For businesses using Glo
Acceptable Use Policy
What may and may not be done with Glo, and what a business is responsible for when it records information about its own customers.
Version 1.5. Effective 1 October 2026.
Glo
Published at /legal/acceptable-use
Operated by Connor Wu trading as Glo, ABN 23 380 080 435, Unit B14, 161 Arthur Street, Homebush West NSW 2140. Contact: hello@welcomeglo.com. Privacy matters: hello@welcomeglo.com.
Before you start
Most of this policy is common sense: do not break the law with our software, do not go looking in other people's accounts, and look after the information your clients have trusted you with. The parts that need more explanation are the ones about your clients' information (section 6), the notes field and receipt images (section 7), marketing (section 8) and the Finances module (section 9). Those four sections are where a business is most likely to get into trouble without meaning to, so they are the longest.
Section 12 sets out what happens if something goes wrong. We have written it so that you get told first, get a chance to fix it, and keep your records no matter what. That section exists to protect you, and it says so.
Nothing in this policy is legal advice about your own business. If you want to know whether a particular thing you do is lawful, ask someone qualified to tell you.
1. What this policy is
1.1 It is part of your agreement with us
This Acceptable Use Policy forms part of your subscription agreement with us. That agreement is made up of six things, and this is the order they come in:
- the Terms of Service, at
/legal/terms; - our Refunds and Cancellations Policy, at
/legal/refunds; - this Acceptable Use Policy, at
/legal/acceptable-use; - our Privacy Policy, at
/legal/privacy; - our Data Processing Addendum, at
/legal/data-processing; and - the Plan you chose.
When you agree to the Terms, you agree to this policy as well. Words defined in the Terms have the same meaning here. Clause 3.2 of the Terms sets out the same six things in the same order, deliberately, so that the two documents cannot drift.
Two documents we publish are not part of that agreement at all, because they
govern a different relationship: the Client Terms of Use at /legal/client-terms,
which are between us and your clients, and the SMS Terms at /legal/sms, which are
between us and the person receiving a text. Section 3.3 explains why that split
exists and why it is in your interest.
1.2 If this policy and another document disagree
If something in this policy conflicts with the Terms of Service, the Terms win, except that:
- the Refunds and Cancellations Policy comes first on anything about refunds, cancellations, or what happens when a payment fails;
- the Data Processing Addendum comes first on our handling of personal information about your clients; and
- the Privacy Policy always governs how we handle personal information.
This policy is about how the Service is used, not about what we do with your data.
One more exception, and it runs in your favour: where this policy gives you a shorter timeframe, a larger refund or a stronger protection than the Terms do, this policy applies. Section 12 is written that way on purpose. We are not going to use a precedence rule to take back a protection we have written down.
1.3 We apply this policy as it is written
We do not have a general power to decide that something you have done is unacceptable when this policy does not say so. If we want to rely on this policy against you, we have to point at the part of it you have not followed, and tell you which part. Section 12 sets out exactly what we can do and when.
1.4 Where you can find it
This policy is published at /legal/acceptable-use, free to read, without an
account, at any time.
We do not rely on a rule you were never shown. If we ever try to rely on a part of this policy against you and you were not given a fair chance to read it, that is our problem and not yours.
1.5 Nothing here takes away your rights under the Australian Consumer Law
Nothing in this policy excludes, restricts or modifies any right you have under the Australian Consumer Law. Some of those rights cannot be excluded by any agreement, and we are not trying to exclude them. Where anything in this policy conflicts with them, the law wins and that part of this policy does not apply.
This sits at the front rather than the back, so that it is obvious which one wins.
2. Words we use
These definitions are deliberately written so that they still work as Glo grows. If we later publish a phone app or connect to accounting software, these words already cover it, as they cover the text messages Glo sends, and you will not be asked to sign a new agreement just because a feature arrived.
2.1 "The Service" means the Glo software and everything we provide with it, however you reach it: in a web browser, through any Glo App, or through any page we host for you or for your clients. That includes your booking page, your clients' tracking pages, and the invoice and quote pages you send them.
2.2 "A Glo App" means any application we publish for a phone, tablet or computer. A Glo App is a way to reach the Service. It is not a separate service.
2.3 "Public Pages" means the pages we host that your clients can reach without logging in, including your booking page and the tracking, invoice and quote pages reached through a link you or the Service sends them.
2.4 "You" and "your" means the business that holds the Glo subscription, and the person who agreed to the Terms on its behalf.
2.5 "Your team" means every person you invite into your Glo account, whatever their role.
2.6 "Your clients" means the people and businesses you supply your services to. They are your customers, not ours. They do not have Glo accounts and they pay us nothing.
2.7 "Client Data" means the personal information about your clients that is in your Glo account, including names, phone numbers, email addresses, the addresses where the work happens, booking history, messages, notes, receipt images and payment records.
It also includes details of the things you work on. Today the Service records those as vehicles: make, model, year, size and registration. If we add other kinds of item, we will update this policy before we do.
2.8 "Messages" means anything the Service sends on your behalf or at your direction, by email, by text message where we provide it, by push notification where we provide it, or by any other means we later add.
2.9 "We", "us" and "our" means Connor Wu trading as Glo, the operator of Glo.
3. Who this policy binds
3.1 You
This policy binds you for everything done in your Glo account by you, by your team, or by anyone else you have given access to it.
It does not make you responsible for what somebody does after breaking into your account, so long as you tell us as soon as you know, or as soon as you reasonably should have known, and it does not make you responsible for anything caused by a failure on our side. If your account is compromised, we work with you on it. We do not turn section 12 on you for being the victim of it.
3.2 Your team
Everyone you invite into your account is bound by this policy. You are responsible for making sure they know the parts that apply to them, particularly sections 6, 7 and 8. In practice that means: before you invite someone, tell them that your clients' details are not theirs to take, copy or use elsewhere.
