Privacy & Transparency

    Privacy Policy

    This Privacy Policy explains how AISmartBooking collects, uses, and protects your information when you use our scheduling and booking services.

    Who We Are & Controller Status

    The AISmartBooking platform is operated by Haircuts By Stetson ("we", "us", "our"), which is the data controller responsible for personal data processed through the Service.

    For any privacy questions, data access requests, or complaints, contact us at support@aismartbooking.com.

    Information We Collect

    When you use AISmartBooking, we collect information required to provide the scheduling service:

    • Account Data: Name, email, phone number, and (where applicable) billing information.
    • Client Data: Names, contact details, appointment histories, and payment information for clients booking appointments.
    • Technical Data: IP address, device information, and usage statistics for improving the service.

    How We Use Your Information

    We use the information collected exclusively to:

    • Provide and maintain the scheduling and booking services.
    • Bill and administer your software subscription.
    • Send automated appointment reminders and confirmations (SMS/email).
    • Protect against fraud and ensure service security.

    Third-Party Service Providers

    We share data only with essential third-party services necessary to run the platform, including secure cloud infrastructure, email/SMS delivery, payment processors, and (where enabled) Google Calendar for staff calendar sync. These providers process data only to deliver the requested service.

    How We Use Google User Data

    AISmartBooking offers an optional Google Calendar integration so staff members can keep their work appointments and personal calendar in sync. This section explains exactly which Google user data we access, why we access it, and how we protect it.

    Scopes we request and why

    • https://www.googleapis.com/auth/calendar.events — Read existing calendar events to detect conflicts and prevent double-bookings, and create, update, or delete events that correspond to appointments booked through AISmartBooking. This is required so the staff member's Google Calendar accurately reflects their work schedule.
    • https://www.googleapis.com/auth/userinfo.email and openid — Confirm which Google account is being connected so we can attach the integration to the correct staff profile.

    Limited Use compliance

    AISmartBooking's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertisements, we do not sell it, and we do not allow humans to read it except (a) with the user's explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized.

    How we store and protect Google data

    • OAuth refresh and access tokens are encrypted at rest using AES-GCM before being stored.
    • Calendar events created or read on a staff member's behalf are scoped to that staff member's tenant only and are never shared across tenants.
    • Google user data is never sold, rented, or shared with third parties for advertising or unrelated purposes.
    • We do not use Google user data to train generalized AI or machine learning models.

    Retention and revocation

    We retain Google tokens and synced event references only while the integration remains connected. You can revoke AISmartBooking's access at any time by:

    Once revoked, stored tokens are deleted and no further calendar data is accessed.

    Legal Basis for Processing

    We process personal data on the following legal bases:

    • Performance of a contract — to provide the Service you have subscribed to (account creation, bookings, notifications, billing).
    • Legitimate interests — to secure the Service, prevent fraud and abuse, and improve product quality.
    • Consent — for optional integrations (such as Google Calendar) and non-essential communications, which you can withdraw at any time.
    • Legal obligation — where we are required to retain records or respond to lawful requests.

    Payments — Paddle as Merchant of Record

    Our order process is conducted by our online reseller Paddle.com. Paddle is the Merchant of Record for all our orders. Paddle provides all customer service inquiries related to billing and handles returns, refunds, chargebacks, and tax compliance.

    When you purchase a subscription, personal and payment data (such as name, email, billing address, and card details) is collected and processed by Paddle in its role as an independent data controller for payment processing, in accordance with Paddle's own privacy notice available at paddle.com/legal/privacy. We receive limited transaction metadata from Paddle (such as subscription status, plan, and last four digits of the card) to operate your account.

    Data Retention

    We retain personal data only for as long as needed to provide the Service and to meet legal, accounting, or reporting obligations:

    • Account and tenant data — for the life of your account, and up to 12 months after account closure, after which it is deleted or anonymized.
    • Booking and client records — retained while your account is active; you can request earlier deletion subject to tax/accounting retention requirements.
    • Billing records — retained for the period required by applicable tax law (typically 6–10 years); billing data held by Paddle is retained per Paddle's policy.
    • Support communications and logs — up to 24 months.
    • OAuth tokens (e.g., Google Calendar) — deleted immediately upon disconnection or revocation.

    Data Rights and Contact

    You have the right to access, correct, or delete your personal data. For privacy requests or questions about this policy, please contact us:

    support@aismartbooking.com

    This Privacy Policy was last updated on December 2025.

    We may update this policy periodically to reflect changes in our services or legal requirements.

    ← Back to Home