Legal
Privacy Policy
What we collect, why we collect it, who sees it, and how you stay in control. Written in plain English.
Never sold
We don't sell your information or share it with advertisers.
Only what's needed
Just enough to make and manage your bookings.
Cards stay with Stripe
We never see or store your card number.
You're in control
See, correct or delete your information any time.
Who we are
In short: BookInnTime is a booking platform. This policy explains how we handle personal information, in line with the Australian Privacy Principles.
BookInnTime is an Australian business. We run the website at bookinntime.com and the BookInnTime app, where customers find local businesses and book them, and businesses take and manage those bookings. In this policy, “we”, “us” and “our” mean BookInnTime, and “you” means anyone who uses it.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are outside Australia, the privacy laws where you live may give you further rights, and we will honour those as well.
What we collect
In short: Only what's needed to make and manage bookings: contact details, booking details, and — for businesses — what they choose to publish.
When you book
- Your name, email address and, if you give it, your phone number.
- The booking itself: the business, service, date and time, any answers you give to the business’s questions, and any notes you add.
- If you pay online, a record of the payment (amount, status, refunds). Your card details go straight to Stripe — we never see or store your card number.
If you create an account
- Your name, email address and country, and a securely hashed version of your password. We never store the password itself and cannot recover it.
- Businesses you save, your booking history, and messages between you and businesses.
- If you sign in with Google: your Google account identifier, name and email. We never receive your Google password.
If you list a business
- Your business name, category, location, opening hours, services, prices, photos and booking page content — most of which is public by design, because that’s what customers see.
- Your login email, and your Stripe account connection if you take payments online. Stripe collects the identity and bank details it needs directly; we only receive the account’s status.
- If you subscribe to Pro, a record of your subscription. Billing is handled by Stripe.
Automatically
- Your approximate country, from your connection, to show businesses that can serve you and to count visits. We don’t keep your IP address with this.
- An anonymous visit counter held only for the length of a browser tab, used to understand how many people use the site and app.
- For security, the IP address and time of sign-in attempts, so we can stop people guessing passwords.
- Technical error reports when something breaks, so we can fix it.
How we use it
In short: To make your bookings happen, keep your account safe, and improve the service. Never to sell to advertisers.
- To create, confirm, change and cancel bookings, and to send the related emails (confirmations, reminders, changes and receipts).
- To pass your booking details to the business you booked, so they can serve you.
- To process payments, deposits and refunds through Stripe.
- To run accounts, including signing you in and resetting passwords.
- To let customers and businesses message each other about a booking.
- To keep the platform secure and prevent fraud, abuse and spam.
- To understand, in aggregate, how the service is used so we can improve it.
- To meet our legal obligations, such as tax and record-keeping.
Information stored overseas
In short: Some of our providers store data outside Australia, mainly in the United States. We only use providers with strong security.
Our service providers operate globally, so your information may be stored or processed outside Australia, including in the United States, the European Union and other countries where Cloudflare operates. Before using a provider, we take reasonable steps to make sure it protects personal information to a standard comparable to the Australian Privacy Principles.
How we protect it
In short: Encrypted connections, hashed passwords, limited access, and protection against password guessing.
- Every connection to bookinntime.com is encrypted (HTTPS).
- Passwords are stored only as secure one-way hashes.
- Repeated failed sign-ins are slowed and then blocked.
- Card details are handled entirely by Stripe, which is certified to the highest payment-security standard (PCI DSS Level 1).
- Access to personal information is limited to what’s needed to run the service.
How long we keep it
In short: For as long as your account is open or a booking needs a record, then we delete or anonymise it.
We keep account information while your account is open. Booking and payment records are kept for as long as they’re needed for the booking, and afterwards for up to seven years where tax and financial record-keeping laws require it. Security records such as sign-in attempts are kept for a short period only.
When information is no longer needed, we delete it or make it anonymous.
Your choices and rights
In short: You can see, correct or delete your information. Email us and we'll help — usually within 30 days.
- Access and correction. You can ask for a copy of the personal information we hold about you, and ask us to correct anything that’s wrong. Much of it you can update yourself in your account.
- Deletion. Businesses can delete their account from their dashboard settings. Customers can ask us to delete theirs at support@bookinntime.com. Some records (such as payments) may need to be kept for legal reasons first.
- Emails. Booking emails are part of the service. We don’t send marketing emails without your permission, and any we do send will have an unsubscribe link.
- Staying anonymous. You can browse without an account. To book, a business needs a way to contact you.
Children
In short: BookInnTime isn't intended for children under 16 to use on their own.
The service is not directed at children under 16, and we don’t knowingly collect their information without a parent or guardian. A parent or guardian can make bookings on a child’s behalf.
If something goes wrong
In short: If a data breach is likely to cause you serious harm, we'll tell you and the privacy regulator.
If we experience a data breach that is likely to result in serious harm, we will notify the people affected and the Office of the Australian Information Commissioner (OAIC), as required under the Notifiable Data Breaches scheme, and tell you what we’re doing about it and what you can do.
Questions and complaints
In short: Email us first. If you're not happy with our answer, you can complain to the OAIC.
For any privacy question, request or complaint, email support@bookinntime.com. We’ll acknowledge it promptly and aim to resolve it within 30 days.
If you’re not satisfied with how we’ve handled a complaint, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
In short: If we change anything important, we'll let you know before it takes effect.
We may update this policy as the service grows. The date at the top shows when it last changed. If we make a significant change, we’ll tell account holders by email or in the app before it takes effect. You can also read our Cookie Policy for how we use cookies.
Questions?
Talk to a real person.
We reply to every message, usually within two business days.
support@bookinntime.com