Privacy Policy
The short version: we collect only what the Service needs to work, the booking widget sets no cookies and does no tracking of your website's visitors, and we never sell personal information to anyone. Booking data belongs to the account holder whose form collected it.
1. Who we are
Slotly is a booking service operated by Cloud Pixel ("Slotly", "we", "us", "our") from Australia. This policy explains how we handle personal information in connection with bookslotly.com, app.bookslotly.com and the embeddable booking widget (the "Service"). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Two kinds of people interact with Slotly, and we treat their information differently:
- Account holders — people who sign up and put a Slotly calendar on their website. For their information, we are the data controller.
- Visitors — people who make a booking through a calendar embedded on an account holder's website. We process their information on the account holder's behalf and on the account holder's instructions.
2. Information we collect
From account holders
- Account details: your email address and a securely hashed password (we never store your password in plain text).
- Configuration: your booking forms, schedules, form fields, themes and other settings.
- Payment records: payments are processed by Stripe. We do not see or store card numbers — we keep a record of the purchase (such as the purchase email and plan) so we can apply your upgrade.
- Support correspondence: emails you send us.
From Visitors (booking data)
- The date and time slot requested, and the answers the Visitor gives to the account holder's form fields — commonly a name and email address, plus whatever custom fields the account holder has configured.
- The booking widget sets no cookies and does no cross-site tracking, fingerprinting or advertising analytics of Visitors.
Automatically
- Marketing site metrics: when you view a page on bookslotly.com we record the page path, your IP address, an approximate location derived from that IP (typically country, region and city), the referring site and your browser's user-agent string. We use this to understand our traffic and where our visitors come from. This applies to our own marketing pages only — it is set with no cookies and does not identify you by name. This log is retained for a limited period and then deleted.
- Session cookies: app.bookslotly.com uses a cookie to keep account holders signed in. It is strictly necessary for the Service and is not used for tracking.
- Server logs: like most web services, our servers keep standard request logs (such as IP address and user agent) for security and debugging, retained for a limited period.
3. How we use information
- To provide and operate the Service: showing availability, capturing bookings, and letting account holders manage them.
- To process payments and apply upgrades.
- To send service emails — for example booking notifications (if the email add-on is enabled), security notices, and important account or service announcements such as changes to terms or a service shutdown notice.
- To secure, debug and improve the Service.
We do not sell personal information, and we do not use booking data for advertising or share it with data brokers. We do not send marketing email to Visitors.
4. If you booked through someone's website
If you made a booking through a calendar embedded on a website, that website's owner (our account holder) decided what information to ask for and is responsible for how it is used outside Slotly. We store and process that booking on their behalf so they can manage it. To access, correct or delete a booking you made, contact the website owner first — they can action it directly in their dashboard. You can also contact us and we will assist where we reasonably can.
5. Who we share information with
We share personal information only with the service providers we need to run Slotly:
- Stripe — payment processing (see Stripe's own privacy policy).
- Hosting and infrastructure providers — the servers and databases the Service runs on.
- Email delivery providers — to send the service and notification emails described above.
We may also disclose information where required by law, or as part of a sale, transfer or reorganisation of the business (in which case this policy would continue to apply to the transferred information and we would notify account holders).
6. Where information is stored
Our infrastructure and service providers may store or process information outside Australia. Where they do, we take reasonable steps to ensure it is handled consistently with this policy and the Australian Privacy Principles.
7. Security
We take reasonable technical and organisational measures to protect personal information, including encryption in transit (HTTPS), hashed passwords, and access controls. No system is perfectly secure, so we cannot guarantee absolute security; if we become aware of a data breach that is likely to result in serious harm, we will notify affected people and the regulator as required by law.
8. Retention and deletion
- Account and booking data is retained while the account is active, so account holders can manage their booking history.
- Account holders can delete bookings from their dashboard and can request deletion of their entire account and its data by contacting us. We action deletion requests within a reasonable period, subject to records we must keep by law (for example, payment records).
- If Slotly is ever discontinued, we will give account holders at least 60 days' notice (see our Terms of Service) and keep data exportable during that period. After the shutdown date, account and booking data will be permanently deleted, except for minimal records we are legally required to retain.
9. Your rights
You may request access to, or correction of, the personal information we hold about you. If you are in a jurisdiction that grants additional rights (such as the EU/UK GDPR), you may also have rights to erasure, restriction, portability and objection, which we will honour where they apply. To make a request, email us at the address below; we may need to verify your identity first.
If you have a complaint about how we have handled your information, contact us and we will respond within a reasonable time. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. Changes to this policy
We may update this policy from time to time. The current version will always be available at this page, with its effective date shown above. For material changes we will notify account holders by email or in the dashboard.
11. Contact
Privacy questions and requests: [email protected].