Tidyly Privacy Policy
Tidyly is operated by ABK Digital (ABN 73 674 188 619) in Tamworth, New South Wales, Australia.
This Privacy Policy applies to personal information handled through Tidyly, including tidyly.au, user accounts, team workspaces, public Scheduling pages, messages, customer and lead management, documents, communications, integrations, analytics, subscription billing, and connected customer-payment workflows.
Where the Privacy Act 1988 (Cth) applies to us, we handle personal information in line with that Act and the Australian Privacy Principles. Other laws may also apply to particular records or communications.
Scope and Responsibilities
This policy covers visitors, account holders, invited team members, businesses using Tidyly, and people whose information is entered into or submitted through Tidyly, such as customers, prospective customers, suppliers, and job applicants.
A business using Tidyly controls the customer and lead information it enters or collects through its workspace. That business is responsible for having a lawful reason to collect and use the information, giving any notices required by law, respecting marketing preferences, keeping workspace access appropriate, and responding to its customers. Tidyly handles that information to provide and protect the platform and to follow the business's authorised instructions, subject to our own legal obligations.
This policy is a general privacy policy. A short notice shown at the point where information is collected may give extra details about a specific form, feature, promotion, or integration. Third-party services also apply their own privacy policies when you choose to use them.
Tidyly is intended for business users and is not directed to children. Do not place sensitive information in free-text fields or uploads unless it is reasonably necessary, lawful, and appropriate for the relevant service.
Personal Information We Collect
- Account and identity information: name, email address, authentication user ID, sign-in provider, account and session status, and temporary anonymous onboarding session data where used.
- Account-security information: whether two-factor authentication is enrolled, the enrolled factor record held by Firebase Authentication, recent-authentication state, recovery or reset information, and limited security-event records.
- Team and access information: profile details, workspace membership, roles, invitations, permissions, and access activity.
- Business information: business name, applicable business and tax registration identifiers, owner and contact details, service categories and areas, addresses, descriptions, social and website links, branding, images, publication settings, and connected-location information.
- Customer, lead, and support information: names, contact details, enquiry content, service needs, addresses, access notes, status, outcomes, notes, tasks, activities, message history, support messages, attachments, and related account or page context.
- Scheduling and document information: requested and confirmed dates, time windows, assigned team members, calendar events, quotes, invoices, customer details, line items, payment status, and generated-file metadata.
- Subscription, payment, and accounting information: plan and billing status, provider customer or account IDs, checkout and transaction references, amounts, timestamps, refunds, disputes, payout or reconciliation status, payment-method type, and masked card details such as brand and last four digits where supplied by the payment provider.
- Integration information: connected-service account, tenant, place, location and calendar identifiers; sync settings and snapshots; event, invoice, payment, customer, review and mapping data; token expiry data; and encrypted OAuth credentials where Tidyly stores them.
- Email, notification, and review-invitation information: recipient and sender details, content, delivery status, bounce or complaint events, invitation eligibility, and related purchase or account context.
- Media and file information: business-branding, team, job, support, and document-branding uploads, together with file names, storage references, type, size, and related metadata.
- Analytics and attribution information: pages and features used, events, referral source, campaign parameters, cookie or browser identifiers, session identifiers, device and browser details, approximate location derived by providers, and conversion-attribution fields.
- Technical and security information: request and webhook metadata, timestamps, error and diagnostic records, fraud or abuse-prevention signals, audit records, and hashed network identifiers where implemented.
Tidyly does not store full card numbers or card security codes. Payment providers collect and process those details in their secure payment environments.
How We Collect Information
- Directly from you when you create or secure an account, set up a business, manage a team, contact support, connect a service, issue a document, take a payment, or otherwise use Tidyly.
- From a Tidyly business or its authorised users when they add or manage customer, lead, team, job, scheduling, document, payment, or communication information.
- From customers and visitors who submit forms, request bookings, use payment or shared links, communicate with a Tidyly business, or interact with public scheduling.
- Automatically through authentication, cookies, local storage, analytics, server logs, security controls, and normal browser or device communications.
- From connected providers and their webhooks or APIs, including Google and Firebase, Stripe, Afterpay, Xero, Resend, Meta, Telegram, and Trustpilot, when the relevant service or workflow is used.
If you give us personal information about another person, you must be authorised to do so and, where required, tell them about this policy.
Why We Use Personal Information
- To create accounts, authenticate users, provide optional two-factor authentication, maintain sessions, enforce permissions, and help recover or secure accounts.
- To operate workspaces, teams, public scheduling, directory listings, leads, customer records, messages, bookings, jobs, quotes, invoices, files, and related business workflows.
- To process subscriptions and connected customer payments, keep payment and accounting records in sync, support refunds or disputes, and reconcile transactions.
- To connect and operate services chosen by the business, including calendars, accounting, payments, email, review invitations, and support notifications.