If someone on your team breaks this policy, we deal with you, not with them directly, unless the law requires otherwise or the conduct is serious enough that we need to disable that person's login to stop harm continuing. If we do disable an individual login, we tell you why, in writing, and your account keeps working.
3.3 People who use the Public Pages
Your clients are not bound by this policy. What they can and cannot do on the
pages we host for them is in the Client Terms of Use at /legal/client-terms,
which is written for them, is linked from the pages they can reach, asks three
things of them and no more, and gives them notice and a right of reply before we
block anything. That document also promises them that blocking never cancels
their booking, never takes their money and never affects any right they have
against you.
We did it that way deliberately. A person who booked a job with you never agreed to a subscription and should not be handed a business's rulebook.
3.4 Anyone else
If you connect something to your Glo account, or authorise a third party to act in it, this policy applies to what they do there as if you had done it yourself.
4. What you and your team must not do
These rules apply to you and to your team.
4.1 Do not use the Service to break the law
Do not use Glo to do anything unlawful under Australian law, or under the law of anywhere else that applies to you. That includes fraud, harassment, threats, stalking, discrimination and dealing in stolen goods.
4.2 Do not upload content you have no right to use
Do not upload, store or send through the Service anything that infringes someone else's copyright, trade mark or other rights, or that is defamatory, obscene, or otherwise unlawful. Your logo, your service descriptions, your terms and your photos of your own work are yours to use. Someone else's are not.
4.3 No malware or harmful code
Do not upload, send or link to viruses, worms, ransomware, or any other code designed to damage, disable or gain unauthorised access to a computer system.
4.4 Do not go looking in anyone else's account
Do not attempt to access, and do not access:
- another business's account or data;
- another person's booking, invoice, quote or tracking page;
- any part of the Service you have not been given access to; or
- the underlying systems, databases or infrastructure the Service runs on.
Attempting counts. You do not have to succeed for this to be a breach. We mean a deliberate or reckless attempt. Clicking something, getting a "not found", and moving on is not a breach of this rule and we will not treat it as one.
We have built the Service to make this hard, and the records of one business are kept separate from those of another.
None of that removes the rule. It is here because a business trusting us with its client list is entitled to know that the rule exists and that we mean it.
4.5 Do not test our security without written permission
Do not probe, scan or test the security or availability of the Service, or of any system it depends on, unless we have given you permission in writing first. That includes vulnerability scanning, penetration testing, load testing, fuzzing, credential stuffing, and denial of service testing of any kind.
This rule has a door in it, and section 11 is that door. If you have found something and want to report it responsibly, read section 11. We would much rather hear from you than not.
If you want permission to test, ask us at hello@welcomeglo.com before you start. We will not unreasonably refuse a sensible request from a customer who wants to satisfy themselves about the security of a system holding their client list, and we will tell you in writing what is in scope.
4.6 No automated scraping or bulk extraction
Do not use robots, spiders, scrapers or other automated means to extract data from the Service, and do not systematically download the Public Pages.
This is not a rule against getting your own data out. See section 5.1. It is a rule against harvesting, and in particular against harvesting client details off Public Pages.
4.7 Do not circumvent our limits or other protections
The Service limits how often certain requests can be made. Do not work around those limits, and do not disable, interfere with or attempt to defeat any other security or authentication measure.
4.8 No reverse engineering
Do not copy, decompile, disassemble or reverse engineer the Service, or attempt to derive its source code, except where a law gives you a right to do so that cannot be excluded by an agreement. Where a law gives you that right, the law wins and this clause does not apply to that extent.
4.9 No reselling or white-labelling without an agreement
Do not resell, sublicense, rent, lease or provide the Service to anyone else as though it were your own product, and do not operate it as a service for other businesses, unless we have agreed to that in writing.
To be clear about what this does not stop. Using Glo to serve your own clients, under your own business name, with your own logo and colours on your booking page, on your own terms and your own cancellation policy, is exactly what Glo is for. That is not white-labelling, and nothing in this clause limits it. A small "Made with Glo" mark appears on documents the Service generates for you. Please leave it there.
If you do want to offer Glo to other businesses, talk to us. That is a conversation, not a refusal.
4.10 No spam, and no unsolicited marketing
Do not use the Service, or anything you get out of it, to send unsolicited commercial messages. Section 8 sets this out properly, because it is the rule most often broken by accident and the one with the biggest fines behind it.
4.11 Do not interfere with the Service for other people
Do not do anything that damages, disables, overburdens or impairs the Service, or that interferes with anyone else's use of it.
4.12 Do not pretend to be someone you are not
Do not misrepresent who you are, what business you operate, or your relationship with any person or organisation, including us. Do not use the Service in a way that suggests we endorse you, are responsible for the work you do, or are a party to your contract with your client. We are not, and section 9.6 explains why that matters to you as well as to us.
5. What this policy does not stop you doing
We have written this section because acceptable use policies have a habit of being read as "everything not expressly permitted is forbidden". That is not how this one works.
5.1 Your data is yours, and getting it out is not a breach. Anything you can get out of Glo, you may download, print, copy into a spreadsheet, hand to your accountant and take to another product. Section 4.6 is about scraping other people's data, not about extracting your own.
The built-in exports cover your Finances records and reports: the CSV exports
on the Reports page, the PDFs of documents you have issued, and the permanent free
records download at /dashboard/finances/records, which is open to Owner and
Admin users and keeps working even if your subscription lapses.
Clause 12.4 of the Terms of Service says the same thing and scopes it the same way.
For anything else in your account, including your bookings, clients, vehicles, messages and notes, email us at hello@welcomeglo.com and we will get it out for you at no charge.
5.2 You can use your own business information however you like, subject to the law and to the rest of this policy. It is your business.
