Privacy Policy

How we handle personal information — yours, and your customers'.

Last updated: 20 August 2026

Plain-English note: this is a draft. It has been written to describe honestly what Toby actually does with information, but it has not been reviewed by a lawyer. Anything in a [dashed box] still needs to be filled in. Please don't rely on it — as a customer or as the owner of Toby — until a solicitor has looked over it and the gaps are closed.

1. Who we are

Toby is an AI SMS receptionist for Australian trade businesses. A tradie diverts their unanswered calls to an Australian mobile number we provide. Toby texts the caller back, has a normal SMS conversation, and books a quote visit — or the job itself — into the tradie's calendar.

Toby is operated by [Registered entity name — to be inserted], of Queensland, Australia. Written contact: hello@hellotoby.com.au. In this policy, "we", "us" and "our" mean that business. You can reach us at hello@hellotoby.com.au.

This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (the APPs).

2. Two groups of people, and who is responsible for what

Almost every privacy question about Toby comes down to telling these two groups apart.

The tradie — our customer

The trade business that subscribes to Toby. We collect their information directly, to set up and run the service and to bill them. We deal with them as our own customer, and this policy applies to that information in the ordinary way.

The tradie's callers — everyone else

The people who ring the tradie, don't get an answer, and end up texting Toby. They are not our customers. They rang a plumber, not us. Their information reaches us only because we run the tradie's phone answering for them.

For caller information, the tradie decides what happens: it is their business, their customer relationship and their booking. We handle that information on their behalf, to provide the service to them, and we do not use it for our own purposes — we don't sell it, we don't market to callers, and we don't use one tradie's callers to do anything for another tradie. Each business's data is kept separate.

Both we and the tradie may have obligations under the Privacy Act for the same information. If you are a caller and you want something changed or deleted, you can come to us (see section 10) and we will act, or pass it to the tradie where it is properly their call.

3. What we collect

From the tradie

  • Contact details — name, business name, mobile number and email.
  • How the business runs — trading hours, breaks, days closed, the suburbs served, the jobs taken and not taken, and how Toby should talk. This is what Toby is set up from.
  • The owner's mobile number, so we can text booking, cancellation and reschedule alerts.
  • Calendar access, if connected — an authorisation token for Google Calendar (or the details needed for another calendar system), and the busy times we read back from it.
  • Billing details, and enough records to invoice and meet tax obligations.

From the tradie's callers

  • Mobile number — the number that rang, or that texted.
  • Call metadata — that a call came in from that number, at what time, and that it went unanswered. Toby does not answer the call and no call is recorded.
  • The content of the SMS conversation — everything typed, both directions, including anything volunteered that we never asked for.
  • Name, as given during the conversation.
  • Job description — what needs doing.
  • Address or suburb — where the work is.
  • Booking details — the day and time of the visit, and the matching entry written into the tradie's calendar.
  • Delivery information from the phone network, so we know whether a message actually arrived.
  • Opt-out records — if someone replies STOP, we record that number as opted out (see section 7).

We collect only what a booking needs. We never ask a caller for a date of birth, a licence, a bank account or a payment card, and Toby has no way to take a payment. If a caller volunteers something sensitive anyway, it sits in the message log like the rest of the conversation — so please don't put anything in a text that you wouldn't want kept.

4. Why we collect it, and the law behind it

Under APP 3 we only collect personal information that is reasonably necessary for what we do. What we do is book a visit, so we collect what a visit needs: who you are, where the job is, what the job is, and when. Specifically:

  • To reply to a missed call and hold the conversation.
  • To make, move and cancel bookings, and to keep them from clashing with each other or with the tradie's calendar.
  • To tell the tradie what happened — a text for each booking, cancellation and reschedule.
  • To remind the customer the day before the visit, so fewer people are stood up.
  • To honour opt-outs and meet our obligations under the Spam Act 2003 (Cth).
  • To keep the service working, investigate faults, and prevent misuse or fraud.
  • To bill the tradie and keep the records the law requires.

Under APP 6 we use and disclose personal information for the purpose it was collected for, and for closely related purposes a person would reasonably expect — or where the law requires it. We do not sell personal information. We do not disclose it to anyone for their own direct marketing. Under APP 5, this policy — together with what Toby says in the conversation — is how we tell callers who has their information and why.

5. Who else sees it

Running an SMS receptionist means other companies necessarily touch the messages. We describe them by category, because the specific suppliers can change:

  • The tradie. Obviously — the whole point is that they get the job. They see the conversation, the booking and the caller's number.
  • A telecommunications provider. An Australian carrier or messaging provider supplies the mobile number and carries every text in and out. They necessarily process the number and the message content, and keep their own records of messages sent, as carriers do.
  • An AI model provider. Toby's replies are generated by a large language model run by a third party. The conversation — including the name, job and address in it — is sent to that provider so it can produce the next reply.
  • Calendar providers. If the tradie connects Google Calendar or another calendar system, booking details are written into it and held under that provider's own terms.
  • Hosting and infrastructure providers, who run the servers and store the database and backups.
  • Professional advisers, or a regulator or court, where we are required or permitted by law to disclose.

We choose suppliers on the basis that they handle information only to provide their service to us. We are not going to quote you contract terms we haven't checked line by line — if you want to know exactly who our current providers are, email hello@hellotoby.com.au and we will tell you.

