Noti Privacy Policy
Version 1.1 · Effective 28 September 2026
1. Who we are and what this covers
Noti is operated by F.A Lemon & P Lemon, a partnership trading as Noti, ABN 42 966 457 260, Sydney NSW, Australia. For privacy questions and requests, contact hello@noti.com.au.
This policy covers Noti: the app at app.noti.au, customer pages at customer.noti.au, businesses' booking pages, the emails and texts Noti sends, and noti.au. It does not cover Noti Custom, our consultancy at noti.com.au, or Neeve, a separate health app. Each has its own policy.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988.
2. Two groups of people
People who use Noti to run a business — owners and the people they invite. You have an account with us, and we are responsible for your information.
Their customers — the people those businesses serve. You probably have no account with us. A business decides what it records about you and why; Noti stores and processes it on the business's behalf. If you want to see, correct or remove what a business holds about you, ask that business first. We will help it respond, and you can always contact us.
3. What we collect about people who use Noti
- Account: name, email address, and a password — stored only as a one-way hash by our sign-in provider, so we cannot read it. If you add a passkey we hold only its public part; the private key stays on your device. Optionally a mobile number and a photo.
- Business: business name, ABN, address, trading details, and who works there and in what role.
- Billing: your plan, what you have paid and owe, and a label for the card you pay with (for example "Visa ending 4242"). We never see or store card numbers. If you take card payments, Stripe tells us your payout bank's name and the last four digits of the account.
- Activity and security: what you do in Noti — including which customer, job or document you opened, and when (see section 10) — sign-ins, devices you pair, and technical information our providers record, such as IP address and browser.
4. What businesses keep in Noti about their customers
Whatever the business records, which can include: name, phone, email, addresses and places; bookings, jobs and what was done; quotes, invoices, receipts and payments (never card numbers); messages sent to the customer and their replies; answers to the business's booking questions; notes; photos taken by the business, or added by the customer to their own booking; and whether the customer agreed to texts or emails.
How it reaches Noti: the business enters or imports it; the customer enters it on the business's booking page, waitlist or a link the business sent; or it arrives as a reply to a message.
When somebody uses a booking page, we also record their IP address and the contact details they typed, only to stop the page being abused, and delete that record after 30 days.
5. Why we use it
- To provide Noti: store information, show it to the people a business authorises, send the messages the business asks us to send, take the payments it asks us to take, and bill businesses for Noti.
- To keep Noti secure and working: prevent abuse, investigate problems, and keep the records described in section 10.
- To meet our legal obligations.
We do not sell personal information. We do not use it for advertising. We do not use anything businesses keep in Noti to train artificial-intelligence models, and Noti has no AI features.
Combined figures. Noti's software can calculate typical timings for a type of business — such as how many days customers take to pay — as the middle value across at least five businesses, each with at least five examples. These figures never include prices, names, customers or jobs. They are not shown anywhere in Noti today. Because a middle value can match one business's own figure, we treat these figures as business information and never publish them outside Noti.
6. Messages, and how to stop them
- Businesses send booking confirmations, reminders, quotes, invoices and receipts through Noti. Texts come from Noti's shared number; emails arrive as "Business name (via Noti)".
- Marketing messages are only sent to people who agreed to receive them.
- Reply STOP (or UNSUBSCRIBE, CANCEL, END or QUIT) to a Noti text and no business on Noti will text you from that number again. Reply START to undo it. Because the number is shared, a STOP applies to every business that texts you through Noti.
7. Who else handles it
We use these providers to run Noti:
| Provider | What it does for Noti | What it receives | Where |
|---|
| Supabase | Database, sign-in, file storage, server functions | Everything stored in Noti | Sydney, Australia |
| Stripe | Card payments for businesses; billing businesses for Noti | Payment details, card details (entered directly with Stripe), a business's identity and bank details for verification | Australia and overseas, including the USA |
| Twilio | Sending and receiving texts | Phone numbers and message text | USA |
| Resend | Sending email | Email addresses and message content | USA |
| Cloudflare | Hosting the app and pages, blocking attacks | Traffic and IP addresses | Global network |
| OpenStreetMap (Nominatim) | Turning an Australian address into a map location | The address | Europe |
| Esri (ArcGIS) | Map images | Your IP address and the map area viewed — not addresses | USA |
| Google Fonts | The typeface in Noti's app | Your IP address and browser details | USA |
| esm.sh and unpkg | Delivering open-source code to your browser | Your IP address | Global |
We also disclose information where the law requires it. We do not disclose personal information to anybody for their own marketing.
Noti's database and files are stored in Sydney, Australia. Some providers in section 7 process information overseas — mainly in the USA and Europe — to deliver texts and emails, process payments and show maps. We use established providers whose terms require them to protect the information they handle, and we send them only what they need to do their job.
9. Cookies and browser storage
Noti uses no advertising or analytics cookies, and no analytics or tracking service. The app keeps a few things in your browser's local storage so that it works: your signed-in session, which business you last opened, a shared-device token if the device is paired, an invite you are part-way through accepting, and screen preferences. Booking pages and customer links keep none of these.
10. Keeping it safe
- Each business's information is kept apart in the database itself, not only by the app.
- Information is encrypted in transit (HTTPS) and stored with our database provider's encryption at rest.
- Roles decide who in a business can see and do what, and only an owner can make or remove an owner.
- Shared devices unlock with a personal PIN that locks after five wrong tries.
- Every time somebody opens an individual customer, job or document, Noti records who, what and when, in a log that nobody can edit or delete. The business's owners and managers can read it.
- Customer photos are private to the business, uploaded one at a time through a short-lived permission.
No system is perfectly secure. If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and tell affected businesses without undue delay.
11. How long we keep it
- While a business uses Noti, we keep its information.
- If a business's plan lapses, nothing is deleted, and the business can still export everything.
- If an owner closes a business, there is a 30-day recovery period in which it can be reopened. After it ends the business cannot be reopened or used, and nobody can sign in to it. We keep its operational and customer information only for as long as we need it for the purposes in this policy or the law requires, and then delete or irreversibly anonymise it. We keep only records we are required by law to keep — such as our own tax records of what the business paid Noti — for as long as the law requires. An owner can ask us at any time what we still hold about their closed business and when it will be deleted.
- Booking-page abuse records (IP address and contact details) are deleted after 30 days.
- The access log (section 10) is kept for as long as the business's records are.
- Backups held by our hosting provider age out on their normal schedule. We do not edit backups, and restore them only to recover the service.
- Businesses: Settings → Your data exports everything, on every plan, at any time, and you can correct most information in the app yourself.
- Anybody can ask us for the personal information we hold about them, or ask us to correct it, at hello@noti.com.au. We respond within 30 days and do not charge for a request.
- A business's customer: the business holds your information, so please ask it first. It can export, correct, archive or merge your record in the app, and we will help it respond.
13. Children
Noti is for businesses and is not directed at children. A business's customers may include children — for example, when a parent makes a booking — and the business is responsible for handling that information appropriately.
14. Complaints
Contact hello@noti.com.au. We will acknowledge your complaint within 5 business days and respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992.
15. Changes to this policy
We will tell businesses before this policy changes in a way that matters, by email and in the app. Every version is kept and dated.
Noti is the trading name of F.A Lemon & P Lemon, ABN 42 966 457 260, Sydney NSW, Australia. hello@noti.com.au. Version 1.1, effective 28 September 2026.