Privacy Policy
Version 2026-09-25
This Privacy Policy explains how notjust. Workshop ("Workshop"), a privately operated software project provided under the notjust. name ("notjust.", "we", "us"), handles personal data belonging to people who use Workshop and customers of businesses using Workshop.
Privacy questions can be sent to:
1. Who is responsible
Each workshop decides what information it records about its customers and why.
For that information, the workshop is the controller and notjust. processes the information on the workshop's behalf as its processor under our Data Processing Terms.
For information relating to people who create and use Workshop accounts, notjust. is responsible for the processing described in this Privacy Policy.
2. What we hold
Team accounts
We hold:
- email address;
- name;
- role; and
- sign-in records.
Customers of a workshop
Depending on how a workshop uses Workshop, we may hold:
- name;
- phone number;
- email address;
- booking information;
- information about the vehicles, equipment or other items brought in;
- job information;
- notes; and
- answers to booking questions created by the workshop.
This information may be entered by workshop staff or directly by a customer using the workshop's booking page.
Shopify
When a workshop connects its Shopify store, Workshop receives information needed for the connected functionality.
This may include:
- orders and draft orders;
- order numbers;
- tags;
- totals;
- payment status;
- items; and
- item costs.
When a workshop enables features that require customer information, Workshop may also receive the customer's:
- name;
- email address; and
- phone number.
This information is used to identify the customer on a job and contact them where required for the workshop service.
Customer messages
When a workshop connects Podium or WhatsApp, the messages sent to and received from a customer about their job are kept with the job, with the customer's phone number.
Access records
We keep records of access to and processing of customer details, including who accessed or processed the information.
3. What we use personal data for
We use personal data only as needed to operate Workshop and provide the functionality selected by the workshop.
This includes:
- managing bookings;
- managing workshop jobs;
- identifying customers and what they bring in;
- providing workshop reporting;
- connecting supported integrations;
- sending booking confirmations;
- sending booking reminders;
- sending booking cancellations; and
- sending team invitations.
Personal data belonging to workshop customers is not sold.
It is not used for advertising.
It is not used to make automated decisions about individuals.
4. Who can see personal data
A workshop's team can access its information according to the roles assigned within Workshop.
The database enforces separation between workshops so that one workshop cannot read another workshop's data.
Revenue and cost reports are limited to managers and owners.
Authorised notjust. personnel may access customer data only where needed to keep Workshop operating or where a workshop asks us for support.
Access is limited to people who need it for those purposes.
5. Where data is kept and who helps us
Workshop data is stored in Sydney, Australia.
We also use service providers to operate particular parts of Workshop.
Some of these providers process information outside Australia.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and sign-in: accounts, bookings, customer details and synced orders | Sydney, Australia |
| Vercel | Runs the app; privacy-friendly page-view and performance measurement without cookies | United States |
| Resend | Sends booking confirmations, reminders, cancellations and team invitations | United States |
| Stripe | Subscription billing for businesses using Workshop; not customer payments | United States |
| Shopify | Source of orders, draft orders and customer information when a workshop connects its store | Canada / global |
| Google Fonts | Serves the font selected for a workshop's booking page; the visitor's browser fetches it | United States |
| Podium | Texts, payment links and review invites to a job's customer (name, phone, message), when the workshop connects its Podium | United States |
| Meta (WhatsApp) | WhatsApp messages to and from a job's customer (phone, message), when the workshop connects its WhatsApp Business number | United States / Ireland |
| Lightspeed | Sales and customer details on the workshop's own till, when it connects its Lightspeed Retail store | Canada / global |
Where applicable privacy law imposes requirements concerning overseas disclosures of personal information, we take the steps required of us in relation to those disclosures.
6. How personal data is protected
Workshop uses technical and organisational measures designed to protect personal data.
These include:
- encryption in transit using HTTPS;
- encryption at rest, including backups;
- access controls per workshop;
- access controls according to user role;
- logging of access to customer details; and
- a written incident-response process.
Workshop owners can see their own applicable access log in Settings.
No internet-connected system can guarantee absolute security.
7. Data breaches
We maintain a written process for responding to security incidents.
If we become aware of a personal data breach affecting information that Workshop processes for a workshop, we will notify the affected workshop without undue delay and in accordance with our Data Processing Terms.
We will provide information reasonably available to us about what happened and what we are doing in response.
8. How long we keep information
Bookings and customer details
Bookings and customer details are kept for as long as the workshop keeps its Workshop account, unless the workshop deletes them earlier.
Shopify data
Shopify data is kept while the Shopify store is connected.
When Shopify tells us that Workshop has been removed from the store, synced data is deleted 48 hours later.
When Shopify passes a customer's valid erasure request to Workshop, that customer's details are removed from the workshop's jobs.
Access records
Access records are kept for 12 months.
Closed Workshop accounts
When a workshop closes its account and requests deletion, its Customer Data is deleted from active systems within 30 days.
Backups roll over within a further 7 days.
Information may be retained where and for so long as applicable law requires us to retain it.
9. Cookies
Workshop uses only cookies or similar browser storage needed for the app to work.
These are used for:
- staying signed in;
- remembering which business and site the user is viewing; and
- remembering display preferences, such as light or dark mode and how the job board is laid out.
Workshop's page-view measurement does not use cookies.
The public booking page does not set cookies.
If a workshop chooses a Google Font for its public booking page, the visitor's browser requests that font from Google.
10. Access and correction
If you booked with a workshop and want to see or correct the personal information connected with your booking, you should normally contact that workshop.
The workshop can manage customer information through Workshop and we will assist the workshop where needed.
You may also contact:
If you use Workshop as a team member and want to request access to or correction of personal information that notjust. holds about your Workshop account, you may contact us at the same address.
We may need to verify your identity before acting on a request.
11. Deletion requests
If you are a customer of a workshop and want your personal information deleted, you should normally contact the workshop you booked with.
The workshop can manage customer information in Workshop and we will assist where needed.
You may also contact:
Deletion requests are subject to any information that applicable law permits or requires to be retained.
Shopify customer-erasure requests are handled as described in section 8.
12. Privacy complaints
If you believe personal information has been handled incorrectly, you can make a privacy complaint by contacting:
Please explain the issue and provide enough information for us to investigate it.
We will review the complaint, investigate the circumstances where appropriate and respond within a reasonable time.
We may contact you if we need additional information.
Where the Australian Privacy Act applies, you may also have the right to complain to the Office of the Australian Information Commissioner if you are not satisfied with how your complaint has been handled.
13. Changes to this Privacy Policy
We may update this Privacy Policy if Workshop, our providers or applicable legal requirements change.
The version date at the top of this page identifies the current version.
If we make a material change to how Workshop handles personal data, we will update this Privacy Policy accordingly.
14. Contact
For privacy questions, access, correction or deletion requests:
For security issues: