Last Updated: August 31, 2026
This Privacy Policy (“Privacy Policy“) explains how JAVISTAB, trading as JavisTab (“JavisTab“, “we“, “us“, or “our“), collects, uses, discloses, stores, and protects personal information when you access or use JavisTab, including our website, WordPress plugins, reservation software, SaaS services, APIs, integrations, customer accounts, documentation, support services, and related products and services (collectively, the “Services“).
This Privacy Policy applies to information collected through:
- https://javistab.com/
- JavisTab WordPress plugins;
- JavisTab SaaS services;
- JavisTab customer accounts;
- support channels;
- email communications;
- APIs and integrations; and
- other Services that link to this Privacy Policy.
By using the Services, you acknowledge the practices described in this Privacy Policy.
1. WHO WE ARE
Legal Entity: JAVISTAB
Trading Name: JavisTab
Registered Address: Minh Khai, Vinh Tuy, Hanoi
Email: service@javistab.com
Website: https://javistab.com/
For privacy inquiries, please contact us at service@javistab.com.
Where required by applicable law, JavisTab may appoint a Data Protection Officer (“DPO”) or an EU/UK representative.
2. IMPORTANT DISTINCTION: CUSTOMER DATA VS. JAVISTAB DATA
JavisTab may process personal information in two different capacities.
2.1 JavisTab as Controller
JavisTab acts as a controller, business, or equivalent entity when determining the purposes and means of processing information relating to:
- JavisTab Account holders;
- website visitors;
- prospective customers;
- purchasers;
- billing contacts;
- newsletter subscribers;
- support contacts;
- business contacts; and
- users interacting directly with JavisTab.
2.2 JavisTab as Processor / Service Provider
When a restaurant or other business uses JavisTab to collect and manage reservation information concerning its own customers, JavisTab generally processes that information on behalf of the restaurant.
In that context:
Restaurant = Controller / Business
JavisTab = Processor / Service Provider / Data Intermediary, as applicable
The restaurant remains primarily responsible for determining:
- what personal information it collects;
- why it collects it;
- what notices it provides;
- the applicable lawful basis or consent;
- retention periods; and
- how it responds to data-subject requests.
This distinction is consistent with the controller/processor framework under GDPR and UK GDPR.
3. INFORMATION WE COLLECT
Depending on how you use the Services, we may collect the following categories of information.
3.1 Account Information
When you create a JavisTab account, we may collect:
- name;
- business name;
- email address;
- phone number;
- username;
- password or authentication credentials;
- country;
- timezone;
- website/domain;
- restaurant information; and
- account preferences.
3.2 Billing Information
When you purchase a License or Subscription, we may receive:
- billing name;
- billing address;
- country;
- transaction information;
- subscription information;
- invoice information;
- payment status; and
- limited payment-method information.
Payment card information may be processed directly by third-party payment processors.
JavisTab generally does not require or intentionally store complete payment-card numbers.
3.3 Restaurant and Business Information
Customers may provide:
- restaurant name;
- address;
- opening hours;
- table configuration;
- capacity;
- reservation rules;
- menus or service information;
- contact information;
- booking settings;
- POS configuration; and
- integration credentials.
3.4 Reservation Information
Where JavisTab is used as a restaurant booking system, Customer Data may include:
- guest name;
- email address;
- telephone number;
- reservation date;
- reservation time;
- number of guests;
- table assignment;
- booking status;
- special requests;
- notes;
- cancellation information;
- booking source;
- payment/deposit status; and
- other information entered by the restaurant or guest.
The restaurant determines which information is collected through its JavisTab booking forms.
3.5 Technical Information
We may automatically collect:
- IP address;
- browser type;
- operating system;
- device type;
- language;
- timezone;
- referring URL;
- pages viewed;
- timestamps;
- log information;
- approximate location derived from IP;
- plugin version;
- software version;
- error logs; and
- security information.
3.6 Cookies and Similar Technologies
We may use cookies, pixels, local storage, session technologies, and similar technologies for:
- authentication;
- security;
- preferences;
- analytics;
- performance;
- functionality; and
- marketing, where legally permitted.
