Privacy Policy

Last updated: 28 August 2026

1. Introduction

CourseSpot Pty Ltd (ABN 62 695 422 710)("CourseSpot", "we", "us", "our") operates a software platform that helps small creative and wellness studios manage course bookings, payments, and student communication. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

CourseSpot is also used by studios in New Zealand. For those studios and their students, we handle personal information in accordance with the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs). Where this policy refers to an APP, the equivalent IPP applies to them.

By using CourseSpot, you consent to the practices described in this policy.

2. Information We Collect

Business Owners (Studio Operators)

When you create a CourseSpot account, we collect:

  • Full name and email address (via our authentication provider)
  • Studio/business name and chosen subdomain
  • Contact phone number and business address
  • Brand assets (logo, colour preferences)
  • Email configuration preferences

Payment and banking details are collected directly by Stripe (our payment processor) and are not stored on CourseSpot servers.

Students (End Users)

When students book courses or register interest through a studio's CourseSpot site, we collect on behalf of the studio:

  • First name, last name, and email address
  • Phone number (optional)
  • Course booking and interest preferences
  • Marketing consent status and date

Payment card details are collected directly by Stripe during checkout and are never stored on CourseSpot servers.

Automatically Collected Information

We may collect technical information such as IP addresses, browser type, and usage data to maintain platform security and improve our services.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the CourseSpot platform
  • Process course bookings and facilitate payments
  • Send transactional emails (booking confirmations, reminders, cancellation notices)
  • Send marketing communications where explicit consent has been given
  • Provide customer support
  • Comply with legal obligations

4. Third-Party Service Providers

We share personal information with the following third-party providers to operate our platform. Each stores or processes it in the United States unless stated otherwise.

  • Stripe (United States) — Payment processing. Business owner details (name, email) are shared to create connected payment accounts. Student payment card details are collected directly by Stripe. Stripe Privacy Policy
  • Clerk (United States) — Authentication and identity management. Clerk Privacy Policy
  • Cloudflare (United States) — Bot detection on the sign-up form, through Cloudflare Turnstile, which Clerk loads when someone creates a CourseSpot account. Receives the visitor's IP address, browser user-agent and TLS fingerprint, together with the identifier of our Turnstile widget and the page it was loaded on. Cloudflare Turnstile Privacy Policy
  • Vercel (United States) — Application hosting, file storage, and the AI gateway through which requests to the AI providers below are routed. Vercel Privacy Policy
  • Resend (United States) — Transactional and marketing email delivery. Resend Privacy Policy
  • PostHog(United States) — Product analytics on CourseSpot's own pages. Receives how the platform is used: pages visited, clicks, and the email address and name of a signed-in studio owner. On our marketing and setup pages it also receives a recording of the browser session. PostHog Privacy Policy
  • Neon (United States) — Database hosting. All account, student and booking records are stored in Neon's Sydney, Australia region; Neon itself is a United States company. Neon Privacy Policy
  • Inngest (United States) — Background job processing (sending scheduled emails, importing students, reconciling payments). Receives the record identifiers and the intermediate results of each job step, which can include a student's name and email address. Inngest Privacy Policy
  • Google (United States) — Three services. Google Analytics measures use of our marketing site and of studio setup and administration pages, and measures the results of our advertising on Google (see section 9). Google Maps address autocomplete receives the address a studio owner types when setting or editing their studio's location. Google Fonts serves a studio's chosen typeface to visitors of that studio's booking widget when it is embedded in the studio's own website and the studio has picked a non-default font, which sends the visitor's IP address to Google. Google Privacy Policy
  • Sentry (United States) — Error monitoring. When something goes wrong, Sentry receives the technical details of the error (the page, browser and device, and diagnostic data) together with a replay of the browser session leading up to it, with typed text and media masked. Sentry Privacy Policy
  • OpenAI (United States) — Two uses. Its AI models power CourseSpot's AI features: the assistant in the studio administration area (which can include the studio's booking and student records when the studio owner asks about them), the chat widget a studio can enable on its public booking site (text typed into it by the studio's customers is sent to OpenAI to generate a reply), importing a studio's existing website during setup, and generating text for studio pages. Separately, our marketing site and landing pages carry OpenAI's ChatGPT Ads measurement pixel, which reports when a visitor creates a studio or requests a demo so that OpenAI can match it to an advertisement shown in ChatGPT (see section 9). OpenAI Privacy Policy
  • Anthropic (United States) — AI model used to classify the columns of a spreadsheet during student import. Receives the column headings and a small number of truncated sample values from each column, not the full roster. Anthropic Privacy Policy
  • Black Forest Labs (United States) — AI image generation for studio pages. Receives the text prompt a studio owner writes and the name of the course it is for. Black Forest Labs Privacy Policy
  • Discord (United States) — Delivers messages sent through our contact and demo request forms (name, email address and message) to our team. Discord Privacy Policy

