Last updated 5 September 2026 · Version 1
1. Who we are
BookMyVenue is a booking platform run by Angus Lewington, a sole trader, ABN 32 385 519 280 (we, us, our). We are based in New South Wales, Australia.
This policy covers the website at bookmyvenue.com.au, the platform at app.bookmyvenue.com.au, the booking pages and the booking widget that businesses put on their own websites, and the emails and text messages the platform sends.
Privacy contact: Angus Lewington, [email protected]. Put the word Privacy in the subject line.
We treat ourselves as bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The platform holds health information for clinics, so we hold everything on it to that standard, not only the clinic records. The clinic records module is engineered against named obligations in the Privacy Act and the Health Records and Information Privacy Act 2002 (NSW) (HRIPA). Our Trust & security page lists the guarantees the database enforces and the automated tests that check them.
2. Two kinds of personal information, two roles
We handle personal information in two different roles. The role decides who you should contact first.
Information we collect for ourselves. When you visit our website, ask for a demo, or open and run a business account, we decide why and how your information is collected. We are responsible for it under this policy.
Information we hold for a business. When you book, order or attend an appointment with a business that uses BookMyVenue, that business collects your information. It decides what to ask, why, and how long to keep it, within the rules built into the platform. That business is responsible for your record under privacy law, and a clinic is responsible under HRIPA as well. We store and process the record for the business, on its instructions, under our Terms of Service and this policy.
If you have a question about a booking, a clinical record or a message you received, ask the business first. If it cannot help, or you would rather come to us, email us and we will help.
3. What we collect
3.1 Visitors to bookmyvenue.com.au
- Server logs: your IP address, browser type, the pages you visit, the time, and the page that sent you. We keep these logs for security and troubleshooting and delete them after 14 days. Cloudflare keeps its own network logs under its privacy policy.
- Analytics: Google Analytics 4 sets cookies (names starting with _ga) and records page views and events. It is the only outside service the website loads on its own. We use the aggregate figures to see which pages people read. We do not use it for advertising.
- Demo requests: your name, venue name, email, phone, type of venue, number of venues, the booking system and point of sale you use now, and anything you add in the notes. We use these to reply to you.
- Spam screening: before a demo request reaches us, the form sends your name, email, message, IP address and browser type to Akismet, a spam-detection service run by Automattic, Inc. The form also keeps a short-lived count of submissions per IP address to slow down abuse. A request that Akismet flags as spam is dropped and never reaches us.
- Delivery: the demo request is delivered to our inbox as an email through Twilio.
3.2 Businesses that use the platform
When a business opens an account, we collect from its owner and team:
- Names, work emails, mobile numbers, roles (owner, manager, staff, read-only) and sign-in details. Passwords are stored as Argon2id hashes. We cannot read them.
- Business details: trading and legal name, ABN, address, timezone, opening hours, services, prices, menus, floor plans and booking policies. The ABN and legal name print on tax invoices and receipts.
- Team records the business keeps in the platform: rosters, clock-in and clock-out times, timesheets, and the tip and commission figures the platform calculates from them.
- Notification settings, including the phone number and email address the business uses to receive booking texts and emails.
- Devices the business pairs with the platform, such as registers, kitchen displays and handhelds, and the pairing tokens for them.
- Whether the business has connected a Stripe account. Stripe collects the business's identity documents and bank details on Stripe's own pages. We never see or store them.
- Calendar feeds the business connects, so the platform can read busy times from another calendar.
- Reports the platform generates from bookings and sales.
- Support emails and the messages in them.
3.3 Customers of a business (guests, clients, patients, vehicle owners)
When you book, order or attend through the platform, the business collects, and we hold:
- Your name, mobile number and email address.
- Booking details: the service or table, the date and time, the practitioner or staff member, party size, and any notes or requests you add.
- Dietary requirements and allergies you tell the venue, so the kitchen can act on them.
- For automotive and trades bookings: the vehicle's make, model, year, registration and odometer reading.
- For clinics: intake forms, consent records (which version of the wording you agreed to, and when), guardian details where a parent or guardian acts for a minor, and the clinical notes the practitioner writes. This is health information. See section 4.
