Privacy Policy
Last updated:
1. About This Policy
OneBookPlus (ABN 17 971 013 775) ("we", "us", "our") operates the OneBookPlus platform at onebookplus.com.au. This policy explains how we collect, use, disclose, and protect your personal information in compliance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. Information We Collect
Account Information
- Name, email address, and password when you create an account, or your identity token if you sign in with Google or Apple
- Business name, ABN, address, and phone number
- Payment and billing information for website purchases (processed securely via Stripe, we never store card numbers)
- For subscriptions purchased in our iOS app, billing is handled entirely by Apple, we receive only subscription status (plan, renewal and expiry dates), never your payment details
- Multi-factor authentication (MFA) enrolment data, including TOTP authenticator secrets
Mobile App Data
- Push notification device tokens (Apple Push Notification service), if you enable notifications
- Device type and app version, used for compatibility and support
- Biometric unlock (Face ID / Touch ID) is processed entirely on your device, biometric data never leaves your phone and is never sent to us
Business Data
- Contacts and client records you create
- Invoices, quotes, bookings, orders, and expenses
- Financial and accounting data, including P&L, revenue, GST, and BAS summaries
- Daily sales records and reporting data
- Point of Sale (POS) transaction data, including items sold, payment methods, and terminal sessions
- Service listings and booking page configurations
- Marketing campaign data, email templates, and contact lists
- Google Reviews data and review request history
ATO and Tax Data
The ATO Tax Lodgement feature is in development and not yet available. Once released, if you use it, we may collect and process additional sensitive data:
- Tax File Numbers (TFNs) and ABN details for tax lodgement purposes
- BAS (Business Activity Statement) lodgement data, including GST amounts, PAYG, and instalment figures
- Tax return data prepared for submission to the Australian Taxation Office
- ATO Digital Service Provider (DSP) authentication tokens and session data
Tax data is handled under enhanced security controls in accordance with ATO DSP operational framework requirements. This data is encrypted at rest and in transit and subject to stricter access controls and audit logging.
Automatically Collected
- IP address, browser type, device information
- Pages visited and features used (via Google Analytics and Vercel Analytics)
- Anonymous interaction analytics on our public website (our own system, not a third party): which pages you view, how far you scroll, where on a page you click, whether you started and abandoned a form, whether you copied text from a page (we record how many characters, never the text itself), a signal when your pointer leaves the page towards the browser bar, and page performance timings. No form field values are ever captured, and the visitor identifier is a daily-rotating hash that cannot be linked back to you or across days.
- Cookies for authentication and preferences
- Session activity logs, including login times, idle timeouts, and security events
When You Open a Document Someone Sent You
Invoices, quotes, sales orders and job updates are shared as a private link. When you open one, we record that the document was opened and, if you act on it, whether you accepted or declined it. Alongside that we store the date and time, your IP address, your browser's user-agent string, whether the device is a phone, tablet or desktop, and the referring page if your browser sent one. That record is visible only to the business that sent you the document, so it can tell whether its invoice or quote was read. It is not used for advertising, it is never sold, and it is not combined with the website analytics described above.
These records are kept for as long as the business keeps the document they belong to. When the business closes its OneBookPlus account, they are deleted with the rest of its data, on the schedule in the data retention section below. If you would rather a business did not hold this record of your visit, ask that business: it is their record, and they can delete the document it hangs off.
