Your customers’ data is yours. Here is exactly what we do with it.
Pressly is operated from Melbourne, Australia. We handle personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles. This policy covers two groups: you, the business that uses Pressly, and your customers, whose messages and bookings pass through it.
What we collect
- Your account: name, email, password hash, business name, address, timezone, and the services, prices and hours you configure.
- Your customers’ records: names, phone numbers, email addresses, addresses, and the messages, bookings, quotes, invoices and notes you or Pressly attach to them.
- Messages: the content of SMS, email and web-form conversations that go through your Pressly inbox, including replies Pip, our AI, drafts or sends on your behalf.
- Calls: when you turn the receptionist on, calls to your Pressly number are answered by Pip. We keep the caller’s number, the time and length of the call, a written transcript of what was said, and what Pip did about it. The audio itself is streamed to our speech provider to be understood and answered; we do not keep a recording of the audio.
- Your website and booking page: for pages published through Pressly we count page views and enquiries so you can see whether the page works. We do the same on our own pages. We do not use cookies for this and we do not build a profile of a visitor: the visitor is turned into a one-way fingerprint that cannot be turned back into a person, and the day is part of that fingerprint, so the same visitor is a different number tomorrow and cannot be followed from one day to the next. Counts are kept for 30 days and 12 months in daily totals.
- The record of changes: who in your business changed what — a price, the hours, someone’s access — with the values before and after, kept for 24 months so you can answer “who did this” yourself.
- Payments: handled by Stripe. We never see or store full card numbers.
- Connected accounts: when you connect a provider, we keep the account and destination identifiers, the permissions you grant, encrypted access credentials, and the status of requests made through that connection. Calendar connections import busy times and keep a record of the booking copies Pressly sends to Google. Slack connections keep the chosen workspace and channel and message delivery status. Advertising connections keep the accounts, campaign settings and provider results needed to manage your campaigns.
- Technical: IP address, browser, and error reports so the service stays up, and a record of sign-in attempts so accounts can be protected from guessing.
Why we use it
- To run your business inside Pressly: answer enquiries, book jobs, send confirmations and reminders, take payments, and keep one record per customer.
- To let Pip reply to your customers using only the facts you have configured. The part of a conversation needed to answer is sent to our AI provider to generate the reply, and a spoken call is streamed to the same kind of provider to be heard and answered. We choose paid provider tiers whose terms say customer content is not used to train their models; the provider may still hold it briefly for its own safety checks.
- To bill you, support you, and tell you about changes to the service.
We do not sell personal information, and we do not use your customers’ details to market anything to them.
Who we share it with
Only the providers needed to deliver the service, each under their own privacy terms:
- Stripe, for subscriptions and customer payments.
- Twilio, to send and receive SMS on your business number.
- Resend, to send and receive email.
- Google, to generate Pip’s replies and to hear and answer spoken calls.
- Sentry, for error monitoring.
- Google, only if you choose to sign in with Google.
- Google Calendar, when you connect a calendar to check busy times and add Pressly bookings.
- Slack, when you connect a workspace and enable handoff notifications or a messaging automation.
- Google Ads and Meta, when you connect an advertising account and manage campaigns through Pressly.
Some of these providers process data outside Australia. We choose providers that commit to equivalent protections.
Activity on websites hosted elsewhere
A business can install Pressly’s optional website activity script on a website it manages. The script sends page views, page paths without query strings or fragments, referring hostnames, and clicks classified as call, email, booking or contact. It does not read form contents or send the phone number, email address, link text or destination behind a click. The activity records use no visitor fingerprint or persistent visitor identifier, and the script uses no cookies or browser storage. Network requests still involve technical information such as IP addresses in the operation of our infrastructure.
Event receipts are retained for up to 30 days to avoid counting a retried event twice; daily counts by page and referring hostname are retained for up to 12 months, with expired records removed by scheduled cleanup. Page paths may themselves contain personal information. Businesses should install the script only on public pages and explain its use in their own privacy notice. The supplied installation can wait for an analytics consent signal and stop when consent is withdrawn; the business configures its own consent manager. The script also respects Do Not Track and Global Privacy Control. Counts are available to the business’s owners and admins and are included in business export and deletion. They are not sent to advertising networks by this feature.
Accounts you connect
Connecting an account is optional. The provider shows the permissions Pressly requests, and you approve access in your own account. You can disconnect it from Pressly or revoke access in the provider’s settings. Disconnecting does not undo actions already completed there: calendar entries, delivered Slack messages and advertising campaigns may remain in the provider’s account. Review those there, including any campaigns that may still be spending.
Your customers’ rights, and yours
- Customers can opt out of SMS at any time by replying STOP. Pressly honours it immediately and will not text that number again for your business.
- You can download everything Pressly holds for your business at any time, from Settings, as one portable file.
- You can delete your business from inside Pressly. Customer records, messages and bookings are deleted with it, after a short grace period in case it was a mistake. Invoices and payment records are kept as long as tax law requires.
- Anyone can ask what we hold about them, ask for it to be corrected, or complain, by writing to support@usepressly.com. We respond within 30 days. If you are not satisfied, you can contact the Office of the Australian Information Commissioner.
How we protect it
Data travels encrypted and is held on servers we operate. Inside your business, access is limited by role: an owner or admin sees everything, a staff member sees the work assigned to them. Our own staff reach a business’s records only to support you, and when we read your history of changes the reading itself is recorded against the person who read it.
Cookies and browser storage
Pressly sets cookies to keep you signed in and to protect the sign-in itself, and remembers small display choices such as light or dark. We do not use advertising or cross-site tracking cookies, and the counting on published pages uses no cookie at all. The cookies page lists each one, what it is for and how long it lasts.
Websites and booking pages we host for a business
When a customer of yours visits a page Pressly publishes for you or makes a booking on it, that information belongs to your business: you decide what to do with it, and we hold it on your behalf. Your own obligations to your customers are yours, and a Pressly policy is not a substitute for your business’s own.
Changes
If this policy changes in a way that matters, we will email account owners before it takes effect.