Privacy

Privacy policy

Last updated 14 September 2026

1. Summary

  • Tokn runs online booking and live queues for appointment-based businesses such as dental practices, clinics, physios, vets, cosmetic clinics and barbers.
  • We collect only what’s needed to run a booking: typically your name, mobile number and the appointment you chose.
  • Booking forms don’t ask for health information. Clinical records stay with the business, in its own systems.
  • We don’t sell or rent personal information, and we don’t use it for third-party advertising or cross-site tracking.
  • Our main database is hosted in Australia. Some service providers are overseas (see section 8).
  • You can ask to access, correct or delete your information, or object to how we use it, by emailing next@tokn.live. We respond within 30 days.

2. Who we are and our role

In this policy, “Tokn”, “we”, “us” and “our” mean the operator of the Tokn service at tokn.live and app.tokn.live. For privacy matters, contact us at next@tokn.live.

We play two different roles, depending on the information:

  • When you book with a business through a Tokn booking page, queue or app, that business decides why and how your booking information is used. It is the controller (in India, the “data fiduciary”; in California, the “business”). Tokn handles that information on the business’s behalf and under its instructions, as a processor or service provider. For questions about how the business uses your information, contact the business directly. We will help it respond.
  • For our own purposes, Tokn is the controller. This covers our websites, Tokn user accounts, business accounts and billing, security logs, and our communications with businesses.

This policy is written to meet the Australian Privacy Act 1988 and Australian Privacy Principles, the EU and UK General Data Protection Regulation (GDPR), India’s Digital Personal Data Protection Act 2023, US state privacy laws including the California Consumer Privacy Act (CCPA/CPRA), New Zealand’s Privacy Act 2020, and the anti-spam laws that apply to our messages.

3. What we collect

Information you give us

  • Bookings and walk-ins: your name and mobile number; the business, service, practitioner, date and time you chose; and anything you add in an optional field. That might be your pet’s name and species, the name of the person the booking is for, or a short note (up to 280 characters).
  • Tokn accounts: your mobile number or email address, name, saved profiles for people you book for, and your preferences.
  • Business accounts: the owner’s and staff members’ names, emails, phone numbers and sign-in details; business details such as address, hours, services, prices and photos; and subscription and billing records.
  • Messages to us: anything you send when you email us, reply to our messages or ask for support.

Information created when you use Tokn

  • Queue and visit data: your token number, check-in and arrival times, status (for example waiting, in progress, completed, cancelled or no-show), and estimated times.
  • Ratings you choose to leave after a visit.
  • Payments: where a business offers online payment, or a business pays for a subscription, the payment is processed by our payment provider. We receive the amount, status and a reference from them. We never receive or store full card or bank details.
  • Device and technical data: IP address, browser and device type, pages requested, timestamps and error logs. If you turn on notifications, we also store a push notification token for your device.

Information we collect only with your permission

  • Location: if you allow it, your device location is used to show nearby businesses and estimate travel time for leave-now reminders. It is used when the request is made and is not stored as a location history. You can switch it off at any time in your browser or device settings.
  • Push notifications: only if you turn them on.

Information from other sources

  • From businesses: reception staff may enter your name and mobile number when you walk in or book by phone.
  • From sign-in providers: if you sign in with Google, we receive your name, email address and profile picture from Google.
  • Business contact information from public sources: to tell businesses about Tokn, we may collect business names, roles, and business phone numbers and email addresses. These come from the business’s own website, public directories and public professional profiles. We record where each detail came from, contact businesses only in their professional capacity, and stop immediately if asked.

You don’t have to give us your information. Where it’s practical, such as asking a general question, you can deal with us without identifying yourself or by using a pseudonym. A business can’t hold your place in a queue or confirm a booking without a name and a way to reach you, though.

4. Health and other sensitive information

Tokn is not a medical records system. Our booking forms don’t ask about symptoms, conditions, treatment or other health information. Please don’t include it in notes. Your booking may show that you visited a particular type of business, such as a dental practice or clinic. That information is used only to run your booking and is visible only to that business and to you.

We don’t intentionally collect other sensitive information, such as racial or ethnic origin, religious or political beliefs, sexual orientation, biometric or genetic data, or government identifiers. If you include it anyway, we delete it when we become aware of it, unless the business needs it and you have agreed.

5. How we use it, and our legal bases

We use personal information only for the purposes below, and for purposes directly related to them that you would reasonably expect:

PurposeLegal basis (where the GDPR or a similar law applies)
Creating and managing bookings and live queuesPerformance of a contract with you (or steps you ask us to take before one)
Booking confirmations, delay updates and remindersPerformance of a contract; legitimate interests in running the service
Push notifications and using your device locationYour consent, which you can withdraw in your browser or device settings
Business accounts, subscriptions and billingPerformance of a contract; legal obligations (tax and accounting)
Security, fraud and abuse prevention, service logsLegitimate interests in keeping Tokn safe and working; legal obligations
Improving Tokn using aggregated or de-identified dataLegitimate interests
Emailing businesses about ToknLegitimate interests, or consent where the law requires it
Responding to legal requests and enforcing our termsLegal obligations; legitimate interests

Where we rely on consent, you can withdraw it at any time. That won’t affect anything we did before you withdrew it. In India, where consent is the basis, you can withdraw it as easily as you gave it, by emailing next@tokn.live.

