Privacy Policy
How your personal information is handled when you book online with a business that uses You'reOnTime.
Last updated 27 September 2026
In short. This booking site is run by You'reOnTime on behalf of the business you are booking with. The business decides what information it asks for and how it uses it, and its own privacy policy applies to your dealings with it. We host the booking site, keep it secure, send confirmations and reminders on the business's behalf, and never sell your information. Card details are entered directly with Stripe, our payment processor, and never touch our servers.
This page is written for people using online booking. It is a tailored version of, and should be read together with, the full You'reOnTime Privacy Policy, which governs if there is any inconsistency.
- Who we are and our role
- Information collected when you book
- How the information is used
- Deposits, card details and payments
- Logging in to manage your bookings
- Confirmations, reminders and marketing
- Reviews, vouchers, maps and other features
- Cookies and storage on this site
- Who we share information with
- Where information is stored
- Security
- How long information is kept
- Your rights and how to exercise them
- Booking for someone else, and children
- Complaints
- Contacting us
- Changes to this policy
1. Who we are and our role
NEWCHURCHTEK PTY LTD (ACN 159 180 337) as trustee for C D & A VAN NIEUWKERK FAMILY TRUST (ABN 33 589 622 372), trading as You'reOnTime (we, us, our), provides salon, spa, barber and clinic management software. Businesses that subscribe to our software (each a business) can offer online booking, and we host their booking sites at youreontime-booking.com and on custom addresses.
When you book with, buy from or otherwise deal with a business through its booking site, the business decides how and why your personal information is collected and used. Under the Australian Privacy Act 1988 (Cth) the business is the entity that collects your information, and under the GDPR and UK GDPR it is the data controller. We process your information on the business's behalf and on its instructions as a data processor. This means:
- the business's own privacy policy applies to how it uses your information, including any notes, photographs, health information or marketing preferences it records about you;
- the business is responsible for obtaining any consents required from you, and for responding to your requests to access, correct or delete your information; and
- if you contact us about information held in a business's records, we will refer you to the business or pass your request on to them, and help them respond.
We act as a data controller in our own right only for limited purposes: operating, securing and maintaining the booking site (including detecting fraud, spam, abuse and security incidents), sending you one-time login codes, responding to enquiries or requests you send directly to us, complying with our own legal obligations, and producing aggregated statistics that do not identify you.
We respect your rights under the Privacy Act and the Australian Privacy Principles, and, where they apply, the GDPR, the UK GDPR and Data Protection Act 2018, and Bermuda's Personal Information Protection Act 2016 (PIPA).
2. Information collected when you book
Depending on how the business has set up its booking site and which features you use, the following information is collected through this site:
- Contact details: your first and last name, email address and mobile telephone number, which are needed to complete a booking.
- Optional details: your postal address, date of birth, how you heard about the business, a promotion code and any notes you add for the business, where the business asks for them.
- Appointment details: the location, services, staff member (or "first available"), date and time, price, any deposit or cancellation fee that applies, and your attendance and cancellation history.
- Payment status: whether a deposit was paid or a card was saved, the amount, the card brand and last four digits, and a payment reference. We do not receive your card number, expiry date or security code (see section 4).
- Login codes: your mobile number or email address when you ask for a one-time code to log in (see section 5).
- Purchases and reviews: gift vouchers, memberships, packages, products you buy, and reviews you leave, where the business offers these features.
- Campaign details: if you arrive from a link that contains campaign tags (utm parameters), those tags are stored on your device for up to 30 days and attached to your booking so the business can see which promotion brought you.
- Technical information: your IP address, the date and time of your visit, the pages you use, your browser, operating system and device type, and error reports, which our servers and monitoring tools record automatically.
You do not have to provide this information, but without your name, email address and mobile number the business cannot accept an online booking or send you confirmations and reminders.
Information you enter is also remembered on your own device so it can be filled in for you next time (see section 8). It is not sent to us until you submit a booking.