3. How We Use Your Information
- To provide and maintain the OneBookPlus platform and all installed apps
- To process subscription payments, app purchases, and manage billing via Stripe
- To process client payments on your behalf via Stripe Connect
- To send transactional emails (invoices, quotes, payment reminders, booking confirmations)
- To provide customer support
- To improve our services and develop new features
- To comply with legal obligations (e.g. tax reporting, ATO requirements)
- To submit tax lodgements to the ATO on your behalf (when using the ATO Tax Lodgement app)
- To sync data with third-party integrations you enable (Mailchimp, Google Calendar)
- To enforce security policies, including MFA, session management, and brute force protection
4. How We Share Your Information
We do not sell your personal information. We may share data with:
- Service providers: Supabase (database and authentication), Stripe (payments and billing), Apple (App Store billing and push notifications for the iOS app), Resend (email delivery), Vercel (hosting), Google (analytics and calendar integration), Anthropic (Claude, AI Companion paid app and chat widget; see /trust for the full subprocessor list)
- Third-party integrations: Mailchimp (marketing sync), Google Ads, and Facebook Ads, only when you explicitly enable these integrations. Xero (accounting sync) is in development and not yet available
- Australian Taxation Office (ATO): When the ATO Tax Lodgement feature is released, tax lodgement data will be submitted directly to the ATO via their secure API when you use it
- Your clients: When you send invoices, quotes, or booking confirmations, your business details are shared with the recipient
- Your team members: Data is shared within your business account with team members based on their role and permissions
- Legal requirements: If required by Australian law or to protect our rights
5. Data Storage and Security
Your business records, files and sign-in data are stored in Australia, in AWS ap-southeast-2 (Sydney). Some specialist suppliers process a defined slice of data overseas, and every one of them is listed row by row in the OneBookPlus subprocessor table. Every supplier is named, with what it can see and where it processes it, in the OneBookPlus subprocessor table. We implement industry-standard security measures including:
- Encryption in transit (HTTPS/TLS) and at rest
- Each business's records are fenced off inside the database itself, not just in the application code, so one business can only reach its own data
- Secure authentication with support for email and password, Google, and Sign in with Apple
- Multi-factor authentication (MFA) using TOTP authenticator apps
- Configurable session timeouts and idle lockouts
- Brute force protection with account lockout after failed login attempts
- Regular security reviews
Overseas Disclosure
Your primary database is hosted in Sydney, Australia. Some of our service providers (including Stripe, Resend, Vercel, and Anthropic) process limited data in the United States under their own compliance programs. Where personal information is disclosed overseas, we take reasonable steps as required by APP 8 to ensure the recipient handles it consistently with the Australian Privacy Principles.
Enhanced Security for ATO Tax Lodgement
When the ATO Tax Lodgement app is installed, additional security controls are enforced in line with ATO DSP requirements:
- Mandatory MFA for all users with access to tax data
- Reduced session duration (24 hours) and idle timeout (15 minutes)
- Stricter brute force protection (5 attempts with 15-minute lockout)
- Comprehensive audit logging of all data access, form edits, and submissions
- ABN validation against the Australian Business Register (ABR)
6. App Marketplace and Third-Party Apps
OneBookPlus offers an App Marketplace with optional apps you can install. When you install an app:
- The app may access specific data within your account as needed to function
- Paid apps are billed separately and managed through your billing settings
- You can uninstall apps at any time, which revokes their data access
- Third-party integrations (e.g. Mailchimp) may transfer data to external services governed by their own privacy policies
7. Your Rights
Under Australian Privacy law, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and data
- Export your data at any time via the Settings page
- Opt out of marketing communications
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
How to Delete Your Account
- In the iOS app: open Settings, then Delete account. This permanently deletes your account and, if you are the only member, your business and all of its data
- By email: contact support@onebookplus.com.au from your account email, we action verified deletion requests within 7 days
- Deleting your account does not cancel a subscription billed through the Apple App Store, cancel it in your device's subscription settings first (see our Refund Policy)
We respond to privacy requests (access, correction, deletion) within 30 days as required by the Privacy Act. We may ask you to verify your identity before actioning a request.
8. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law (e.g. financial records for 5-7 years per ATO requirements).
ATO tax lodgement records and audit logs are retained for a minimum of 5 years in compliance with Australian tax law, even after account deletion.
9. Data Breaches
We participate in the Notifiable Data Breaches (NDB) scheme under the Privacy Act. If a data breach is likely to result in serious harm, we will notify affected users and the OAIC without undue delay, including what happened, what data was involved, and what we are doing about it. Our incident handling process is published at /security/incident-response.
10. Cookies
We use the following categories of cookies:
- Essential cookies, required for authentication, session management, and core platform functionality. These cannot be disabled as the platform would not function without them.
- Analytics cookies, Google Analytics is used on public pages only (not within your dashboard) to understand how visitors use our website. These cookies are only set after you provide consent via our cookie banner. You can withdraw consent at any time by updating your cookie preferences.
We do not use advertising or tracking cookies. No cookie data is sold to or shared with third-party advertisers. Analytics scripts are not loaded at all until you accept them in the cookie banner.
To change your choice, open the cookie preferences panel. It reopens on whatever you chose last, and turning analytics off takes effect straight away on the page you are reading, without a reload. The same control sits in the footer of every page.
11. Third-Party Links
Our platform may contain links to third-party websites and services (including Stripe, Xero, Google, and Facebook). We are not responsible for the privacy practices of those websites and services.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or a notice on our platform.
13. Contact Us
If you have questions about this privacy policy or wish to exercise your privacy rights, contact us at:
- Email: hello@onebookplus.com.au
- Address: Melbourne, VIC, Australia
Reviewed by Bishal Shrestha