Where required by law, we will request consent before using non-essential cookies.
4. HOW WE USE PERSONAL INFORMATION
We may use personal information to:
- provide and operate the Services;
- create and manage Accounts;
- process purchases;
- manage Licenses;
- process Subscription renewals;
- provide customer support;
- communicate service updates;
- send transactional communications;
- provide software updates;
- prevent fraud and abuse;
- maintain security;
- diagnose technical problems;
- improve the Services;
- analyze aggregate usage;
- comply with legal obligations;
- enforce our Terms; and
- protect our rights and property.
Where legally permitted, we may also use business contact information for marketing communications.
You may unsubscribe from marketing communications at any time.
5. LEGAL BASES FOR PROCESSING — GDPR / UK GDPR
Where GDPR or UK GDPR applies, we may rely on one or more of the following legal bases:
Contract
Where processing is necessary to:
- provide the Services;
- process your purchase;
- administer your Account;
- provide support; or
- perform our contractual obligations.
Legitimate Interests
Where processing is necessary for legitimate business interests, including:
- security;
- fraud prevention;
- service improvement;
- business administration;
- direct marketing where legally permitted;
- enforcing contractual rights; and
- defending legal claims.
We consider and balance our interests against individuals’ rights and freedoms.
Consent
Where applicable law requires consent, we will request it.
You may withdraw consent at any time, although withdrawal does not affect processing already carried out lawfully before withdrawal.
Legal Obligation
We may process information where necessary to comply with legal or regulatory obligations.
6. CALIFORNIA PRIVACY RIGHTS
If you are a California resident and the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), applies to our processing, you may have rights including:
- right to know/access;
- right to delete;
- right to correct;
- right to opt out of sale or sharing;
- right to limit certain uses or disclosures of sensitive personal information;
- right to non-discrimination; and
- other rights provided by applicable California law.
California law provides consumers with control over personal information and includes rights concerning access, deletion, correction and opting out of sale or sharing, subject to statutory exceptions.
Sale or Sharing
JavisTab does not sell personal information for monetary consideration.
Where legally applicable, we will honor valid opt-out requests concerning sale or sharing of personal information.
Sensitive Personal Information
We do not intentionally request sensitive personal information from restaurant guests through the standard JavisTab booking functionality.
Customers should not use JavisTab to collect sensitive personal information unless such collection is lawful, necessary, properly configured, and supported by the applicable legal requirements.
7. SINGAPORE PDPA
Where Singapore’s Personal Data Protection Act (“PDPA”) applies, JavisTab will handle personal data in accordance with applicable requirements.
These may include requirements concerning:
- notification;
- consent;
- purpose limitation;
- accuracy;
- protection;
- retention;
- access and correction;
- overseas transfers;
- accountability; and
- data breach notification.
The PDPC identifies these as core obligations under Singapore’s PDPA.
Where JavisTab acts as a data intermediary processing information on behalf of a restaurant, the restaurant generally remains responsible for determining the purposes and manner of processing, while JavisTab will maintain appropriate protection and retention practices applicable to its role.
8. HOW WE SHARE PERSONAL INFORMATION
We may disclose personal information to:
Service Providers
Such as providers of:
- cloud hosting;
- databases;
- payment processing;
- email delivery;
- SMS delivery;
- analytics;
- customer support;
- security;
- monitoring;
- backups;
- infrastructure; and
- software development services.
Third-Party Integrations
Where enabled by the Customer, information may be transmitted to:
- POS systems;
- payment processors;
- CRM platforms;
- email services;
- SMS providers;
- analytics platforms;
- automation services;
- reservation platforms; and
- other integrations.
Legal and Regulatory Authorities
We may disclose information where reasonably necessary to:
- comply with law;
- respond to lawful requests;
- enforce legal rights;
- investigate fraud;
- protect users; or
- protect JavisTab’s rights, property, or security.
