Skip to content
SameDay Co

Privacy

Privacy, in plain English

What SameDay Co collects, why, who else sees it, how long it is kept, and what you can require us to do about it.

Last updated 27 August 2026.

Who this is, and what it covers

SameDay Co runs Meta and Google advertising for chiropractic clinics in New Zealand. Operated by Bishal Barua, who is the agency responsible under the Privacy Act 2020 for the personal information described here.

This policy covers samedayco.com: every page, form, calculator and booking on it. It does not cover the ad accounts we run for a clinic. Those live inside the clinic's own Meta and Google accounts, the clinic owns them, and what happens to the data in them is governed by the clinic's own privacy policy and by Meta's and Google's terms.

Every request in this policy goes to hello@samedayco.com. That address is monitored, and it is the contact route for access, correction, deletion and complaints.

What we collect

All of it is either typed in by you or sent by your browser. None of it is bought from a data broker, scraped, or taken from anywhere other than this site.

  • Free check form: your name, your clinic, your email address, a link to your website or Google Business Profile, and whether you are running ads now. Your phone number and any notes are optional.
  • Fix sheet: your email address, and nothing else.
  • Application form: your name, your email address, your phone number, your clinic and its website, your role, your vertical, your region, whether you run ads now, how many new appointment slots you can take, and what you can invest.
  • Booking calendar: the calendar on the booking page belongs to Cal.com and runs inside a frame on our page. It takes your name, your email address, the slot you pick and anything else you type into it, and it sends that to Cal.com directly rather than through our site.
  • Server side: when a form is submitted, the IP address it came from is held in the server's memory so a single address cannot flood the form. It is counted, not stored: nothing is written to a database, and the entry goes when the server process recycles.
  • When a form fails to send: the contents of that submission are written to our hosting log, so an enquiry is not silently lost during an outage. That is the only circumstance in which form contents are stored anywhere other than email.
  • Measurement: which pages you open on this site, where you arrived from, your device and browser, an approximate location worked out from your IP address, and a short list of named actions. This is set out in full under Cookies and tracking.
  • The invisible field: every form carries a field you cannot see and automated spam scripts fill in. If it comes back filled, the submission is thrown away. Nothing is sent and nothing is stored.

The calculator is the exception

The numbers you type into the ROI calculator never leave your browser. They are not sent to our server, not written to your device, and not visible to us or to anyone else. The maths runs where you are sitting.

The one thing recorded is that the calculator was used at all, with none of your figures attached to it.

Why we collect it

Principle 1 of the Privacy Act 2020 allows an agency to collect personal information only for a lawful purpose connected with what it does, and only where the information is actually necessary for that purpose. Purpose by purpose, here is ours.

  • Form details: to read your enquiry, work out whether we can help, and reply. That is the entire use.
  • The fix sheet address: to send you the sheet you asked for, and to reply if you write back.
  • Booking details: so the call lands in both calendars and you get a confirmation.
  • The IP address: to stop a single source flooding the form. It is not used to identify you and nothing else is done with it.
  • Measurement data: to see which ads and which pages bring clinics here, so the advertising budget goes to the ones that work rather than the ones that feel like they work.

What we do not do with it

There is no CRM, no customer database and no mailing list. Enquiries arrive as email and stay as email, which is the whole of what we hold.

We do not sell, rent or trade personal information, we do not use it to build a profile of you, and we do not pass one clinic's enquiry to another clinic. If the law compels a disclosure, for example a court order, we will comply with it and tell you unless we are legally barred from telling you.

Who else sees it

Five companies receive personal information from this site. There is no sixth.

  • Vercel hosts the site. It sees every request your browser makes, which includes your IP address, and it keeps the server logs. A form that fails to send lands in those logs in full.
  • Resend delivers form submissions to our mailbox as email. It handles whatever the form contained, including your email address, which is also set as the reply address so a reply goes straight back to you.
  • Google receives measurement data through Google Tag Manager, into Google Analytics: the pages you open here, where you arrived from, an approximate location from your IP address, your device and browser, and the named actions listed below.
  • Meta, meaning Facebook and Instagram, receives the same kind of measurement data through the Meta pixel, which Google Tag Manager also loads. If you have a Facebook or Instagram account, Meta can match this visit to it. That is how we know which Meta ad brought a clinic here.
  • Cal.com runs the booking calendar. It sees your name, your email address, the slot you pick and anything else you type into the calendar, and it sends the confirmation.

Three of them work for us. Two also work for themselves

Vercel, Resend and Cal.com hold information in order to do a job we have asked them to do, and act on our instructions. If we tell them to delete something, it goes.

Google and Meta are not the same. They receive measurement data and they also use it for their own purposes under their own terms, which we do not set and cannot undo after the fact. That is the honest position, and it is why the opt-outs below matter more than anything we could promise on their behalf.

Information that goes overseas

Vercel, Resend, Google, Meta and Cal.com all store and process data outside New Zealand.

Principle 12 of the Privacy Act 2020 governs personal information that goes to an overseas company. We rely on the data protection terms each of these companies publishes and contracts on. Those protections are not identical to New Zealand law, and information held by Google or Meta is subject to the laws of the countries they operate in.