Automated decisions. Tokn estimates wait times and suggests when to leave, based on the queue. These estimates don’t produce legal or similarly significant effects, and staff at the business can always override them. We don’t use profiling to make decisions about individuals.

6. Messages we send

  • Service messages: sign-in codes, booking confirmations, queue and delay updates, reminders and cancellations, sent by SMS, WhatsApp, push notification or email. These are part of the service, so they don’t carry marketing and don’t need an unsubscribe. You can switch off optional channels such as WhatsApp or push.
  • Marketing: we never send marketing to people because they booked with a business on Tokn. When we email businesses about Tokn, each message identifies Tokn, gives our contact details and includes a simple way to unsubscribe. We act on unsubscribe requests within 5 business days (usually immediately), and we keep a minimal suppression record so we don’t contact you again. This meets the Australian Spam Act 2003, the EU and UK ePrivacy rules, the US CAN-SPAM Act, and similar laws.

7. Who we share it with

We share personal information only as described here:

  • The business you book with and its authorised staff, so they can serve you.
  • Service providers who host, secure and deliver Tokn for us. They are bound by contract to use the information only to provide their services to us, to keep it secure, and to delete or return it when the service ends.
  • Professional advisers, such as lawyers, accountants and auditors, under confidentiality.
  • Authorities, where the law requires it, or where it is necessary to protect someone’s life, health or safety, or to establish, exercise or defend legal claims.
  • A buyer or successor if Tokn is involved in a merger, acquisition or sale of assets. They would have to protect the information in line with this policy, and we would tell you first.

On shared screens, such as a waiting-room queue display, names are shortened. People booking can only ever see their own place in the queue.

We do not sell personal information and do not “share” it for cross-context behavioural advertising, as those terms are defined in US state laws. We have not done so in the past 12 months.

Our service providers

ProviderWhat they doWhere data may be processed
SupabaseDatabase, sign-in, file storage and server functionsAustralia (Sydney region); support access may occur from other countries
VercelWebsite and app hosting, content delivery, request logsUnited States and global edge network
Amazon Web Services (SNS)SMS sign-in codes and booking text messagesIndia (Mumbai region)
TwilioWhatsApp booking notifications, where enabledUnited States
GupshupBackup delivery of sign-in codes in IndiaIndia
Google (Firebase Cloud Messaging)Push notifications, if you turn them onUnited States and global
Google (Maps Platform and Sign-In)Maps, travel-time estimates, nearby search, and optional Google sign-inUnited States and global
Razorpay and CashfreePayment processing in India (subscriptions, and bookings where a business offers online payment)India
Our email providerSending and receiving email at next@tokn.liveVaries by provider; covered by the protections described below

Which providers are used depends on your country and the features a business turns on. We update this list before we add a provider that handles booking information.

8. International transfers

Tokn’s main database is in Australia. Some providers listed above process data in other countries, including the United States and India, and their support teams may access it from elsewhere.

  • Australia: before disclosing personal information overseas, we take reasonable steps, including contractual commitments, to make sure recipients handle it consistently with the Australian Privacy Principles.
  • EU, EEA and UK: where information about people in these regions is transferred to countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum (or the EU–US Data Privacy Framework, where a provider is certified), with supplementary measures where needed. You can ask us for a copy of the relevant safeguards.
  • India: we transfer personal data outside India only to countries not restricted by the Government of India under the Digital Personal Data Protection Act 2023.

9. Cookies and similar technologies

The tokn.live website doesn’t use advertising or analytics cookies, and we don’t use third-party tracking pixels. The Tokn app at app.tokn.live uses only strictly necessary cookies and browser storage. These keep you signed in, remember a booking in progress, keep the service secure, and (if you turn them on) deliver push notifications. Because they are essential, they don’t require consent under EU and UK rules. If you block them, sign-in and booking won’t work.

Some pages load map content from Google, which may set its own cookies under Google’s privacy policy. We honour Global Privacy Control signals, although we don’t sell or share personal information in the first place. If we ever add optional cookies, we will ask first and update this section.

10. Security and data breaches

We protect personal information with measures that match its sensitivity, including:

  • Encryption in transit (HTTPS/TLS) and encryption at rest by our hosting providers.
  • Row-level access controls, so each business and each person can reach only their own records.
  • Least-privilege staff access, separate keys for server functions, and restricted API keys.
  • Minimal collection, shortened names on shared screens, and scheduled deletion of old data.

No system is completely secure. If a data breach is likely to cause serious harm, we will contain it, assess it promptly, and notify affected people and regulators as the law requires. That includes notifying the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, the relevant supervisory authority within 72 hours under the GDPR, and the Data Protection Board of India. Where we act for a business, we will tell that business without undue delay so it can meet its own obligations.