Corporate Transactions
Personal information may be transferred as part of:
- merger;
- acquisition;
- financing;
- restructuring;
- sale of assets; or
- similar corporate transaction.
9. DATA RETENTION
We retain personal information only for as long as reasonably necessary for:
- the purposes described in this Privacy Policy;
- providing the Services;
- maintaining business records;
- resolving disputes;
- enforcing agreements;
- preventing fraud;
- complying with legal obligations; or
- establishing, exercising, or defending legal claims.
Customer Data retention may additionally be governed by the applicable agreement and DPA.
10. INTERNATIONAL DATA TRANSFERS
JavisTab may use service providers located in different countries.
Where GDPR or UK GDPR applies, international transfers will be conducted using an applicable lawful transfer mechanism, such as:
- adequacy decisions;
- Standard Contractual Clauses;
- UK transfer mechanisms;
- appropriate safeguards; or
- another lawful mechanism.
GDPR Article 44 requires applicable safeguards for transfers to third countries, while UK GDPR similarly regulates restricted international transfers.
11. SECURITY
JavisTab implements reasonable technical and organizational measures designed to protect personal information.
Measures may include:
- access controls;
- authentication controls;
- encryption in transit;
- secure hosting;
- logging;
- monitoring;
- backups;
- vulnerability management;
- security updates;
- incident response procedures; and
- employee or contractor confidentiality obligations.
No internet-based system can guarantee absolute security.
Customers are responsible for securing:
- WordPress installations;
- hosting accounts;
- administrator accounts;
- passwords;
- API credentials;
- plugins;
- themes; and
- devices.
12. DATA BREACHES
If JavisTab becomes aware of a confirmed personal-data breach affecting Customer Data, JavisTab will take reasonable steps to:
- investigate;
- contain the incident;
- mitigate harm;
- preserve relevant information;
- notify affected Customers where legally required; and
- cooperate with applicable legal obligations.
Where JavisTab acts as a processor/data intermediary, notification to the Customer will generally be made in accordance with the applicable DPA.
13. YOUR PRIVACY RIGHTS
Depending on applicable law, you may have rights to:
- access personal information;
- correct inaccurate information;
- request deletion;
- restrict processing;
- object to processing;
- withdraw consent;
- request portability;
- opt out of certain marketing;
- opt out of sale or sharing where applicable; and
- lodge a complaint with a relevant supervisory authority.
Requests may be submitted to: service@javistab.com
We may need to verify your identity before completing a request.
14. CHILDREN’S INFORMATION
The Services are intended primarily for businesses and adults.
JavisTab does not knowingly solicit personal information directly from children for independent use of the Services.
Restaurant customers are responsible for determining whether their booking forms may collect information concerning minors and for complying with applicable children’s privacy laws.
15. THIRD-PARTY SERVICES
JavisTab may integrate with third-party services.
Those services operate independently and may have separate privacy policies.
JavisTab is not responsible for privacy practices of third parties that operate independently from JavisTab.
16. MARKETING COMMUNICATIONS
We may send:
- transactional emails;
- security notifications;
- service announcements;
- product updates;
- educational content;
- promotional communications.
You may unsubscribe from promotional communications.
You cannot opt out of essential transactional or security communications while maintaining an Account where those communications are necessary to provide the Services.
17. DO NOT TRACK
JavisTab may not respond to every browser-based “Do Not Track” signal unless required by applicable law.
Where applicable privacy law requires recognition of Global Privacy Control or another legally recognized opt-out signal, JavisTab will process such signals as required.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically.
Material changes may be communicated through:
- the website;
- email;
- the JavisTab dashboard; or
- other reasonable means.
The updated Privacy Policy becomes effective on the date specified at the top.
19. CONTACT US
Privacy inquiries:
JAVISTAB
Trading as JavisTab
Email: service@javistab.com
Address: 458 Minh Khai,Hanoi, VietNam
Where applicable, you may also have the right to contact the relevant data protection authority in your jurisdiction.
Last Updated: August 31, 2026



