This version applies to you now, whether you are creating a BookIQ.ai account today or already had one. It only adds to what this policy tells you and commits us to more than the last version did; it widens nothing we do with your information and takes no right away, so we have not held it behind the 30 days’ notice we give for a material change. The version it replaces is 2026-08-29, which you can read here.
What changed in this version: the policy said what we collect and what we use it for, but it never said why we are permitted to, how long each kind of information stays, what we do if there is a data breach, where to complain if we get it wrong, or how information about a child is handled. Four sections are new: section 1a (children and young people), section 2b (purpose, legal basis and retention, one entry per purpose), section 4b (data breaches, and when we tell you) and section 6a (complaints, and how to escalate to the OAIC or your own supervisory authority). One existing sentence has been CORRECTED rather than added to, and we would rather point at it than let you find it: section 5 used to say flatly that security and access logs are kept for 12 months. That was not accurate. Most of the audit tables that are switched on for deletion are on 12 months, but the audit trails behind invoices, tax, payments and consent are kept for 7 years under the same rule as the financial records the same section already described; an audit table that nobody has switched on yet is not deleted at all; and the sign-in log kept by the service that authenticates you is not on a deletion timetable and is not erased with your account. Sections 2b and 5 now say all of that. Nothing about what we do with your information has changed — the policy now states the basis for it, how long it lasts, and where that answer is uncomfortable. Carried over from 2026-08-29: section 5 says exactly what an account deletion erases and which files stay with the business; from 2026-08-05: section 3a names every subprocessor we engage, and section 3b explains where your information is processed when it leaves Australia.
Data Controller
BookIQ.ai is operated by PairOx Pty Ltd (registered in Australia), the data controller for the purposes of GDPR (where applicable). Where this policy uses "we", "us", or "BookIQ.ai" it refers to PairOx Pty Ltd.
1. Information We Collect
We collect information you provide directly to us, such as your name, email address, phone number, business details, and payment information. We also collect usage data and device information to improve our services.
1a. Children and Young People
BookIQ.ai is a tool for running a business, and it is not directed at children. You must be at least 18 to open or use a BookIQ.ai account — clause 1a of our Terms of Service says so. We do not knowingly collect personal information directly from a child. We should be plain about the limits of that: we do not ask a visitor their age and we have no way to verify it, so we rely on what an account holder tells us. If you believe a child has given us information directly, email privacy@bookiq.ai and we will delete it.
Separately, a business that uses BookIQ.ai can record information about its own clients, and some of those clients are children — a parent books an appointment for a child, and the business records the child’s name, contact details, date of birth or a note about the service. Where that happens the business decides what to record and why, and clause 4a of the Terms of Service requires it to have a lawful basis for putting that information into the service, which for a child normally means the consent of a parent or guardian. We hold it for the business under this policy, and we do not use a client’s information for BookIQ.ai’s own marketing. If you are a parent or guardian and you want a child’s information removed, ask the business directly — it can delete a client record from inside BookIQ.ai — or email privacy@bookiq.ai and we will act on it ourselves where we are able to.
2. How We Use Your Information
Provide, maintain, and improve our booking and business management services
Process transactions and send related information
Send technical notices, updates, security alerts, and support messages
Respond to your comments, questions, and customer service requests
Monitor and analyze trends, usage, and activities in connection with our services
2a. SMS Program & Consent
When you opt in to SMS (text) messages, we collect your mobile phone number together with a record of your consent — including the date and time of the opt-in and the source where it was given (for example a booking form, sign-up form, or a consent recorded by the business you booked with). We use this information to send appointment reminders, booking notifications, and account alerts. Marketing messages are sent only with your separate, explicit marketing consent.
SMS opt-in consent and phone numbers are never shared with or sold to third parties or affiliates for their marketing purposes. Phone numbers are shared only with our SMS delivery subprocessor (Twilio, listed in section 3a) solely to deliver the messages you opted in to receive.
You can opt out at any time by replying STOP to any message (reply HELP for help), by updating your communication preferences in your account or client portal, or by contacting us at privacy@bookiq.ai. Message frequency varies, and message & data rates may apply.
2b. Why We Are Allowed To Use It, and How Long We Keep It
Sections 1 and 2 say what we collect and what we do with it. This section sets out, purpose by purpose, the legal basis we rely on and how long the information stays. Where we name a basis we mean: contract — we need it to give you the service you asked for; legal obligation — a law requires us to keep or produce it; legitimate interests — we rely on our own interest in running and protecting the service, weighed against yours, and you can object under section 6; and consent — you chose it and can withdraw it at any time. Australian privacy law does not use those labels: under the Australian Privacy Principles we collect only what we reasonably need for the functions described here, and we say below which of them need your consent either way.
