Privacy Notice
Version 1.0 · Effective 26 September 2026
Summary
- WagDay is booking and management software for pet care facilities. Each facility decides what it records about its customers, their pets and its staff; WagDay holds that information to run the service for the facility.
- We handle contact, account, booking, payment and pet care details. Pet vaccination and medical records are linked to the pet’s owner.
- We use service providers to host, store, message, take payments and monitor the service. Some are overseas; Appendix A lists them and what is still to be confirmed.
- Analytics from PostHog start only if you accept them in the cookie banner.
- You can ask for access, correction or deletion. Some financial records are kept even after deletion. You can complain to us, and then to the OAIC.
Who is responsible
Operators. WagDay handles the account, subscription, billing and support details of the business that signs up (the operator) for its own purposes.
Staff. A facility adds its staff and records their contact details, schedules, time entries, qualifications and leave. WagDay holds these records for the facility.
Customers and pet owners. A facility collects its customers’ details, pet profiles and booking history, directly or through its booking widget, customer portal or mobile app. The facility decides how it uses those records to care for your pet. WagDay holds and processes them on the facility’s behalf. For questions about a facility’s own decisions, contact the facility; we will help where the records are in WagDay.
What we handle and where it comes from
- Names, email addresses, phone numbers, postal addresses and emergency contacts, from operators, staff and customers, or entered by a facility.
- Pet profiles, care notes, booking history, photos and videos, report cards and incident reports, entered by customers and facility staff.
- Messages sent by email, SMS and push notification, and SMS replies.
- Payment and invoice details. Card details are collected by our payment providers.
- Sign-in and session details, IP addresses, and device and browser information collected when you use the service.
- Details from services a facility connects, such as accounting or marketing tools.
Pet vaccination and medical records
Facilities record pets’ vaccinations, vaccination certificates and medical history. These are records about animals, not human health information, and we do not treat them as sensitive information under the Privacy Act. They are linked to the pet’s owner, and documents and notes can include the owner’s name, contact details or vet details, so we handle them as personal information of the owner.
How we use it
- Run accounts, bookings, care workflows and payments.
- Send booking confirmations, reminders and facility messages.
- Provide support and answer questions.
- Keep the service secure, prevent abuse and fix errors.
- Understand how the service is used, with analytics limited as described below.
- Offer optional AI features: help-centre answers, reading vaccination certificates, and drafting messages.
Access and correction
You can ask for access to, or correction of, your personal information. In the customer portal, customers can update their pets’ details and notification preferences and download a copy of their data. For anything else, ask your facility or contact us at the address below. We may need to confirm your identity and involve the facility. If we cannot give access or make a correction, we will tell you why.
Deletion
A facility can erase a customer’s records, and you can ask us or the facility to do so. Erasure removes contact details, notes, messages and media files, but some records stay. Invoices are kept for accounting and audit purposes, with notes and line items cleared. Invoice-view events are kept, with IP addresses and browser details cleared, until they are deleted after 24 months. Appendix B sets out how long we keep each kind of record.
Complaints
If you have a privacy complaint, email us with the details. We will look into it and reply. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC).
Contact
Privacy contact: hello@wagday.com.au
Appendix A: service providers
A configured region or endpoint does not by itself guarantee where data is stored. “To be confirmed” means we do not yet have verified evidence for that detail. We review this list whenever we add a provider or change how we use one.
| Provider | Purpose | Data categories | Region/country | Contractual residency status | Safeguard |
|---|---|---|---|---|---|
| Neon | Facility databases and the shared control-plane database | Account, business, staff, customer, pet, booking, message and payment records | Australia (configured Sydney region, aws-ap-southeast-2) | To be confirmed | A separate database for each facility; provider transfer terms to be confirmed |
| Vercel | Application hosting, plus Web Analytics and Speed Insights on every page | Requests to the service, application data in transit, page views and performance measurements | Australia (configured syd1 functions region) | To be confirmed | Web Analytics and Speed Insights are not controlled by the cookie banner; provider transfer terms to be confirmed |
| Cloudflare R2 | File storage | Pet and booking photos and videos, vaccination certificates, medical documents, signatures and data-export files | To be confirmed | To be confirmed | Certificates and exports are served through short-lived signed links; provider transfer terms to be confirmed |
| Cloudflare Turnstile | Bot protection on the embedded booking widget | Challenge token, IP address and browser signals | To be confirmed | To be confirmed | Used only to check the booking request is from a person; provider transfer terms to be confirmed |
| Clerk | Operator and staff sign-in and organisation membership | Name, email address, sign-in and session details, organisation membership | To be confirmed | To be confirmed | To be confirmed |
| Stripe | WagDay subscriptions and facility payment processing | Customer and business contact details, card and payment details, transaction records | To be confirmed | To be confirmed | To be confirmed |
| Square | Optional payment provider, off unless switched on | Customer, merchant and transaction details when enabled | To be confirmed | To be confirmed | To be confirmed |
