Tableside

Consumer Health Data Privacy Policy

Last updated: August 1, 2026

This Policy is required by Washington's My Health My Data Act and addresses the same rights for residents of Nevada (SB 370) and Connecticut. It explains how Bizsys Consulting LLC handles consumer health data — a broad category that, under those laws, can include the simple fact that you booked a particular appointment. It supplements, and does not replace, our Privacy Policy.

1. What counts as consumer health data

These laws define consumer health data very broadly: information that identifies your past, present, or future physical or mental health status. That includes bodily functions and symptoms, but it also includes the health-care services you seek or receive — and booking a massage, physical therapy, or similar wellness appointment can fall within that definition even though we are not a medical provider and collect no diagnoses.

We take the conservative reading and treat appointment information as consumer health data throughout this Policy.

2. What we collect and where it comes from

We collect this information directly from you when you book on a Business's booking page, or from the Business when its staff enters an appointment on your behalf:

  • the service you booked and its date, time, and duration;
  • the provider you were matched with, and — if the Business offers it — a preference you expressed about that provider;
  • anything you choose to type into the optional notes field on the booking form;
  • your name, phone number, and email address, which tie the above to you; and
  • whether you agreed to receive text message reminders.

The notes field is optional and free-form. We ask you not to include health details there, and the form says so, but anything you do enter is treated as consumer health data.

3. How we use it

Only to provide the booking service you asked for: creating and managing your appointment, delivering it to the Business, sending you confirmations and reminders, and keeping the platform secure and working. We do not use it to profile you, to make inferences about your health, or to decide what you see.

4. Who we share it with

We share it only with parties who need it to deliver the booking:

  • the Business you booked with, which is the reason the booking exists;
  • our email provider, to deliver your confirmation and reminder;
  • our SMS provider, if you opted in to text reminders;
  • our hosting and database providers, which store it on our behalf; and
  • Google Calendar, if that Business has connected sync — the service, time, notes, and your contact details are written as an event on the calendar they chose.

Each is contractually limited to processing it for us and may not use it for their own purposes. The current list is on our subprocessors page.

5. We do not sell it

Bizsys Consulting LLC does not sell consumer health data, and we will not. Under Washington law a sale requires a signed authorization from you on a specific statutory form; we do not seek that authorization because we do not engage in the practice it would permit.

6. Advertising and analytics

We do not send what you booked to any advertising or analytics provider. Our booking confirmation pages report only an anonymous transaction identifier and an amount, never the service name. Google Calendar is not advertising or analytics; if the Business has connected it, that disclosure is described in Section 4.

On booking pages for businesses located in Washington and Nevada we disable third-party analytics and advertising tags entirely, including any tag the Business itself has configured. Everywhere else, Google Ads cookies stay off until you accept the cookie banner, you can turn all tags off with Your Privacy Choices, and we honor the Global Privacy Control signal automatically.

7. Your rights

You have the right to:

  • confirm whether we collect, share, or sell your consumer health data, and access it, including a list of who we shared it with;
  • withdraw consent to our collection and sharing of it;
  • have it deleted; and
  • not be discriminated against for exercising any of these rights.

When you ask us to delete, we delete it from our live systems and direct our processors to do the same. Two narrow exceptions, both required of us by other law: records proving you agreed to receive text messages are retained, without other details, because federal telemarketing law requires us to be able to produce them; and payment records are retained for tax and accounting.

8. How to exercise your rights

Email support@booktableside.com with the phone number or email address you booked with. We will verify that the request is really yours and respond within 45 days, and we will tell you if we need a further 45 days.

Because the Business you booked with holds its own copy of your appointment records and decides how it uses them, the fastest route is often to ask the Business directly — it has tools built into Tableside to answer you. Contact us either way and we will help route the request.

9. Appeals

If we decline your request, our response will explain why and how to appeal. To appeal, reply to that response or email support@booktableside.com with "Appeal" in the subject line. We will respond within 45 days. If we deny the appeal, you may complain to the Washington Attorney General or the attorney general of your state.

10. Retention and security

Appointment records are kept while the Business's account is active so it has its own history. Personal details attached to bookings are removed automatically once an appointment is old enough that no one needs them, and are removed immediately on a valid deletion request. Everything is encrypted in transit, access is limited to staff who need it, and employee access to consumer health data is restricted to what is necessary to operate and support the service.

Contact

Bizsys Consulting LLC, support@booktableside.com

7901 4th St N # 20814, St. Petersburg, FL 33702