Privacy Policy
Last updated
SlotPaid is booking software for independent service professionals. This policy explains what personal data we handle, why, and what you can do about it — whether you run a business on SlotPaid (a provider) or book an appointment with one (a client).
The short version: we collect what's needed to run bookings, payments, and reminders. We don't sell personal data, don't show ads, and don't use tracking or advertising cookies.
1. Who we are and our role
SlotPaid is an online service operated by SlotPaid (“SlotPaid,” “we,” “us”). You can reach us at privacy@slotpaid.com.
- For provider accounts and visitors to slotpaid.com, we are the controller: we decide how and why that data is used.
- For client data — the details you enter when booking with a provider, and the notes and history a provider keeps about you — the provider is the controller and SlotPaid processes it on their behalf, under our Data Processing Addendum. If you're a client and want to access, correct, or delete that data, contact the provider you booked with. We'll help them respond, and if you contact us directly we'll pass your request on.
2. Data we collect
Providers and their staff
- Account details: name, email address, and password (stored as a hash by our authentication provider), or your Google account email if you sign in with Google.
- Business profile: business name, booking-page address, logo, accent color, timezone, services and prices, working hours, availability, cancellation policy, reminder settings, and review link.
- Team members: names, emails, schedules, and commission settings for staff you invite.
- Billing: your plan and subscription status. Subscriptions are sold by Polar, our merchant of record, which collects your card and billing details directly — we never see them.
- Payment settings: your payment link, or — if you connect your own Stripe account — a restricted API key (stored encrypted), its last four characters, and the account's name, country, and ID. Your identity and bank details stay with Stripe under your own agreement with them; we never receive them.
- Connected calendars: if you connect Google Calendar or Outlook, we store an encrypted access token and the connected account's email. We read the times you're busy so clients can't book over them, and we create, update, and delete events for your SlotPaid bookings. We don't read the contents of events we didn't create.
Clients (people booking an appointment)
- Contact details: name, email address, and phone number if you provide one.
- Booking details: the service, time, staff member, status, and answers to any questions the provider asks when you book.
- Provider records: notes, tags, custom pricing, referral source, package credits, waitlist requests, and dates such as your first-visit anniversary that the provider keeps about you.
- Payments: you pay the provider directly — through their payment link, or by card on their own Stripe account. For card payments we receive the payment status and a reference to any saved card — never the full card number. For link payments, we store the reference you give us, if any.
- Client account: if you choose to create one for faster rebooking, your login email.
Everyone
- Technical data: IP address, browser and device type, and pages requested, recorded in server logs by our hosting provider for security and troubleshooting.
- Messages: a record of the reminders and notifications we send (channel, time, delivery status).
- Activity history: an audit log of booking changes (created, rescheduled, cancelled, marked no-show) and who made them.
- Support: anything you send us when you contact us.
We don't ask for sensitive data such as health information. Providers can write their own booking questions — see the Terms for what they may and may not collect.
3. How we use data, and our legal bases
- To provide the service — take bookings, check availability, sync calendars, send confirmations and reminders, process payments, and let clients reschedule or cancel. Basis: performing our contract with providers, and the provider's basis for client data.
- To bill providers and keep financial records. Basis: contract and legal obligation.
- To keep SlotPaid secure — prevent fraud and abuse, enforce our Terms, and debug problems. Basis: legitimate interests.
- To contact providers about their account, security, and changes to the service. We'll only send product news if you haven't opted out. Basis: contract and legitimate interests.
- To meet legal obligations such as tax, accounting, and responding to lawful requests.
We don't sell personal data, share it for cross-context behavioral advertising, or use it to train third-party AI models. We never contact a provider's clients for our own marketing.
4. Google and Microsoft account data
SlotPaid's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google and Microsoft calendar data only to prevent double-bookings and keep your SlotPaid bookings in your calendar; we don't use it for advertising, don't sell it, and don't let people read it except with your permission, for security, or where the law requires. You can disconnect a calendar at any time from Settings → Integrations, which deletes the stored token, or revoke access from your Google or Microsoft account.
6. How long we keep data
- Provider accounts: for as long as the account is open. After you close your account we delete or anonymize its data, including your client records, within 30 days, except what we must keep for legal, tax, or dispute reasons.
- Client data: for as long as the provider keeps it, or until their account is closed.
- Backups: deleted data can remain in encrypted backups for up to 30 more days before it's overwritten.
- Payment and billing records: as long as tax and accounting law requires (typically up to 7 years). Polar and Stripe keep their own records under their own policies.
- Server logs: for a limited period set by our hosting provider, usually no more than a few weeks.
7. Security
All traffic is encrypted in transit with TLS. Each provider's data is isolated at the database level with row-level security, so one business can't read another's records. Calendar access tokens are encrypted at rest, and payment card data is handled entirely by Stripe, which is PCI DSS Level 1 certified. Access to production systems is limited to people who need it. No system is perfectly secure; if a breach affects your data we'll notify you and, where required, the relevant authorities.
8. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct inaccurate data;
- delete your data;
- object to or restrict certain processing, or withdraw consent you've given;
- receive your data in a portable format;
- complain to your local data protection authority, or to Morocco's Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), where we are based.
Providers can update most of their data in the dashboard. To close your account, export your data, or make any other request, email privacy@slotpaid.com. We'll respond within 30 days (45 days where US state law allows) and may need to verify your identity first. We won't treat you differently for exercising these rights.
Moroccan law
SlotPaid is based in Morocco and processes personal data in line with Law No. 09-08 on the protection of individuals with regard to the processing of personal data. It gives you the rights above to be informed, to access, to correct, and to object to processing on legitimate grounds.
US state privacy rights
Residents of California and other states with comprehensive privacy laws have the rights above to know, correct, and delete. We don't sell or “share” personal information as those laws define it and don't use sensitive personal information to infer characteristics about you. You can use an authorized agent to make a request on your behalf.
Text messages
Reply STOP to any SlotPaid text message to stop receiving texts from that provider. See our SMS Terms.
9. International transfers
SlotPaid is operated from Morocco, and most of our subprocessors store data in the United States, so your data may be processed outside the country where you live. If you're in the European Economic Area, the UK, or Switzerland, we transfer your data under the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism, with appropriate safeguards. Transfers from Morocco are made in line with Law No. 09-08.
10. Children
Provider accounts are for adults only. SlotPaid isn't directed at children under 16, and we don't knowingly collect their data directly. Some providers, such as tutors, serve minors: in that case a parent or guardian should book on the child's behalf, and the provider is responsible for obtaining any consent the law requires. If you believe a child has given us data without that consent, contact privacy@slotpaid.com and we'll delete it.
12. Changes to this policy
If we make material changes, we'll email providers and update the date above at least 14 days before they take effect. We'll never apply a change to data we already hold in a way that is less protective without your consent where the law requires it.
13. Contact
Questions or requests: privacy@slotpaid.com.