5.3 You can criticise us in public. Nothing in this policy stops you writing a review, posting about a problem, telling other businesses what you think, or raising a complaint with a regulator. We do not ask for your silence as a condition of using our software.
5.4 You can connect other software where we provide a way to do so, including accounting software, and use it to move your own data. Doing so does not breach section 4.6 or 4.9.
5.5 Ordinary heavy use is fine. A busy week, a big import, a long booking history, a batch of invoices on the last day of the quarter: none of that is misuse. Section 4.7 is aimed at people deliberately defeating protections, not at customers being busy.
6. Your clients' information: what you are responsible for
This is the most important section in this policy, and the one with the most in it for you to actually do.
The short version: you decide what goes into Glo about your clients, so you are responsible for what goes in. We hold it and protect it. We do not choose it.
6.1 You are the one who decides
Glo gives you fields. You fill them in. We do not tell you what to record about a client, we do not require you to record anything beyond what is needed to take a booking, and we do not go through your records deciding what should be there. That means the decisions, and the responsibility for them, sit with you.
6.2 You need a lawful basis, and your clients need to be told
Before you put a person's details into Glo, you need to be entitled to hold them, and that person should know their details are going into a booking system.
Practically, for most businesses:
- If the client booked through your Glo booking page, they typed their own details in themselves, and we show them a collection notice at the point they do it, naming both you and us. For that path the telling is ours. You are still responsible for anything you record about them afterwards that they would not expect from having made a booking.
- If you typed their details in yourself, from a phone call, a text message, a business card or an old customer list, it is on you to have told them. A sentence when you take the booking is usually enough: "I will put your details into my booking system so I can confirm the job and send you the invoice."
- If you imported an old list, think about where it came from and whether those people would expect to hear from you.
You must also tell your clients that you use a booking and invoicing platform to
run your business, and where they can read about how it handles their
information. The easiest way to do that is a line in your own terms or on your
own website pointing at our Privacy Policy at /legal/privacy. We have written
that policy so it speaks directly to your clients, not only to you, which makes
this easier for you than it would otherwise be.
6.3 Collect what you need, not what might be handy
Only put into Glo what you actually need to do the job, invoice for it, and keep your records. Every extra field is one more thing to protect, one more thing that could be exposed, and one more thing a client can ask you about.
6.4 Accuracy is your responsibility
You are the source of what is in your account. We do not invent, guess, buy or enrich client records. You must take reasonable care that what you record is accurate, and keep it up to date where it matters. If a client tells you something is wrong, fix it.
Where we can help you keep things accurate, we do. Phone numbers are stored in a single consistent format. A returning client is recognised by a verified email address rather than by us guessing that two similar records are the same person. We do not silently merge records.
6.5 Your clients can ask to see what you hold about them
An individual can ask to see the personal information a business holds about them, and can ask for it to be corrected if it is wrong. That applies to what you hold about your clients, and it applies to what we hold.
Two things follow.
First, assume everything in a client's record can end up in front of that client. That includes the notes field. Section 7 deals with this properly.
Second, if one of your clients contacts us instead of you, we will not turn them away. We acknowledge their request within 5 business days and answer it within 30 days ourselves, whichever route it takes. That is the commitment in our Privacy Policy and we are not going to make them chase you for it.
In most cases we will also pass the request to you, because you know who they are, you can verify them on the spot and you can fix the record in front of them, and we will tell them we have done that. If we pass a request to you, respond to us within 14 days and tell us what you did. If you do not, we deal with it ourselves and tell you what we did, which may mean giving that person the information we hold about them.
6.6 Only invite people who should see it
Every person you invite into your account can see client information. Invite the people who need it to do their job, and nobody else.
Some things worth knowing when you decide:
- The Finances module is limited to the Owner and Admin roles. A team member with the Staff role cannot reach it at all, including the PDFs, the CSV exports and the records download. Your takings, your expenses and your reports are not visible to staff.
- Everything else in the account, including client contact details and booking history, is visible to your team. If that is not what you want for a particular person, do not invite them.
- Vehicle registration numbers are never shown on any page your clients can reach, and the booking page never asks for one.
6.7 Do not upload sensitive information
Glo is a booking, client and invoicing system for a business. It is not designed or built to hold sensitive information, and you must not put it there.
Do not record:
- a person's health information of any kind, including medical conditions, injuries, disabilities, allergies, medications, or the reason someone cannot attend an appointment;
- genetic or biometric information, including face, fingerprint or voice data;
- information about a person's racial or ethnic origin, political opinions, membership of a political association, religious beliefs, philosophical beliefs, trade union or professional or trade association membership, sexual orientation or practices, or criminal record.
This rule is about people, not animals. The Privacy Act protects information about an identified person, so a note about an animal is not health information and this rule does not catch it. If the work involves animals, a note that a dog needs a muzzle, or is on medication, or reacts badly to a dryer, is a note about the animal and you may record it. The rule applies again the moment a note is about the owner rather than the animal.
This rule protects you. Information in those categories is treated more strictly by the law than ordinary contact details are, generally cannot be collected without the person's consent, and turns an ordinary data problem into a serious one. Keeping it out of Glo keeps that risk out of your business.
Government identifiers are a separate rule. Tax file numbers, Medicare numbers, driver licence numbers, passport numbers and pension or concession card numbers are not sensitive information in the technical sense, but the law puts its own restrictions on what a business may do with them, and tax file numbers have a rule of their own again. Glo has no field for any of them. Do not put one in a field meant for something else.
If you genuinely need to record something practical, record the practical fact and not the underlying reason. "Access via side gate, ring bell" instead of a note about someone's mobility. "Do not use scented products" instead of a note about an allergy. The first version gets the job done and carries none of the risk.
If you have already recorded something in one of these categories, delete it. If you are not sure whether something counts, ask us at hello@welcomeglo.com and we will tell you what we think, or tell you that it is a question for a lawyer.
