You'reOnTime

Privacy Policy

How your personal information is handled when you book online with a business that uses You'reOnTime.

Last updated 27 September 2026

In short. This booking site is run by You'reOnTime on behalf of the business you are booking with. The business decides what information it asks for and how it uses it, and its own privacy policy applies to your dealings with it. We host the booking site, keep it secure, send confirmations and reminders on the business's behalf, and never sell your information. Card details are entered directly with Stripe, our payment processor, and never touch our servers.

This page is written for people using online booking. It is a tailored version of, and should be read together with, the full You'reOnTime Privacy Policy, which governs if there is any inconsistency.

  1. Who we are and our role
  2. Information collected when you book
  3. How the information is used
  4. Deposits, card details and payments
  5. Logging in to manage your bookings
  6. Confirmations, reminders and marketing
  7. Reviews, vouchers, maps and other features
  8. Cookies and storage on this site
  9. Who we share information with
  10. Where information is stored
  11. Security
  12. How long information is kept
  13. Your rights and how to exercise them
  14. Booking for someone else, and children
  15. Complaints
  16. Contacting us
  17. Changes to this policy

1. Who we are and our role

NEWCHURCHTEK PTY LTD (ACN 159 180 337) as trustee for C D & A VAN NIEUWKERK FAMILY TRUST (ABN 33 589 622 372), trading as You'reOnTime (we, us, our), provides salon, spa, barber and clinic management software. Businesses that subscribe to our software (each a business) can offer online booking, and we host their booking sites at youreontime-booking.com and on custom addresses.

When you book with, buy from or otherwise deal with a business through its booking site, the business decides how and why your personal information is collected and used. Under the Australian Privacy Act 1988 (Cth) the business is the entity that collects your information, and under the GDPR and UK GDPR it is the data controller. We process your information on the business's behalf and on its instructions as a data processor. This means:

We act as a data controller in our own right only for limited purposes: operating, securing and maintaining the booking site (including detecting fraud, spam, abuse and security incidents), sending you one-time login codes, responding to enquiries or requests you send directly to us, complying with our own legal obligations, and producing aggregated statistics that do not identify you.

We respect your rights under the Privacy Act and the Australian Privacy Principles, and, where they apply, the GDPR, the UK GDPR and Data Protection Act 2018, and Bermuda's Personal Information Protection Act 2016 (PIPA).

2. Information collected when you book

Depending on how the business has set up its booking site and which features you use, the following information is collected through this site:

You do not have to provide this information, but without your name, email address and mobile number the business cannot accept an online booking or send you confirmations and reminders.

Information you enter is also remembered on your own device so it can be filled in for you next time (see section 8). It is not sent to us until you submit a booking.

3. How the information is used

Information collected through the booking site is used to:

Where the GDPR or UK GDPR applies, the business relies on its own lawful basis, usually the performance of a contract with you or your consent. For the limited purposes where we act as controller, we rely on our legitimate interests in operating a secure and reliable service and on our legal obligations.

We do not use your information to market our own services to you, we do not combine your bookings across different businesses into a single profile, and we do not sell personal information.

4. Deposits, card details and payments

A business may require a deposit or pre-payment when you book, or may ask you to save a card that it can charge if you cancel late or do not attend. The business's cancellation policy and the amount involved are shown to you before you enter your card details.

Deposits, saved cards and other card payments made through the booking site are processed by Stripe, a third-party payment processor integrated with our software. You enter your card details directly into a secure payment form provided by Stripe. Even though that form appears inside the booking page, your card number, expiry date and security code go straight to Stripe and are never received, stored or transmitted by us.

We receive and store a payment token, the card brand, the last four digits of the card, the amount and the status of the transaction, so that the business can reconcile payments and, where you have agreed, charge a deposit or cancellation fee to your saved card. Saved cards are held by Stripe against a customer record for the business, not by us.

Stripe is an independent data controller of the information you give it and may use it to prevent fraud and comply with its own legal obligations. Stripe's privacy policy applies, and its payment form may set cookies or identifiers for fraud prevention.

When you buy a gift voucher for another person, the recipient's name and email address or mobile number are collected so the voucher can be delivered. You confirm you have the recipient's permission to provide this.