5. Overseas Disclosure

Personal information may be transferred to and processed in the United States by every provider named in section 4, other than where that section states the data is stored in Australia. We disclose this in accordance with Australian Privacy Principle 8 and, for studios and students in New Zealand, Information Privacy Principle 12 of the New Zealand Privacy Act 2020. We take reasonable steps to ensure these providers handle your information in a manner consistent with those principles.

6. Data Retention

  • Active accounts: Data is retained for as long as the account remains active.
  • Closed accounts: Account data is retained for 90 days after closure, then permanently deleted.
  • Financial records: Booking and payment records may be retained for up to 7 years to comply with Australian taxation requirements.
  • Student data:Retained for as long as the studio's account is active, or as required by law.

7. Your Rights

Under the Australian Privacy Act (and, in New Zealand, the Privacy Act 2020), you have the right to:

  • Access the personal information we hold about you (APP 12)
  • Request correction of inaccurate or outdated information (APP 13)
  • Request deletion of your personal information, subject to any legal retention requirements
  • Withdraw consent for marketing communications at any time using the unsubscribe link in any email

To exercise these rights, contact us at privacy@coursespot.app. We will respond within 30 days.

8. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. This includes:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of data at rest
  • Access controls and authentication requirements
  • Tenant-level data isolation

9. Cookies

CourseSpot uses essential cookies for authentication and platform operation. These are strictly necessary and cannot be disabled.

We also use Google Analytics on our marketing site (coursespot.app) and on studio administration and setup pages to understand how the platform is used and to improve it. Google Analytics sets first-party cookies (such as _ga) and collects usage information such as pages visited, approximate location, and device type. We do not use cookies to personalise or target advertising. You can opt out of Google Analytics using Google's browser add-on.

We advertise CourseSpot on Google and in ChatGPT, and measure whether that advertising works. When you arrive at coursespot.app from one of those advertisements, the click identifiers in the link (such as Google's gclidand the UTM parameters) are kept in your browser's local storage for up to 90 days and, if you create a studio in that time, recorded against the studio account so we know which advertisement brought you. On our marketing site and landing pages, OpenAI's ChatGPT Ads pixel stores a first-party cookie (_oaiq) for the same purpose and reports to OpenAI when a visitor creates a studio or requests a demo, so that OpenAI can match it to an advertisement shown in ChatGPT. Neither is used to show you advertising elsewhere.

We use PostHog on the same pages, to understand how studio owners set up and run a studio. PostHog stores an identifier in your browser so that repeat visits are recognised as the same person, and records pages visited and elements clicked. On our marketing and studio setup pages it also records the session itself: the pages as they appeared, mouse movement and clicks, and browser console messages. Text you type into a form is hidden from those recordings, which are kept for 30 days. Sessions are not recorded on studio administration pages, where student details appear.

This applies to CourseSpot's own pages. Analytics on a studio's public booking site is controlled by that studio through its own settings, under its own privacy policy.

10. Children's Privacy

CourseSpot is not directed at children under 16. We do not knowingly collect personal information from children under 16 without verifiable parental consent. If you believe we have collected such information, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Your continued use of CourseSpot after changes are posted constitutes your acceptance of the updated policy.

12. Complaints

If you believe we have breached the Australian Privacy Principles, please contact us at privacy@coursespot.app. We will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). In New Zealand, you may complain to the Office of the Privacy Commissioner.

13. Contact Us

For any privacy-related enquiries, please contact us at:

CourseSpot Pty Ltd (ABN 62 695 422 710)

Email: privacy@coursespot.app