Privacy Policy
Last updated: March 2026
1. Information We Collect
We collect information you provide directly when you create an account, set up your business profile, or use our services. This includes:
- Account information (name, email address, password)
- Business information (business name, industry, timezone, contact details)
- Client data you add to the platform (names, phone numbers, email addresses, appointment history)
- Payment information processed through our payment partner, Stripe
- Usage data and analytics to improve our services
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send appointment reminders and notifications on your behalf
- Provide customer support
- Monitor and analyse usage trends
- Detect and prevent fraud or abuse
3. Data Security
We take data security seriously. Your data is protected by:
- Encryption at rest for personally identifiable information (PII) using pgcrypto
- HTTPS encryption for all data in transit
- Row-level security (RLS) at the database level for complete tenant isolation
- Regular security audits and vulnerability assessments
- Role-based access controls within your organisation
4. Data Sharing
We do not sell your personal information. We share data only with:
- Stripe — for payment processing
- Twilio — for SMS notifications
- Resend — for email delivery
- AnswR — if you enable the AI receptionist add-on (appointment data only)
These providers are bound by their own privacy policies and data processing agreements.
5. Your Rights
Under the Australian Privacy Act and GDPR (where applicable), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a machine-readable format
- Withdraw consent for data processing
To exercise these rights, contact us at [email protected].
6. Data Retention
We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., financial records).
7. Cookies
We use essential cookies to maintain your session and preferences. We do not use third-party tracking cookies or advertising cookies.
8. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or through a notice on our platform.
9. Contact Us
If you have questions about this privacy policy, please contact us at [email protected].