5. Logging in to manage your bookings

Login is not required to make a booking. If the business has enabled it, you can log in to view, change or cancel your bookings and update your details. We verify your identity by sending a one-time code to your mobile number or email address. We do not ask you to create a password and we do not use social media logins.

One-time codes expire within minutes. Once you have logged in, a token is stored in a cookie on your device so you stay logged in on that device. Your login is specific to the business whose booking site you are using.

6. Confirmations, reminders and marketing

Our software sends appointment confirmations, reminders, follow-ups and rebooking prompts by SMS, email and app notification on behalf of the business. These are service messages that form part of the booking you have requested, not marketing. You can reply to confirm, cancel or leave a message, and your reply is delivered to the business. You can ask the business to stop sending reminders, but it may then require you to confirm appointments in another way.

Separately, a business can use our software to send email and SMS marketing to its clients. Whether you receive marketing is decided by the business, which is responsible for complying with applicable marketing laws, including the Spam Act 2003 (Cth) and, in the EEA and UK, the ePrivacy rules, and for obtaining your consent where required. Every marketing email includes an unsubscribe link and every marketing SMS includes an opt-out instruction. Opting out of marketing does not stop appointment confirmations and reminders. We do not send our own marketing to people who book through a business's site.

7. Reviews, vouchers, maps and other features

Reviews. If you leave a review, the business may publish your rating, review text, first name and the date of the review on its booking site. Reviews are not displayed with your email address or telephone number. Contact the business if you want a review edited or removed.

Gift vouchers, memberships and store purchases. Where offered, these are processed in the same way as bookings and payments described above.

Maps. Booking sites show the business's locations using Google Maps. Google may collect technical information about your device when a map is displayed, under Google's privacy policy.

Contact forms. Messages you send through the business's contact page are delivered to the business.

Links. The booking site links to websites we do not control, including the business's own website and social media pages. Their privacy policies apply to those sites.

8. Cookies and storage on this site

The booking site uses cookies and your browser's local storage for the purposes below. All of these are needed for the site to work; none are used by us for advertising.

What Purpose How long
Session cookie Remembers which business's site you are using and your language choice. Browser session
Booking in progress (local storage) Keeps your selected location, services, staff, date and details as you move between steps. Until replaced by your next booking
Remembered details cookie Saves the name, email, phone and address you typed so they can be filled in next time you book on this device. Up to 12 months
Login token cookie Keeps you logged in after you enter a one-time code. Up to 12 months, or until you log out
Campaign tags Stores utm parameters from the link you arrived on so the business can attribute your booking to its promotion, and stops the same click being counted twice. 30 days (local storage), 1 day (cookie)
Stripe Cookies and identifiers set by Stripe's secure payment form for fraud prevention. Set by Stripe

The site also loads fonts, scripts and map images from third-party content delivery networks and from Google, which receive your IP address and technical information about your browser when those files are requested.

Analytics added by the business. A business can add its own analytics or advertising tags to its booking site, such as Google Tag Manager, Google Analytics or a Meta (Facebook) pixel. Any such tags are chosen and controlled by the business, are covered by its privacy policy, and may set cookies on your device. We do not place advertising or social media tracking cookies of our own on booking sites and we do not build advertising profiles of people who book.

You can clear or block cookies and local storage in your browser settings. If you do, you will need to re-enter your details each time you book and may not be able to stay logged in.

9. Who we share information with

Information collected through the booking site is shared with:

Our service providers are bound by contract to keep information confidential, to use it only to provide services to us, and to protect it to a standard consistent with this policy and applicable law. We do not disclose personal information to third parties for their own direct marketing purposes.

10. Where information is stored

We are based in Australia. The booking site and our software are hosted with third-party cloud providers, and some of our service providers, including SMS and email delivery, payment processing and support tools, are located or store data outside Australia, including in the United States and the European Economic Area. Your information may therefore be transferred to, stored in and accessed from countries other than the one you live in.

Before disclosing personal information overseas we take reasonable steps, as required by Australian Privacy Principle 8, to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles. Where the GDPR or UK GDPR applies we rely on adequacy decisions, the European Commission's Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum, together with any supplementary measures identified in a transfer risk assessment. Where PIPA applies we transfer information overseas only where we are satisfied the recipient will provide a comparable level of protection. You can request a copy of the relevant safeguards by contacting us.

11. Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. On the booking site this includes encrypting data in transit using TLS and at rest with our hosting providers, hosting with providers that maintain independently audited security programs, one-time codes rather than passwords for client logins, never storing full card details on our systems, restricting our staff's access to what is needed to provide support, and regular backups, monitoring, patching and vulnerability management.

No transmission over the Internet and no method of electronic storage is completely secure, so we cannot guarantee absolute security. If you believe someone else has accessed your bookings, please contact the business or us immediately.

12. How long information is kept

Your booking and client record is held in the business's account, and the business decides how long it is kept, subject to its own legal obligations. The business can delete your record at any time. When a business stops using our software we retain its account data for a limited period so it can export it or reactivate the account, and then delete it from our production systems. Deleted data may persist in encrypted backups for a further period until those backups are cycled.

One-time login codes expire within minutes. SMS and email delivery logs are kept for as long as needed to demonstrate delivery, investigate problems and comply with telecommunications and anti-spam laws. Technical logs and error reports are kept for a limited period for security and troubleshooting. We may keep de-identified or aggregated statistics indefinitely.

13. Your rights and how to exercise them

You may ask to access, correct or delete the personal information held about you. Because the business controls your record:

We will respond to requests made to us within a reasonable time, and in any event within 30 days. We may need to verify your identity first. We do not charge for making a request or for correcting information. There may be circumstances where information cannot be deleted, for example where the law requires it to be kept or it is needed to establish or defend legal claims. If that happens we will tell you and explain how you can complain.

If you are in the EEA or the United Kingdom

You have the rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object (including at any time to direct marketing), not to be subject to solely automated decisions with legal or similarly significant effects, and to withdraw consent. These rights are subject to conditions and exceptions, and where the business is the controller they are exercisable against the business. We will respond to requests made to us within one month, extendable by up to two further months for complex requests. You may lodge a complaint with your local supervisory authority (see edpb.europa.eu) or the UK Information Commissioner's Office (ico.org.uk).

If you are in Bermuda

You have the rights to access and correct your information, to request erasure or blocking of information that is no longer relevant, to object to processing for direct marketing or where it is likely to cause substantial damage or distress, to withdraw consent to processing of sensitive personal information, and to complain to the Bermuda Privacy Commissioner (privacy.bm).

Automated decisions

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The booking site applies rules configured by the business, such as deposit and cancellation rules, "first available" staff selection and flags for missed appointments. Any decision to refuse a booking or charge a fee is made under the business's own policies and can be reviewed by the business on request.

14. Booking for someone else, and children

If you book an appointment, buy a voucher or complete a form for another person, including a child in your care, you confirm that you are authorised to provide their information and to agree to this policy on their behalf.

Booking sites are not directed at children under 16, and we do not knowingly collect personal information directly from children under 16 without the consent of a parent or guardian. Bookings for a child should be made by a parent or guardian. If you believe we hold information about a child without appropriate consent, please contact us and we will take steps to delete it.

15. Complaints

If you believe your privacy has been breached or you have a concern about how we have handled your personal information, please contact us using the details below with enough detail for us to investigate. We will acknowledge your complaint, treat it confidentially and aim to resolve it within 30 days. If you are not satisfied you may complain to the relevant regulator: in Australia the Office of the Australian Information Commissioner (oaic.gov.au); in the EEA your national data protection authority; in the United Kingdom the Information Commissioner's Office; and in Bermuda the Office of the Privacy Commissioner. If your complaint concerns how the business has used your information, raise it with the business, and you may also complain to the regulator where the business is located.

16. Contacting us

Questions about this policy, requests to exercise your rights and complaints can be sent to our Privacy Officer through youreontime.com/contact, or by post to NEWCHURCHTEK PTY LTD, Attention: Privacy Officer, at our registered office in Australia. For questions about your appointment, your record or the business's cancellation policy, please contact the business directly using the details on its booking site.

17. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, our software or the law. The current version is always available at this address and the date of the latest update appears at the top of the page. Your continued use of a booking site after a change takes effect means you accept the updated policy.

This page summarises how our full Privacy Policy applies to online booking. The full policy also covers our website and the businesses that subscribe to our software, and governs if there is any inconsistency between the two. Portions of this policy are based on a template © Progressive Legal Pty Ltd (ACN 607 068 708) trading as Progressive Legal (2021). All Rights Reserved.