Creating and running your account. Uses your name, email address, phone number, password or the sign-in identity you chose, your business details, and the record of which version of these documents you accepted and when. Legal basis: contract — there is no account without it; and legal obligation for the acceptance record itself, which is the evidence of consent we are required to be able to produce. How long: while your account is active, then on the deletion timetable in section 5.
Running a business’s bookings, clients, staff and messages. Uses everything you and your clients put into BookIQ.ai — appointments, client contact details and notes, service, staff and pricing records, and messages in the in-app inbox. Legal basis: contract with the account holder; and, for information about a business’s own client, the basis the business itself relies on, which clause 4a of the Terms of Service requires it to have. How long: for as long as the business keeps the record. Be clear about what that means: nothing deletes a booking, a client record or a message automatically. A business deletes them from inside BookIQ.ai, and deleting your own account does not delete the business or its records — section 5 explains that.
Taking and reconciling payments. Uses your billing identity, the amount, currency and status of each payment, and the payment-method details Stripe returns to us (such as the card brand and last four digits). We never receive or store your full card number: Stripe collects it directly. Legal basis: contract, and legal obligation for the tax and accounting records. How long: 7 years for financial records, as section 5 says. Nothing deletes those, and an account deletion does not.
Sending email and SMS about a booking or an account. Uses your email address and mobile number, the content of the message and whether it was delivered. This covers booking confirmations, reminders, receipts, security alerts and support replies. Legal basis: contract — those messages are part of the service you asked for; and consent for anything we describe as marketing, which section 2a covers. How long: the delivery record is kept with the message it relates to. You can withdraw SMS consent at any time by replying STOP, and we keep the record of the opt-out itself so that we can honour it.
Push notifications to the BookIQ mobile app. Uses the push token your device issues and the content of the notification. Legal basis: consent — your phone asks you before we can send any, and turning notifications off withdraws it. How long: until you turn notifications off, sign out on that device, or your account is deleted, at which point the device tokens are removed with it (section 5).
Product analytics and error monitoring. Uses product usage events, device and request information, and the diagnostics we need to reproduce a fault. Legal basis: consent, and only consent. Nothing is initialised until you accept on the cookie banner; declining, or using the reset button in section 3, stops it. How long: for as long as PostHog and Sentry hold it under our settings with them — they are named in section 3a. Withdrawing consent stops any further collection but does not by itself erase what was already sent; ask us at privacy@bookiq.ai if you want that too.
Keeping the service secure and investigating misuse. Uses sign-in events, IP addresses, device identifiers and audit records of who changed what. Legal basis: legitimate interests — protecting accounts and being able to investigate an incident; and legal obligation where a law requires the record. How long: it depends on the record, and a single number would be wrong for most of them. A sweep runs weekly inside our database over a register of audit tables and deletes or archives what is past its age: most entries on that register are set to 12 months, and the audit trails behind invoices, tax, payments and consent are set to 7 years, for the same statutory reason section 5 gives for financial records. Two limits on that sweep, stated because they are true rather than because they are flattering. First, a newly created audit table joins the register automatically but joins it switched OFF, so until a person reviews it and switches it on, nothing deletes it — discovery is automatic, enabling is not. Second, the sign-in log kept by the service that authenticates you — a row for every authentication and account-security event on your account, which today means sign-ins and sign-outs, session refresh and revocation, sign-up, password, re-authentication and email-confirmation requests, password changes, second-factor enrolment and use, and changes to or deletion of the account itself, recording the account it belongs to, the email address involved, the method and the time, and, for the second-factor events, the IP address they came from — sits outside that sweep, and outside the erasure list in section 5, and is not on an automatic deletion timetable today. Ask us at privacy@bookiq.ai and we will delete your entries from it: every row in that log carries the id of the account it belongs to, so yours can be identified and removed.
The AI features. Uses the audio you or your clients record, the transcripts made from it, documents you upload, and the text of prompts. Section 3a names the provider. Legal basis: contract — you switch the feature on and ask for the result; and consent where another person is recorded, which the business must obtain before recording them. How long: your own search, voice and AI conversation history is erased with your account (section 5), and the audit record of AI requests is one of the 12-month entries on the register described in the security purpose above. There is no setting inside BookIQ.ai today that lets a business choose a shorter period for it; if you need one, email privacy@bookiq.ai and we will tell you what we can do.
