Privacy Policy
Last updated: 29 July 2026
1. Overview
This Privacy Policy explains how Schedvia ("we", "us", "our"), based in New South Wales, Australia, collects, uses, and shares personal information when you use the platform at schedvia.com (the "Service"). We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This Policy covers both businesses who use Schedvia and the customers who book or buy through a business's page.
2. Two roles: businesses and their customers
When a customer books or buys through a business's Schedvia site, that information is collected for the business — the business is responsible for how it uses its customer list, and customers should direct requests about their booking data to the business first. We process that data to run the Service on the business's behalf, and this Policy governs our handling of it.
3. Information we collect
From businesses: account details (name, email, password), business profile (name, contact details, address, branding, photos), staff details you enter, plan and payment status, and support correspondence.
From booking customers: name, email, phone, service address (for mobile bookings), booking details, and — only where they tick the box — a marketing opt-in for the business they booked with.
From newsletter sign-ups: where a business runs a newsletter sign-up on its site, we store the email address you enter, along with the date and your IP address, as a record that the sign-up was made. This is used only to operate that business's list; you can unsubscribe at any time.
Automatically: basic usage and device data (such as IP address and browser type in server logs), and a session cookie to keep you signed in.
4. How we use information
To provide and operate the Service; process bookings, orders, invoices and payments; send booking confirmations, reminders and notifications by email and SMS; calculate travel times and availability; provide reporting to businesses; keep the Service secure and prevent abuse; and comply with legal obligations. We do not use booking customers' details for our own marketing.
5. Payment information
Card payments are processed by Stripe. Card numbers are entered directly with Stripe and never touch our servers — Stripe handles card data under its own security standards (PCI DSS). We store limited payment records such as amounts, status, and Stripe identifiers needed to operate the Service.
6. How we share information
We share personal information only as needed to run the Service: with Stripe (payments), our email delivery provider, our SMS delivery provider, and our hosting, storage, and content-delivery providers. Booking customer details are shared with the business being booked. We do not sell personal information, and we may disclose information where required by law.
7. Text messages (SMS) and consent
When a customer types their mobile number into a booking page, that number and their consent are used only to send the booking texts named beside the field: a confirmation and one reminder for that appointment. The number is disclosed to the business being booked, so it can carry out the booking, and to our SMS delivery provider, so the message can be delivered. Beyond those two purposes we do not share, sell, or rent mobile numbers or SMS consent to any third party, and we never pass consent given to one business on to another. Consent can be withdrawn at any time using the link in any text, which stops every text to that number across the whole platform.
8. Where data is stored (overseas disclosure)
The Service's database is hosted in Sydney, Australia. Some providers we rely on — payment processing, email and SMS delivery, and the content-delivery network that serves images — operate globally, so limited personal information (for example, an email address being delivered to, or a payment record) may be processed in the United States or other countries under those providers' safeguards.
9. Data retention and deletion
We keep information for as long as an account is active or as needed to provide the Service, resolve disputes, and meet legal and accounting requirements. We keep encrypted off-site backups on a rolling schedule. When an account is closed, we delete its data after a short wind-down period, except records we're required to retain by law.
10. Security
We use reasonable technical and organisational measures to protect personal information, including encrypted connections (TLS), hashed passwords, access controls, and daily off-site backups. No method of transmission or storage is completely secure, so we can't guarantee absolute security. If a data breach occurs that is likely to result in serious harm, we will notify affected people and the OAIC as required by the Notifiable Data Breaches scheme.
11. Cookies
We use a single essential cookie to keep you signed in, and it is always on.
On our own marketing pages (our home page, pricing, FAQ, demos, sign-up and sign-in), we ask before setting anything else. If you accept, we use Google Analytics, Google Ads, Microsoft Advertising and Microsoft Clarity to understand which pages help people find us and whether our advertising works. If you decline, none of them load. You can change your mind by clearing this site's cookies in your browser.
Inside the app — your dashboard, and every booking page, shop and website we host for a business — we set no advertising or analytics cookies of our own at all.
Businesses can add their own advertising pixels (such as Meta, Google, TikTok or X) to their own public booking and shop pages. Where they do, that business decides what is collected and their own privacy policy applies to it, not this one.
12. Marketing communications
Businesses may receive occasional product emails from us about their own account and the Service; you can unsubscribe from non-essential messages at any time. Booking customers only ever receive marketing from a business if they explicitly opted in when booking, and every marketing message includes a way to unsubscribe.
13. Access, correction, and complaints
You may request access to or correction of the personal information we hold about you, or ask us to delete it, by emailing the address below — we'll respond within a reasonable time. Booking customers should also contact the business they booked with, which controls that relationship. If you're unhappy with how we've handled your information, contact us first; you can also complain to the Office of the Australian Information Commissioner (oaic.gov.au).
14. Children
The Service isn't directed at children and isn't intended for anyone under 16. We don't knowingly collect data from children.
15. Changes
We may update this Policy from time to time. Material changes will be notified by reasonable means. The "last updated" date above reflects the current version.
16. Contact
For privacy questions or requests, email support@schedvia.com.