Privacy Policy

Last Updated: January 18, 2026

Effective: January 18, 2026

Introduction

Welcome to Appointa. This Privacy Policy explains how the entity that owns and operates Appointa (the "Company," "we," "us," or "our"), a Delaware Limited Liability Company, collects, uses, discloses, and protects personal information when you use our website, platform, and related services (collectively, the "Services").

Protecting your privacy is a top priority for us. We are committed to being transparent about the data we collect and how we use it. This policy is designed to help you understand your privacy rights and how to exercise them, in accordance with applicable data protection laws including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable privacy laws.

This Privacy Policy is incorporated into our Terms of Service. By using our Services, you agree to the collection and use of information in accordance with this policy.

1. Scope of This Policy & Our Role

This policy applies to all users of our Services, including:

  • Providers (or Subscribers): Businesses or individuals who subscribe to our Services to manage their appointments.
  • End Customers (or Clients): Individuals who book appointments with Providers through our platform.
  • Website Visitors: Individuals who browse our website.

Understanding Our Role in Data Processing

It is crucial to understand our role in processing your data, which depends on how you interact with our Services:

Appointa as Data Controller: When we collect personal information from Providers to create and manage their accounts, process subscription payments, and communicate with them directly, we act as the Data Controller. This means we determine the purposes and means of processing that data.

Appointa as Data Processor: When Providers use our Services to collect and manage information about their End Customers (e.g., names, contact details, appointment information), the Provider is the Data Controller, and Appointa acts as the Data Processor. We process this data on behalf of and in accordance with the instructions of the Provider.

Important for End Customers: If you are an End Customer, your data is primarily controlled by the Provider with whom you booked an appointment. Any questions or requests regarding your data should first be directed to that Provider. We will assist Providers in responding to such requests as required.

2. Information We Collect

We collect different types of information depending on your interaction with our Services.

2.1. Information You Provide to Us

From Providers:

CategoryExamplesPurpose
Account InformationName, email address, password, business name, business address, phone numberAccount creation and management, customer support, communications
Billing InformationPayment card details, billing address (processed by Stripe)Subscription payment processing
Business ProfileService descriptions, pricing, availability schedules, portfolio images, logosCreating public booking pages and providing the Services
Client/Customer DataNames, email addresses, phone numbers, appointment details of your End CustomersEnabling appointment booking and management on your behalf

From End Customers:

CategoryExamplesPurpose
Booking InformationName, email address, phone numberBooking appointments, sending confirmations and reminders, OTP verification
Appointment DetailsSelected service, date, time, any notes providedFacilitating the appointment with the Provider

2.2. Information We Collect Automatically

When you use our Services, we automatically collect certain information:

Usage Data:

  • Features used and actions taken within the Services
  • Pages and screens viewed
  • Clicks and navigation patterns
  • Date, time, and duration of your activities

Device and Technical Information:

  • IP address, browser type and version
  • Operating system, device type
  • Screen resolution, language and timezone settings

2.3. Information from Third Parties

We may receive information from:

  • Third-party integrations: When you connect your Appointa account with third-party services
  • Payment processors: Transaction status and fraud prevention data from Stripe
  • Analytics providers: Aggregated usage insights

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1. To Provide and Operate the Services

  • Creating and managing your account
  • Processing appointments and bookings
  • Sending transactional communications (confirmations, reminders, OTP codes)
  • Providing customer support
  • Processing subscription payments

3.2. To Improve and Develop the Services

  • Analyzing usage patterns to improve functionality
  • Developing new features and services
  • Conducting research and analytics

3.3. For Security and Protection

  • Detecting and preventing fraud, abuse, and security incidents
  • Protecting the rights, property, and safety of our users
  • Enforcing our Terms of Service
  • Complying with legal obligations

3.4. Legal Basis for Processing (GDPR)

For users in the EEA, UK, and Switzerland, we process personal data based on:

PurposeLegal Basis
Providing the ServicesPerformance of a contract
Processing paymentsPerformance of a contract
Security and fraud preventionLegitimate interests
Analytics and improvementLegitimate interests
Legal complianceLegal obligation
Marketing communicationsConsent

4. How We Share and Disclose Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1. With Service Providers

We share information with third-party vendors who perform services on our behalf. These providers are contractually obligated to protect your data.