- To validate business or location information, prevent fraud and misuse, investigate incidents, enforce our terms, and maintain platform reliability.
- To provide support, administer the service, communicate changes, answer privacy requests, and manage complaints or legal claims.
- To understand feature use, diagnose problems, improve Tidyly, measure advertising with permission, and report aggregated or de-identified trends.
- To comply with tax, accounting, court, regulatory, law-enforcement, and other legal obligations.
We use personal information only for the purpose for which it was collected, a related purpose you would reasonably expect, a purpose you consent to, or another purpose permitted or required by law.
We do not use private customer or workspace content to train a general-purpose artificial intelligence model.
Public Scheduling and Shared Links
When a business publishes Tidyly Scheduling, selected information is intentionally made public. This may include its name, service options, service area, contact details, booking availability, links, and branding image. Eligible businesses may also appear in directory and discovery pages.
Public message and Scheduling forms collect information for the displayed business. Quote, invoice, booking, payment, download, and other shared links may be accessible to anyone who receives the unique link, so users should share them carefully.
Search engines, social networks, web archives, and other third parties may index, cache, copy, or redistribute information that was public. Removing it from Tidyly may not immediately remove copies controlled by those third parties.
Customer, Lead, Communication, and Support Data
Customer and lead information is stored in the relevant business workspace so authorised users can respond, schedule work, prepare documents, record outcomes, and follow up. Workspace roles determine normal access. Authorised Tidyly personnel may access limited information where reasonably necessary for support, security, abuse prevention, legal compliance, or dispute handling.
Email and notification providers may process recipient details, message content, and delivery events. When a business uses the Trustpilot review-invitation workflow, Trustpilot and the email delivery provider may receive the customer's name, email address, and relevant purchase or service timing needed to send and administer the invitation.
Support messages may include your name, email, role, business or user identifier, current page, message, attachments, and diagnostic context. Tidyly may send a limited copy to a restricted Telegram channel so authorised support personnel can respond. We may also send restricted new-account alerts containing basic account and sign-in details for operational oversight.
When you request a free template or another resource, we may store your name, email, requested resource, referral and campaign context, consent wording and version, consent time, delivery and download activity, a hashed network identifier used to prevent abuse, and marketing-preference history.
Billing, Payments, Accounting, and Connected Services
Stripe processes Tidyly subscriptions and connected customer payments. Stripe may process checkout, recurring payments, payment links, refunds, disputes, payouts, identity checks, business verification, bank details, and risk information. Afterpay may be available through Stripe for eligible transactions.
Payment providers collect full card or bank details directly. Tidyly stores only the provider identifiers, statuses, amounts, timestamps, masked payment-method details, tokenised payment-method references, and consent records reasonably needed to run and support the workflow. A tokenised reference is not a card number but can permit later provider-processed charges where the customer has authorised recurring collection.
Connected-service credentials are restricted and encrypted where stored by Tidyly. Disconnecting a service stops future authorised use but does not necessarily delete records already required for transactions, reconciliation, tax, security, or legal purposes.
If a business joins the Tidyly Partner Program, we store its partner membership, public partner code, terms acceptance, Stripe Connect account and capability status, link visits, random attribution tokens, attributed business identifiers, trial and paid-customer status, commission calculations, invoice and refund references, payout status, and Stripe transfer references. Partner attribution uses a secure first-party cookie containing a random server-side token for up to 30 days; it does not place the partner's account identifier or payment authority in the cookie.
If a business connects Xero, Tidyly may synchronise relevant customer contacts, invoices, payments, refunds, account mappings, tenant details, and sync status. If Google Calendar is connected, Tidyly may read availability and create or update job-related events according to the settings selected by the business.
Each payment, accounting, calendar, email, or review-invitation provider applies its own terms and privacy policy to information it processes as an independent service provider or controller.
Overseas Storage and Disclosure
Tidyly is operated from Australia, but many service providers use global infrastructure. Personal information may therefore be stored in or accessed from countries outside Australia.
- Firebase Authentication, including authenticator-app two-factor authentication, processes data in the United States. Other Google and Firebase services may use infrastructure and support locations in the United States and other countries where Google operates.
- Stripe, Resend, Meta, Telegram, Trustpilot, Xero, and their subprocessors may process information in the United States and other countries in which they or their subprocessors operate.
Provider locations and subprocessor arrangements can change. Where Australian privacy law requires it, we take reasonable steps before an overseas disclosure, including assessing the provider, limiting the information disclosed, using contractual and technical safeguards, and applying access controls. Different countries may not provide the same privacy protections as Australia.
Security and Two-Factor Authentication
We use technical and organisational safeguards designed for the nature of the information and the risks involved. These include authenticated API access, role-based permissions, database and storage rules, encryption in transit, encryption at rest provided by our infrastructure, encrypted connected-service credentials where stored, signed-webhook verification, audit records, monitoring, and restricted administrative access.
