PRIVACY POLICY
1. Our commitment to privacy
Together Hospitality Group is committed to protecting the privacy and personal information of our guests, customers, employees, contractors, suppliers and other people who interact with us.
This Privacy Policy explains COMUNA CANTINA CITY PTY LTD ABN 65 638 588 333trading as Together Hospitality Group, and its related entities, brands and venues from time to time, including Comuna Cantina and Casa Event Space, collect, hold, use and disclose personal information.
In this policy, “Together Hospitality Group”, “we”, “us” and “our” refer to the relevant Together Hospitality Group entity that collects or handles your personal information.
We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable Australian laws, including the Spam Act 2003 (Cth).
2. What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Depending on how you interact with us, the personal information we collect may include:
your name, telephone number, email address, residential or delivery address;
your date of birth, age or age range;
booking and reservation details;
event and function enquiry information;
details about celebrations, functions, meetings or other occasions you are organising;
guest numbers, seating preferences and accessibility requirements;
food allergies, dietary requirements and other information relevant to safely serving you;
payment, transaction, billing and refund information;
loyalty program membership and participation information;
your dining, ordering and venue preferences;
feedback, reviews, survey responses and correspondence;
information contained in enquiries, complaints or incident reports;
photographs, video recordings and CCTV footage;
website usage information, device information, IP address, browser type and online identifiers;
marketing preferences and information about how you interact with our emails, advertisements and digital content;
identification information where reasonably required to confirm your age, identity or entitlement to enter or remain at a licensed venue;
employment application information, including your résumé, employment history, qualifications and references; and
information relating to suppliers, contractors and business partners.
You are not required to provide us with personal information. However, if you do not provide information that we reasonably require, we may not be able to process your booking, order, function enquiry, membership, application or other request.
3. Sensitive information
Some information you provide may be considered sensitive information under Australian privacy law. This may include health information relating to allergies, dietary requirements, accessibility needs or medical assistance.
We will generally only collect sensitive information where:
you have consented to its collection;
it is reasonably necessary to provide our services or protect your safety;
we are required or authorised to collect it by law; or
another permitted exception applies.
Please only provide health or other sensitive information that is relevant to your booking, event or experience with us.
4. How we collect personal information
We may collect personal information directly from you when you:
make a restaurant reservation;
place an online, takeaway or delivery order;
attend one of our venues;
enquire about or book an event, celebration, meeting or function;
join a loyalty program, membership program or mailing list;
enter a competition, promotion or giveaway;
purchase a gift card or voucher;
communicate with us by telephone, email, social media, online form or in person;
provide feedback or submit a complaint;
apply for employment or contract work;
interact with our website, advertisements or digital platforms; or
participate in a survey, promotion, event or activation.
We may also collect personal information from third parties, including:
restaurant reservation and booking platforms;
online ordering and table-ordering platforms;
point-of-sale and payment providers;
delivery platforms;
loyalty and customer relationship management platforms;
event organisers and the person making a group booking;
social media platforms;
digital advertising and analytics providers;
recruitment agencies and referees;
building managers, security providers or emergency services;
suppliers and business partners; and
publicly available sources.
If another person makes a booking or event enquiry on your behalf, we may receive your information from that person. The person providing the information should have your permission to give it to us.
5. Why we collect and use personal information
We may collect, hold and use personal information to:
accept, manage, confirm and modify reservations;
process food, beverage, takeaway and delivery orders;
plan and deliver events, functions, meetings and celebrations;
communicate with booking organisers and guests;
process payments, deposits, gift cards, vouchers and refunds;
provide appropriate service based on dietary, accessibility or other reasonable requirements;
operate loyalty, membership and rewards programs;
personalise your experience and remember relevant preferences;
respond to enquiries, feedback and complaints;
manage lost property;
maintain safety, security and responsible service practices at our venues;
investigate incidents, suspected fraud, misconduct or unlawful activity;
manage access to licensed premises and comply with liquor licensing requirements;
administer competitions, promotions and events;
send marketing communications where we have the appropriate consent or are otherwise permitted by law;
understand how our websites, advertisements, venues and services are used;
measure and improve our menus, customer experience, marketing and business operations;
undertake reporting, forecasting and business analysis;
recruit and assess employees and contractors;
manage relationships with suppliers, landlords, building managers and business partners;
protect our legal rights and respond to legal claims;
comply with our legal, regulatory, insurance and record-keeping obligations; and
carry out other purposes explained to you at the time of collection.
We may also use aggregated or de-identified information for reporting, research, operational analysis and business planning where that information no longer reasonably identifies an individual.
6. Reservations, orders and event enquiries
When you make a reservation, order or event enquiry, your information may be collected through a third-party booking, ordering, payment or event-management platform.
These providers may collect information under their own privacy policies as well as on our behalf. We encourage you to review the privacy terms presented by the relevant provider when completing your booking or transaction.
For event and function enquiries, we may collect details including:
the organiser’s contact details;
the preferred date and time;
the nature and purpose of the occasion;
estimated guest numbers;
food and beverage requirements;
accessibility and dietary requirements;
budget and package preferences;
payment and deposit information; and
information required to prepare a proposal, contract or event plan.