6.8 A vehicle registration is not a toy
Where the work you do is on vehicles, the Service records a registration. Vehicle registration numbers can identify a person. Record one only if you need it for the work. Do not use it to look up anyone, and do not publish it.
6.9 If something goes wrong with client information
If you think client information in your Glo account has been exposed, taken, sent to the wrong person, or accessed by someone who should not have seen it, tell us at hello@welcomeglo.com as soon as you can. Do not wait until you are certain.
You may have your own obligation to assess and report a data breach, and so may we. We will work with you on it. What we need from you is prompt notice and straight answers, and what you will get from us is what we know, when we know it.
And here is when. Where personal information we hold for you is lost, or accessed or disclosed without authorisation, we will tell you without undue delay and in any case no later than 24 hours after we first have reasonable grounds to suspect it, and within a further 24 hours of concluding that it is likely to be an eligible data breach under the Notifiable Data Breaches scheme. Clause 7.2 of our Data Processing Addendum carries the same two clocks and the detail behind them, and clause 12.7 of the Terms of Service repeats them.
Suspicion is earlier than certainty, and it is deliberately the earlier clock. You may have your own obligations to your own clients, and you cannot start on them until you know.
6.10 What we do on our side
This clause is here so the obligations in this section do not look one sided.
- We do not use your clients' information for our own marketing. We do not sell it, rent it, or share it with anyone except the providers listed in our Privacy Policy, who process it in order to run the Service.
- We do not sign in as you. If we need to see inside your account to help you with a problem, you add us to your team yourself, with your knowledge, and remove us afterwards. Where one of us does need to act on an account from our side, we can see the business's own record and its activity. What we can see does not include your notes, your messages or your receipt images.
- Actions in your account, including anything we do from our side, are written to an append-only audit log, recorded against the person who took them. Ask us at hello@welcomeglo.com and we will send you the entries for your business.
- The records of different businesses are kept separate from one another.
- We tell you plainly in the Privacy Policy which providers we use, what they do, and which of them process information outside Australia.
7. The notes field, and receipt images
These two get their own section because they are the two places where personal information turns up that nobody intended to put there.
7.1 A note about a client is that client's personal information
The free-text notes field on a client record is not a private scratchpad. It is part of that person's record. If that person asks to see what you hold about them, the note is part of the answer, and the general position is that they are entitled to see it.
So the working rule is simple:
Write every note as though the client will read it, because one day they might.
7.2 What belongs in a note
Things that help you do the job: access instructions, gate codes you have been given permission to keep, where to park, what the client asked for last time, which products they prefer, whether the dog is friendly.
A word about codes, because a note is a weak place to keep one. Where a client has asked you to keep a gate or keysafe code, it is theirs to give and you may record it. Understand what you are relying on when you do. A note is ordinary text, not a password vault: it is readable by everyone on your team (clause 7.4) and it appears in any export you take. Prefer the least revealing thing that still gets you in, for example "code on file, call before arriving" or a keysafe location without the combination. If you do record a code, ask the client to change it when the work ends, and take it out of the note when you no longer need it. Never record an alarm code, a house alarm PIN or a password, whatever permission you have been given: those protect more than a gate, and the consequence of losing one is not proportionate to the convenience of storing it.
7.3 What does not belong in a note
- Anything in the sensitive categories in section 6.7. A note is the single most common place health information ends up by accident, usually as an explanation for why an appointment moved. Do not write it down.
- Opinions about a person that you would not say to their face. "Difficult customer, watch out" is personal information, it is a statement about that person, and it can be requested, disputed and quoted back at you.
- Information about someone other than the client, such as a neighbour, an ex partner, an employee or a family member. That is a third person's information in a record they cannot see and cannot correct, and it also makes it harder for everyone if the client asks for access, because their record now contains someone else's details.
- Financial details you do not need. Never record full card numbers. Glo never sees or stores card numbers by design, and typing one into a notes field defeats that on purpose.
- Passwords, alarm codes or keysafe codes that you have not been asked to keep.
7.4 Notes are not hidden from your team
Everyone you invite into your account can read the notes on a client record. If a note is something you would not want your team reading, do not write it.
7.5 Receipt images
The Finances module lets you attach a photo of a receipt to an expense. The image is stored with the expense, and it is included in your exports.
A receipt photo often contains more than the receipt. A supplier docket can carry a name, a card's last four digits, a loyalty number, a signature, a delivery address, or a staff member's name. A photo taken quickly on a phone can catch something else on the desk, a screen, or a piece of paper next to it.
So, before you upload:
- Look at what is actually in the frame.
- Crop out anything that is not the receipt.
- Do not upload documents that are not receipts, such as identity documents, medical paperwork, bank statements or anything relating to an employee.
Everything in section 6.7 applies to the contents of an image just as it applies to a typed field. An uploaded photograph of a Medicare card is exactly the thing section 6.7 is asking you not to do.
7.6 We do not read your notes or your receipts
We do not read, mine, analyse or use the content of your notes, your messages or your receipt images for our own purposes. What we can see from our side does not include them, as section 6.10 says. We reach them only where you have asked us to help you with a specific problem, or where the law requires us to, and we do not do it by signing in as you.
8. Marketing: the rules that apply to what you send
The Spam Act 2003 (Cth) applies to your business directly. It is not something we can comply with on your behalf, and it is not something you can outsource to us.
It also applies to us. The Act catches anyone who sends a message or causes one to be sent, so when the Service sends on your behalf we are liable alongside you, not instead of you. That is why this is a rule in this policy and not just friendly advice, and it is why section 8.9 matters to both of us.
This section tells you what the Act requires, in the language of a small business.
8.1 What counts as marketing
A message is a commercial electronic message if one of its purposes is to offer, advertise or promote goods or services. Not the main purpose. One of them.
That test catches more than people expect:
- A message that is ninety per cent factual and ten per cent promotional is entirely commercial. There is no small print exception.