Regional defaults, weather, travel time, public holidays and QR images. Uses your IP address to pick a sensible currency and time zone, an appointment’s coordinates for weather and travel estimates, and the value encoded into a QR code. Section 3a names each provider and what it receives. Legal basis: legitimate interests — showing you the right defaults without making you configure them. How long: we do not keep the lookup beyond answering it, except for an address-lookup cache that is cleared daily, and except where the answer is saved onto the record it belongs to.
An account or channel you connect. Uses whatever the integration you switched on sends and receives — the third group in section 3a lists them. Legal basis: consent — nothing is sent until you connect the account, and disconnecting it withdraws that consent. How long: until you disconnect it. The other provider keeps its own copy of what it received, under its own terms, and we cannot delete that for you.
Meeting our legal obligations and defending claims. Uses financial records, the record of which documents you accepted, and material relevant to a dispute, a chargeback or a regulator’s enquiry. Legal basis: legal obligation, and legitimate interests in establishing, exercising or defending legal claims — the GDPR calls those Art. 17(3)(b) and 17(3)(e), which section 5 already relies on. How long: 7 years for financial records; for anything else, for as long as the claim or the limitation period that applies to it.
Where we rely on legitimate interests you can object under section 6, and we will stop unless we have compelling grounds we can show you. Where we rely on consent you can withdraw it at any time; that stops what happens next but does not undo what was already done while the consent stood.
3. Cookies & Tracking
We use cookies for sign-in and, with your permission, for product analytics (PostHog) and error monitoring (Sentry). On your first visit we ask whether you accept analytics & error-monitoring cookies. You can change your choice at any time using the button below — it will reset your preference and show the banner again on the next page load.
3a. Subprocessors
The list below names the third parties that process personal information on our behalf so that BookIQ.ai can run. Which of them apply to you depends on the features you use: the core platform subprocessors are involved in every account, and the rest are engaged only when you turn on the relevant feature or connect the relevant account. We keep this list current and we update it before engaging a new subprocessor that processes personal information. If you would like to know more about any of them, email privacy@bookiq.ai.
Core platform — used for every account
Supabase (Sydney, Australia) — primary database, authentication and file storage. Receives everything you and your clients enter into BookIQ.ai.
Vercel (United States, with a global edge network) — website and application hosting. Receives web request metadata including IP addresses; requests are served from the edge location closest to the visitor, which may be outside Australia.
Stripe (United States) — payments and subscription billing. Receives billing identity, payment-method metadata, and subscription and invoice records.
Migadu (Switzerland) — receiving email sent to our addresses. Receives inbound message content.
Sentry (United States) — error and performance monitoring, only with your consent. Receives error reports, device and request information, and session diagnostics used to reproduce a fault; on-screen text is masked before it is sent.
PostHog (United States) — product analytics, only with your consent. Receives product usage events and device information.
Google (United States) — Sign in with Google, and Google Maps for addresses and geocoding. Receives the sign-in profile you choose to share and the addresses looked up.
Apple (United States) — Sign in with Apple. Receives the sign-in identity you choose to share.
Expo (United States) — delivery of push notifications to the BookIQ mobile app. Receives device push tokens and notification content, and passes the notification to Apple’s or Google’s push service for final delivery to the device.
Twilio (United States) — sending SMS and phone-number verification. Receives phone numbers and the content of the messages you send.
OpenAI (United States) — the AI features (assistant, transcription, document understanding and semantic search). Receives audio recordings and transcripts you or your clients submit, uploaded documents, and prompt content.
Location, scheduling and utility services
ip-api.com (processing location not published by the provider) — approximate location from an IP address, used to set regional defaults such as currency and time zone. Receives the visitor’s IP address.
Open-Meteo (European Union) — weather for an appointment’s location. Receives appointment coordinates.
OSRM (community-hosted; processing location not published) — travel-time estimates between two points. Receives origin and destination coordinates.
goQR (Germany) — generating QR-code images for payment and sharing links. Receives the encoded value, which can include a booking or invoice reference, and the IP address of whoever views the code.
Nager.Date (European Union) — public-holiday calendars. Receives a country code and a year only, and no personal information.
Accounts and channels you connect — used only if you connect them
Square (United States), PayPal (United States), Alipay (China) and WeChat Pay (China) — payments taken through a payment account you connect. Receive payer identity and transaction data.