Authenticator-app two-factor authentication is voluntary. If you enable it in Security settings, Tidyly asks Firebase Authentication to create a setup secret. Your browser displays that secret as a QR code or manual key so you can add it to a compatible authenticator app. You must enter a current six-digit code to complete enrolment. Future sign-ins then require an authenticator-app code when Firebase requests the second factor.
The setup secret exists temporarily during enrolment and is not written to Tidyly's business database or security-event log. Firebase Authentication retains the enrolled factor information needed to verify future codes. Tidyly records limited security events—such as two-factor authentication being enabled, disabled, or reset by support—together with the user, time, actor, and any required support-case reason. We do not store the changing six-digit authenticator codes in those records.
If you lose access to your authenticator app, support may require identity checks and a written reason before an authorised administrator resets the factor. A reset removes enrolled factors and revokes active refresh sessions. Never send an authenticator setup key or current code by email, chat, or support attachment.
No online service can guarantee absolute security. If a data breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner as required by law.
How Long We Keep Information
We keep personal information only for as long as it is reasonably needed to provide and secure Tidyly, maintain business and account history, support users, resolve disputes, enforce agreements, and meet tax, accounting, fraud-prevention, and other legal obligations.
- Account and workspace information is generally kept while the account or relevant service relationship remains active and for a reasonable period afterwards.
- An enrolled authenticator factor is kept by Firebase Authentication until it is unenrolled or the account is deleted. Limited security and administrative audit events may be kept longer to investigate misuse and demonstrate account changes.
- Transaction, invoice, payment, tax, and accounting records may commonly need to be kept for at least five years, or longer where another legal requirement or dispute applies.
- Support, communication, analytics, and technical logs are kept for periods proportionate to their operational, security, legal, and troubleshooting purpose.
When information is no longer required, we take reasonable steps to delete or de-identify it. Copies may remain for a limited period in protected backups, archives, provider systems, or records placed beyond ordinary use until normal deletion cycles complete.
Access, Correction, Deletion, and Other Requests
You can update many account and business details in the Tidyly dashboard. For access, correction, deletion, or another privacy request that is not available in-product, email the Privacy Officer at support@tidyly.au or use tidyly.au/contact. No special form is required.
Please identify the information or account involved and what you want us to do. We may ask for information needed to verify your identity and authority before releasing or changing records. If a business using Tidyly controls the record, we may refer the request to that business or work with it to respond.
We will respond within a reasonable period and generally aim to do so within 30 days. There is no charge to make a request. If the law permits a reasonable, non-excessive charge for providing access, we will explain it before proceeding.
We may refuse or limit a request where the law allows or requires us to do so, including where it would unreasonably affect another person's privacy, reveal legally privileged material, prejudice an investigation, or conflict with required record-keeping. If we refuse, we will normally give written reasons and explain how to complain, unless the law prevents us from doing so.
Service Messages and Marketing Choices
We may send account, authentication, security, billing, transaction, support, product-operation, and legal notices needed to provide or administer Tidyly. These service messages are not marketing and may continue while you use the relevant service.
We send optional electronic marketing only where we have consent or another lawful basis. Marketing messages identify the sender and provide a working unsubscribe method. You can also opt out by contacting support@tidyly.au. We will action an electronic marketing unsubscribe within five working days, as required by the Spam Act 2003 (Cth).
Free-template and lead-magnet forms that request marketing consent use an unticked choice and record the wording, time, source, and later preference changes. Withdrawing marketing consent does not stop essential service communications or a message you specifically asked us to send.
A business using Tidyly is responsible for the legal basis, sender identification, and unsubscribe handling for marketing it sends to its own customers or leads through its workspace.
Privacy Questions and Complaints
Email the Privacy Officer at support@tidyly.au with the subject “Privacy complaint”, or use tidyly.au/contact. Describe what happened, the account or business involved, the outcome you are seeking, and any relevant dates or documents.
We will acknowledge and investigate the complaint, may ask for further information, and will respond within a reasonable period. We generally aim to provide a substantive response within 30 days. If more time is reasonably needed, we will explain why and provide an updated timeframe.
If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, by calling 1300 363 992, or by writing to GPO Box 5288, Sydney NSW 2001. The OAIC generally expects you to raise the complaint with us first and allow about 30 days for a response.
Changes and Contact Details
We may update this policy when our services, providers, data practices, or legal obligations change. We will publish the revised policy and change the Last Updated date. If a change materially affects how we handle personal information, we will take reasonable steps to provide additional notice where appropriate.
Privacy Officer — ABK Digital (ABN 73 674 188 619), Tamworth NSW 2340, Australia. Email: support@tidyly.au. Online contact: tidyly.au/contact.
For privacy questions about information held in a particular Tidyly business workspace, you may also contact that business directly.