- A link in the message counts as part of the message. If a booking confirmation links to a page listing your packages and prices, that link can make the whole message commercial.
- What you call the message makes no difference. Calling something a "notification" does not change what it is.
8.2 Booking a job is not consent to be marketed to
This is the one that catches small businesses.
A client books a job, gives you their mobile so you can tell them when you are coming, and gets a receipt. That is not consent to send them a "time for your next booking" offer. The regulator has said so specifically, including where the contact details were collected in order to send a receipt or a tax invoice.
If you want to send offers, you need consent for that, captured separately, and you need to be able to prove you have it. A pre-ticked box is not consent. A tick box that bundles several different things together is not consent. Sending someone a message to ask for consent is itself a marketing message, so you cannot do that either.
8.3 The opt-in field in Glo, and what it means
Every client record in Glo has a marketing opt-in setting. It is off by default, for every client, and it is off deliberately. Nothing in the booking flow turns it on quietly.
Only turn it on when the client has actually agreed, and record how and when they agreed. If a client asks to stop hearing from you, turn it off. Under the Spam Act, a withdrawal of consent takes effect at the end of five business days beginning on the day it is sent, which is the Act's own term for it. The regulator's public guidance renders the same rule as "five working days", and it is the same rule either way. Act on it promptly and do not send anything else to that person in the meantime.
8.4 Do not use Glo to send unsolicited commercial messages
Whatever ways of sending we provide now or later, by email, by text message, by push notification or otherwise, you must not use them to send commercial messages to people who have not consented. That includes:
- messaging a client through the Service with an offer, when they only ever consented to messages about their booking;
- loading a purchased, scraped, swapped or inherited contact list into Glo and messaging it;
- using contact details you obtained through Glo to market somewhere else, such as by exporting them into a bulk email tool.
The last one matters: taking the details out of Glo first does not change the rules that apply to them.
8.5 Keep the automatic messages transactional
The messages the Service sends for you are transactional. The complete list today is: a booking received notice, a booking accepted notice, a booking declined notice, a change to a price, a change to a time, a job completed notice, a payment received notice, a refund notice, a cancellation notice, the one email telling your client that a reply is waiting for them, and the one email offering another time after a checkout that was never finished.
Each of the last two is sent once and never again, once per conversation and once per booking respectively, and the reply-waiting email says so in the message itself.
Two of the list are commercial messages, and we treat them as such. The unfinished-checkout email and the one sent when you turn a booking down both invite your client to pick another time and link to your price list, which is enough to make them commercial electronic messages under the Spam Act. So both carry a working unsubscribe, in the message and in the headers your client's email app reads, and an address that has used it is never sent either of them again by your business. You do not have to do anything to make that happen and you cannot turn it off.
Every other message in the list carries no promotion, tells your client a fact about their own booking, and is sent without marketing consent for that reason.
Do not put promotions into any of them. Several fields you control appear in the messages we send or in the pages they link to, including your business description, your own terms, your cancellation policy and anything you write in a message thread. If you use one of those fields to advertise a special offer, the message stops being transactional and becomes a commercial message, and all of the consent, identification and unsubscribe rules apply to it. That would change the character of every automatic message your business sends.
8.6 Identify yourself, and give a working way out
Any commercial message you send must:
- accurately identify your business as the sender, with contact details that will still work at least 30 days later. It must name you, not us. We are the software that sent it; you are the business that authorised it, and the law asks who authorised it;
- include an unsubscribe option that works, presented clearly, and it must keep working for at least 30 days after the message goes out;
- be free and simple to unsubscribe from. No premium rate numbers, no charges, no requirement to create an account or log in, and no requirement to give any personal information other than the address the message went to;
- be actioned when someone opts out, in all cases within five business days, which is the statutory maximum, and sooner if you can.
8.7 Text messages
Where we provide a way to send a text message through the Service, additional rules apply because of how text messaging works in Australia.
If messages go out under an alphanumeric sender name rather than a mobile number,
the recipient cannot reply STOP to it. A sender name is not a phone number and
cannot receive anything. That means the opt-out has to be somewhere the recipient
can actually reach, and the SMS Terms at /legal/sms set out the arrangements.
Glo sends four text messages on a business's behalf, when a booking is confirmed, cancelled or changed, and when a business sends a client the quote they asked for. See our SMS Terms.
8.8 You have to be able to prove consent
If a regulator asks, the burden of proving consent falls on the business that sent the message. Keep a record of who consented, when, how, and to what. That record is worth more than any assurance from us, from a marketing tool, or from whoever gave you the list.
8.9 If we receive a complaint
If we receive a spam complaint, or a regulator contacts us, about messages sent from your account, we will tell you, tell you what has been said, and ask you for your side of it before we do anything, unless the law requires us to act immediately. Section 12 governs what we can then do.
9. Using the Finances module properly
9.1 The documents are yours
An invoice, adjustment note or quote issued from your Glo account is your document. It carries your business name, your ABN and your numbers. Our name is not on it, apart from a small "Made with Glo" mark that cannot be mistaken for us being a party to the transaction.
9.2 Your ABN and your GST status are yours to get right
You enter your own ABN and you tell Glo whether you are registered for GST. We do not verify either, and we do not decide either. Everything the module produces follows from what you entered.
Two consequences worth being blunt about:
- If you tell Glo you are GST registered when you are not, your invoices will show a GST line you are not entitled to charge. That is a problem with the tax office, and it is yours.
- If your ABN is wrong or out of date, your tax invoices are not compliant, and your customers may not be able to claim what they should be able to claim.
Check both when you set up, and check them again if anything about your registration changes.
9.3 Do not issue a document you know to be wrong
Do not issue an invoice, adjustment note, quote or report that you know misstates what was supplied, what was charged, what was paid, or what tax applies. Do not issue a tax invoice for a sale that did not happen. Do not back-date a document to a period it does not belong to.