3. How the information is used
Information collected through the booking site is used to:
- create and manage your appointment in the business's calendar and client records;
- send you booking confirmations, reminders, follow-ups and rebooking prompts on the business's behalf;
- let the business contact you about your appointment;
- take a deposit or pre-payment, or save a card for a cancellation or no-show fee, in line with the business's cancellation policy shown to you before you book;
- check whether you are an existing client of the business so that the right prices, deposit rules and preferences apply;
- let you log in to view, change or cancel your bookings;
- keep the site secure and prevent fraud, spam and abuse;
- report to the business on how its booking site and marketing campaigns are performing; and
- fix faults and improve our software, using aggregated or de-identified data wherever possible.
Where the GDPR or UK GDPR applies, the business relies on its own lawful basis, usually the performance of a contract with you or your consent. For the limited purposes where we act as controller, we rely on our legitimate interests in operating a secure and reliable service and on our legal obligations.
We do not use your information to market our own services to you, we do not combine your bookings across different businesses into a single profile, and we do not sell personal information.
4. Deposits, card details and payments
A business may require a deposit or pre-payment when you book, or may ask you to save a card that it can charge if you cancel late or do not attend. The business's cancellation policy and the amount involved are shown to you before you enter your card details.
Deposits, saved cards and other card payments made through the booking site are processed by Stripe, a third-party payment processor integrated with our software. You enter your card details directly into a secure payment form provided by Stripe. Even though that form appears inside the booking page, your card number, expiry date and security code go straight to Stripe and are never received, stored or transmitted by us.
We receive and store a payment token, the card brand, the last four digits of the card, the amount and the status of the transaction, so that the business can reconcile payments and, where you have agreed, charge a deposit or cancellation fee to your saved card. Saved cards are held by Stripe against a customer record for the business, not by us.
Stripe is an independent data controller of the information you give it and may use it to prevent fraud and comply with its own legal obligations. Stripe's privacy policy applies, and its payment form may set cookies or identifiers for fraud prevention.
When you buy a gift voucher for another person, the recipient's name and email address or mobile number are collected so the voucher can be delivered. You confirm you have the recipient's permission to provide this.
5. Logging in to manage your bookings
Login is not required to make a booking. If the business has enabled it, you can log in to view, change or cancel your bookings and update your details. We verify your identity by sending a one-time code to your mobile number or email address. We do not ask you to create a password and we do not use social media logins.
One-time codes expire within minutes. Once you have logged in, a token is stored in a cookie on your device so you stay logged in on that device. Your login is specific to the business whose booking site you are using.
6. Confirmations, reminders and marketing
Our software sends appointment confirmations, reminders, follow-ups and rebooking prompts by SMS, email and app notification on behalf of the business. These are service messages that form part of the booking you have requested, not marketing. You can reply to confirm, cancel or leave a message, and your reply is delivered to the business. You can ask the business to stop sending reminders, but it may then require you to confirm appointments in another way.
Separately, a business can use our software to send email and SMS marketing to its clients. Whether you receive marketing is decided by the business, which is responsible for complying with applicable marketing laws, including the Spam Act 2003 (Cth) and, in the EEA and UK, the ePrivacy rules, and for obtaining your consent where required. Every marketing email includes an unsubscribe link and every marketing SMS includes an opt-out instruction. Opting out of marketing does not stop appointment confirmations and reminders. We do not send our own marketing to people who book through a business's site.
7. Reviews, vouchers, maps and other features
Reviews. If you leave a review, the business may publish your rating, review text, first name and the date of the review on its booking site. Reviews are not displayed with your email address or telephone number. Contact the business if you want a review edited or removed.
Gift vouchers, memberships and store purchases. Where offered, these are processed in the same way as bookings and payments described above.
Maps. Booking sites show the business's locations using Google Maps. Google may collect technical information about your device when a map is displayed, under Google's privacy policy.
Contact forms. Messages you send through the business's contact page are delivered to the business.