We may retain enquiry information for a reasonable period to respond to your request, manage future communications and maintain appropriate business records.
7. Payments
Payments may be processed by third-party banks, payment gateways, point-of-sale providers and online ordering platforms.
We generally do not retain complete payment-card details. Payment information is usually processed and stored by the relevant payment provider in accordance with its own security and privacy practices.
We may retain transaction records, payment references, partial card details, billing information and refund information where reasonably required for accounting, fraud prevention, customer service and legal compliance.
8. Loyalty programs and marketing
Where you join a loyalty or membership program, subscribe to updates, enter a promotion or otherwise consent to marketing, we may use your information to send you:
venue news and announcements;
offers, rewards and member benefits;
birthday offers or vouchers;
information about events and functions;
new venue, menu or product announcements;
competitions and promotions; and
other information we believe may be relevant to you.
We may personalise these communications using information such as your venue preferences, transaction history, membership activity, birthday or prior interactions with us.
We will only send electronic marketing communications where we have consent or another lawful basis to do so.
You may unsubscribe at any time by:
using the unsubscribe link in an email;
replying “STOP” where that option is provided in an SMS;
adjusting your account or membership preferences; or
contacting us using the details at the end of this policy.
We will process unsubscribe requests within the period required by law. We may still send non-marketing communications that are necessary to manage an existing booking, order, payment, membership or other transaction.
Providing your details for a reservation, purchase or one-off enquiry does not automatically mean that you have agreed to receive unrelated marketing communications.
9. Website analytics, cookies and advertising technologies
Our websites and digital services may use cookies, pixels, software development kits and similar technologies.
These technologies may collect information including:
your IP address;
device and browser information;
pages viewed and links selected;
the date and time of your visit;
referring websites;
general location information;
booking or enquiry actions;
interactions with advertisements; and
online identifiers associated with your browser or device.
We may use this information to:
operate and secure our websites;
remember preferences;
understand website traffic and customer behaviour;
measure reservations, enquiries and advertising performance;
improve our website and customer experience;
deliver or measure relevant advertising; and
create aggregated business and marketing reports.
Our websites may use services provided by companies such as Google and Meta, and may use other analytics, advertising or social media providers from time to time.
These providers may receive online identifiers and information about your interaction with our website. They may combine that information with information they hold through their own services, subject to their own privacy policies and account settings.
You can limit some tracking technologies by:
changing your browser settings;
clearing or blocking cookies;
using available cookie-preference controls;
adjusting your Google, Meta or other advertising account settings; or
using browser or device-level privacy controls.
Blocking cookies may affect the functionality of parts of our website, including reservations, orders or online forms.
10. CCTV and venue security
Our venues and surrounding operational areas may use CCTV and other security systems for purposes including:
protecting guests, employees and property;
maintaining venue safety and security;
managing access to restricted or licensed areas;
investigating incidents, complaints, theft, property damage or misconduct;
supporting responsible service and venue-management practices;
assisting law enforcement or emergency services where appropriate; and
establishing, exercising or defending legal or insurance claims.
CCTV footage may capture identifiable images, movements and interactions and may therefore constitute personal information.
CCTV footage is only accessed by authorised people where reasonably required. It may be disclosed to police, emergency services, insurers, legal advisers, security providers, building management or other parties where authorised or required by law, or where reasonably necessary to investigate or respond to an incident.
We retain CCTV footage only for as long as reasonably required for security, operational, legal or insurance purposes, subject to the capacity and configuration of the relevant system.
We do not use CCTV footage for facial recognition or biometric identification unless we separately notify affected individuals and have an appropriate legal basis to do so.
Appropriate signage may be displayed at venues where CCTV operates.
11. Photographs, video and venue content
We may take photographs or video at public events, venue activations, launches or promotional occasions.
Where imagery focuses on an identifiable individual, we will take reasonable steps to obtain consent where appropriate. General crowd or atmosphere photography may be undertaken where people would reasonably expect photography to occur.
You may advise our team if you do not wish to be photographed. We will take reasonable steps to accommodate the request, although we cannot guarantee that a person will not appear incidentally in general crowd imagery.
12. When we disclose personal information
We may disclose personal information to:
our related entities, venues and brands;
reservation, ordering and event-management providers;
payment processors, banks and financial institutions;
point-of-sale and loyalty platform providers;
food delivery providers;
email, SMS and marketing providers;
website hosting, cloud storage, analytics and advertising providers;
information technology, cybersecurity and software providers;
professional advisers, including lawyers, accountants, auditors and insurers;
landlords, building managers and security providers where relevant to an incident or venue operation;
contractors, consultants and service providers assisting our operations;
recruitment providers and referees;
regulators, courts, law enforcement and government authorities;
a purchaser, investor or adviser involved in a proposed or completed sale, restructure, merger or acquisition of all or part of our business; and
other parties where you have consented or where disclosure is authorised or required by law.
We require service providers handling information on our behalf to use it only for the agreed purpose and to take reasonable steps to protect it.
We do not sell personal information in the ordinary meaning of selling customer databases for monetary payment.
