Privacy Policy

Last updated: May 2026

Template notice: This document is a starting point. Before publicly launching, have it reviewed by counsel and reconciled against your actual data flows (which third parties you send data to, which jurisdictions data is stored in, retention windows, etc.).

1. Who we are

appointments.page ("we", "us") provides a multi-tenant appointment booking platform. This policy explains what information we collect, how we use it, and the choices you have.

2. Information we collect

From tenants (account holders)

  • Account details: name, email, business name, and authentication credentials (via Supabase Auth).
  • Billing details: handled by Stripe; we store a Stripe customer ID and subscription ID, not card numbers.
  • Operational data you create: services, employees, customers, appointments, notifications, and templates.
  • Usage data: requests, errors, and performance metrics (Sentry).

From booking-page visitors (your customers)

  • Information your customer enters into your booking form (typically name, email, phone, and appointment selections).
  • Limited technical metadata (IP, user-agent) needed to operate the booking page and detect abuse.

3. How we use information

  • To operate the Service: store your data, render bookings, send notifications.
  • To process payments and manage subscriptions (via Stripe).
  • To send transactional email (account, booking reminders) via Resend.
  • To detect abuse, debug, and improve the platform.
  • To comply with legal obligations.

We do not sell personal information. We do not use Customer Data to train AI models.

4. Third-party processors

The Service relies on the following sub-processors. A current and more detailed list — including data categories and processing regions — is maintained on our Sub-processors page.

  • Supabase — authentication and Postgres hosting.
  • Vercel — application hosting.
  • Stripe — payment processing.
  • Resend — transactional email.
  • Sentry — error monitoring (optional, only if configured).
  • Google — Calendar sync (only if you connect it).
  • Twilio — SMS reminders (only on plans that include SMS).

5. Data retention

Tenant account data is retained for as long as your account is active. When you delete your account, we delete or anonymize associated data within 30 days, except where retention is required by law (e.g. tax and billing records).

6. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data. Email support@appointments.page to make a request and we will respond within the timeframe required by applicable law.

7. Security

We use TLS for data in transit, encrypt tenant-stored integration credentials at rest, and follow row-level tenant isolation in the database. No system is perfectly secure; report suspected vulnerabilities to support@appointments.page.

8. International data transfers

The Service operates on infrastructure hosted in multiple regions. Your data may be processed in countries other than the one where you reside. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.

9. Changes

We may update this policy. Material changes will be announced via email or in-app notice at least 14 days before they take effect.

10. Contact

Privacy questions or data requests: support@appointments.page.