Links. The booking site links to websites we do not control, including the business's own website and social media pages. Their privacy policies apply to those sites.
8. Cookies and storage on this site
The booking site uses cookies and your browser's local storage for the purposes below. All of these are needed for the site to work; none are used by us for advertising.
| What | Purpose | How long |
|---|---|---|
| Session cookie | Remembers which business's site you are using and your language choice. | Browser session |
| Booking in progress (local storage) | Keeps your selected location, services, staff, date and details as you move between steps. | Until replaced by your next booking |
| Remembered details cookie | Saves the name, email, phone and address you typed so they can be filled in next time you book on this device. | Up to 12 months |
| Login token cookie | Keeps you logged in after you enter a one-time code. | Up to 12 months, or until you log out |
| Campaign tags | Stores utm parameters from the link you arrived on so the business can attribute your booking to its promotion, and stops the same click being counted twice. | 30 days (local storage), 1 day (cookie) |
| Stripe | Cookies and identifiers set by Stripe's secure payment form for fraud prevention. | Set by Stripe |
The site also loads fonts, scripts and map images from third-party content delivery networks and from Google, which receive your IP address and technical information about your browser when those files are requested.
Analytics added by the business. A business can add its own analytics or advertising tags to its booking site, such as Google Tag Manager, Google Analytics or a Meta (Facebook) pixel. Any such tags are chosen and controlled by the business, are covered by its privacy policy, and may set cookies on your device. We do not place advertising or social media tracking cookies of our own on booking sites and we do not build advertising profiles of people who book.
You can clear or block cookies and local storage in your browser settings. If you do, you will need to re-enter your details each time you book and may not be able to stay logged in.
9. Who we share information with
Information collected through the booking site is shared with:
- the business you are booking with, and members of its staff who have permission to view client records;
- service providers that help us operate the booking site, including cloud hosting and data storage providers, database and backup providers, SMS and email delivery providers, push notification services, payment processors, mapping services, and error monitoring and support tools;
- third-party applications that the business chooses to connect to its account, at the business's direction;
- our professional advisors, and law enforcement, regulators and government agencies where required or authorised by law or where necessary to protect the rights, property or safety of any person; and
- a prospective purchaser or investor in connection with a change of control of our business, under confidentiality obligations and bound to honour this policy.
Our service providers are bound by contract to keep information confidential, to use it only to provide services to us, and to protect it to a standard consistent with this policy and applicable law. We do not disclose personal information to third parties for their own direct marketing purposes.
10. Where information is stored
We are based in Australia. The booking site and our software are hosted with third-party cloud providers, and some of our service providers, including SMS and email delivery, payment processing and support tools, are located or store data outside Australia, including in the United States and the European Economic Area. Your information may therefore be transferred to, stored in and accessed from countries other than the one you live in.
Before disclosing personal information overseas we take reasonable steps, as required by Australian Privacy Principle 8, to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles. Where the GDPR or UK GDPR applies we rely on adequacy decisions, the European Commission's Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum, together with any supplementary measures identified in a transfer risk assessment. Where PIPA applies we transfer information overseas only where we are satisfied the recipient will provide a comparable level of protection. You can request a copy of the relevant safeguards by contacting us.
11. Security
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. On the booking site this includes encrypting data in transit using TLS and at rest with our hosting providers, hosting with providers that maintain independently audited security programs, one-time codes rather than passwords for client logins, never storing full card details on our systems, restricting our staff's access to what is needed to provide support, and regular backups, monitoring, patching and vulnerability management.
No transmission over the Internet and no method of electronic storage is completely secure, so we cannot guarantee absolute security. If you believe someone else has accessed your bookings, please contact the business or us immediately.
12. How long information is kept
Your booking and client record is held in the business's account, and the business decides how long it is kept, subject to its own legal obligations. The business can delete your record at any time. When a business stops using our software we retain its account data for a limited period so it can export it or reactivate the account, and then delete it from our production systems. Deleted data may persist in encrypted backups for a further period until those backups are cycled.