Meta (WhatsApp Business, Facebook, Instagram — United States), LINE and LINE Pay (Japan and Asia-Pacific), WeChat (China), Telegram and Viber (processing location not published), and Kakao (South Korea) — messaging channels you connect. Receive your clients’ channel identifiers or phone numbers and the content of the messages sent.
X (Twitter) and LinkedIn (United States) — publishing posts from a social account you connect. Receive the post content and media you publish.
Slack (United States) and Zoom (United States) — team notifications and meeting links. Receive notification content, and the participant name, email and scheduling details for a meeting.
Microsoft (Outlook and Microsoft 365; region depends on your Microsoft tenant) — calendar, contacts and email integration. Receives calendar events, contacts and email metadata.
HubSpot (United States) — CRM sync. Receives client contact records.
Xero (processing location depends on your Xero account), Intuit QuickBooks (United States), MYOB (Australia) and Mailchimp (United States) — accounting and marketing sync. Receive invoice and client billing records, and for Mailchimp, client email addresses and engagement data.
Toast (United States) — point-of-sale sync. Receives order and customer records.
Statutory recipients — not our subprocessors
Government e-invoicing portals (Mexico, Brazil, Italy) — where you issue an electronic invoice that a country’s law requires to be filed, the invoice is transmitted to that country’s tax authority, including your client’s identity and tax identifiers. Those authorities are statutory recipients, not processors acting on our behalf.
Configured in our software but not enabled today
Our software also contains integrations for Anthropic, Microsoft Azure OpenAI, Microsoft Azure Cognitive Services Speech, Amazon Web Services (Amazon Polly and Amazon Transcribe), Google Gemini, Google Cloud Speech-to-Text, Google Cloud Text-to-Speech, Google Cloud Translation, DeepL, Mapbox, HERE Technologies and SendGrid. None of them is enabled on BookIQ.ai today and no personal information is being sent to them. We will update this list before enabling any of them.
3b. Where Your Information Is Processed
BookIQ.ai is operated from Australia and your account data is stored in Sydney, Australia. Some of the subprocessors listed above operate outside Australia — principally in the United States, and in the European Union and Switzerland — so using BookIQ.ai involves disclosing personal information to overseas recipients. If you connect one of the optional accounts or regional payment and messaging services listed in section 3a, personal information may also be disclosed in that provider’s country, including Japan, South Korea, China, Mexico, Brazil and Italy. The country for each subprocessor is shown in section 3a where we are able to state it.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on the data-processing terms offered by each subprocessor, which for these transfers incorporate the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies.
If you would like more detail about a particular transfer, contact us at privacy@bookiq.ai.
4. Data Security
We implement appropriate technical and organizational measures to protect the security of your personal information. However, please note that no method of transmission over the Internet or electronic storage is 100% secure.
4a. Which Uploads Are Publicly Readable
Images you publish as part of your public presence — your business logo, banner, and service photos — are stored in publicly-readable storage and can be viewed by anyone with the image link, including people who are not signed in; everything else you upload, including profile photos, documents, and any media you mark as not public, is stored privately and is served only through short-lived links issued to you or to the business you are booking with.
4b. If There Is a Data Breach
If personal information we hold is lost, or is accessed or disclosed without authorisation, we treat it as a suspected data breach, contain it and investigate it. What we then owe you is set by law, and we commit to it here so that you can hold us to it:
In Australia, under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), we assess a suspected breach within 30 days of becoming aware of it. If we conclude it is an eligible data breach — one likely to result in serious harm — we notify the Office of the Australian Information Commissioner and the people at risk as soon as practicable after reaching that conclusion.
Where the GDPR applies to the information, we notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to people’s rights and freedoms; and where it is likely to result in a high risk to them, we tell the affected people directly and without undue delay.
How we will tell you. By email, to the address on your account. If we cannot reach you that way we publish the notice on bookiq.ai. It will say what happened, what information was involved, what we have done about it, and what we suggest you do.
If it affects your clients’ information. Where you use BookIQ.ai to hold information about your own clients and a breach affects it, you may have your own duty to notify them and the regulator. We will give you the detail you need in order to do that, and we will not treat that as your problem alone.
If you think you have found a security problem in BookIQ.ai, please tell us at privacy@bookiq.ai rather than publishing it, and give us a reasonable chance to fix it.