- Orders, receipts, gift cards, event tickets, function quotes and waitlist entries.
- If you choose to save a card, or a business asks for a card guarantee against no-shows: the card brand, the last four digits, the expiry, and a Stripe token that lets Stripe charge that card again. The card number goes to Stripe and never reaches our systems.
- Whether you ticked the marketing box, and when.
- The confirmations, reminders and updates we send you, and whether each one was sent, skipped or failed.
- If you reply to a text from the platform, we record the reply as received. Replying does not change your settings. See section 7.
3.4 Customer accounts
If you create a customer account, we hold your mobile number and the one-time codes we text you to sign in. There is no password. A signed-in session lasts 90 days on that device.
4. Sensitive information, including health information
Some of what a business collects is sensitive information under the Privacy Act: health information in intake forms, consent records and clinical notes, and allergies or dietary needs, which can reveal health information.
We hold sensitive information only for the business that provides the service to you, and only where you or your guardian have consented, or the law allows it. We do not use it for anything else. Our own platform administrators are structurally walled off from clinical data by the database, and a standing automated test fails if that wall ever opens.
Clinics use the platform's records module. The rules it enforces are described in section 11 (Security) and section 12 (How long we keep information).
5. How we collect
- Directly from you: on booking pages, in the widget on a business's website, in the platform, on our demo form, and by email or text.
- From the business you deal with: it may enter your details at the counter or over the phone, write notes, or import its existing client list (for example, from a Fresha export). The business is responsible for having the right to load that information.
- From our service providers: Stripe tells us the state of a payment. Our text and email providers tell us whether a message was delivered.
- Automatically: server logs and cookies, as described in sections 3 and 13.
We collect only what the service needs. For clinics, intake forms are collected after a booking exists and can never block one.
6. Why we use personal information
We use personal information to:
- take, hold, change and cancel bookings and orders, and show them to the business's team;
- send confirmations, reminders and updates about your bookings and orders (see section 7);
- process deposits, prepayments, refunds and receipts through Stripe;
- let a business run its diary, floor plan, till, roster and reports;
- keep clinic records in the form the law requires;
- answer support requests and demo enquiries;
- invoice businesses for their subscription;
- keep the platform secure, detect abuse, and prevent fraud and spam;
- meet legal obligations, including tax record-keeping, health record retention and the Notifiable Data Breaches scheme;
- understand how our website is used, in aggregate.
We do not sell personal information. We do not share it with advertisers. We do not send marketing messages unless you ticked the marketing box, and today the platform sends no marketing messages at all: that feature is not built.
7. Texts and emails
The platform sends messages about things you did: booking confirmations, reminders, changes, cancellations, order updates, intake links and sign-in codes. They go out under the business's name and use the wording the business chose. Businesses also receive texts and emails about new bookings.
- Texts to Australian mobiles are sent through Australian Phone Company. Twilio is our fallback text provider. Each provider receives your mobile number and the text of the message.
- Emails are sent through Twilio's email service, which receives your email address and the message.
- A message that cannot be delivered, for example because a landline was given where a mobile was needed, is recorded as skipped with the reason. It is never marked as sent.
To stop texts or emails, tell the business, or email us. A business can also switch off any message type for its venue. Replying to a text does not change your settings, so please contact the business or us instead.
8. Calendars and Google user data
A practitioner can link an outside calendar to the platform by pasting its private .ics address, for example the secret address of a Google Calendar. The platform polls that feed and stores only the busy intervals and a one-way hash of each event's summary, so it can block a slot the practitioner has already given away elsewhere. It never stores event titles or attendees, and it never writes to the outside calendar. The practitioner can remove the calendar at any time.
BookMyVenue does not ask for access to your Google account today. If we add a Google sign-in or a direct Google Calendar connection, we will request only the narrowest scope the feature needs, use the data only to provide that feature to you, never sell it or use it for advertising, and let you disconnect at any time, which deletes the tokens we hold.
