Privacy Policy

How Abeco collects, uses, shares, stores and protects personal information, and how you can exercise your privacy rights.

Last updated 21 September 202615 min read
Last updated: This Privacy Policy was last updated on 21 September 2026.

Abeco (also known as Abeco AI) is an AI-assisted booking, client management and marketing platform for service businesses. This Privacy Policy explains, in plain English, what personal information we collect, why, who we share it with, how long we keep it, and your rights.

"Abeco", "we", "us" and "our" means the operator of the Abeco platform and https://abeco.io, based in Adelaide, South Australia. "You" means anyone whose personal information we handle.

1. Scope and the laws we follow

We are based in Australia and handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where they apply, we also comply with:

  • the EU General Data Protection Regulation (GDPR), for individuals in the European Economic Area;
  • the UK GDPR and the Data Protection Act 2018, for individuals in the United Kingdom; and
  • the California Consumer Privacy Act as amended (CCPA), to the extent it applies to us (see section 14).

2. Our role: controller and processor

Whose informationOur roleWho decides how it is used
Website visitors, demo and contact form submitters, newsletter subscribersController (APP entity)Abeco
Account holders, billing contacts and staff users of an Abeco accountController (APP entity)Abeco
End-customers of a business using Abeco (for example, people who book an appointment)Processor / service providerThe business that uses Abeco (our customer)

When a salon, clinic, studio or other business uses Abeco to manage its bookings, the business is responsible for the personal information of its own clients. We process that information only on the business's instructions and under our Terms and Conditions and data processing terms. If you booked with a business that uses Abeco and have a question about your data, please contact that business first. We will help them respond.

3. What personal information we collect

Website visitors

  • Technical information such as IP address, browser type, device type, operating system, referring page, pages viewed and approximate location (country or city level).
  • Your cookie consent choice, and other preferences stored in your browser. See our Cookie Policy.
  • If you accept analytics cookies, information about how you use our website.

Demo requests and contact forms

  • Your name, email address, phone number, business name, industry, number of staff or locations, and the message you send us.
  • The details of any demo you book, including the date, time and the video-conferencing link.

Account holders and staff users

  • Account details: name, business name, business address, email, phone number, login credentials (passwords are stored in hashed form), role and permissions.
  • Billing information: plan, invoices, billing contact and transaction records. Card and wallet details are collected and stored by our payment processors, not by us.
  • Configuration data: services, prices, staff schedules, locations, templates, website content and connected integrations.
  • Usage and log data: features used, log-in times, IP addresses and error reports.
  • Support records: emails, call notes, chat messages and training sessions.

End-customers of businesses using Abeco (processed on the business's behalf)

  • Contact details: name, email, mobile number.
  • Booking details: services booked, staff member, date, time, location, add-ons, notes, attendance, check-in records and booking history.
  • Payment-related records: deposits, gift cards, coupons and invoices. Card details are handled by Stripe or PayPal.
  • Communication records: notifications and reminders sent by SMS, email or WhatsApp, and marketing preferences.
  • Reviews and public social content that the business monitors or responds to through our reputation and social tools.

Businesses should collect sensitive information (such as health details) only where needed and with appropriate consent.

4. How we collect personal information

  • Directly from you, when you fill in a form, book a demo, sign up for a trial, contact support or use the platform.
  • Automatically, through server logs, browser storage and, with your consent, analytics cookies.
  • From our customers, when a business imports or enters its clients' data, including during data migration from other software.
  • From third parties, such as payment processors (payment status), connected calendars and video tools, and public review sites and social platforms that a business connects to Abeco.

You can browse our website anonymously, but we need identifying details to provide an account, run a demo or answer an enquiry.

We use personal information only for expected or lawful purposes. The table shows our GDPR / UK GDPR legal basis.

PurposeExamplesLegal basis (GDPR / UK GDPR)
Providing the platformCreating accounts, taking bookings, sending notifications, hosting websitesPerformance of a contract
Billing and paymentsCharging subscriptions, issuing invoices, processing refundsContract; legal obligation
Responding to enquiries and demosReplying to contact forms, scheduling and running demosLegitimate interests; steps before a contract
Support, onboarding and trainingSetup, data migration, staff training, troubleshootingContract; legitimate interests
Security and fraud preventionMonitoring log-ins, detecting abuse, protecting accountsLegitimate interests; legal obligation
Improving our servicesUnderstanding feature use, fixing bugs, developing featuresLegitimate interests
Website analyticsMeasuring traffic and page performanceConsent
Marketing to youProduct news, tips and offers by emailConsent, or legitimate interests for existing customers (you can opt out at any time)
Legal complianceTax records, responding to lawful requests, enforcing our termsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights. Ask us if you would like more detail.

6. Abeco AI features and how data is used

Abeco AI includes features such as an AI booking assistant that suggests good slots and fills gaps from a waitlist, no-show risk scoring that can trigger extra reminders, AI-drafted review replies, sentiment analysis of reviews, and AI content suggestions for social posts and emails. Here is how we approach AI:

  • We use AI to provide features to our customers. Booking, review and content data is processed by AI models only to deliver the feature the business has turned on, for example to score the no-show risk of an upcoming appointment or to draft a reply to a review.
  • We do not sell personal information, and we do not share it with third parties for their own advertising.
  • We do not allow AI providers to train their general-purpose models on our customers' data. Where we use third-party AI services, we engage them under terms that restrict use of the data to providing the service to us.
  • People stay in charge. AI outputs such as review-reply drafts and content suggestions are suggestions. The business reviews and approves them before anything is published or sent.
  • No solely automated decisions with legal effects. Features like no-show risk scoring affect things like reminder frequency. They are not used to make decisions about individuals that have legal or similarly significant effects.

