Privacy Policy
Last updated: [DATE — to set]. This policy is a working draft pending legal review.
This Privacy Policy explains how [Legal Entity], [Jurisdiction] ("we", "us") collects and processes personal data when you use Scheduleit (the "Service"). We are the data controller for the personal data described here. Where you use the Service to process personal data of your own users, you are the controller and we act as your processor under our Data Processing Agreement.
Data we collect
- Account data — name and email address you provide at sign-up, and authentication data (a hashed password).
- Usage and content data — the schedules, endpoints, and (for the email channel) verified recipient addresses you configure, plus delivery metadata (timestamps, status codes, attempt counts).
- Payment data — handled by our reseller and Merchant of Record, Polar. We do not store your card details; we receive limited subscription/status information from Polar.
- Technical data — IP address and request metadata, used for security, abuse prevention, and operating the Service.
Why we process it, and our legal basis
- To provide the Service you asked for (performance of a contract).
- To secure the Service and prevent abuse (legitimate interests).
- To bill and manage subscriptions (contract / legal obligation).
- To communicate with you about the Service and support (contract / legitimate interests).
Retention
We keep account data for the life of your account. Event and delivery records are retained while relevant to operating and supporting your use; dead-lettered delivery records are retained for [30] days. We delete or anonymise personal data when it is no longer needed, subject to legal retention requirements.
Sharing and sub-processors
We share personal data only with the service providers needed to run the Service, listed on our Sub-processors page (database hosting, email delivery, payments, and application hosting). We do not sell personal data.
International transfers
Some sub-processors may process data outside your country. Where required, such transfers are covered by appropriate safeguards (e.g. Standard Contractual Clauses).
Your rights
Subject to applicable law (including the GDPR), you may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent where processing relies on it. To exercise these rights, contact us (below). You may also complain to your local data-protection authority.
Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed credentials, and access controls. No system is perfectly secure; we cannot guarantee absolute security.
Contact
Data controller: [Legal Entity], [Business Address]. Contact privacy@getscheduleit.app or our contact page. [If applicable, name a Data Protection Officer / EU or UK representative here.]