Issued documents in Glo cannot be edited or deleted. That is deliberate and it protects you: it is what makes your records credible to an accountant, to a customer and to the tax office. If something is wrong, you correct it the proper way, with an adjustment note or by voiding the document, and the original stays visible. Do not try to work around that by any other means.
9.4 Do not represent a Glo report as an ATO document
Glo never lodges anything with the ATO, has no connection to ATO systems, and receives no approval from the ATO for anything it produces.
So do not tell anyone, and do not imply to anyone, that a report or document produced by Glo has been lodged with, checked by, approved by, or accepted by the ATO. It has not.
The GST summary in the module is a worksheet. It totals the figures you recorded, on the basis you selected, over the period you chose. It is there to help you or your accountant prepare a lodgement. It is not a lodgement, and it is not a substitute for one. Every report states the basis it was prepared on, for exactly that reason.
9.5 We do not give tax advice, and the module does not either
Glo is a tool for recording what happened in your business. It is not a tax agent and it is not a BAS agent.
- Expense categories organise your spending. They do not tell you what is deductible.
- The vehicle logbook records the trips and the kilometres you enter. It does not apply a cents per kilometre rate, does not calculate a claim, and does not tell you what you may deduct.
- Nothing in the Service is advice about your tax position.
If you want to know how a particular transaction should be treated, ask a registered tax agent or BAS agent. This limit is not us being unhelpful: giving that advice for a fee without registration is against the law, and a tool that pretended otherwise would be doing you no favours.
9.6 Your work is your work, and your contract with your client is yours
When your client pays you through Glo, the money goes into your payment account. It does not pass through ours, and we take no cut of it. You set your prices, you write your own terms and your own cancellation policy, you set your own deposit and cancellation window, and you do the work.
That means we are not the seller of the services you supply to your clients, we are not a party to your contract with your client, and we do not decide disputes between you and your client about the work, a deposit or a refund. Those are yours to resolve. This is stated as plainly as we can put it because if a client ever complains to us about a job you did, we will tell them the same thing and point them back to you.
9.7 Your records are your obligation, and we have built for it
Australian businesses must keep their business records for at least five years, in English, and be able to get at them. That is your obligation, not ours.
We have built two things so that a problem with your subscription can never stop you meeting it:
- A complete export of your financial records, emailed to the account owner's address without you having to ask for it. The Terms of Service commit to that on two events: your billing settles into unpaid and Finances locks, and a downgrade to a Plan that no longer includes issuing new invoices. It is not sent automatically when you cancel part way through a period you have paid for, when we restrict your account under section 12, when the agreement ends, or when you close your account. In each of those situations we send you the same export by hand, before your access changes.
- A permanent, free download of your records inside your account, at
/dashboard/finances/records, which is not tied to your subscription and keeps working while your account is locked.
Clause 14.6 and clause 14.7 of the Terms of Service set both of those out in full.
One thing to add on your side: do not treat Glo as the only copy of your business records. Download your records periodically and keep a copy somewhere you control. That is good practice with any software, and it is the reason we built the download to be free and permanent rather than something you have to ask for.
10. Keeping your account secure
10.1 Look after your login
Keep your password to yourself. Do not write it where others can find it, do not reuse it on other sites, and do not share it with anyone, including us. We will never ask you for your password.
Glo requires a strong password, and it will tell you what it needs when you set one.
10.2 One login per person
Give everyone on your team their own login. Do not share a single login between people.
Shared logins are worth avoiding for a practical reason as much as a security one: the audit log records who did what, and we can tell you who did what when you ask. A shared login makes it record nothing useful. When you need to know who changed a price or cancelled a booking, a shared login is the difference between an answer and an argument.
10.3 Remove people when they leave
When someone leaves your business, remove or disable them in Glo the same day.
When you do, their access ends promptly. They do not stay signed in on their phone, and closing the laptop lid does not keep them in.
Removing a person's access does not delete anything they created. Their bookings, notes and invoices stay in your records.
10.4 Treat the links you send as keys
The links the Service sends to your clients, for tracking a booking, viewing an invoice or viewing a quote, are unguessable by design. Anyone who has the link can open the page, which is the point: your client should not have to create an account to see their own invoice.
So treat them accordingly. Do not post them publicly, do not put them in a shared document, and do not forward one client's link to a different client. If you think a link has gone to the wrong person, tell us.
10.5 Tell us if something looks wrong
If you think someone has got into your account, or into your team's, or you see something in your account you cannot explain, email us at hello@welcomeglo.com promptly. Change the password as well, but tell us either way.
Prompt beats certain. We would much rather look at something that turns out to be nothing than hear about a real problem three weeks later.
10.6 Keep your own equipment in order
Your devices, your internet connection and your email accounts are yours to look after. If we publish a Glo App, keep it reasonably up to date, since we may stop supporting older versions after giving reasonable notice, particularly when a phone operating system changes.
10.7 What we do on our side
We take security seriously and maintain measures appropriate to the information we hold, including controls on who can access it, encrypted connections, and separation between the records of different businesses. Passwords are stored in a form that cannot be read back. We keep an append-only audit log, and we can send you your own entries when you ask, as section 6.10 explains. The database and the systems that run the Service are hosted in Sydney.
There is no tracking pixel on your dashboard, on your booking page, or on the
tracking, invoice, quote and unsubscribe pages your clients open, and none on the
legal pages at /legal either. None of those pages carries an
advertising tag, or a third party script of any kind, and the pages your clients open
never will. Our public marketing pages, where we advertise Glo to detailing
businesses, may carry an advertising tag, and they are the only Glo pages that ever
carry one. Our Cookie Policy at /legal/cookies is where that is
set out in full.
No system can be guaranteed completely secure. If you believe your account or your information has been affected, email hello@welcomeglo.com and we will treat it as a priority.