You have a way out of each. To keep measurement data away from Google and Meta, use the opt-outs below: they stop the data before it is sent, rather than asking for it back afterwards. To keep an enquiry away from Vercel, Resend and Cal.com, do not use the form or the calendar. Email hello@samedayco.com instead and it will be answered the same way.

Cookies and tracking

The site loads Google Tag Manager, and Tag Manager loads two things: Google Analytics and the Meta pixel. Both set cookies in your browser.

There is no cookie banner on this site. New Zealand has no cookie consent requirement of the kind the European Union has, so a banner here would be theatre rather than consent. The opt-outs are set out in full instead, which is the part that actually changes what is collected.

  • Google Analytics cookies give your browser a random identifier, so three visits from the same browser are counted once rather than as three separate visitors.
  • Meta pixel cookies let Meta connect this visit to a Facebook or Instagram account, and to an ad you may have clicked to get here.
  • Cal.com sets its own cookies inside the calendar frame on the booking page, under Cal.com's policy rather than ours.
  • None of these cookies carry your name, your email address or your phone number. Your browser's site settings will show you exactly which ones are set.

The actions the tags record

Both tags record a page view every time you open a page here, including when the site moves between pages without a full reload.

On top of that, eight named actions are reported to Google Analytics: submitting the free check form, asking for the fix sheet, using the calculator, submitting an application, an application that meets our criteria, booking a call, clicking our email address, and clicking a main button through to the free check, application or booking page. Seven of those eight also go to Meta. Clicking a main button goes to Google only, and Meta is told one thing Google is not told separately: that you opened the system page or the results page.

What travels with an action is the kind of action it was, a number we use to rank one action against another, and for a button or email click, the words on the link and where it pointed. None of them carries your name, your email address or your phone number.

Two features are deliberately switched off. Meta advanced matching and Google enhanced conversions both work by sending a scrambled copy of your email address and phone number so the platform can match you to an account it already holds. Neither is enabled here. No name, no email address and no phone number reaches Google or Meta from this site.

How to stop the tracking

Any one of these works on its own, and they can be combined.

  • Block or delete cookies in your browser's settings, or use a browser with tracking protection turned on by default. That stops both tags.
  • Install Google's own opt-out add-on, which switches off Google Analytics on every site you visit, not only this one.
  • Change the ad preferences on your Meta account, which controls how Meta uses what it collects about you.

Do Not Track

Your browser may have a Do Not Track setting. Neither Google nor Meta acts on it, so switching it on will not stop either tag here. We would rather say that plainly than let the setting do nothing while you assume it is working. Use the opt-outs above instead.

How long it is kept

What we hold: enquiries and booking confirmations sit in our email mailbox. They are kept while we are talking and afterwards as the record of that conversation. Ask us to delete yours and we will, and the reply will confirm it is done.

We keep no database of our own and no backup archive, so deleting the email is the whole of what is in our hands.

What the others hold: each of the five keeps what it holds under its own retention rules, which we do not set. The exception is Google Analytics, where the retention period is a setting on our own analytics property.

How it is kept safe

The site is served over an encrypted connection throughout. The key that lets it send email is held as a server setting and never reaches your browser. The form is rate limited, so a single source cannot submit it repeatedly.

There is no customer database here, which removes the thing an attacker would normally be after.

No system is perfectly safe. If personal information held here were lost or exposed in a way likely to cause you serious harm, the Privacy Act 2020 requires us to notify you and the Office of the Privacy Commissioner, and we will.

Your rights: access and correction

Principles 6 and 7 of the Privacy Act 2020 give you two rights over personal information an agency holds about you. Both are free to use, and you do not need a lawyer or a form.

  • Access, principle 6: email and ask what is held about you. We will acknowledge quickly and answer in full within 20 working days, which is the limit the Act sets. There is no charge.
  • Correction, principle 7: tell us what is wrong and what it should say, and we will fix it. If we do not agree that it is wrong, you can require us to attach a statement of the correction you asked for, and we will attach it so that anyone who sees the information sees your version alongside it.
  • Deletion: the Privacy Act 2020 does not give a general right to erasure. We will delete what we hold if you ask anyway. That is a promise we are making, not a legal minimum we are meeting.
  • Proving it is you: a request from the email address we already hold is enough. If you no longer have that address, identifying the enquiry will do.

If you are not happy with how this went

Tell us first. Email hello@samedayco.com with what happened, and you will get a reply from the same address that answers everything else.

If that does not settle it, complain to the Office of the Privacy Commissioner. It is free, it does not need a lawyer, and it is the regulator that enforces the Privacy Act 2020. The Commissioner will usually ask that you have raised the matter with us first.

Children

This site sells an advertising service to clinic owners. It is not aimed at children, and nothing on it is built to appeal to them. We do not knowingly collect personal information from anyone under 16. If you believe a child has sent something through this site, email hello@samedayco.com and it will be deleted.

When this policy changes

The date at the top changes whenever this page does, and the change ships at the same time as the thing it describes. If a new company starts receiving personal information from this site, it is named here in the same release that switches it on, not in a tidy-up afterwards.

That is a working rule, not a sentiment: the code that loads the tags carries a note saying the same thing, so the next person to add one is told before they add it.

Contact

Email hello@samedayco.com. That is the address for an access request, a correction, a deletion, a complaint, or a question about who holds what.

Operated by Bishal Barua.