Privacy Notice
Last updated: 5 October 2026
Archived document version. Later updates do not change this text.
For account, service or privacy enquiries and complaints, contact us. Document archive.
Service provider and contact
BizAppMaker is operated by SOHYUN PARK, ABN 45 229 308 688. References to we, us or our in this document mean SOHYUN PARK operating BizAppMaker.
For service, account and privacy enquiries, access or deletion requests, or complaints, email [email protected] or use the contact form at bizappmaker.com/contact. Please identify the business or account involved and describe your request. Do not send passwords or full payment-card details.
Who this is about
This policy explains how we handle personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
There are two different groups of people here, and it matters which one you are.
- Businesses that subscribe to the platform. We hold their information as the organisation responsible for it.
- Customers who book, order or use a business's app or website. The business controls its customer and service records; we process those records to operate the service and also handle platform security, support and compliance information for our own responsibilities.
What we collect from businesses
- Contact details of the owner and anyone they invite: name, email, mobile.
- The email address you use to sign in, and a scrambled form of your password. We never store the password itself and cannot read it.
- Business details: trading name, address, opening hours, services and prices. If you switch invoicing on, your ABN as well.
- Billing details needed to charge the subscription. Card numbers are handled by the payment provider and never reach our servers.
- Usage records: when someone signed in, what they changed. These help us answer support questions and investigate problems.
If you sign in with Google or Apple
Choosing Google to sign in provides an account identifier and authorised profile information such as your name, email and profile-photo reference. We do not receive your Google password or request access to your Gmail, contacts, calendar or files.
We match you by the provider identifier rather than by the email address, so changing your email at Google does not put you into somebody else's account.
Customer apps also support Sign in with Apple. Apple provides an account identifier and, when authorised and available, your name and email or a private relay email address. We do not receive your Apple password.
Images you upload
Logos and other brand images you upload are stored with our cloud provider and served from a public address, because they have to load inside an app before anyone signs in. Treat them as public.
Profile photos may appear publicly beside your reviews, and photos you attach to a published review are public. Private upload originals are kept separately from the versions used for public display. Do not upload confidential information or another person's photo without permission.
What a business collects from its clients
When someone books or orders through an app or website, the business collects contact details, booking and order history, selected services or menu items, payment status, loyalty activity, reviews, and requests the customer chooses to provide. Messages and support conversations are kept to handle the enquiry and maintain a record.
Businesses may record service preferences or treatment notes. Please avoid putting unnecessary sensitive information into free-text requests, reviews or messages.
A business that collects health information or other sensitive information must establish the appropriate lawful basis and obtain any consent required for that information and its intended use. Accepting general app terms is not consent to collect health information. Internal customer notes are available to authorised business staff, rather than published to other customers.
When a business uses the Manager app and receipt printing, order details such as customer name, items and request notes are sent to its registered devices and printers. The business is responsible for protecting its devices and disposing of printed copies securely.
Enquiries sent through this website
If you use the contact form, we keep what you sent us — business name, your name, email, and anything else you chose to add — so that we can reply and so we have a record of the conversation.
We do not sell it, and we do not add you to a marketing list you did not ask for.
How information is kept separate
Business records are scoped to the relevant business, with access checks for signed-in accounts, staff roles and supported guest operations. Platform administration and public booking or ordering use their own access controls.
These controls are designed to prevent one business from accessing another business's private customer, booking or payment information. Public business information and reviews are deliberately available to visitors; authorised support access may be needed to operate the platform.
Who else sees it
We use a small number of providers to run the service. Each one only receives what it needs to do its part.
- Amazon Web Services (AWS), for hosting, database, backups and uploaded files.
- Stripe for platform subscriptions and supported customer payments; Square where a business enables supported Square payments. Payment providers handle card details; we retain payment references, status and transaction records, not full card numbers.
- An email provider, for booking confirmations, invoices and account emails.
- Firebase Cloud Messaging and Apple notification services, for device delivery of booking and order updates and, where you have opted in, offers and promotions. We store device notification tokens and your notification preferences. Operating-system notification permission and optional promotional consent are separate; you can change promotional preferences in your profile.
- Google or Apple, if you choose their sign-in service.
Where it is stored
Our primary servers, database and uploaded photos and files are currently hosted by Amazon Web Services in the United States, in the US East (Northern Virginia, us-east-1) region. This means information provided from Australia, New Zealand, Canada and other countries is transferred to and stored in the United States.
Payment, sign-in, email and notification providers may process information in other countries according to their own service arrangements. The primary AWS storage location does not mean that every provider processes data only in the United States. We will update this notice when our arrangements change.
How long it is kept
Business and booking data is retained while the subscription runs. After the paid subscription actually ends, the normal export window is ninety days. At the end of that window we review and delete or de-identify ordinary customer and business data through our reviewed closure process. This is an operator-reviewed process, not an automatic deletion of every record on day ninety. A cancellation request made before the paid period ends does not start that window.
Records needed for outstanding payments, disputes, fraud investigations or legal obligations, including financial records, may be retained separately for as long as required. They are restricted to those purposes and reviewed before disposal. Account deletion and the closure of an entire business are separate processes.
Operational database backups normally expire after seven days, server backups use seven daily recovery points, and superseded upload versions normally expire after thirty days. Eligible upload deletion also removes stored file versions. Manually retained recovery copies may remain longer where needed for recovery or a legal hold, with restricted access and a disposal review. Backups are not used for ordinary access; if a backup is restored, recorded deletion requests must be reapplied before normal service resumes.
You can request an export or deletion through our contact form. We verify the request and any authority to act for a business before releasing or deleting information.
Access, correction and complaints
You can ask what we hold about you, ask us to correct it, and ask us to delete it. For booking, order or service records, you can ask the business or contact us for assistance. We coordinate requests with the business where it controls the relevant records; you can contact us directly about your platform account or our own handling of information.
Use the contact form on this website and mark your enquiry as a privacy request or complaint. Explain what happened and how we can contact you. We will investigate and respond, requesting identity verification where needed. You may also contact the privacy regulator relevant to your location, including the Office of the Australian Information Commissioner at oaic.gov.au, New Zealand's Office of the Privacy Commissioner at privacy.org.nz, or Canada's Office of the Privacy Commissioner at priv.gc.ca.
Data breaches
We investigate suspected personal-information breaches, take steps to contain them, and notify affected people, businesses and regulators where required by applicable law. The notification rules and time limits depend on the affected country and information.
Cookies
We use browser storage for sign-in, application drafts and recovery of booking or order progress. We do not currently use advertising or cross-site tracking cookies on this website.
When you sign in — here or on the management screens — your browser keeps a sign-in token so that you stay signed in. It is removed when you sign out. On a shared computer, sign out when you are finished.