Privacy Policy

Effective date: 10 September 2026
Last updated: 10 September 2026

This Privacy Policy explains how WebClimb Consulting, trading as ClimbCal (ClimbCal, we, us or our), collects, holds, uses, discloses, and protects personal information when you use our websites, scheduling service, workspace tools, and public booking pages (the Service).

1. Who this policy applies to

This policy applies to:

  • people who create or use a ClimbCal workspace (Workspace Users);
  • businesses and professionals who offer appointments through ClimbCal (Hosts);
  • people who make or manage a booking through a public booking page (Guests); and
  • people who contact us, visit our website, or otherwise interact with ClimbCal.

A Host decides which services it offers and what information it asks Guests to provide. Hosts may have their own privacy obligations and policies.

If you are a Guest, you should contact the Host regarding the Host’s independent use of your information. This policy describes ClimbCal’s handling of information.

We manage personal information in accordance with applicable privacy laws, including the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.

2. Personal information we collect

Account and workspace information

We may collect:

  • your name and email address;
  • authentication and account identifiers;
  • workspace or organisation details;
  • your role, permissions, and team memberships;
  • team invitations; and
  • account, notification, and workspace preferences.

Scheduling information

We may collect:

  • working hours and availability;
  • time zone and display preferences;
  • event types, durations, locations, and descriptions;
  • booking windows, buffers, limits, and cancellation terms;
  • intake questions and notification settings; and
  • calendar connection and synchronisation settings.

Guest and booking information

When a Guest makes or manages a booking, we may collect:

  • name and email address;
  • phone number, where requested by the Host;
  • selected appointment date and time;
  • answers to booking questions;
  • booking status and history;
  • cancellation or rescheduling information; and
  • communications associated with the booking.

A Host should only request information that is reasonably necessary for the appointment. Hosts should avoid requesting sensitive information unless it is necessary and they have an appropriate legal basis to collect it.

Billing and transaction information

We may collect:

  • subscription plan and seat quantity;
  • billing status and renewal information;
  • transaction amounts and currency;
  • payment, refund, and dispute status; and
  • references supplied by our payment provider.

Stripe processes payment card and bank-account information. ClimbCal does not store complete payment card details.

Connected calendar information

If you connect Google Calendar or Microsoft Outlook, we may receive:

  • your connected account identifier;
  • calendar names and identifiers;
  • calendar event times and availability information;
  • selected conflict and destination calendars;
  • synchronisation status and diagnostic information; and
  • access and refresh credentials needed to maintain the connection.

Calendar credentials are stored in encrypted form.

Communications

We may collect information contained in:

  • support requests;
  • feedback;
  • complaints;
  • emails and other messages; and
  • communications relating to account or booking administration.

Technical information

When you use the Service, we may automatically collect:

  • IP address;
  • browser and device type;
  • operating system;
  • request dates and times;
  • pages and features used;
  • referring page;
  • session or cookie identifiers; and
  • security, error, performance, and diagnostic events.

3. How we collect information

We may collect personal information:

  • directly from you;
  • from a Host or another authorised Workspace User;
  • when a Guest submits a booking;
  • from connected services such as Clerk, Stripe, Google, Microsoft, or Postmark;
  • through cookies, sessions, logs, and similar technologies; and
  • where otherwise authorised or required by law.

Where practicable, you may contact us anonymously or using a pseudonym. However, we generally need identifying information to provide accounts, bookings, payments, support, or connected services.

4. How we use personal information

We may use personal information to:

  • create accounts and authenticate users;
  • administer workspaces, roles, and team access;
  • publish and operate booking pages;
  • show availability and prevent conflicting bookings;
  • create, confirm, change, or cancel appointments;
  • connect calendars and create or update calendar events;
  • process subscriptions, booking payments, and refunds;
  • send transactional emails and service communications;
  • provide customer support;
  • investigate errors and service problems;
  • detect fraud, abuse, and security threats;
  • enforce our terms and protect our legal rights;
  • monitor and improve the reliability and performance of the Service;
  • comply with legal and regulatory obligations; and
  • establish, exercise, or defend legal claims.

We may use aggregated or de-identified information where it no longer reasonably identifies an individual.

We do not sell personal information.

5. When we disclose personal information

We may disclose personal information in the following circumstances.

Hosts, Guests, and workspace members

Booking information is shared with the relevant Host and authorised workspace members so they can provide and manage the appointment.

Guests receive relevant Host, event, and booking information.

