Privacy policy
Last updated: 6 May 2026
This policy explains what information Bookzyr collects when you use our website and services, how we use it, and the choices you have. We are based in Australia and follow the Australian Privacy Principles, the GDPR for users in the EU/UK, and the CCPA for users in California.
1. Who we are
Bookzyr ("we", "us", "our") is operated by Bookzyr Pty Ltd, registered in Australia. If you have questions about this policy or your data, contact us at privacy@bookzyr.com.
2. Information we collect
We collect information in three ways:
You give it to us
- Account information: name, email, business name, phone number, business address.
- Payment information: handled by our payment processor (Stripe). We do not store full card numbers.
- Client and booking data: when you use Bookzyr to manage clients and bookings, that data is processed on behalf of your business — see Section 6.
- Support & communications: messages, screenshots and feedback you send us.
Automatically
- Device & usage: IP address, browser type, pages visited, referring URL, timestamps.
- Cookies and similar: see our Cookie policy.
From third parties
- If you sign in with Google or Meta, we receive basic profile information from those services.
- If you connect a calendar (Google, Apple) or marketing pixel (Meta, Google), we receive event data needed to provide that integration.
3. How we use your information
- To provide, operate and improve the Bookzyr service.
- To process payments and prevent fraud.
- To send you transactional emails (booking confirmations, receipts, account notices).
- To send marketing emails about Bookzyr — only if you've opted in. You can unsubscribe at any time.
- To respond to support requests.
- To meet legal and accounting obligations.
4. Legal bases for processing (GDPR users)
We rely on the following legal bases:
- Contract — to provide the service you signed up for.
- Legitimate interests — to improve the product, prevent fraud, and run our business.
- Consent — for marketing emails and non-essential cookies.
- Legal obligation — for tax, accounting and regulatory compliance.
5. Sharing your information
We do not sell your personal information. We share it only with:
- Service providers who help us run Bookzyr — hosting (AWS), payments (Stripe), email (Postmark), analytics (Google Analytics), customer support (Intercom). They process data under strict contracts.
- Integrations you authorise — Google, Meta, Apple, etc. — only when you connect them.
- Authorities — when required by law or to protect our rights and users.
- An acquirer — if Bookzyr is acquired or merged, we'll notify you in advance.
6. Client and booking data (for businesses using Bookzyr)
If you are a salon, barber or spa using Bookzyr, the personal data of your clients (names, contact details, appointment notes, photos) is processed by us on your behalf. You are the data controller; we are the processor. You are responsible for having a valid legal basis to collect and process that data, and for honouring your clients' rights.
7. Data retention
We keep your personal information for as long as your account is active. After you close your account, we delete or anonymise most data within 90 days, except where we must retain it for legal, tax or fraud-prevention reasons (typically up to 7 years for financial records).
8. International transfers
Your data may be processed in Australia, the EU and the United States. When data leaves your region, we use approved safeguards such as Standard Contractual Clauses.
9. Security
We use encryption in transit (TLS) and at rest, role-based access controls, regular backups and routine security testing. No system is perfectly secure — if we discover a breach that affects you, we will notify you and the relevant authority within 72 hours.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct or update that information.
- Delete your information ("right to be forgotten").
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@bookzyr.com. We'll respond within 30 days.
11. Children
Bookzyr is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has given us their information, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product evolves. Material changes will be notified by email or in-app at least 30 days before they take effect. The "Last updated" date at the top reflects the latest revision.
13. Contact
Questions, requests or concerns: privacy@bookzyr.com.