6. Information going overseas

Some of the providers above operate outside Australia, or use servers outside Australia. That means personal information handled by Toby may be processed overseas. Under APP 8 we have to take reasonable steps to make sure an overseas recipient handles it consistently with the APPs, and to tell you where it is likely to go. The countries our current providers process information in are [Countries where our providers process data — to be confirmed].

7. Text messages, and what STOP does

Every message Toby sends is about a booking — answering a call that was missed, arranging a time, confirming it, or reminding someone about it. We do not send marketing or promotional messages to callers, and tradies are not permitted to use Toby to send them either.

Under the Spam Act 2003 (Cth), anyone can tell us to stop. Reply STOP (or STOPALL or UNSUBSCRIBE) to any message from Toby and:

  • the number is recorded as opted out immediately, before anything else happens to the message;
  • we send one final message confirming it, and nothing after that;
  • a later missed call from that number gets no reply at all — Toby will not start a new conversation with someone who has opted out, and will not make a booking on their behalf that they'd never be told about.

If you opted out and change your mind, reply START and you will be able to use it again.

8. How long we keep it

  • Bookings. A booking stays live until the visit has been and gone. Shortly after that it is moved into an archive, kept there for a set period — six months by default — and then permanently deleted.
  • Cancellations. When a customer cancels, we keep a permanent record that the booking existed and was cancelled. This is deliberate: it is the record that explains why a job that was in the diary isn't any more, and it is not covered by the deletion above.
  • Message logs. We keep a log of messages in and out, including delivery results, so a missing confirmation can be told apart from a delivered one. We keep these for 180 days after the visit, after which they are deleted. Cancellation records and opt-outs are kept indefinitely.
  • Opt-outs — kept indefinitely, on purpose. If you reply STOP, the record that you did is the only thing standing between you and being texted again. Deleting it would mean forgetting you ever asked us to stop — so we keep opt-out records for good. They hold your number and the fact you opted out, and nothing else.
  • Tradie account records. Kept while the account is open, and afterwards for as long as we need them for tax, accounting and legal purposes.

Under APP 11.2, when we no longer need information and no law requires us to keep it, we destroy it or de-identify it.

9. Security, and where the data lives

Honestly, in general terms: messages travel over encrypted connections; access to the database and the dashboard is restricted to the people who need it to run the service; each business's data is separated by business; the database is backed up, and backups are treated as carefully as the database itself. The database is deliberately not kept in consumer file-sync folders, which can corrupt it. Data is hosted at Australia (Sydney) for website data; the booking service host is being finalised.

No system is perfectly secure, and we're not going to claim otherwise. What we can say is that we don't collect what we don't need, which is the only protection that never fails.

10. Seeing your information, and correcting it

Under APP 12 you can ask for a copy of the personal information we hold about you, and under APP 13 you can ask us to correct it if it's wrong. Email hello@hellotoby.com.au and tell us what you're after.

  • We'll ask enough to be sure it's really you — usually the mobile number the messages went to.
  • We aim to respond within 30 days.
  • It's free. If a request is unusually large or repeated we may discuss costs first, and we'll never charge for making a request.
  • If we can't give you access, or won't make a correction, we'll tell you why in writing.

You can also ask us to delete information about you. We'll do that where we can — but two things we will not delete are an opt-out record (deleting it would mean texting you again, which is the opposite of what you asked for) and records we're legally required to keep. If your request is really about the tradie's own customer records, we'll tell you and put you in touch with them.

You can deal with Toby anonymously or under a pseudonym where it's lawful and practical, but be aware a booking needs a name and an address to be worth anything to the tradie turning up.

11. Complaints

If you think we've mishandled your personal information, tell us first: hello@hellotoby.com.au. We'll acknowledge it, look into it properly, and write back — normally within 30 days.

If you're not happy with how we handle it, you can complain to the Office of the Australian Information Commissioner (the OAIC), which is the regulator for the Privacy Act. Their website is oaic.gov.au, and they can be contacted through the details published there. You don't need our permission to go to them.

12. If something goes wrong

If there's a data breach that is likely to cause serious harm, we'll follow the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act: contain it, assess it, and notify the people affected and the OAIC. Where the breach involves a tradie's callers, we'll tell the tradie as well, because they are the ones those people actually know.

13. This website, and the "Give him a go" demo

The demo on the home page is a real conversation with the same AI model that answers calls, in a sandbox. Nothing you type there books anything, and no tradie is contacted. But it is not a toy in privacy terms:

  • We keep the conversation. What you type is sent to our server and to the AI model provider to generate the reply, and we store the exchange — we use it to see how Toby is handling real questions and to improve it.
  • If you leave a mobile number or an email address in the "leave a number" box, we store it and use it to follow you up about Toby — that's what it's for. We don't pass it on to anyone else. If you'd rather we deleted it, email us and we will.
  • Please don't type anything into the demo you wouldn't want kept — a real customer's details, for instance.

Otherwise the site is deliberately plain. It sets no cookies, has no advertising, and loads nothing from other companies — no third-party analytics, no tracking pixels, no social buttons. It stores two small values in your own browser (how many demo messages you've sent, and whether you've dismissed the callback offer); those stay on your device. Our hosting provider keeps standard server logs, including IP addresses, for security and troubleshooting.

14. Changes to this policy

If we change how we handle information, we'll update this page and change the "last updated" date at the top. If a change is significant and affects tradies using the service, we'll tell them directly.

15. Contact us

Privacy questions, requests and complaints all go to the same place: hello@hellotoby.com.au. A real person reads it.

Postal address: Queensland, Australia. Written contact: hello@hellotoby.com.au. Operated by [Registered entity name — to be inserted].