Our Privacy Policy sets out the detail, including which of our providers are United States companies and which of them process information outside Australia.
11. Reporting a security problem
If you have found a security issue in Glo, we want to hear about it, and we will treat you well for telling us.
11.1 How to report
Email hello@welcomeglo.com with "Security" in the subject line. Please include:
- what you found, and where;
- the steps to reproduce it;
- what an attacker could do with it; and
- how we can contact you.
Please do not post it publicly first, and please do not include other people's personal information in your report. A description is enough. If you need to show us a record to prove the point, tell us it exists rather than sending it.
11.2 What we commit to
If you report in good faith, as described in 11.3:
- We will acknowledge your report within 5 business days.
- We will tell you what we plan to do about it within 20 business days, and keep you posted until it is closed.
- We will not take legal action against you, and we will not ask anyone else to. We will not report you to the police or to a regulator for the research itself, and if a third party brings action against you over research that stayed inside these rules, we will say publicly that it was authorised.
- We will credit you by name when we fix it, if you want the credit. If you would rather stay anonymous, that is fine too.
Two limits on that promise. We can only speak for ourselves: we cannot give you permission to test systems belonging to our hosting, database, payment or email providers, and this commitment does not bind them. And we do not pay bounties. There is no reward programme.
11.3 What "good faith" means here
Your report is in good faith, and section 11.2 applies, if all of this is true:
- You only used your own account and your own test data. You did not access, modify, download or keep any other business's data, or any real person's personal information. If you came across someone else's data by accident, you stopped immediately, told us, and did not keep a copy.
- You stopped at proof. Once you had enough to show the issue exists, you stopped. You did not go further to see what else you could reach.
- You did not break, degrade or interrupt the Service. No denial of service, no load or stress testing, no deleting or altering data, no spam, no mass account creation.
- You did not attack people. No phishing, no social engineering of us, of our customers or of our providers, and nothing physical.
- You did not use anyone's credentials but your own, and you did not use credentials found elsewhere.
- You gave us reasonable time before going public, which we take to be 90 days from your report, or sooner if we have fixed it and agreed with you. If you think the public needs to know sooner, talk to us and we will work it out.
- You did not demand payment in exchange for telling us, or for not publishing.
- You complied with the law.
11.4 Testing without permission is still a breach
If you test outside these rules, section 4.5 applies and section 12 applies with it. The safe harbour in 11.2 is tied to the conditions in 11.3, and there is no version of it that covers taking someone's data.
11.5 If you are a customer reporting something you noticed
You do not need to be a researcher to use this section. If you saw something odd in your own account, something that looked like another business's information, or an email that arrived when it should not have, just tell us. That is a report, it counts, and nothing about it puts you at risk.
12. What happens if this policy is broken
This section is written to be fair, and to be seen to be fair. Read it as a protection: it tells you exactly what we can do, what we cannot do, what warning you get, and how to push back.
12.1 We start with the smallest thing that fixes the problem
Our response must be proportionate to what has actually happened. We will take the least restrictive step on this list that deals with the problem, and we will not take a more restrictive step while a less restrictive one would work. The list is:
- We contact you and ask about it.
- We ask you to fix it, and say what fixing it looks like.
- We restrict the specific thing causing the problem, and nothing else.
- We restrict your account's ability to make changes.
- We suspend access.
- We end the agreement, under the Terms of Service.
We do not skip steps because it is easier. If we do take a step further down the list, we will tell you in writing why the step above it would not have worked.
12.2 You get told, and you get a chance to fix it
Except in the situations listed in 12.3, before we restrict, suspend or terminate anything we will:
- email you, at the address on your account;
- tell you specifically what we say has happened, and which part of this policy or the Terms it relates to;
- give you at least 14 days to fix it or to tell us we have it wrong; and
- take no step you cannot undo before that period has ended.
If you fix it within that period, that is the end of it.
12.3 When we can act immediately
We can restrict or suspend access without the notice period in 12.2 only in these situations, and no others:
- there is a genuine and immediate security threat to the Service, to your data or to another customer's data;
- the Service is being used to break the law;
- there is a real and immediate risk of harm to a person;
- a court, a regulator or a law requires us to act; or
- a provider the Service depends on has required us to act and there is no lawful way to keep the Service running otherwise. If that happens we restrict only what that provider actually requires, we tell you what was required and by whom, we lift it the moment it is resolved, and we refund the part of your subscription covering the time you were restricted.
This list is closed. There is no "and anything similar" at the end of it. It is the same closed list as clause 11.4 of the Terms of Service, deliberately, so that this policy can never assert a power the Terms do not give us.
If we do act immediately, we will email you within two business days telling you what we did, why, which of the five situations above we say applies, and what has to happen for it to be lifted.
12.4 What a restriction never does
Whatever step we take:
- We do not delete your data as a penalty. Not your bookings, not your clients, not your invoices, not your receipts.
- Your records download keeps working, and your export still comes. The free
records download at
/dashboard/finances/recordsis not affected by any step in this section, and we send you a complete export of your financial records by hand before your access changes, as section 9.7 explains. If a restriction ever meant you could not get your records out, tell us and we will fix it, because that is not the intention and it is not what the Terms allow. - We do not charge you a fee to be reinstated. No reactivation fee, no administration fee, no penalty of any kind.
- We restrict the narrowest thing that works. Where the problem does not involve your clients, we leave your booking page and your clients' tracking pages running. Your clients should not lose their appointment because of an argument between us.
We also have a built-in step that restricts changes without locking anybody out: your team can still sign in and see everything, nothing can be changed, and your booking page tells visitors to contact you directly. We built it that way on purpose, because a business in a dispute still needs the phone number of the client they are seeing this afternoon.
12.5 We do not decide what these documents mean
We will not rely on a claim that you have broken this policy unless we can point to what you did and to the part of the policy it relates to. We do not have the final say on what these documents mean. A court does.
