Protecting Customer and Venue Data in Booking, POS and Delivery Systems
Share
Hospitality venues hold more information than they often realise: reservations, phone numbers, delivery addresses, dietary notes, loyalty profiles, staff accounts, rosters, sales, supplier prices, CCTV, invoices and payment-system records. Protecting it starts with knowing where it is, collecting only what is needed, limiting access, securing accounts and devices, controlling exports, setting retention rules and preparing for an incident.
Do not assume that a small venue is automatically outside the Privacy Act, or that a software provider owns the whole responsibility. Check coverage and contracts, then apply sensible information-security practices across the full data lifecycle.
Check which privacy obligations apply
The Office of the Australian Information Commissioner (OAIC) provides a small-business checklist. Some businesses with annual turnover of $3 million or less may still be covered because of their activities or the information they handle. Other laws, contracts, payment rules and state or territory obligations may also apply.
If the Privacy Act covers the venue, the Australian Privacy Principles include requirements for personal-information handling. APP 11 requires covered entities to take reasonable steps to protect personal information and to destroy or de-identify it when it is no longer needed, subject to lawful retention requirements.
Coverage can be complex where a venue:
- operates with related entities or franchises;
- provides a health service or holds health information;
- trades in personal information;
- handles tax file numbers;
- uses overseas systems;
- participates in loyalty or profiling arrangements;
- shares data between businesses; or
- experiences a possible eligible data breach.
Obtain privacy advice for uncertainty. Even where the Act does not apply, poor data handling can harm customers, staff and the business.
Make a simple data map
List each system and information flow.
| System | Typical information | Access | Export or sharing | Retention owner |
|---|---|---|---|---|
| Booking platform | Name, contact, party, notes | Hosts and managers | Email, calendar, marketing links | Venue manager |
| POS | Orders, staff login, sales and refunds | Service staff and managers | Accounting, loyalty, reporting | Owner/accounts |
| Delivery platform | Name, order, address and contact | Expediter and manager | Platform and driver | Channel owner |
| Payroll/rostering | Identity, hours, bank and employment data | Owner, payroll, managers | Payroll adviser/provider | Employer |
| CCTV/access | Images, timestamps and entry records | Restricted managers | Security, insurer, police where lawful | Owner |
| Shared drives/messages | Reports, incidents, exports and documents | Varies | Staff and external advisers | Document owner |
For each, ask:
- Why is the information collected?
- Is every field necessary?
- Who can see, change, export or delete it?
- Where is it stored and backed up?
- Which supplier or overseas service receives it?
- How long is it needed?
- How is access removed?
- What happens after a breach or lost device?
Do not forget paper booking sheets, printed delivery dockets, screenshots, downloads and personal phones.
Minimise collection
Collect information needed to deliver the service, meet obligations or manage a defined business purpose. Avoid open text fields that invite unnecessary medical, family or financial detail.
For dietary or accessibility requirements:
- ask only what the venue needs to plan the service;
- use respectful, factual wording;
- restrict access to relevant roles;
- avoid copying details into public briefings; and
- delete or de-identify according to the approved retention rule.
Do not photograph identity documents or payment cards “just in case”. Do not store complete card details in a booking note, spreadsheet, email or message. Use the approved payment provider process.
Give each person their own account
Shared logins remove accountability and make access difficult to revoke.
- create named accounts;
- assign the lowest practical access;
- separate refund, discount, reporting and administration permissions;
- require multi-factor authentication where available;
- use strong unique passwords and an approved password manager;
- prevent password sharing;
- review administrator accounts; and
- remove access promptly when roles change or employment ends.
Check service accounts and old owners too. A former manager’s active administrator login is a material gap even if no misuse is known.
Review permissions at a set frequency and after staff, provider or venue changes. Record who approved high-level access.
Secure POS, tablets and venue devices
Apply the Australian Cyber Security Centre’s current small-business guidance and provider requirements.
- keep operating systems and apps supported and updated;
- use device locks and short automatic lock times where practical;
- restrict app installation;
- separate staff or guest Wi-Fi from sensitive systems where supported;
- secure routers and change default credentials;
- protect remote access;
- use reputable endpoint protection and backups;
- disable unused accounts and services;
- do not leave admin screens visible to customers;
- keep devices physically secure; and
- know how to lock or wipe a lost device.
POS availability is also an operational issue. Maintain a controlled outage process that does not lead staff to write full card details or customer lists on loose paper.
Back up and test recovery
Identify which venue records can be restored by each provider and which must be backed up separately. Protect backups from the same compromised account or device where practicable, restrict access and test restoration at planned intervals.
A successful backup notification is not a recovery test. Confirm that an authorised person can restore the required data within an operationally useful time and that the restored copy is complete, current enough and protected. Record the test, problems and corrective actions.
Keep an offline contact list for critical providers, advisers and incident roles without copying unnecessary customer data.
Control exports and reports
A CSV download can contain more personal information than the screen shows.
Before exporting:
- Confirm purpose and authorised recipient.
- Select only required fields and date range.
- Use an approved secure location.
- Name the file without unnecessary personal information.
- Share through the approved method.
- Record or restrict access where risk warrants.
- Delete working copies after the task, subject to retention rules.
Do not send a full customer list because an adviser asked for “sales data” if aggregated or de-identified information will do.
Screenshots can expose names, addresses, order details and system information. Crop or redact only where the resulting record remains accurate, and do not use customer data in training examples.