4.2. Between Providers and End Customers

  • End Customer booking details are shared with the relevant Provider
  • Provider public business information is displayed to End Customers

4.3. For Legal Reasons

  • To comply with applicable laws, regulations, or legal processes
  • In response to valid requests by public authorities
  • To protect our rights, property, or safety

4.4. In Case of a Business Transfer

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your personal information becomes subject to a different privacy policy.

5. Our Third-Party Service Providers

We use the following third-party service providers:

CategoryProviderPurpose
Cloud InfrastructureSupabase (AWS)Database hosting, authentication, file storage
Payment ProcessingStripeSubscription billing, payment processing
SMS CommunicationsTwilioOTP verification, appointment notifications
Application HostingVercelWeb application hosting
Email DeliveryResendTransactional email delivery
AnalyticsPostHogUsage analytics
Error MonitoringSentryError tracking and debugging
MapsGoogle MapsLocation display on booking pages

6. International Data Transfers

Appointa is headquartered in the United States, and our primary data processing facilities are located in the US and Europe. When you use our Services, your personal information may be transferred to, stored, and processed in countries other than your own.

6.1. Transfers from the EEA, UK, and Switzerland

We ensure transfers are subject to appropriate safeguards:

  • Standard Contractual Clauses (SCCs): We rely on SCCs as a legal mechanism for transfers to countries without an adequacy decision.
  • Adequacy Decisions: Where applicable, we transfer data to countries deemed adequate by the European Commission.
  • Supplementary Measures: We implement additional technical and organizational measures where necessary.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected.

Data CategoryRetention Period
Provider Account DataDuration of account + 3 years
End Customer DataAs instructed by Provider, or until account termination + 30 days
Billing Records7 years (tax/accounting requirements)
Security Logs1 year

8. Data Security

We implement technical and organizational security measures to protect your personal information.

8.1. Technical Measures

  • Encryption in Transit: All data is encrypted using TLS 1.2 or higher
  • Encryption at Rest: Data stored in our databases is encrypted
  • Access Controls: Role-based access on a need-to-know basis
  • Data Isolation: Row Level Security (RLS) ensures Providers only access their own data

8.2. Organizational Measures

  • Comprehensive security policies and procedures
  • Regular employee training on data protection
  • Vendor security assessments
  • Incident response procedures

9. Your Data Protection Rights

Regardless of your location, you may:

  • Access your data: Request information about what personal data we hold
  • Correct your data: Update or correct inaccurate information
  • Delete your data: Request deletion of your personal information
  • Export your data: Receive a copy in a portable format

How to Exercise Your Rights

For Providers: Access and update most information directly through your account settings, or contact us at privacy@appointa.com.

For End Customers: Contact the Provider with whom you booked your appointment, as they are the Data Controller for your information.

Response Time: We respond within 30 days for GDPR and 45 days for CCPA requests.

10. Additional Information for EEA, UK, and Swiss Users (GDPR)

Under the GDPR, you have these additional rights:

  • Right to Restrict Processing: Request restriction under certain conditions
  • Right to Object: Object to processing based on legitimate interests
  • Right to Data Portability: Receive data in a structured, machine-readable format
  • Right to Withdraw Consent: Withdraw consent at any time

Supervisory Authority: You have the right to lodge a complaint with a supervisory authority in your country of residence.

Contact our privacy team at privacy@appointa.com for any data protection inquiries.

11. Additional Information for California Residents (CCPA/CPRA)

We do not sell your personal information as defined by the CCPA.

We do not share your personal information for cross-context behavioral advertising.

Your CCPA Rights

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise your rights, email us at privacy@appointa.com.

12. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Services.

TypePurpose
Strictly NecessaryEssential for authentication and security
FunctionalRemember your preferences and settings
AnalyticsUnderstand how users interact with our Services

You can control cookies through your browser settings. See our Cookie Policy for more details.

13. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe your child has provided us with personal information, please contact us at privacy@appointa.com.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will:

  • Post the updated policy with a new "Last Updated" date
  • Provide notice through email for material changes
  • Your continued use after changes constitutes acceptance

15. Contact Us

If you have any questions about this Privacy Policy, please contact us:


Document Version: 1.0