12.6 Your right to have it looked at again
If we restrict, suspend or terminate anything, you can ask us to review it. Reply to the email we sent you, or write to hello@welcomeglo.com, and tell us why you think we have it wrong.
We will look at it again properly, with what you have said in front of us, and give you a written answer within 10 business days. If we got it wrong, we undo it, and if the mistake cost you paid-for access, we refund that part of what you paid.
None of this takes away any other right you have. You can complain to a regulator, take the matter to a court, or seek advice, at any time, and you do not have to use our review process first. Depending on what the complaint is about, the relevant bodies include the Australian Competition and Consumer Commission, your state or territory fair trading or consumer affairs office, the Office of the Australian Information Commissioner for privacy matters, and the Australian Communications and Media Authority for spam and text messaging matters.
12.7 Ending the agreement
Ending the agreement is governed by the Terms of Service, not by this policy, and the notice, cure period, export and refund provisions there apply. This policy does not create any additional right for us to terminate.
12.8 If we get it wrong
If we suspend or restrict your account and it turns out we should not have, we restore access immediately, refund the part of your subscription covering the time you were locked out, and tell you in writing what happened.
12.9 A restriction does not last indefinitely
We lift any restriction or suspension as soon as the problem that caused it is resolved, and we tell you the same day.
If a restriction under this policy has run for 60 days and the problem is still not resolved, we will either lift it or end the agreement under the Terms of Service, with the notice, the export and the refund that the Terms require. Nobody sits in limbo. Clause 11.4 of the Terms carries the same 60 day maximum.
13. Reporting a problem with someone else's use of Glo
13.1 How to report
If you think someone is using Glo in a way that breaks this policy, email hello@welcomeglo.com. Please tell us what you saw, where you saw it, when, and any link involved. If you are reporting content on a booking page, an invoice or a quote, include the link.
13.2 What we do with a report
We will acknowledge it, look into it, and take whatever step in section 12 is proportionate. Where we can, we will tell you the outcome, though sometimes we cannot say much about another business's account.
13.3 We keep the reporter's details to ourselves
We will not pass your identity to the person you reported unless you agree, or the law requires it.
13.4 What we cannot help with
We cannot resolve a dispute between a business using Glo and its customer about the work itself: the quality of a job, a price, a deposit, a cancellation fee or a refund. We are not a party to that contract, we do not handle the money, and we do not decide who is right.
That does not mean the client has no rights. Under the Australian Consumer Law the business must do the work with due care and skill, fit for the purpose the client told them about, and within a reasonable time. If it fails, the client may be entitled to have it fixed, done again, or to compensation, and for a major failure the choice is theirs. Those rights are against the business, they are real, and nothing on this page touches them.
So take it up with the business directly, and if that does not work, your state or territory fair trading or consumer affairs office and the Australian Competition and Consumer Commission can help.
We will act on unlawful use of Glo, on misuse of personal information, and on security problems. Those are ours.
13.5 If someone is in danger
If you believe someone is in immediate danger, call 000. Do not wait for us.
14. Changes to this policy
14.1 We will tell you before we change it
We may need to update this policy, for example when the law changes, when we add a feature, or when we find a rule that is not doing its job.
If a change materially affects you, we will give you at least 30 days notice, by email to the address on your account and in the Service, before it takes effect. We will tell you what has changed, not just that something has.
A change that takes nothing away from you takes effect as soon as we publish it. Correcting an error, making a rule clearer, and adding a feature or a protection. It still gets a new version number and effective date, and we still say what changed. The 30 days is for a change that takes something away from you, and where it is not obvious which kind a change is we treat it as the kind that needs the 30 days. That call is not ours to make in our own favour.
14.2 If you do not accept a change
If you do not accept a change that materially affects you, you can cancel before it takes effect and we will refund the unused part of anything you have already paid. You do not have to give a reason, and there is no fee.
14.3 Changes we may have to make immediately
We may make a change immediately where the law requires it, or where it is necessary to deal with a genuine and immediate security problem. If we do, we will tell you as soon as we can and explain why.
You may then cancel within 30 days of that notice, and we will refund the unused part of anything you have already paid. You do not have to give a reason, and there is no fee. We have written it that way because a right to cancel "before it takes effect" is no right at all once the change has already happened.
14.4 What we will not do
We will not change this policy retrospectively to make something you already did a breach.
14.5 Versions
Each published version carries a version number and an effective date at the top of this page. This one is version 1.5. When we change it, we will tell you what changed and not just that something did, and we will give you the previous version if you ask for it.
15. Contact
- General and support: hello@welcomeglo.com
- Privacy, and anything about personal information: hello@welcomeglo.com
- Security reports: hello@welcomeglo.com, with "Security" in the subject line
- By post: Connor Wu trading as Glo, Unit B14, 161 Arthur Street, Homebush West NSW 2140
Related documents. The first five, with the Plan you chose, are the agreement described in clause 1.1:
- Terms of Service,
/legal/terms. The agreement this policy forms part of. - Refunds and Cancellations,
/legal/refunds. First on anything about refunds, cancellations or a failed payment. - Privacy Policy,
/legal/privacy. What we do with personal information. - Data Processing Addendum,
/legal/data-processing. The terms on which we handle personal information about your clients on your behalf. - Cookie Policy,
/legal/cookies. Read as part of the Privacy Policy. - Subprocessors,
/legal/subprocessors. Every provider that handles your data, what it does, and where. Read as part of the Data Processing Addendum.
These two are not part of your agreement with us, because they govern a different relationship:
- Client Terms of Use,
/legal/client-terms. The one your clients are covered by, not this policy. See clause 3.3. - SMS Terms,
/legal/sms. Between us and the person receiving a text. The page clause 8.7 refers to.
Questions about this document?
Email hello@welcomeglo.com.