Privacy policy
The privacy policy. Shorter than you feared.
The security page explains what we can see and what we keep, with the evidence. This page is the formal version: who we are, what we collect, why, where it lives, and how to make us hand it over or delete it.
Last updated 13 August 2026.
Who we are
Crazy Duck is online booking software for Australian accounting practices, built and operated in Melbourne, Australia. The operator — "we" in this policy — is Blue Horse Studios Pty Ltd (ABN 37 689 863 670), the company behind OneHQ. You can reach us at hello@crazyduck.com.au for anything in this document, and a person will answer.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and this policy is written to satisfy them — but mostly it is written so you can actually read it.
Two kinds of people, two different promises
If you run a practice, you are our customer. We collect what the signup form asks for and what you configure — practice name, your name, your work email, your staff's names and work emails, your services and prices, and the calendar connections your staff or your IT administrator grant. Calendar tokens are encrypted with AES-256-GCM under a key held outside the database.
If you booked an appointment with your accountant through a page we power, your details are your accountant's records, held by us on their instructions. We hold your name, your email address and mobile number (both encrypted), and what you booked. We never hold your tax file number, financial details, documents, or a card number — the booking page takes no payment. We will never market to you, and the only messages you receive from our systems are about the appointment you booked. Questions about your information are best put to your accountant first; we help them answer.
What we use it for
Running bookings — offering times, writing appointments, sending confirmations and reminders in your practice's name — plus support when you ask for it, and billing for the practice subscription. That is the list. We do not sell personal information, share it for advertising, or build profiles from it. Nothing on this website or in the booking pages loads an analytics tag or a third-party script.
Where it lives, and who else touches it
The database and all backups are hosted with AWS in Sydney, on encrypted storage, and nothing is replicated to another region. Backups age out within 35 days of a deletion. Three parties can touch personal information beyond us:
AWS, Sydney — hosting and outbound email delivery. Google and Microsoft — the appointment we write into a staff member's calendar lives in that calendar, wherever the firm's own Google or Microsoft tenant lives, under the firm's own agreement with them. Stripe — practice subscription billing only. Your card details go from your browser to Stripe directly and never touch our servers, and no client of a practice ever pays anything through us. If this list ever grows, every practice is told first, by name.
Cookies
This website sets none — which is why there is no cookie banner. The application at app.crazyduck.com.au sets one cookie, to keep a signed-in person signed in. There are no advertising or analytics cookies anywhere.
How long we keep it
For as long as the practice uses Crazy Duck, because appointment history is the practice's record. If a practice leaves, we send them everything we hold on request and delete the practice within 30 days; backups age out within a further 35. A practice that signs up and abandons setup is deleted after six months, with a warning a month before.
Seeing it, fixing it, deleting it
Ask, and we will send you what we hold about you or your practice, correct anything that is wrong, or delete it — within 30 days, done by a person rather than a button, which is how we keep the answer honest. If you are a client of a practice, we may direct the request through your accountant, because the records are theirs and they can verify who you are.
If something goes wrong
If we have a data breach that is likely to cause you serious harm, we notify the affected practices directly and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires — in plain words, with what happened, what it touched and what we have done.
Complaints
Write to hello@crazyduck.com.au and we will respond within a business day and work it through with you. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
If we change this policy in a way that matters — a new sub-processor, a new use, a different retention period — every practice is emailed before the change takes effect, not told by a changelog afterwards.