Back to SpaLedg

Privacy Policy

Last updated: 5 July 2026

Who we are

SpaLedg is operated by SpaLedg (ABN: to be confirmed). SpaLedg is ledger, booking, and payout software built for spas, massage studios, and salons, currently offered as a beta product primarily to businesses in Australia. This policy explains what personal information we collect through the app, why we collect it, and the rights you have over it. It applies to shop owners, staff, and therapists whose accounts are created inside a shop, and — where a shop chooses to store them — the shop's own clients.

What we collect

Account information: your email address and authentication details. Shop information: shop name, address, phone number, ABN, currency, tax settings, and operating hours. Staff information: therapist names, contact details, wage arrangements, and employment dates entered by the shop owner. Transaction data: sales, tips, discounts, service records, expenses, cash drawer counts, cash movements, and staff payouts. Client information: any customer name, phone number, or appointment details a shop chooses to record. Billing information: subscription status, invoices, and payment method metadata from Stripe (SpaLedg does not store full card numbers). Security and diagnostic information: sign-in activity, rate-limiting records, and an audit trail of changes to financial records, kept to protect your account and investigate disputes.

How we use your information

We use your information to operate the ledger and reports, calculate therapist commissions and wages, synchronise data in real time across devices, authenticate and secure access to your shop's data, process subscription billing and send billing-related notices, respond to support requests, detect and prevent abuse (for example through rate limiting), and maintain an audit trail so financial records can be reviewed or reconstructed if something goes wrong. During the beta period we may also use aggregated, de-identified usage patterns to fix bugs and improve the product.

Our legal basis for handling your information

SpaLedg is built and operated primarily for businesses in Australia and is designed around the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth): we only collect personal information that is reasonably necessary to run the service, we don't sell personal information, and we give you ways to access, correct, or delete it (see below). If you or your clients are located in the European Union or United Kingdom, we rely on performance of a contract and our legitimate interest in running the service as our bases for processing under the GDPR/UK GDPR. SpaLedg does not currently have a dedicated EU or UK representative appointed under Article 27 GDPR; if you operate a business in the EU/UK and this is a compliance requirement for you, please contact us before relying on SpaLedg so we can discuss whether we can meet your requirements.

Who we share data with

We share data with the service providers that run SpaLedg on our behalf, and with no one else except as required by law. Supabase provides authentication, database, file storage, and realtime sync, and hosts our production database in the Asia-Pacific (Singapore, ap-southeast-1) region. Stripe processes subscription payments, invoices, payment methods, and customer billing portal sessions, and may process data outside Australia under its own privacy policy. Vercel hosts the application and its edge network. Sentry may receive technical error logs (stack traces and request metadata) to help us diagnose bugs — we configure it to avoid sending full financial records where possible. Each of these providers is contractually restricted to using your data only to provide their service to us; we do not permit them to use it for their own marketing purposes.

Where your data is stored

Your shop's operational data (sales, expenses, staff, clients, drawer records) is stored in Supabase's Asia-Pacific (Singapore) region as its primary location. Billing data passes through Stripe's global payment infrastructure, and application hosting/edge requests pass through Vercel's global network — both under their own published privacy and security terms. If your business is subject to specific data residency requirements (for example, a requirement that financial data never leave Australia), please contact us before relying on SpaLedg so we can confirm whether our current infrastructure meets that requirement.

How long we keep your information

We keep your account and shop data for as long as your account is active. Financial and audit records (sales, expenses, drawer closings) may be retained for longer where Australian tax law requires businesses to keep records for a minimum period (generally five years), or where our payment provider's own rules require retention of billing records. When you close your account, we delete or de-identify data that we are not otherwise required to keep within a reasonable period, as described in the next section.

Your privacy rights

You can ask us to access, correct, export, or delete the personal information we hold about your account or your shop, by contacting us using the details below. Under the Australian Privacy Principles you have the right to access and correct your personal information and to make a complaint about how we've handled it; if you're not satisfied with our response, you can escalate a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If GDPR/UK GDPR applies to you, you additionally have rights to erasure, restriction of processing, data portability, and to object to processing, subject to the exceptions in that law, and you may lodge a complaint with your local supervisory authority. Some financial or billing records may need to be retained even after a deletion request where required by law or by our payment provider's own rules — where that applies, we'll tell you what we're keeping and why.

Keeping your data secure

Data in transit to and from SpaLedg is encrypted (HTTPS/TLS). Shop data is protected by row-level security so that one shop's staff cannot see another shop's records, even though all shops share the same database. Every change to a sale, expense, or daily cash closing is written to an audit log capturing who made the change and what changed. We rate-limit sensitive actions to reduce the risk of automated abuse. No method of transmission or storage is 100% secure, and we can't guarantee absolute security, but we work to keep these protections current as the product matures out of beta.

Children's privacy

SpaLedg is a business tool and is not directed at, or knowingly used to collect personal information from, children under the age of 18. If you believe a child has provided us with personal information, please contact us and we will delete it.

Cookies and session data

SpaLedg uses strictly necessary cookies and local session storage to keep you signed in and to remember basic display preferences. We do not currently use third-party advertising cookies or cross-site tracking.

Changes to this policy

We may update this Privacy Policy as SpaLedg moves out of beta or as our data practices change. We'll update the "last updated" date above, and where a change is material we'll aim to also notify shop owners by email or an in-app notice.

Contact us

For privacy questions, or to make an access, correction, export, or deletion request, contact SpaLedg at support@spaledg.com.