BookMyVenue's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Overseas disclosure
The platform and its database run in Australia, in Oracle Cloud's Sydney region. Some providers in the table above process data outside Australia, mainly in the United States: Cloudflare's network is worldwide, and Stripe, Twilio, Google and Automattic process data in the United States.
Before we use a provider, we check that it is an established service with published security and privacy commitments, and we send it only what its job needs. Clinical notes and intake forms are stored only in our database in Australia. Like all web traffic to the platform, the pages that display them pass through Cloudflare's network in transit.
11. Security
- All traffic to our websites and the platform uses HTTPS.
- Passwords are hashed with Argon2id. Customer accounts are passwordless and sign in with a one-time code.
- Each business's records are kept apart by row-level security in the database, tied to the login and never to the web address. An automated cross-tenant test checks that a request for another business's data fails.
- Roles are set per venue: owner, manager, staff and read-only. Money views and clinical records are limited by role, and refused access attempts are logged.
- Clinical notes are append-only. An amendment is a new entry that points at the original. Nothing is edited in place or deleted.
- Money is recorded in an append-only journal that nothing, including the application, can write to directly.
- Our own platform administrators are walled off from clinical data by the database, with a standing test that fails if that changes.
- Intake links are single-use and carry their token in a part of the web address that never reaches a server log.
- We take a full backup of the database before every change to its structure, and keep those backups on our infrastructure in the same Australian region.
If a data breach is likely to cause serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and the people affected, as the Notifiable Data Breaches scheme requires, and we will tell the affected business so it can meet its own obligations.
No system is proof against every attack. We publish what the platform enforces, and what it does not do yet, on the Trust & security page, and we document hosting, subprocessors, backups and incident response for businesses on request.
12. How long we keep information
- Clinic records: seven years from the last service. A person who was a minor at the time of care is kept until they turn 25. A record with no date of birth is never disposed of automatically, because the minor rule cannot be checked. Disposal takes two steps, propose then confirm, and every disposal lands in a permanent ledger. A legal hold overrides all of this. The platform enforces these rules; the clinic decides when to dispose within them.
- Money records: the payment journal is append-only and is kept for at least five years, as tax law requires.
- Bookings, orders, client lists and reports: kept while the business's account is open, because the business needs its own history.
- Message and access logs: kept while the business's account is open and for as long as we need them to investigate a problem.
- Website server logs: deleted after 14 days.
- Demo requests: kept while we deal with the enquiry and as a record of it.
- Google Analytics data: kept by Google for the period set in our Analytics account.
When a business closes its account, we keep its data so it can export it or come back. On request we delete it, except records that the clinic retention rules, a legal hold or another law require us to keep, and except the payment journal.
If you are a customer and want your details removed, ask the business, or ask us. The clinic retention rules apply to health records, and the platform refuses a disposal the rules forbid.
14. Access and correction
- Businesses: your team's details, your settings and your client records are in the platform, and your client list and reports export to CSV whenever you want. Email us for anything you cannot reach yourself.
- Customers: sign in to your account to see and update your details, see your past bookings, and see the intake forms you filled in and the consents you gave. A practitioner's clinical notes are never shown there. You can also ask the business, or email us.
- Clinic records: HRIPA gives you the right to access your health records held by a clinic. Ask the clinic. The platform gives it an export of your record. A clinical note cannot be edited: a correction is added as an amendment that points at the original, so the record shows both.
We respond to access and correction requests within 30 days. We may need to check who you are before we release information. If we or a business refuse a request, you will get the reason in writing.
15. Complaints
Email [email protected] with the subject Privacy complaint. We will acknowledge it within 7 days, look into it, and reply within 30 days.
If you are not satisfied with our reply, you can complain to the Office of the Australian Information Commissioner (www.oaic.gov.au, 1300 363 992). If your complaint is about health information held for a clinic in New South Wales, you can also complain to the NSW Information and Privacy Commission (www.ipc.nsw.gov.au, 1800 472 679).
16. Changes to this policy
We update this policy when the platform changes what it collects or who it shares with. The date and version at the top change each time. Businesses with an account get an email about material changes.
17. Contact
Angus Lewington, sole trader, ABN 32 385 519 280. [email protected]. See also our Terms of Service.