We may use de-identified, aggregated data to improve our features.

7. Who we share personal information with

We share personal information only where needed to run our business and provide the platform. We use carefully chosen service providers (sub-processors) who are bound by contract to protect the data and to use it only on our instructions.

CategoryProvider(s)Purpose
Cloud hosting and infrastructureGoogle Cloud PlatformHosting the platform, customer websites, databases and backups
Payment processingStripe, PayPalSubscription billing, booking deposits, gift card and invoice payments
SMS and WhatsApp messagingSMS gateway and WhatsApp messaging providersSending booking notifications and reminders
Email deliveryTransactional and marketing email providersSending notifications, receipts, account emails and campaigns
Calendar and video integrationsGoogle Calendar, ZoomSyncing appointments and creating meeting links when a customer connects them
AnalyticsWebsite and product analytics tools, including Google AnalyticsUnderstanding use of our website and platform (website analytics only with consent)
AI servicesAI model providersPowering Abeco AI features, under restricted-use terms

We may also share information with professional advisers, with regulators or courts where required or authorised by law, with a buyer or successor of our business under confidentiality obligations, or with your consent.

If you connect a third-party service (for example Google Calendar, Zoom, Facebook or Google Business Profile) to your Abeco account, the information you share with that service is also governed by its own privacy policy.

8. Overseas disclosure and international transfers

Some of our service providers store or access data outside Australia. Depending on the provider and your configuration, this may include the United States, countries in the European Union, the United Kingdom, Singapore and other countries where our providers operate. Where we can, we choose Australian data centre regions for primary hosting on Google Cloud Platform.

Before disclosing personal information overseas, we take reasonable steps to make sure the recipient handles it in a way that is consistent with the APPs. We usually do this through contractual commitments. For transfers of personal data from the EEA or UK to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.

9. How long we keep personal information

We keep personal information only for as long as we need it for the purposes in this policy, or as long as the law requires. Typical periods are:

DataTypical retention
Contact and demo enquiries that do not become customersUp to 24 months after our last interaction
Account and platform data (including end-customer data)For the life of the account, then deleted or de-identified within 90 days of closure, unless the customer asks for earlier deletion
BackupsOverwritten on a rolling cycle, usually within 35 days
Billing and tax recordsAt least 7 years, as required by Australian tax law
Security and server logsUsually up to 12 months
Marketing preferences and opt-outsKept for as long as needed to respect your choice

After these periods, we securely delete or de-identify the information.

10. How we protect personal information

We use reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include:

  • encryption in transit (TLS/SSL, including free SSL on hosted websites) and encryption at rest on our cloud infrastructure;
  • role-based access controls, so staff users see only what their role allows, and restricted internal access on a need-to-know basis;
  • hashed passwords and monitoring of log-in activity;
  • regular backups and tested recovery processes;
  • vetting of service providers and contractual data protection obligations; and
  • staff confidentiality obligations.

No system is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. Where the GDPR or UK GDPR applies, we will also notify the relevant supervisory authority. Where the breach involves data we process for a customer, we will tell that customer without undue delay so they can meet their own obligations.

11. Cookies and similar technologies

Our website uses a small number of browser storage items that are strictly necessary. For example, we remember your cookie consent choice and personalise our thank-you page after you submit a form. Analytics and marketing cookies are only set if you accept them. You can change your choice at any time using the "Cookie settings" link in the website footer. For full details, see our Cookie Policy.

12. Your rights and choices

Under Australian law, you can ask to access the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. If you are in the EEA or UK, you also have the right to:

  • request erasure of your personal data;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • data portability (receive your data in a structured, machine-readable format);
  • withdraw consent at any time, without affecting processing that took place before you withdrew; and
  • lodge a complaint with your local data protection authority.

You can opt out of marketing emails at any time by clicking the "unsubscribe" link in any marketing email or by contacting us. We will still send you essential service messages, such as billing and security notices.

How to exercise your rights

  1. Email [email protected] with the subject line "Privacy request", or use our contact page.
  2. Tell us what you are asking for (for example, access, correction or deletion) and which email or account it relates to.
  3. We may ask you to verify your identity before we act on the request, to protect your information.
  4. We aim to respond within 30 days. If we need more time, or cannot meet the request (for example because the law requires us to keep certain records), we will explain why.

We do not usually charge for requests. If you are an end-customer of a business that uses Abeco, we will pass your request to that business, which is responsible for responding. We will help them do so.

13. Children

Our website and platform are designed for businesses and are not directed at children. We do not knowingly collect personal information from children under 16 for our own purposes. Businesses that use Abeco may take bookings for minors (for example, a child's haircut booked by a parent). In that case the business is responsible for getting any necessary parental consent. If you believe a child has given us personal information directly, please contact us and we will delete it.

14. Note for California residents (CCPA)

Where the CCPA applies, you have the right to know, delete and correct your personal information, to opt out of its "sale" or "sharing", and not to be discriminated against for exercising these rights.

We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined in the CCPA. Categories and purposes are described in sections 3 and 5. To make a request, see section 12.

15. Complaints

If you have a concern about how we have handled your personal information, please contact us first so we can try to resolve it:

  1. Email [email protected] with the subject line "Privacy complaint" and describe your concern.
  2. We will acknowledge your complaint within 5 business days and aim to give you a full response within 30 days.
  3. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

16. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new "last updated" date, and give account holders reasonable notice of significant changes by email or in the platform.

17. Contact us

For any privacy question, request or complaint:

  • Email: [email protected]
  • Phone: +61 1300 886 899 (Monday to Friday, 09:00–18:00 ACST)
  • Post: Abeco, Level 21/25 Grenfell St, Adelaide SA 5000, Australia

Have a question about how Abeco handles your data, or need a data processing agreement for your business?

Contact our team