Review providers and integrations
For booking, POS, loyalty, delivery, payroll, Wi-Fi and marketing suppliers, confirm:
- information collected and purpose;
- where data is hosted;
- security and authentication options;
- staff and vendor access;
- sub-processors or integrations;
- backup and recovery;
- breach notification process;
- retention and deletion;
- data export on exit;
- ownership and permitted use;
- support contacts; and
- contract allocation of responsibilities.
Turn off integrations that are no longer used. Removing the visible app icon does not necessarily revoke its access.
Do not claim that a well-known platform makes the venue secure. Configure the product properly and understand what remains the venue’s task.
Create retention and disposal rules
Different records have different legal, tax, employment, licence, food-safety, insurance and dispute needs. Build a schedule with a qualified adviser.
For each record type, state:
- owner;
- business or legal purpose;
- start event;
- retention period or review trigger;
- storage location;
- access;
- hold for dispute or investigation;
- approved destruction or de-identification method; and
- evidence of disposal where appropriate.
Do not keep booking exports indefinitely because storage is cheap. Equally, do not delete records that must be retained for tax, employment, licence, food-safety or legal reasons.
Dispose of paper securely. Clear downloads, recycle bins, archived mailboxes and old devices—not just the main system.
Handle staff changes
Use a same-day access checklist:
- disable or adjust accounts;
- revoke sessions and tokens;
- recover devices, keys and cards;
- transfer ownership of shared files and integrations;
- change truly shared operational secrets that cannot yet be eliminated;
- remove forwarding rules;
- confirm provider and remote access;
- preserve employment records lawfully; and
- document completion.
Do not delete evidence needed for a workplace process. Separate access removal from record-retention decisions.
Prepare for a suspected data incident
A data incident may involve a lost tablet, email sent to the wrong person, exposed booking sheet, compromised password, fraudulent refund access, unauthorised export or provider breach.
Give staff this response:
- Stop further exposure where safe: lock device, revoke session, recall email or remove public access.
- Preserve relevant logs and evidence.
- Tell the incident lead immediately.
- Record what happened, systems, information, people and time.
- Contact the provider or cyber specialist.
- Assess legal and contractual notification requirements.
- Communicate only approved, accurate information.
- Recover, monitor and review controls.
The OAIC’s Notifiable Data Breaches scheme applies to entities covered by relevant Privacy Act security obligations. Whether an incident is an eligible data breach requires assessment; do not promise customers there is “no risk” before that work.
For active cybercrime or serious compromise, use current cyber.gov.au reporting and recovery guidance and contact police or other authorities where appropriate.
Respond to customer requests
Train staff to recognise privacy questions, access or correction requests, direct-marketing opt-outs and deletion requests. Do not disclose information merely because a caller knows a booking name.
Use an identity-verification method proportionate to the request. Collecting more information than necessary to verify the person can create another risk. Escalate to the responsible manager and record the outcome.
Worked scenario: booking export sent to the wrong email
A manager exports upcoming functions and sends the file to an incorrect external address. The sheet includes customer names, phone numbers, dates and dietary notes.
The manager immediately reports it, asks the recipient to delete the file, preserves the sent message and tells the incident lead. Access to the link is revoked if possible. The venue identifies the data and affected people, contacts its privacy adviser and provider, assesses obligations and records decisions. It then replaces manual email attachments with restricted sharing and a recipient-check step.
The first action is containment, not quietly deleting the sent email from the manager’s mailbox.
Common mistakes
- Assuming every small business is exempt.
- Leaving default administrator accounts active.
- Sharing one POS login across the team.
- Collecting full card or medical details in notes.
- Giving every manager access to every report.
- Emailing complete exports when aggregate data is enough.
- Keeping old integrations and former staff accounts.
- Treating provider security as the venue’s whole plan.
- Deleting records without checking retention duties.
- Hiding an incident because the venue is unsure whether notification applies.
Data protection checklist
- ☐ Check Privacy Act and other legal or contractual coverage.
- ☐ Map systems, data, access, sharing and retention.
- ☐ Remove unnecessary collection and open text fields.
- ☐ Use named accounts and least-privilege access.
- ☐ Enable multi-factor authentication where available.
- ☐ Secure and update POS, tablets, routers and computers.
- ☐ Control exports, screenshots, paper and personal devices.
- ☐ Review provider contracts, integrations and breach contacts.
- ☐ Create a lawful retention and secure-disposal schedule.
- ☐ Remove access promptly after role or staff changes.
- ☐ Train staff to report suspected incidents immediately.
- ☐ Maintain an incident assessment and communication process.
- ☐ Test recovery and review permissions regularly.
Take the next useful action
Open the booking, POS and delivery administration screens and list every person with administrator access. Remove or reduce any account without a current documented need, then enable multi-factor authentication for the remaining administrators.
Use the Free Hospitality Checklists to support repeatable reviews. The Hospitality Operations Master Collection provides editable operating tools. Use the hospitality SOP guide to control the procedure.
General-information limitation: General operational information only. Confirm Privacy Act, state or territory, employee-record, payment, marketing, surveillance, tax, licence, contract and data-breach requirements with qualified privacy, cyber-security, legal and accounting advisers. Security controls reduce risk but cannot guarantee that an incident will not occur.
References
- Small business privacy checklist, Office of the Australian Information Commissioner. Accessed 25 August 2026.
- APP 11 — security of personal information, Office of the Australian Information Commissioner. Accessed 25 August 2026.
- Quick reference guide for responding to data breaches, Office of the Australian Information Commissioner. Accessed 25 August 2026.
- Small business cyber security, Australian Signals Directorate’s Australian Cyber Security Centre. Accessed 25 August 2026.
Source review date: 25 August 2026