Information collected
The booking form records the selected service, session date and time, student first name and age group, experience level, relevant notes, the booking contact’s name, email and phone, consent choices, transaction status and booking reference.
The contact form records the information entered so the enquiry can be answered.
Payment information
Card number, expiry and security code are entered into PayPal-hosted fields. This application does not intentionally receive or store those raw card values. The local SQLite database stores operational payment results such as PayPal order and capture identifiers, status, amount, fees, seller-protection result, processor response, AVS/CVV result codes, card brand and last digits when PayPal returns them.
No shipping address is requested because the website sells bookings and services rather than physical goods. Billing-address details entered during card payment are used in the browser checkout flow and are not written to the application database.
Technical and customer signals
To diagnose checkout failures, prevent duplicate bookings and understand the payment journey, the application may record a keyed, pseudonymous IP hash, user agent, browser and device category, language headers, referral origin/path with URL queries removed, separately allowlisted campaign tags, screen and viewport dimensions, timezone, basic network-quality values, form timing, Hosted Fields eligibility, field-validity events and card brand. It does not log keystrokes, card field contents, raw PAN or security code.
Raw IP storage is disabled by default and can only be enabled by a deliberate server setting. Browser privacy preferences such as Do Not Track and Global Privacy Control may also be recorded so they can be respected in future data-handling decisions.
Use, access and retention
Information is used to supply the booked service, communicate about the booking, reconcile payments, prevent overbooking, investigate payment errors, meet accounting or dispute obligations and improve the booking workflow. Access to the operations dashboard should be limited to authorised staff and protected with strong credentials.
Booking and transaction records should be retained only for as long as required for operational, accounting and legal purposes. Technical telemetry should be reviewed and deleted when it is no longer needed.
Questions or requests
For privacy questions, access or correction requests, email sales@internationaldanceinstitute.com.au. This starter notice should be reviewed against the organisation’s final legal name, location, retention schedule and Australian Privacy Act obligations before launch.