Privacy Policy Last updated: August 29, 2026 Version 2026-08-29 — read the archived copy of this exact version (/legal/privacy-policy/2026-08-29.txt) If you create a BookIQ.ai account now, this is the version that applies to you, from the moment you create it — it is the text shown at signup and the version recorded against your account. If your account already existed on 5 August 2026, this version takes effect for you on 5 September 2026, at the end of the 30 days’ notice we give for a material change; until then the version that applies to your account is 2026-05-11, which you can read here (/legal/privacy-policy/2026-05-11.txt). What changed in this version: section 5 previously said only that personal data is “permanently erased within 30 days” when an account is deleted, with no mention of the files an account deletion deliberately does not remove. It now says exactly what a deletion erases, and that the files you uploaded on behalf of a business — its branding, its service, portfolio and partner-directory media, the documents attached to its records and its e-invoices — stay with that business, on which legal basis, and how to ask us to look at a specific file. Nothing about what we actually delete has changed; the previous wording described it incompletely. Carried over from 2026-08-05: section 3a names every subprocessor we engage, and section 3b explains where your information is processed when it leaves Australia. Data Controller BookIQ.ai is operated by PairOx Pty Ltd (registered in Australia), the data controller for the purposes of GDPR (where applicable). Where this policy uses "we", "us", or "BookIQ.ai" it refers to PairOx Pty Ltd. 1. Information We Collect We collect information you provide directly to us, such as your name, email address, phone number, business details, and payment information. We also collect usage data and device information to improve our services. 2. How We Use Your Information - Provide, maintain, and improve our booking and business management services - Process transactions and send related information - Send technical notices, updates, security alerts, and support messages - Respond to your comments, questions, and customer service requests - Monitor and analyze trends, usage, and activities in connection with our services 2a. SMS Program & Consent When you opt in to SMS (text) messages, we collect your mobile phone number together with a record of your consent — including the date and time of the opt-in and the source where it was given (for example a booking form, sign-up form, or a consent recorded by the business you booked with). We use this information to send appointment reminders, booking notifications, and account alerts. Marketing messages are sent only with your separate, explicit marketing consent. SMS opt-in consent and phone numbers are never shared with or sold to third parties or affiliates for their marketing purposes. Phone numbers are shared only with our SMS delivery subprocessor (Twilio, listed in section 3a) solely to deliver the messages you opted in to receive. You can opt out at any time by replying STOP to any message (reply HELP for help), by updating your communication preferences in your account or client portal, or by contacting us at privacy@bookiq.ai. Message frequency varies, and message & data rates may apply. 3. Cookies & Tracking We use cookies for sign-in and, with your permission, for product analytics (PostHog) and error monitoring (Sentry). On your first visit we ask whether you accept analytics & error-monitoring cookies. You can change your choice at any time using the button below — it will reset your preference and show the banner again on the next page load. Reset cookie preferences 3a. Subprocessors The list below names the third parties that process personal information on our behalf so that BookIQ.ai can run. Which of them apply to you depends on the features you use: the core platform subprocessors are involved in every account, and the rest are engaged only when you turn on the relevant feature or connect the relevant account. We keep this list current and we update it before engaging a new subprocessor that processes personal information. If you would like to know more about any of them, email privacy@bookiq.ai. - Core platform — used for every account - Supabase (Sydney, Australia) — primary database, authentication and file storage. Receives everything you and your clients enter into BookIQ.ai. - Vercel (United States, with a global edge network) — website and application hosting. Receives web request metadata including IP addresses; requests are served from the edge location closest to the visitor, which may be outside Australia. - Stripe (United States) — payments and subscription billing. Receives billing identity, payment-method metadata, and subscription and invoice records. - Resend (United States) — sending transactional email. Receives recipient email addresses and message content. - Migadu (Switzerland) — receiving email sent to our addresses. Receives inbound message content. - Sentry (United States) — error and performance monitoring, only with your consent. Receives error reports, device and request information, and session diagnostics used to reproduce a fault; on-screen text is masked before it is sent. - PostHog (United States) — product analytics, only with your consent. Receives product usage events and device information. - Google (United States) — Sign in with Google, and Google Maps for addresses and geocoding. Receives the sign-in profile you choose to share and the addresses looked up. - Apple (United States) — Sign in with Apple. Receives the sign-in identity you choose to share. - Expo (United States) — delivery of push notifications to the BookIQ mobile app. Receives device push tokens and notification content, and passes the notification to Apple’s or Google’s push service for final delivery to the device. - Twilio (United States) — sending SMS and phone-number verification. Receives phone numbers and the content of the messages you send. - OpenAI (United States) — the AI features (assistant, transcription, document understanding and semantic search). Receives audio recordings and transcripts you or your clients submit, uploaded documents, and prompt content. - Location, scheduling and utility services - ip-api.com (processing location not published by the provider) — approximate location from an IP address, used to set regional defaults such as currency and time zone. Receives the visitor’s IP address. - Open-Meteo (European Union) — weather for an appointment’s location. Receives appointment coordinates. - OSRM (community-hosted; processing location not published) — travel-time estimates between two points. Receives origin and destination coordinates. - goQR (Germany) — generating QR-code images for payment and sharing links. Receives the encoded value, which can include a booking or invoice reference, and the IP address of whoever views the code. - Nager.Date (European Union) — public-holiday calendars. Receives a country code and a year only, and no personal information. - Accounts and channels you connect — used only if you connect them - Square (United States), PayPal (United States), Alipay (China) and WeChat Pay (China) — payments taken through a payment account you connect. Receive payer identity