Service providers

We use service providers that support functions including:

  • authentication and account management, including Clerk;
  • payments and subscriptions, including Stripe;
  • calendar integrations, including Google and Microsoft;
  • transactional email, including Postmark;
  • hosting, databases, storage, security, and monitoring; and
  • professional, legal, accounting, and technical services.

These providers may process personal information to supply services to us or as otherwise permitted by their terms and applicable law.

Legal and safety reasons

We may disclose information where required or authorised by law, or where reasonably necessary to protect:

  • an individual’s safety;
  • our rights or property;
  • the security and integrity of the Service; or
  • the rights and safety of our users or the public.

Business transactions

Information may be disclosed as part of an actual or proposed merger, financing, acquisition, restructure, or sale of assets, subject to appropriate confidentiality protections.

With your direction or consent

We may disclose information when you connect a service, ask us to do so, or otherwise authorise the disclosure.

6. Google user data

ClimbCal uses Google Calendar information only to provide calendar-related features requested by the user, including calendar discovery, availability checking, conflict prevention, synchronisation, and creating or updating booking events.

ClimbCal does not use Google user data for advertising or sell it to third parties.

Our use and transfer of information received through Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

You can disconnect Google Calendar through ClimbCal and may also revoke ClimbCal’s access through your Google account settings.

7. Overseas processing and disclosure

ClimbCal and its service providers may process or store personal information outside Australia.

Overseas recipients are likely to be located in:

  • Australia;
  • the United States; and
  • the EU.

Privacy protections in other countries may differ from Australian law. Where required, we take reasonable steps to select appropriate providers and protect information disclosed overseas.

8. Cookies and similar technologies

ClimbCal uses essential cookies and similar storage technologies for:

  • sign-in and authenticated sessions;
  • account and security functions;
  • support access;
  • user preferences; and
  • maintaining the operation of the Service.

Disabling essential cookies may prevent parts of the Service from working.

If we introduce non-essential analytics or advertising technologies, we will provide any notice and choices required by applicable law.

9. How long we retain information

We retain personal information only for as long as reasonably necessary to:

  • provide the Service;
  • maintain business, billing, and transaction records;
  • meet legal and accounting obligations;
  • resolve disputes;
  • prevent fraud and security incidents; and
  • enforce our agreements.

When a paid workspace subscription cancellation becomes effective or a workspace is closed, ClimbCal currently retains workspace data for 30 days so an eligible workspace can be restored.

After that period, workspace content and related operational data are deleted or irreversibly anonymised through our scheduled deletion process.

Residual copies may remain in backups for a limited period before being overwritten.

We may retain limited billing, transaction, consent, fraud-prevention, security, or legal records for longer where required or permitted by law.

Information retained independently by a Host is subject to the Host’s own retention practices.

10. How we protect information

We use administrative, technical, and organisational safeguards designed to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.

These safeguards include:

  • access controls and authenticated sessions;
  • encrypted calendar credentials;
  • restricted support access;
  • verification of provider communications;
  • monitoring and operational alerts; and
  • using Stripe to handle payment card information.

No internet-based service is completely secure. You should keep your account credentials confidential, use strong authentication where available, and contact us promptly if you believe your account or information has been compromised.

11. Access, correction, and your choices

Subject to applicable law, you may:

  • review and update information through your ClimbCal account;
  • disconnect a connected calendar or service;
  • use links in booking emails to manage an eligible booking;
  • request access to personal information we hold about you;
  • ask us to correct inaccurate, incomplete, or outdated information;
  • request deletion where applicable, subject to legal and operational retention requirements; and
  • opt out of optional marketing messages using the unsubscribe method provided.

We may continue sending essential transactional and service messages.

To request access or correction, contact us using the details below. We may need to verify your identity and authority before responding.

If you are a Guest seeking information controlled by a Host, we may refer your request to that Host.

12. Privacy complaints

If you believe we have mishandled your personal information, please send a written complaint using the contact details below.

Please include enough information for us to understand and investigate the issue. We will acknowledge your complaint and aim to respond within 30 days.

If you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.

13. Children’s privacy

ClimbCal workspaces are intended for people who can enter into a binding agreement.

A person under 18 should make a booking only with the involvement of a parent or guardian where required and where the Host permits it.

We do not knowingly invite children to create workspace accounts. Contact us if you believe a child has provided personal information inappropriately.

14. Changes to this policy

We may update this policy when our Service, practices, or legal obligations change.

We will publish the revised policy on our website and update the “Last updated” date. Where a change is material, we will provide additional notice where appropriate.

15. Contact us

Privacy Officer
WebClimb Consulting, trading as ClimbCal
ABN: 15208264284
Email: support@webclimb.com.au