| Xero | Optional accounting connection chosen by a facility | Customer contact details, invoices, payments and refunds | To be confirmed | To be confirmed | Connection tokens are stored encrypted; provider transfer terms to be confirmed |
| Mailchimp | Optional marketing audience sync chosen by a facility | Name and email address of active customers recorded as opted in to marketing | To be confirmed | To be confirmed | Only customers recorded as opted in to marketing are synced, excluding contacts who are restricted, suppressed or unsubscribed in Mailchimp; the API key is stored encrypted; provider transfer terms to be confirmed |
| Twilio | SMS messages and replies | Phone numbers and message content | To be confirmed | To be confirmed | To be confirmed |
| Resend | Email delivery | Email addresses, names and message content | To be confirmed | To be confirmed | To be confirmed |
| Expo push service | Notifications to the customer mobile app | Device push tokens, notification text and in-app link identifiers | To be confirmed | To be confirmed | Not sent to suppressed contacts; provider transfer terms to be confirmed |
| PostHog | Product analytics, only after analytics consent | Full page addresses (including query strings), usage events, a browser identifier, and device and browser details | United States (the browser may only send to PostHog's US host; storage location unconfirmed) | To be confirmed | Loads only after the visitor accepts analytics cookies; provider transfer terms to be confirmed |
| Sentry | Error and performance monitoring for the web and mobile apps, and session replay in the signed-in dashboard | Error reports with request and device context, and screen recordings of a sample of dashboard sessions | To be confirmed | To be confirmed | Typed input is masked in recordings; AI prompts and responses are not recorded; provider transfer terms to be confirmed |
| Upstash Redis | Rate limiting to protect the service from abuse | IP addresses and account identifiers such as email addresses, with request counters | To be confirmed | To be confirmed | To be confirmed |
| Upstash QStash | Background job delivery | Job contents, which can include names, email addresses and booking details | United States (account and endpoint documented as us-east-1; storage country unconfirmed) | To be confirmed | The app asks QStash to redact job contents from its logs; provider transfer terms to be confirmed |
| Google Maps Platform | Address search, geocoding, maps, routes, and weather for the dashboard and staff heat advisories | Customer and facility addresses, map and route requests, and facility coordinates for weather lookups | To be confirmed | To be confirmed | To be confirmed |
| Vercel AI Gateway | Routing AI requests to the model provider | Help-centre chat questions, vaccination certificates uploaded by staff or by pet owners in the customer app, message-drafting instructions, report card notes and mood with the pet's name where a facility has turned on report card note drafts, and incident report text with the pet's name, including while staff are still writing it, where a facility has turned on incident triage | To be confirmed | To be confirmed | Server-side calls only. Certificate reads go only to providers that don't train on the image, and reads of certificates pet owners upload in the customer app also require zero data retention (refused, not rerouted, when it isn't available). Other requests: provider retention and provider transfer terms to be confirmed |
| Google Gemini (via AI Gateway) | AI help answers, certificate reading, message drafting and report card note drafting | Help-centre chat questions, vaccination certificates uploaded by staff or by pet owners in the customer app, message-drafting instructions, and report card notes and mood with the pet's name where a facility has turned on report card note drafts | To be confirmed | To be confirmed | Certificate reads: no training on the image. Certificates pet owners upload in the customer app are read only under zero data retention, through Google Vertex AI. Staff certificate reads, help answers, message drafting and report card note drafting: no zero-retention guarantee; provider retention and provider transfer terms to be confirmed |
Appendix B: retention
These periods describe how WagDay itself behaves. Providers’ own copies, logs and backups follow their own schedules.
| Record | How long | What happens |
|---|---|---|
| Customer, pet and booking records | Kept while the facility uses WagDay; there is no automatic deletion period | When a facility erases a customer, WagDay removes their contact details, addresses, notes, message content and media files, and renames their pets. Pet vaccination and medical records stay with the vet name, notes, description and documents removed. Booking and payment records stay so the facility's financial history remains complete. |
| Invoices and invoice-view events | Invoices are kept for accounting and audit purposes; invoice-view events are deleted after 24 months | On erasure, invoice rows and their amounts, tax and status stay, with invoice notes and line items cleared. Invoice-view events stay with their IP address and browser details cleared, until a weekly clean-up deletes them at 24 months. |
| Portal sign-in codes, links and sessions | Sign-in codes last 10 minutes and portal sessions up to 60 days; a daily clean-up deletes expired or revoked ones | Erasing a customer also deletes their sign-in codes, sessions and registered mobile devices straight away. |
| Data export files | Download links expire after 48 hours; the file is deleted after 7 days | Exports are kept in a separate storage bucket with a 7-day deletion rule. A link expiring does not by itself delete the file. |
| Operator and staff sign-in accounts | Kept while the person belongs to an organisation on WagDay | One sign-in can be shared across facilities. When a person's records are erased from one facility, their sign-in account is deleted only if they no longer belong to any other organisation. |
| Service provider copies, logs and backups | Set by each provider; periods and backup deletion windows are to be confirmed | Deleting a record in WagDay does not automatically delete copies held by the providers listed above. Ask us about a particular provider. |