Privacy policy
Last updated: 15 September 2026
Who this is about
This policy explains how we handle personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
There are two different groups of people here, and it matters which one you are.
- Businesses that subscribe to the platform. We hold their information as the organisation responsible for it.
- Clients of those businesses, who book through an app. That information belongs to the business. We hold it on their behalf and only act on their instructions.
What we collect from businesses
- Contact details of the owner and anyone they invite: name, email, mobile.
- The email address you use to sign in, and a scrambled form of your password. We never store the password itself and cannot read it.
- Business details: trading name, address, opening hours, services and prices. If you switch invoicing on, your ABN as well.
- Billing details needed to charge the subscription. Card numbers are handled by the payment provider and never reach our servers.
- Usage records: when someone signed in, what they changed. These help us answer support questions and investigate problems.
If you sign in with Google
Choosing Google to sign in means Google tells us your name, your email address and an identifier for your Google account. That is all we receive. We do not get your Google password, and we cannot see your Gmail, contacts, calendar or files.
We match you by the identifier rather than by the email address, so changing your email at Google does not put you into somebody else's account.
Images you upload
Logos and other brand images you upload are stored with our cloud provider and served from a public address, because they have to load inside an app before anyone signs in. Treat them as public.
Do not upload anything private as a logo.
What a business collects from its clients
When someone books through an app, the business collects their name, email, mobile and booking history. Some businesses also record notes relevant to their service — allergies, preferences, health information for treatments.
Health information is sensitive information under the Privacy Act. A business collecting it needs the client's consent and must keep it for the purpose it was given for. The app keeps those notes internal: clients never see them, and neither do staff outside that business.
Enquiries sent through this website
If you use the contact form, we keep what you sent us — business name, your name, email, and anything else you chose to add — so that we can reply and so we have a record of the conversation.
We do not sell it, and we do not add you to a marketing list you did not ask for.
How information is kept separate
Every record in the system carries the identifier of the business it belongs to, and that identifier is taken from the signed-in session rather than from anything the app sends. Queries that cannot have that condition applied safely are refused outright rather than allowed through.
In plain terms: one business cannot see another business's clients, bookings or payments, and the system is built to fail closed rather than guess.
Who else sees it
We use a small number of providers to run the service. Each one only receives what it needs to do its part.
- Cloud hosting, database and file storage, for keeping and serving the data.
- A payment provider, for subscriptions and — when card payments are switched on — for taking money from your clients. They handle card details; we do not store them.
- An email provider, for booking confirmations, invoices and account emails.
- A push notification provider (Firebase Cloud Messaging), for booking alerts and — only if you have agreed — offers and news from the business.
- A text message provider, if and when a business turns that on. It is not connected yet.
- Google, if you choose to sign in with a Google account.
Where it is stored
Our servers and database are currently in the United States (our cloud provider's US East region), so information is stored and processed overseas. Uploaded images are held in the same provider's Sydney region.
We are looking at moving the servers to Australia as the service grows. If that happens we will update this policy rather than move quietly.
How long it is kept
Business and booking data is kept for as long as the subscription runs. After it ends we keep it for ninety days so that it can be exported or a change of mind can be undone, then we delete it.
Some records are kept longer where the law requires it, such as financial records for tax purposes.
Access, correction and complaints
You can ask what we hold about you, ask us to correct it, and ask us to delete it. If you booked through a business's app, ask that business first — the information is theirs, and we will refer your request to them.
If you are not satisfied with how we handle a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Data breaches
If a breach happens that is likely to cause serious harm, we will notify the affected people and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Cookies
This website does not use tracking or advertising cookies, and there is no cookie banner because there is nothing to consent to.
When you sign in — here or on the management screens — your browser keeps a sign-in token so that you stay signed in. It is removed when you sign out. On a shared computer, sign out when you are finished.