Customers & Businesses
Privacy Policy
Last updated: 19 August 2026
How to read this page
1. About this policy
This Privacy Policy explains how Bookspot ("we", "us") manages personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). It applies to Customers who book a service with a Business through the platform and to Business team members (Owners and Staff) who use the platform to run their appointments.
Needs legal review — APP entity status & the small-business threshold
2. What personal information we collect
We collect:
- Customer details: name, email address, phone number, and booking history (service, provider, date, time, and status changes).
- Guest details: the same Customer details when a booking is made without an account, plus the booking-management token needed to control that single booking.
- Business team details: name, email address, phone number, and authentication credentials for Owners and Staff.
- Technical signals: IP addresses and bot-protection signals collected by Cloudflare Turnstile on public surfaces, and session cookies for authenticated Users (see our Cookie Notice).
3. How we collect personal information
We collect personal information directly from you when you enter it to make or manage a booking, or when you create or sign in to an account. We also collect technical signals automatically when you visit the platform, as described in our Cookie Notice.
Needs legal review — APP 5 notification for Guests
4. Why we collect personal information
We collect and hold personal information for these purposes:
- to process, confirm, and manage bookings between Customers and Businesses;
- to send transactional notifications — booking confirmations, cancellations, reschedules, and operational notices to a Business's operations email;
- to let a Customer or Guest manage a specific booking through its management link;
- to authenticate Business team members and operate the /admin console; and
- to secure the platform and prevent abuse, including via Turnstile bot protection.
5. How we use and disclose your information
We use personal information for the primary purpose for which it was collected. We disclose Customer booking details to the Business the booking is made with, so that Business can deliver the service. We do not sell personal information.
We use third-party service providers to operate the platform: Cloudflare (Turnstile bot protection) and Resend (transactional email delivery). Each receives only the personal information needed to perform that service.
Needs legal review — Who is the APP entity for Customer PII (Flag 1)
Standard clause — No secondary use without an exception
6. Marketing communications
We do not send you marketing messages unless you have consented. Where we do, you may opt out at any time using the unsubscribe facility in the message, and we will honour your request within five working days, as required by the Spam Act 2003 (Cth) and APP 7.
Standard clause — Transactional email is not marketing
7. Overseas disclosure
Cloudflare and Resend are global services and may process personal information outside Australia (principally in the United States). Where we disclose personal information to an overseas recipient, APP 8.1 requires us to take reasonable steps to ensure the recipient does not breach the APPs, and we remain accountable for the recipient's handling under s 16C of the Privacy Act.
Needs legal review — APP 8 reasonable-steps evidence
8. Data retention and security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11.1), including technical and organisational security measures (APP 11.3) and multi-factor authentication for platform console access.
We retain personal information only for as long as it is needed for the purposes described in this policy or as required by law, and then destroy or de-identify it (APP 11.2). Customer and booking data is held while a Business is active or in an archived hold, and is deleted in a single transaction when a Business is permanently removed (see our Business Terms). Where a Business is archived, data is retained for a limited period to allow restoration, then deleted.
Needs legal review — Retention periods & backup destruction (Flag 6)
9. Access and correction
You may request access to, or correction of, the personal information we hold about you (APP 12 and APP 13). For booking information, contact the Business first; for platform questions, contact us using the details below. We will respond within a reasonable period.
10. Complaints
If you believe we have breached the APPs, you can complain using the contact details below. We will investigate and respond. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.
11. Cookies and tracking
We use session cookies for authentication and Cloudflare Turnstile signals for bot protection. Details, including how to manage cookies, are in our Cookie Notice. Australia does not require a cookie consent banner, but we are transparent about what we collect.
12. Changes to this policy
We may update this policy from time to time and will publish the updated version on the platform with a revised "last updated" date.