TISCHE™
PricingLog inExplore Tische
LEGAL · PRIVACY

Privacy, made clear.

Version 1.0 · Effective 6 August 2026

The short version

Tische helps hospitality businesses manage reservations, understand guests and run approved campaigns. Venues control how they use their guest data. Tische uses it only to operate, protect and improve the services described here and in the customer agreement. We do not sell personal information.

This Privacy Policy explains how Tische Hospitality (“Tische”, “we”, “us” or “our”) collects, uses, discloses and protects personal information when venues, team members, prospective customers, website visitors and guests interact with our hospitality platform and related services.

1. Our role depends on the interaction

For guest data entered, imported or connected by a venue, the venue generally decides why and how that information is used. The venue is the data controller or responsible entity and Tische acts as its service provider or processor. Guests should first contact the venue about that data. Tische is responsible for information we collect for our own account administration, billing, security, support, website analytics and direct business relationships.

2. Information we collect

Venue and account data

Names, work contact details, venue details, roles, login and support information.

Guest and reservation data

Names, contact details, bookings, waitlist and walk-in records, visit history, preferences, dietary or accessibility notes, loyalty activity and feedback supplied by the guest or venue.

Transaction and integration data

Order summaries, spend, deposits, gift cards, campaign activity and events received from connected booking, POS, payment and messaging providers.

Technical data

Device, browser, IP address, login, audit, diagnostic, cookie and product-usage information.

We collect information directly from account users and guests, automatically through use of the service, and from a venue’s authorised providers or historical data imports. We do not need full payment-card numbers or card security codes; those should be handled by the venue’s configured payment provider.

3. How we use information

  • Provide reservations, waitlists, floor management, online ordering, events, loyalty, gift cards, reporting and customer support.
  • Build a useful guest history and match records from approved sources.
  • Import historical bookings and produce demand forecasts, revenue opportunities and campaign recommendations.
  • Deliver confirmations, reminders and other service messages, plus venue-approved marketing where permitted.
  • Operate integrations, reconcile conversions and attribute a booking to a campaign.
  • Authenticate users, prevent misuse, troubleshoot, audit and protect the platform.
  • Meet contractual, tax, regulatory and legal obligations and establish or defend legal claims.
  • Improve Tische using aggregated or de-identified insights that are not reasonably capable of identifying a person.

4. Reservations and guest communications

When a guest books through a Tische booking link, we share the reservation with the selected venue so it can provide the requested service. Operational messages—such as confirmations, changes and reminders—are separate from promotional marketing. A venue must have an appropriate legal basis or consent before sending a campaign, honour opt-outs and include any promotion conditions required by law. Tische provides approval and suppression controls, but the venue remains responsible for its audience and message.

5. AI recommendations and profiling

Tische may analyse historical and live booking, capacity, visit, purchase and campaign patterns to estimate demand or recommend an audience, offer or operational action. These outputs are predictions, not facts or guarantees. Tische AI Campaigns are designed for venue review: authorised users can inspect and approve the audience, timing, message and offer before a campaign is sent. Guests may contact the relevant venue about its use of their information for marketing or profiling.

6. When we disclose information

We may disclose only the information reasonably needed to venues and their authorised users; infrastructure, hosting, authentication, analytics, support, email and SMS providers; connected POS, booking, payment and other integration partners; professional advisers; a purchaser or successor in a corporate transaction; and regulators, courts or law-enforcement bodies where legally required. Providers acting for Tische must use information only for agreed services and apply appropriate safeguards. Connected third parties also have their own privacy terms.

7. Security and data incidents

We use administrative, technical and organisational safeguards appropriate to the nature of the information, including role-based access, encryption in transit, access logging and controlled service-provider access. No online service can promise absolute security. If a qualifying data incident occurs, we will investigate, contain it and notify affected customers or authorities as required by applicable law. Account administrators should use strong credentials, grant the least access needed and promptly remove former team members.

8. Retention, exports and deletion

We retain information while an account is active and afterwards only as reasonably needed to provide agreed exports, maintain security and audit records, resolve disputes, enforce agreements and comply with legal obligations. Retention periods vary by data type and venue instructions. We may retain aggregated or de-identified data. When instructed by a venue, we will delete or return guest data subject to lawful retention requirements and the customer agreement.

9. International processing

Tische and its providers may process information outside the country where it was collected. Where required, we use contractual, organisational and technical measures intended to protect information across borders. The countries and providers in use may change as the service develops; customers may request current information before contracting.

10. Choices and privacy rights

Depending on location, a person may request access, correction, deletion or restriction; object to or withdraw consent for certain processing; opt out of marketing; or complain to a privacy regulator. Rights are not absolute and identity verification may be required. Guests should contact the venue first for venue-controlled data. Tische will assist the venue with verified requests as required by contract and law.

11. Cookies, children and external links

Our websites may use essential cookies and limited analytics to operate, remember preferences, understand use and protect the service. Browser settings can restrict non-essential cookies, although some features may be affected. Tische is a business hospitality service and is not directed to children. External services linked or connected to Tische are governed by their own privacy notices.

12. Regional notices

Tische is operated from Australia. The Australian Privacy Principles apply where required. If Tische offers services to people covered by another privacy regime, the relevant regional notice supplements this policy. Our California Privacy Notice applies only where the California Consumer Privacy Act applies to Tische and the person making the request.

13. Changes and contact

We may update this policy to reflect product, provider or legal changes. We will post the revised effective date and provide additional notice where a material change requires it. Tische is operated by DREAMLAB STUDIO PTY LTD in Australia. Privacy questions and access, correction or deletion requests may be sent to privacy@tische.com.au, submitted through our Privacy Choices page, or raised through the authenticated support channel.

Launch note. This is a tailored product framework, not legal advice. It must be reviewed by Australian privacy counsel once Tische’s legal entity, service providers, hosting locations and contact details are final.

© 2026 DREAMLAB STUDIO PTY LTD · TISCHE™ is a trademark of DREAMLAB STUDIO PTY LTD
RESOURCESBlog
LEGALPrivacyPrivacy choicesTermsMerchant agreementDPASubprocessors
TRUSTReport IPReport a vulnerability