and transaction data. - Meta (WhatsApp Business, Facebook, Instagram — United States), LINE and LINE Pay (Japan and Asia-Pacific), WeChat (China), Telegram and Viber (processing location not published), and Kakao (South Korea) — messaging channels you connect. Receive your clients’ channel identifiers or phone numbers and the content of the messages sent. - X (Twitter) and LinkedIn (United States) — publishing posts from a social account you connect. Receive the post content and media you publish. - Slack (United States) and Zoom (United States) — team notifications and meeting links. Receive notification content, and the participant name, email and scheduling details for a meeting. - Microsoft (Outlook and Microsoft 365; region depends on your Microsoft tenant) — calendar, contacts and email integration. Receives calendar events, contacts and email metadata. - HubSpot (United States) — CRM sync. Receives client contact records. - Xero (processing location depends on your Xero account), Intuit QuickBooks (United States), MYOB (Australia) and Mailchimp (United States) — accounting and marketing sync. Receive invoice and client billing records, and for Mailchimp, client email addresses and engagement data. - Toast (United States) — point-of-sale sync. Receives order and customer records. - Statutory recipients — not our subprocessors - Government e-invoicing portals (Mexico, Brazil, Italy) — where you issue an electronic invoice that a country’s law requires to be filed, the invoice is transmitted to that country’s tax authority, including your client’s identity and tax identifiers. Those authorities are statutory recipients, not processors acting on our behalf. - Configured in our software but not enabled today - Our software also contains integrations for Anthropic, Microsoft Azure OpenAI, Microsoft Azure Cognitive Services Speech, Amazon Web Services (Amazon Polly and Amazon Transcribe), Google Gemini, Google Cloud Speech-to-Text, Google Cloud Text-to-Speech, Google Cloud Translation, DeepL, Mapbox, HERE Technologies and SendGrid. None of them is enabled on BookIQ.ai today and no personal information is being sent to them. We will update this list before enabling any of them. 3b. Where Your Information Is Processed BookIQ.ai is operated from Australia and your account data is stored in Sydney, Australia. Some of the subprocessors listed above operate outside Australia — principally in the United States, and in the European Union and Switzerland — so using BookIQ.ai involves disclosing personal information to overseas recipients. If you connect one of the optional accounts or regional payment and messaging services listed in section 3a, personal information may also be disclosed in that provider’s country, including Japan, South Korea, China, Mexico, Brazil and Italy. The country for each subprocessor is shown in section 3a where we are able to state it. Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on the data-processing terms offered by each subprocessor, which for these transfers incorporate the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies. If you would like more detail about a particular transfer, contact us at privacy@bookiq.ai. 4. Data Security We implement appropriate technical and organizational measures to protect the security of your personal information. However, please note that no method of transmission over the Internet or electronic storage is 100% secure. 4a. Which Uploads Are Publicly Readable Images you publish as part of your public presence — your business logo, banner, and service photos — are stored in publicly-readable storage and can be viewed by anyone with the image link, including people who are not signed in; everything else you upload, including profile photos, documents, and any media you mark as not public, is stored privately and is served only through short-lived links issued to you or to the business you are booking with. 5. Data Retention We retain your personal data only for as long as necessary to provide our services and comply with legal obligations: - Active accounts: Data is retained while your account is active - Deleted accounts: When you ask us to delete your account we schedule the erasure 30 days out, and you can cancel it at any point in that window. On the 30th day your personal data is irreversibly anonymised or deleted — your name, email address, phone number, address and profile photo; your sign-in identities, passkeys, two-factor factors and active sessions; your device tokens and notifications; your search, voice and AI conversation history; and the IP addresses and device identifiers recorded against you in our audit logs. Before you confirm, we show you the exact list, generated from your own account, of what will be removed and what will be kept. - Files you uploaded for a business are not erased with your account: deleting your account does not delete the business you run on BookIQ.ai. Its bookings, staff records and financial records carry on, so the files you uploaded on the business’s behalf stay with the business — its branding (logo and banner), its service, portfolio and partner-directory media, the documents attached to its records, and its e-invoices. Images the business publishes stay publicly readable (see section 4a). Two things keep them: this is the business’s own material rather than your personal data, and e-invoices and business documents are separately held under statutory record-keeping duties — GDPR Art. 17(3)(b) (compliance with a legal obligation) and Art. 17(3)(e) (establishment, exercise or defence of legal claims). E-invoices and other financial records follow the 7-year period below; the rest are kept for as long as the business keeps them, and the business can delete them from inside BookIQ.ai at any time. If you believe a particular file is your own personal data, email privacy@bookiq.ai and we will assess it individually and delete it where Art. 17 applies. - Financial records: Transaction data is retained for 7 years as required by Australian tax law - Audit logs: Security and access logs are retained for 12 months - Backups: We keep encrypted backups of our production database. Data you delete from the live service can remain in a backup for a short period afterwards — no more than 30 days — and is then overwritten in the normal backup cycle. We do not restore deleted personal data from backup except where we are required to. 6. Your Data Rights (GDPR) If you are a resident of the European Economic Area (EEA), you have certain data protection rights: - Right to access: Request copies of your personal data - Right to rectification: Request correction of inaccurate data - Right to erasure: Request deletion of your personal data. Section 5 sets out what a deletion removes, what it keeps and why; you can start one at bookiq.ai/legal/delete-account - Right to restrict processing: Request limitation of data processing - Right to data portability: Receive your data in a structured format - Right to object: Object to processing of your personal data 7. Contact Us If you have any questions about this Privacy Policy or want to exercise any of your data rights above, please contact us at privacy@bookiq.ai. We will respond within 30 days as required by GDPR. Back to Sign Up (/signup.html)|Terms of Service (/terms-of-service.html)