Effective: 20 July 2026
Privacy Policy
Introduction
At Photonsoft Pty Ltd (ABN 67 656 104 559), an Australian company based in Sydney, we value your privacy and are committed to protecting your personal information. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of personal information provided by users of our software (the "Service") and complies with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as well as the General Data Protection Regulation (GDPR) where applicable. By accessing and using our Service, you agree to the terms and conditions of this Privacy Policy, and you consent to the collection, use, and disclosure of your personal information as described below. If you do not agree with this Privacy Policy, please do not use the Service.
Information we collect
We collect the following types of information when you use our Service:
Personal Information: This includes information you provide to us directly or indirectly, such as your name, email address, phone number, and business information (e.g., name, address, and services offered). We collect this information when you create an account, make a booking, or otherwise interact with our Service.
Usage Information: We collect information about how you use the Service, including the pages you visit, the features you use, and the time you spend on the Service. We may use cookies and other tracking technologies to gather this information.
How we use your information
We use your personal information for the following purposes:
To provide, maintain, and improve the Service, including responding to your inquiries and providing customer support.
To personalise your experience by customising the content, features, and advertisements you see on the Service.
To communicate with you about updates, promotions, and other marketing materials related to the Service.
To protect the security and integrity of the Service and our users' information, and to prevent and detect fraud, security breaches, and other harmful activities.
To comply with legal obligations and enforce our Terms of Service.
We will never sell your personal information to third parties.
Legal basis for processing
We process your personal information based on one or more of the following legal bases:
Your consent, such as when you voluntarily provide us with your personal information.
Performance of a contract, such as when we need to process your personal information to fulfil our obligations under the Terms of Service.
Our legitimate interests, such as improving our Service, maintaining security, and providing customer support.
Compliance with legal obligations, such as responding to lawful requests from authorities.
Sharing your information
We may share your personal information with third parties in the following circumstances:
With your consent, such as when you choose to share your information with a third-party service integrated with our Service.
With service providers who perform functions on our behalf, such as payment processing, data storage, and email delivery. These service providers are prohibited from using your information for purposes other than providing services to us.
In response to a legal request, such as a court order, subpoena, or government investigation, or to comply with applicable laws and regulations.
In connection with a merger, acquisition, or sale of all or a portion of our assets, in which case your information may be transferred to the new owner.
Third-party service providers
We use the following categories of third-party service providers to operate and improve the Service. These providers process personal information on our behalf and are contractually obligated to protect your data:
Analytics and session recording: We use PostHog for product analytics, event tracking, feature flags, and session recording. Session recordings capture your interactions with the Service, including mouse movements, clicks, scrolling, page views, navigation patterns, and text typed into form fields. Password fields and payment-card entry are masked and are not captured; other on-screen content may be recorded. Recordings are used to improve the user experience and diagnose technical issues, and a link to a relevant recording may be shared with our customer-support provider (Intercom) to help resolve a support query. You can opt out of session recording at any time by contacting us at hello@bellabooking.com.
Customer support: We use Intercom to provide in-app customer support and messaging. When you use the Service, Intercom may collect your name, email address, conversation history, and usage data (such as pages visited and actions taken) to enable proactive support and personalised help. Intercom sets its own cookies to provide this functionality.
Error monitoring: We use PostHog to detect and diagnose software errors. When an error occurs, technical information about the error (including browser type, device information, and the actions leading to the error) may be transmitted to PostHog.
Payment processing: We use Stripe to process payments and manage subscriptions, and Square where you choose to enable it. These providers process your payment information directly and are PCI DSS compliant. We do not store your full credit card details on our servers.
Authentication: We use Auth0 to manage user authentication and account security.
Default profile pictures: When a client signs in to a business's online booking page, our authentication provider (Auth0) checks Gravatar — a public profile-picture service operated by Automattic — for a picture the client has publicly linked to their email address, using a hashed form of that address. If one exists, it is shown as the client's default profile picture until they upload their own or remove it; a removed picture is not applied again. Displaying the picture involves the viewer's browser requesting it from Gravatar's servers. Clients can manage or delete their Gravatar at gravatar.com.
Communications: We use Twilio for SMS notifications (such as appointment reminders) and Postmark for email delivery, with SendGrid as a backup email provider. These providers process phone numbers and email addresses as necessary to deliver messages on our behalf.
Cloud infrastructure: We use Microsoft Azure for hosting, storage and AI-powered features, MongoDB Atlas as our database, and Cloudflare for content delivery and security. Some AI-powered features are provided by Azure OpenAI and Anthropic, which process the content you send to those features to generate a response. Your data may be stored on servers located outside your country of residence.
Website import: When you choose to import details from your website, we use Firecrawl to read the publicly available content of the address you provide. Firecrawl receives only that URL and returns the extracted page content to us; it is contractually obligated to protect the data and not to use it for any other purpose.
Google API Services — use of Google user data
Bella Booking integrates with Google APIs to provide optional Google Calendar synchronisation. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access. When you connect a Google account, we access only: the email address of the connected Google account; and, for the calendar(s) you select, the start and end times of events (free/busy information) and the full content of events that Bella Booking has previously created on those calendars.
How we use it. Google user data is used solely to run the calendar-sync feature you have enabled — we read your availability to prevent double-bookings, and we create, update, or delete events on your selected calendar when appointments change in Bella Booking.
Sharing, storage, and retention. Google user data is processed under the practices described elsewhere in this policy — see the "Sharing your information", "Third-party service providers", "Security", and "Data retention" sections.
Disconnecting. You can revoke Bella Booking's access to your Google account at any time by disconnecting Google Calendar from your team-member profile in Bella Booking, or from your Google Account at myaccount.google.com/permissions. Once disconnected, we stop accessing your Google data and delete the access credentials we held.
Website import (setup assistance)
To help you set up quickly, Bella Booking offers an optional feature that reads your own business website. When you provide your website address — during onboarding or from your settings — and choose to scan it, we retrieve the publicly available content of that website (via our service provider Firecrawl) and extract details such as your business name, contact details, services, team, opening hours, brand colours, logo, and social media links.
This feature is user-initiated and processes the website address you supply (and, where applicable, your own public business listing on a booking platform you tell us you currently use). We do not scrape unrelated third-party websites on your behalf. Nothing extracted is applied automatically — each detail is shown as a suggestion that you choose to apply. Extracted results are cached for a short period (currently up to 7 days) to power these suggestions, then deleted. Where extracted content includes personal information about your team members, you remain responsible — as the controller of that information — for having a lawful basis to provide it to us.
Cookies and tracking technologies
We use cookies and similar technologies to operate and improve the Service. These include:
Essential cookies: Required for the Service to function, including authentication and session management.
Analytics cookies: Used by PostHog to understand how users interact with the Service and to improve user experience.
Support cookies: Used by Intercom to provide customer support functionality.
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.
Account access for support
Authorised Bella Booking support personnel may access your account when reasonably necessary to respond to support requests, troubleshoot technical issues, perform maintenance, or ensure compliance with our terms. Such access is limited to what is necessary, logged for accountability, and our personnel are bound by confidentiality obligations. For further details, please refer to the Account Access for Support section in our Terms and Conditions.
Data breach notification
In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme of the Privacy Act 1988 (Cth). Where applicable, we will also comply with GDPR breach notification requirements.
Data retention
We retain your information for as long as your account is active or as needed to provide the Service. To keep your business records intact, individual client records that have appointment or sales history are retained — rather than individually deleted — while your account is active; you can correct them at any time, and they are removed when the account itself is deleted. When an account is no longer subscribed and has become inactive, we automatically delete the account and its data — currently after about 90 days of inactivity for accounts that have previously subscribed, and about 65 days for accounts that only ever trialled. We may keep information longer where required for legal, accounting, or regulatory purposes. Backup copies may be retained in encrypted form for a limited period after deletion, and analytics or aggregated data that cannot identify you may be retained indefinitely. As the business using Bella Booking, you remain responsible for meeting your own record-keeping obligations — for example, the retention periods that apply to health or clinical records in your jurisdiction.
International data transfers
As an Australian company, we comply with Australian Privacy Principle 8 (APP 8) regarding cross-border disclosure of personal information. Some of our third-party service providers are located overseas, including in the United States. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure they comply with the APPs or are subject to a substantially similar privacy framework. Where applicable, we also implement Standard Contractual Clauses or other safeguards approved by the European Commission for transfers outside the European Economic Area (EEA).
Your rights under the GDPR
Under the GDPR, you have the following rights regarding your personal information:
Access: You have the right to request access to the personal information we hold about you.
Rectification: You have the right to request correction of any inaccurate personal information we hold about you.
Erasure: You have the right to request the deletion of your personal information under certain circumstances, such as when the data is no longer necessary for the purposes it was collected or when you withdraw your consent.
Restriction of processing: You have the right to request that we restrict the processing of your personal information under specific circumstances, such as when you contest the accuracy of the data or when the processing is unlawful.
Data portability: You have the right to request that we provide you with a copy of your personal information in a structured, commonly used, and machine-readable format, or that we transfer it directly to another data controller, where technically feasible.
Objection: You have the right to object to the processing of your personal information for direct marketing purposes or when the processing is based on our legitimate interests.
Automated decision-making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you.
Withdraw consent: If we process your personal information based on your consent, you have the right to withdraw your consent at any time. However, this will not affect the lawfulness of the processing before the withdrawal.
To exercise any of these rights, please contact us using the contact information provided below.
Your rights under Australian privacy law
In addition to the rights listed above, as an Australian user you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Photonsoft Pty Ltd is bound by the APPs and is committed to handling your personal information in accordance with these principles.
Under the APPs, you have the right to:
- Request access to the personal information we hold about you (APP 12).
- Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
- Make a complaint to us about a breach of the APPs, and if unsatisfied with our response, lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
We will not disclose your personal information to overseas recipients without your consent or unless required by Australian law. Where we do transfer data internationally, we take reasonable steps to ensure the overseas recipient complies with the APPs.
Security
We take reasonable measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of your information.
Third-party links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies before providing them with your personal information.
Children's privacy
Bella Booking is a tool for businesses and their team members, who must be adults to hold an account. The Service is not directed at children, and we do not knowingly collect personal information directly from a child as a user of the Service.
A business that uses Bella Booking may, however, record details about a client who is a minor — for example, a child added as a family member and booked in by a parent or guardian. In that case the information is provided to us by the business, not collected by us directly from the child, and we handle it in the same way as other client information the business holds. The business is responsible for having any parental or guardian consent required and a lawful basis for recording that information. If you believe a child's information has been provided to us without the appropriate consent, please contact us at hello@bellabooking.com and we will work with the business to address it.
Changes to this privacy policy
We may update this Privacy Policy from time to time. When we make changes, we will post the updated policy on our website and update the effective date. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
Contact us
If you have any questions or concerns about this Privacy Policy, your rights under applicable privacy laws, or our privacy practices, please contact us or email us at: Photonsoft Pty Ltd (ABN 67 656 104 559).
hello@bellabooking.comLast updated: 20 July 2026