5. Data Retention
We retain your personal data only for as long as necessary to provide our services and comply with legal obligations:
Active accounts: Data is retained while your account is active
Deleted accounts: When you ask us to delete your account we schedule the erasure 30 days out, and you can cancel it at any point in that window. On the 30th day your personal data is irreversibly anonymised or deleted — your name, email address, phone number, address and profile photo; your sign-in identities, passkeys, two-factor factors and active sessions; your device tokens and notifications; your search, voice and AI conversation history; and the IP addresses and device identifiers recorded against you in our audit logs. One record is deliberately named here rather than left for you to assume: the sign-in log kept by the service that authenticates you — a row for every authentication and account-security event on your account, which today means sign-ins and sign-outs, session refresh and revocation, sign-up, password, re-authentication and email-confirmation requests, password changes, second-factor enrolment and use, and changes to or deletion of the account itself, recording the account, the email address involved, the method and the time, and, for the second-factor events, the IP address they came from — is not erased with your account today, and neither are the few IP addresses it holds. Ask us at privacy@bookiq.ai and we will delete your entries from it: every row in that log carries the id of the account it belongs to, so yours can be identified and removed. Before you confirm, we show you the exact list, generated from your own account, of what will be removed and what will be kept.
Files you uploaded for a business are not erased with your account: deleting your account does not delete the business you run on BookIQ.ai. Its bookings, staff records and financial records carry on, so the files you uploaded on the business’s behalf stay with the business — its branding (logo and banner), its service, portfolio and partner-directory media, the documents attached to its records, and its e-invoices. Images the business publishes stay publicly readable (see section 4a). Two things keep them: this is the business’s own material rather than your personal data, and e-invoices and business documents are separately held under statutory record-keeping duties — GDPR Art. 17(3)(b) (compliance with a legal obligation) and Art. 17(3)(e) (establishment, exercise or defence of legal claims). E-invoices and other financial records follow the 7-year period below; the rest are kept for as long as the business keeps them, and the business can delete them from inside BookIQ.ai at any time. If you believe a particular file is your own personal data, email privacy@bookiq.ai and we will assess it individually and delete it where Art. 17 applies.
Financial records: Transaction data is retained for 7 years as required by Australian tax law
Audit logs: Each audit table is entered on a retention register with an age against it, and the weekly sweep described in section 2b deletes or archives the entries of every table on that register that has been switched on. Most of the switched-on tables are set to 12 months; the audit trails behind invoices, tax, payments and consent are set to the 7-year period above instead. We are not going to round that up into a promise about every log we hold, because section 2b names two things the sweep does not reach: a table that is on the register but has not been switched on, which nothing deletes, and the sign-in log kept by the service that authenticates you.
Backups: We keep encrypted backups of our production database. Data you delete from the live service can remain in a backup for a short period afterwards — no more than 30 days — and is then overwritten in the normal backup cycle. We do not restore deleted personal data from backup except where we are required to.
6. Your Data Rights (GDPR)
If you are a resident of the European Economic Area (EEA), you have certain data protection rights:
Right to access: Request copies of your personal data
Right to rectification: Request correction of inaccurate data
Right to erasure: Request deletion of your personal data. Section 5 sets out what a deletion removes, what it keeps and why; you can start one at bookiq.ai/legal/delete-account
Right to restrict processing: Request limitation of data processing
Right to data portability: Receive your data in a structured format
Right to object: Object to processing of your personal data
6a. Complaints
If you think we have mishandled your personal information, or we have not answered a request under section 6, tell us first. Email privacy@bookiq.ai with “Complaint” in the subject and tell us what happened and what you would like us to do. We will answer you in writing within 30 days, as section 7 commits. If we need longer than that we will tell you why, and when to expect our answer.
If you are not satisfied with our answer, or we do not answer in time, you can take it further:
In Australia — to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, which carries its current complaint form and contact details. The OAIC normally asks you to complain to us first and to allow us 30 days to respond, which is why the paragraph above comes first.
In the European Economic Area or the United Kingdom — to the data-protection supervisory authority for the country you live or work in, or where the problem happened. In the United Kingdom that is the Information Commissioner’s Office at ico.org.uk.
Anywhere else — to the privacy or data-protection regulator for your country. If you tell us where you are, we will point you at the right one.
Complaining to us is not a precondition of anything else. It does not limit any other remedy you have, and it does not affect your rights under the Australian Consumer Law or any other law that cannot be excluded.
7. Contact Us
If you have any questions about this Privacy Policy or want to exercise any of your data rights above, please contact us at privacy@bookiq.ai. We will respond within 30 days as required by GDPR.