted, and our backups that still hold it expire within 90 days.
- Security records (sign-in history, devices, and the IP address and browser on check-in cards and booking acceptance) are deleted after one year.
- Confirmed launch-place sign-ups are kept until you ask us to delete them. Staff accounts and the record of changes in a hotel (including who viewed access notes) are kept while the hotel uses TableFlow Hotels, and deleted with it.
- Unconfirmed launch-place sign-ups are deleted after 7 days.
- A hotel can download or erase a guest’s information on request.
How we protect it
Information travels encrypted, our backups are encrypted, owners and managers must use two-step sign-in, each person sees only what their role allows, and changes are recorded. If a breach creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada and tell the people and hotels affected as soon as possible.
Your rights
You can ask to see, correct or delete your personal information, or withdraw your consent. Guests of a hotel should contact that hotel first; we help the hotel answer. Write to our Privacy Officer at [email protected]; we answer within 30 days. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
Quebec
For hotels in Quebec, we support their obligations under Law 25, including access requests and incident reporting. Quebec residents can also contact the Commission d’accès à l’information du Québec.
Changes
If we change this policy, we update the date above and tell hotel owners by email before important changes take effect.