$0 for your first month. No lock-in contracts.

Privacy Policy

1. Purpose and Scope

This Privacy Policy explains how Service Cue Pty Ltd (“we”, “us”, “our”) collects, uses, stores, and protects personal information obtained through our website, mobile application, and related services (“the Service”).

We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).

2. What We Collect

We may collect the following personal information:

  • Name, date of birth, and contact details (email, address, phone)
  • Clinic or business information (for professional users)
  • Payment information (securely processed via Stripe — we do not store card numbers)
  • Login credentials and preferences
  • Treatment plans, product prescriptions, and client photos entered by clinics
  • Device and usage data (IP address, browser type, operating system, analytics data)
  • Communications with us (support tickets or emails)

3. Sensitive and Health-Related Information

Clinics may record limited health-related information (such as skin photos, treatment history, reactions, and product usage).

This information is entered by clinics or professionals and is stored securely using encryption at rest and in transit.

Service Cue Pty Ltd is not a healthcare provider and does not create, verify, or modify clinical content.

Clinics must obtain appropriate client consent before entering or sharing sensitive data through the Service.

4. How We Collect Information

We collect data:

  • Directly from you when you register, subscribe, or contact us
  • Automatically through cookies, logs, and analytics tools
  • From third parties where authorised (e.g. integrated apps or payment providers)

5. Purpose of Use

We use personal information to:

  • Provide and operate the Service
  • Verify identity and manage accounts
  • Process payments and subscriptions
  • Send transactional or support communications
  • Enable AI-driven progress tracking and analytics
  • Improve features and user experience
  • Comply with legal and regulatory obligations

We will not use information for other purposes without consent unless required or permitted by law.

6. Artificial Intelligence (AI) Features

Our platform includes AI tools to assist clinics in analysing before-and-after photos and treatment outcomes.

AI systems operate in secure AWS environments and do not train on identifiable data without explicit consent.

AI outputs are informational only and must be verified by qualified professionals.

7. Third-Party Services and Integrations

We use trusted third parties for hosting (AWS), payments (Stripe), and analytics (Google Analytics, Meta Ads).

These providers process data under their own privacy policies and security certifications.

Clinics are responsible for obtaining client consent before connecting third-party platforms.

We are not responsible for the data-handling practices of third-party services.

8. Cookies, Analytics & Re-Marketing

We use cookies and similar technologies to:

  • Remember login status and preferences
  • Improve functionality and performance
  • Conduct statistical analysis (Google Analytics)
  • Deliver re-marketing ads (Google Ads, Meta Ads)

Users can disable cookies in their browser settings but some features may be affected.

Marketing emails comply with the Spam Act 2003 (Cth) and include an unsubscribe option.

9. Disclosure of Information

We may disclose personal information to:

  • Service providers supporting IT, hosting, analytics, and customer support
  • Payment processors (Stripe) to complete transactions
  • Legal and regulatory authorities where required by law
  • Successor entities in case of merger or sale (subject to confidentiality)

We do not rent or sell personal information.

10. Data Storage and Location

All personal information collected through the Service is hosted on secure servers located within Australia.

We do not store or transfer your personal information overseas. Because your data is retained locally in Australia, it remains subject at all times to the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

11. Data Security

We implement multiple security layers, including:

  • AWS default security configurations and monitoring
  • Database-level encryption of sensitive fields
  • JWT tokens for session management
  • Multi-factor authentication (email verification)
  • Firewalls and access controls for authorised staff only

While we take reasonable measures, no system is fully secure.

In case of a breach, we comply with the Notifiable Data Breaches Scheme, assessing within 30 days and notifying affected users and the OAIC if required.

Security Audits & Testing

We periodically conduct penetration testing, vulnerability scanning, and security audits to validate the effectiveness of our controls and maintain industry-standard protection.

12. Data Retention and Deletion

We retain data only as long as necessary for legal, contractual, or operational purposes.

When no longer needed, data is securely deleted or de-identified.

Users may request account deletion by contacting support@servicecue.com.

13. Access and Correction Rights

You may request access to your personal information or ask for corrections to inaccurate data.

Requests are responded to within a reasonable time (typically 30 days).

We may refuse requests where lawful exceptions apply and will provide written reasons.

14. Direct Marketing and Communication Preferences

We may send marketing communications where you have opted in or we reasonably believe you expect them based on our relationship.

You may opt out at any time via unsubscribe links or by emailing support@servicecue.com with “UNSUBSCRIBE”.

15. Data Breach Management

If a data breach is likely to cause serious harm, we will:

  • Assess the incident within 30 days
  • Notify affected individuals and the OAIC
  • Provide guidance on protective measures
  • Implement remediation and audit actions

Legal Privilege in Breach Response

Any investigation reports or forensic materials prepared for legal or regulatory purposes are confidential and legally privileged to the extent permitted by law.

16. Use by Minors

The Service is not intended for use by any person under the age of 18 without the consent and supervision of a parent, guardian, or legally authorised representative.

Where consent for a minor’s participation is obtained, it is the responsibility of the clinic or professional user managing that client to ensure:

  • all information is collected and handled in accordance with the Privacy Act 1988 (Cth) and any applicable state or territory privacy or health-records legislation;
  • the minor’s data is used only for legitimate treatment-support purposes; and
  • appropriate safeguards are maintained to protect the minor’s privacy and security while using the Service.

Service Cue Pty Ltd does not independently verify parental or guardian consent and relies on the clinic to manage and document compliance obligations.

17. Contact and Complaints

For privacy enquiries or complaints, contact:

Service Cue Pty Ltd
Email: support@servicecue.com
Address: Coolum Beach, QLD Australia

We aim to resolve complaints within 30 days.

If unsatisfied, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992.

18. Changes to This Policy

We may update this Policy periodically to reflect changes in our practices or legal obligations. The revised version will be published with the updated date. Continued use after changes signifies acceptance.

19. Version History & Material Changes

Significant amendments to this Policy will be recorded in a version history and may require user re-consent where data usage materially changes.