One-time login codes expire within minutes. SMS and email delivery logs are kept for as long as needed to demonstrate delivery, investigate problems and comply with telecommunications and anti-spam laws. Technical logs and error reports are kept for a limited period for security and troubleshooting. We may keep de-identified or aggregated statistics indefinitely.
13. Your rights and how to exercise them
You may ask to access, correct or delete the personal information held about you. Because the business controls your record:
- requests about information in a business's account should be made to the business in the first instance, and it can act on them directly in our software;
- if you send such a request to us, we will pass it to the business without undue delay and help it respond, unless it concerns information we hold as controller (see section 1), which we will handle ourselves;
- where the business has enabled login, you can view and update many of your details yourself; and
- requests to delete data held in a business's branded client app can be made at youreontime.com/dataremoval.
We will respond to requests made to us within a reasonable time, and in any event within 30 days. We may need to verify your identity first. We do not charge for making a request or for correcting information. There may be circumstances where information cannot be deleted, for example where the law requires it to be kept or it is needed to establish or defend legal claims. If that happens we will tell you and explain how you can complain.
If you are in the EEA or the United Kingdom
You have the rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object (including at any time to direct marketing), not to be subject to solely automated decisions with legal or similarly significant effects, and to withdraw consent. These rights are subject to conditions and exceptions, and where the business is the controller they are exercisable against the business. We will respond to requests made to us within one month, extendable by up to two further months for complex requests. You may lodge a complaint with your local supervisory authority (see edpb.europa.eu) or the UK Information Commissioner's Office (ico.org.uk).
If you are in Bermuda
You have the rights to access and correct your information, to request erasure or blocking of information that is no longer relevant, to object to processing for direct marketing or where it is likely to cause substantial damage or distress, to withdraw consent to processing of sensitive personal information, and to complain to the Bermuda Privacy Commissioner (privacy.bm).
Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The booking site applies rules configured by the business, such as deposit and cancellation rules, "first available" staff selection and flags for missed appointments. Any decision to refuse a booking or charge a fee is made under the business's own policies and can be reviewed by the business on request.
14. Booking for someone else, and children
If you book an appointment, buy a voucher or complete a form for another person, including a child in your care, you confirm that you are authorised to provide their information and to agree to this policy on their behalf.
Booking sites are not directed at children under 16, and we do not knowingly collect personal information directly from children under 16 without the consent of a parent or guardian. Bookings for a child should be made by a parent or guardian. If you believe we hold information about a child without appropriate consent, please contact us and we will take steps to delete it.
15. Complaints
If you believe your privacy has been breached or you have a concern about how we have handled your personal information, please contact us using the details below with enough detail for us to investigate. We will acknowledge your complaint, treat it confidentially and aim to resolve it within 30 days. If you are not satisfied you may complain to the relevant regulator: in Australia the Office of the Australian Information Commissioner (oaic.gov.au); in the EEA your national data protection authority; in the United Kingdom the Information Commissioner's Office; and in Bermuda the Office of the Privacy Commissioner. If your complaint concerns how the business has used your information, raise it with the business, and you may also complain to the regulator where the business is located.
16. Contacting us
Questions about this policy, requests to exercise your rights and complaints can be sent to our Privacy Officer through youreontime.com/contact, or by post to NEWCHURCHTEK PTY LTD, Attention: Privacy Officer, at our registered office in Australia. For questions about your appointment, your record or the business's cancellation policy, please contact the business directly using the details on its booking site.
17. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our software or the law. The current version is always available at this address and the date of the latest update appears at the top of the page. Your continued use of a booking site after a change takes effect means you accept the updated policy.
This page summarises how our full Privacy Policy applies to online booking. The full policy also covers our website and the businesses that subscribe to our software, and governs if there is any inconsistency between the two. Portions of this policy are based on a template © Progressive Legal Pty Ltd (ACN 607 068 708) trading as Progressive Legal (2021). All Rights Reserved.