Legal
Privacy Policy
Operated by OperonFlow Pty Ltd. Last updated 14 June 2025.
View privacy terms for your jurisdiction
Select your country and state / territory to see region-specific provisions. All 49 countries supported by BookingFlow are listed below.
Selected: New South Wales, Australia · Privacy Act 1988 (Cth) & APPs
1. Overview
This Privacy Policy explains how OperonFlow Pty Ltd ("OperonFlow", "we", "us") collects, uses, discloses, and protects personal information when you use BookingFlow ("Service").
The Service supports two roles: Business Users (account holders) and End Customers (people booking with a Business User). Business Users are generally responsible for their own privacy notices to End Customers; this Policy describes OperonFlow's role as platform operator and, where applicable, data processor.
2. Roles and responsibilities
For Business User account data (registration, billing, support), OperonFlow is typically the data controller.
For End Customer booking data submitted through a Business User's page, the Business User is typically the data controller and OperonFlow processes data on their instructions to provide booking, payments, notifications, analytics, and related features.
Business Users must provide End Customers with a lawful basis, privacy notice, and rights mechanisms appropriate to their jurisdiction.
3. Information we collect
We may collect:
- Account and profile data: name, email, phone, business details, country/state, timezone, locale, password hash.
- Booking data: names, contact details, appointment times, notes, payment status, check-in records, waitlist entries.
- Payment metadata: transaction IDs and amounts via Stripe, Paddle, or other processors (not full card numbers stored by us).
- Technical data: IP address, device/browser type, logs, cookies, and usage analytics.
- Integrations: calendar tokens, webhook configurations, and third-party identifiers you connect.
- Communications: support messages, email/SMS delivery logs, and notification preferences.
4. How we use information
We use personal information to:
- Provide, secure, and improve the Service.
- Process bookings, payments, reminders, and customer self-service links.
- Authenticate users and prevent fraud or abuse.
- Provide analytics, reporting, and customer support.
- Comply with law, enforce terms, and protect rights and safety.
- Send service-related communications; marketing only with consent where required.
6. Retention
We retain personal information while accounts are active and as needed to provide the Service, resolve disputes, enforce agreements, and comply with legal obligations.
Business Users may export or request deletion subject to legal retention requirements and backup cycles.
7. Security
We use encryption in transit, access controls, and monitoring appropriate to the nature of the data. No system is completely secure; please use strong passwords and protect account credentials.
8. International transfers
We may process and store information in countries other than your own. Where required, we use appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms.
Business Users who serve End Customers internationally are responsible for lawful cross-border transfers to OperonFlow and onward to subprocessors.
9. Children
The Service is not directed to children under 16 (or the applicable age of digital consent in your jurisdiction). Business Users must not collect children's data through the Service without lawful authority and parental consent where required.
10. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or email where appropriate.
11. Contact
Privacy enquiries and data subject requests relating to OperonFlow's processing: legal@operonflow.com.
End Customers should generally contact the Business User they booked with first; we will assist Business Users in fulfilling requests where we process data on their behalf.
Regional addendum
Regional privacy addendum — New South Wales, Australia
This addendum applies if you are located in, or primarily offer services to individuals in, New South Wales, Australia.
Primary privacy framework identified for your selection: Privacy Act 1988 (Cth) & APPs.
Where mandatory local law in New South Wales, Australia requires otherwise, those mandatory provisions prevail over conflicting terms in this agreement.
Australia — Privacy Act & APPs
Depending on your circumstances, you may have some or all of the following rights, subject to legal exceptions:
- Access and correction under Australian Privacy Principles (APPs).
- Complaints to the Office of the Australian Information Commissioner (OAIC).
- Cross-border disclosure rules apply when data leaves Australia.