13. Overseas disclosures
Some of our technology, reservation, payment, ordering, cloud, analytics, marketing and customer-management providers may store or process information outside Australia.
Depending on the providers used at the relevant time, information may be processed in countries including [CONFIRM RELEVANT COUNTRIES—COMMON EXAMPLES MAY INCLUDE THE UNITED STATES, SINGAPORE, NEW ZEALAND, IRELAND OR OTHER COUNTRIES WHERE SERVICE PROVIDERS OPERATE].
Privacy and data-protection laws in those countries may differ from Australian law.
Where required, we take reasonable steps to ensure overseas recipients handle personal information consistently with applicable Australian privacy requirements. However, some overseas disclosures may occur with your consent or under another permitted exception.
You may contact us for more information about the countries in which a particular service provider may process your information.
14. How we protect personal information
We take reasonable administrative, technical and physical measures to protect personal information from:
misuse;
interference;
loss;
unauthorised access;
unauthorised modification; and
unauthorised disclosure.
These measures may include:
access controls and password protections;
multi-factor authentication where appropriate;
secure payment and technology providers;
employee and contractor confidentiality obligations;
staff access restrictions;
system monitoring and security updates;
physical security controls;
data backup and recovery processes; and
procedures for responding to suspected data breaches.
No internet transmission or information-storage system is completely secure. While we take reasonable precautions, we cannot guarantee the absolute security of information transmitted electronically.
15. Data breaches
We maintain processes for identifying, assessing and responding to suspected data breaches.
Where a breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
We may also notify individuals in other circumstances where we consider notification appropriate to help them protect themselves.
16. Retention and deletion
We retain personal information for as long as reasonably necessary to:
provide our services;
manage our relationship with you;
maintain transaction, booking and event records;
meet taxation, accounting, employment, insurance and legal obligations;
manage disputes, complaints or incidents; and
protect our legitimate business and legal interests.
Retention periods vary depending on the type of information and the reason it was collected.
When personal information is no longer reasonably required and we are not legally required to retain it, we will take reasonable steps to destroy it or permanently de-identify it.
Some information may remain in secure backups until those backups are overwritten or securely deleted in accordance with our normal retention processes.
17. Accessing and correcting your information
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, incomplete, out of date, irrelevant or misleading.
To make a request, contact us using the details below. We may need to verify your identity before processing the request.
We will respond within a reasonable period. In some circumstances, Australian law permits us to refuse access or correction. Where this occurs, we will generally explain the reason, unless we are legally prevented from doing so.
We do not usually charge a fee for making a request. We may charge reasonable costs where permitted by law and will notify you before doing so.
18. Privacy complaints
If you believe we have not handled your personal information appropriately, please contact us using the details below.
Please provide:
your name and contact details;
an explanation of your concern;
relevant dates, venues or transactions; and
the outcome you are seeking.
We will acknowledge and investigate your complaint and aim to respond within a reasonable period.
If you are not satisfied with our response, you may be entitled to contact the Office of the Australian Information Commissioner.
19. Third-party websites and services
Our websites, emails and social media pages may contain links to third-party websites, booking platforms, delivery services, payment providers and social media services.
We are not responsible for the privacy practices, security or content of third-party services that we do not control. You should review the privacy policy of the relevant third party before providing information through its service.
20. Social media
When you interact with us through social media, the relevant social media platform may collect and handle information under its own privacy policy.
Information you post publicly may be visible to other users. Please avoid posting sensitive information, payment information or information about another person in public comments.
Where you contact us privately through social media, we may use the information provided to respond to your enquiry and may transfer relevant details into our customer service or booking systems.
21. Children and young people
Our websites and general hospitality services are not primarily directed to children.
Where information about a child is provided in connection with a family booking, event, dietary requirement, incident or other legitimate purpose, we will handle that information only as reasonably necessary.
Parents and guardians should supervise children when they interact with our websites, competitions, loyalty programs or digital services.
22. Employment applications
If you apply for employment or contract work with us, we may collect information including:
your contact details;
resumé and employment history;
qualifications and licences;
availability and work rights;
referee information;
interview notes;
background or reference-check information; and
other information relevant to assessing your application.
We use this information to assess your suitability, communicate with you and administer the recruitment process.
If your application is unsuccessful, we may retain your information for a reasonable period to consider you for future opportunities, meet legal obligations and manage potential employment-related claims. You may ask us not to retain your information for future opportunities.
23. Changes to this Privacy Policy
We may update this Privacy Policy when our operations, technology providers, venues, services or legal obligations change.
The current version will be published on our website with its effective date. We encourage you to review it periodically.
Material changes may also be communicated through our website, email, membership platform or other appropriate channels.
24. Contact us
For questions, access or correction requests, privacy complaints or requests to withdraw marketing consent, please contact:
Privacy Officer
COMUNA CANTINA CITY PTY LTD Trading as Together Hospitality Group
ABN: ABN 65 638 588 333
Email: info@comunacantina.com.au
Postal address: 12 Creek St Brisbane City 4000
Please include “Privacy Request” in the subject line of your correspondence.
