Privacy Policy

Your privacy matters to us. Learn how Schediz collects, stores and protects your information while helping manage your business.

Last Updated • 18 September 2026

Introduction

Schediz provides software tools that help service businesses manage customers, appointments, quotes, invoices, expenses, images, and daily operations. This Privacy Policy explains how we collect, use, store and protect information when using Schediz.

1. Information We Collect

When you use Schediz, we may collect:

2. How We Use Information

We use collected information to:

3. Customer Data

Users may enter information about their own customers. Users are responsible for ensuring they have permission to collect and store customer information according to local laws.

4. Payments

Payments and subscriptions may be processed through third-party providers including Stripe. Schediz does not receive or store full card numbers or CVCs in its app or subscription backend. Stripe collects card details directly in its hosted Checkout. Schediz receives subscription/customer identifiers, status, billing periods and payment event metadata. Your own business bank details and invoice/payment records are separate from card data and are stored when you enter them. Payment providers manage their own security and privacy practices.

5. Data Storage and Security

Schediz uses Supabase for authentication, its database, private files and server functions. The primary database is hosted in Sydney, Australia. Our providers and their subprocessors may process information in other countries. Communications with Schediz services use HTTPS; this is transport encryption, not a claim of end-to-end encryption.

The app stores account-scoped records, pending changes, preferences, sessions and photo caches on your device for offline use, and synchronises pending changes when connected. Deletion from the current app clears that account's local records. We cannot remotely erase exported documents, copies held by recipients or devices that remain offline; remove Schediz app data from those devices. Reasonable security measures are used to help prevent unauthorized access, misuse, loss or disclosure.

No online system can guarantee complete security.

6. Sharing Information

Schediz does not sell personal information. Information may only be shared when necessary to:

7. User Rights

Users may request:

8. Children's Privacy

Schediz is not intended for children and does not knowingly collect information from minors.

9. Policy Updates

Schediz may update this Privacy Policy periodically. Continued use of Schediz means acceptance of future updates.

10. Account Deletion and Retention

Use Settings → Delete account in Schediz, or the public Schediz account deletion page. Workers can use the Delete account action in Schedule or the same web page. The web path works without installing the app. You must verify account ownership and confirm permanent deletion. Never send your password by email.

For a business owner, deletion removes the Auth login and sessions, profile/business data, customers, jobs, quotes, invoices, expenses, team memberships, QR Requests and tokens, notification devices/preferences/events and private files belonging to that business. Team members lose access to the deleted business; their independent login accounts remain theirs to delete. For a worker deleting their own account, login/profile/memberships and personal files are removed, assignments are cleared, and the employer's business records and business photos remain under that business's control.

Deletion immediately blocks account data access. The server terminates the Stripe customer/subscription before completing account deletion so billing is not left active. A temporary provider failure leaves a pending deletion that is automatically retried every five minutes. If completion is delayed, contact support. Deletion is permanent and is separate from cancelling renewal. Export any business records you need for your own legal/accounting obligations first.

Active business data is kept while the account exists or until you delete individual records. A minimal deletion record (account identifier, request/completion times and retry count) is retained for 30 days after completion, then removed by daily cleanup. Billing identifiers and worker mappings used during deletion are removed from that record when cleanup completes.

Historical subscription transactions and invoices remain with Stripe when a customer is deleted, for payment, accounting, tax, fraud prevention and other legal obligations. They are not used to reactivate Schediz access. Stripe's independent retention period depends on the applicable legal obligation and is described in its Privacy Policy; contact us to exercise rights relating to those records. Schediz does not retain a copy of your operational business records as a general accounting exception.

Provider backups, access/security logs and diagnostic records expire under the provider's configured retention and legal requirements; account deletion does not promise instant removal from backups or provider-controlled records. Local offline copies and documents already sent to other people are outside server deletion. Requests for access, correction, export or deletion assistance can be made to support@schediz.com after ownership verification.

Contact Us

Questions regarding this Privacy Policy?

support@schediz.com