11. How long we keep it

  • Live queue data: deleted automatically after 30 days.
  • Bookings, payments records and ratings: kept for up to 3 years so businesses have their booking history, then deleted or moved to a restricted archive used only for legal, tax and dispute purposes.
  • Tokn and business accounts: kept while the account is open. After you ask us to close it, we delete or de-identify account information within 30 days, except records we must keep by law (for example tax records, usually 5 to 7 years).
  • Technical and security logs: kept for a limited period, normally no more than 90 days, unless needed to investigate an incident.
  • Business contact information used for outreach: deleted when you ask. It is also deleted after 24 months without a response, except a minimal suppression record that keeps you off our lists.

A business may ask us to delete its booking records sooner. When we no longer need personal information, we securely delete it or de-identify it.

12. Your rights

Depending on where you live, you may have the right to:

  • know what personal information we hold about you, and get a copy;
  • correct, complete or update it;
  • delete it;
  • receive it in a portable, machine-readable format;
  • object to, or ask us to restrict, how we use it, including for direct marketing (always honoured);
  • withdraw consent at any time;
  • opt out of the sale or sharing of personal information and of targeted advertising (we don’t do either);
  • nominate someone to exercise your rights if you die or become incapacitated (India);
  • complain to us, and to a privacy regulator (see section 17).

To make a request, email next@tokn.live from the email address or mobile number linked to your booking or account, or tell us how to reach you. We may need to verify your identity before acting. An authorised agent can make a request for you with your written permission. Requests are free. We respond within 30 days, or within any shorter period required by law, and tell you if we need longer (up to the legal maximum) and why. If we refuse a request, we explain why and how to complain or appeal. We will never discriminate against you for exercising your rights.

If your request concerns a booking, we may pass it to the business you booked with, as it controls that information. We will help it respond.

13. Additional information by region

Australia

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. That includes the rules on collection notices, direct marketing and cross-border disclosure (APPs 5, 7 and 8) and your rights to access and correction (APPs 12 and 13). If you’re not satisfied with our response to a complaint, you can contact the OAIC.

European Union, EEA and United Kingdom

Tokn does not currently target individuals in the EU, EEA or UK. Where the GDPR or UK GDPR applies, this policy sets out our legal bases (section 5), international transfers (section 8) and your rights (section 12). You may lodge a complaint with the supervisory authority where you live or work. In the UK, that is the Information Commissioner’s Office (ico.org.uk).

India

Under the Digital Personal Data Protection Act 2023, you can access information about processing, correct, complete, update and erase your personal data, nominate another person, and seek grievance redressal. Grievances go to our Grievance Officer at next@tokn.live, and we respond within 30 days. If you’re not satisfied, you may complain to the Data Protection Board of India.

United States (including California)

In the past 12 months we have collected these categories of personal information:

  • identifiers (name, mobile number, email, IP address);
  • commercial information (bookings and subscriptions);
  • internet activity (logs);
  • approximate or precise geolocation, only with permission;
  • professional information (for business contacts).

The sources, purposes and recipients are described in sections 3, 5 and 7. We do not sell or share personal information, and we don’t use sensitive personal information to infer characteristics. California residents and residents of other states with comprehensive privacy laws can exercise the rights in section 12, and appeal a refused request by replying to our decision.

New Zealand

We handle personal information consistently with the Information Privacy Principles in the Privacy Act 2020. You can complain to the Office of the Privacy Commissioner (privacy.org.nz).

Other countries

If you live somewhere else, you may have similar rights under local law. Email next@tokn.live and we will honour them as required.

14. Children

Tokn accounts are for adults. Children under 16 (under 18 in India) should not create an account or make a booking themselves. A parent or guardian may book on a child’s behalf and gives only the child’s name for that booking. We don’t knowingly collect more information about children, don’t track them, and don’t target them with marketing. If you think a child has given us personal information, email next@tokn.live and we will delete it.

15. Businesses that use Tokn

Businesses using Tokn are responsible for their own privacy obligations to their customers. That includes having a lawful basis to collect booking information and giving any notices their own laws require, such as a collection notice for health services. Tokn processes booking information only on the business’s instructions and keeps it confidential and secure. We help businesses respond to access, correction and deletion requests, and notify them of relevant data breaches. A data processing agreement is available on request at next@tokn.live.

16. Changes to this policy

We will update this policy when our practices or the law change, and show the new date at the top. If a change is significant, we will tell business account holders by email, and people with a Tokn account in the app, before it takes effect. If the law requires it, we will ask for your consent again.

17. Contact and complaints

For any privacy question, request or complaint, contact our Privacy and Grievance Officer at next@tokn.live. Please give enough detail for us to understand the issue. We acknowledge complaints promptly and aim to resolve them within 30 days.

If you’re not satisfied with our response, you can contact a regulator:

  • Australia: Office of the Australian Information Commissioner, oaic.gov.au, 1300 363 992
  • United Kingdom: Information Commissioner’s Office, ico.org.uk
  • European Union and EEA: your local data protection authority (edpb.europa.eu lists them)
  • India: Data Protection Board of India
  • New Zealand: Office of the Privacy Commissioner, privacy.org.nz
  • United States: your state attorney general or privacy agency (for California, the California Privacy Protection Agency, cppa.ca.gov)