Privacy Policy
This Privacy Policy explains how SchedMate (“we”, “us”, “our”) collects, uses, and protects information when you use our website and platform. By using SchedMate, you agree to the practices described here.
1. Information We Collect
- Account information: name, email, password (stored securely via our auth provider), and business details you provide.
- Workspace data: client records, bookings, notes, services, invoices, and related data you store inside SchedMate.
- Usage and diagnostics: pages viewed, product actions, timestamps, campaign tags, referring website hostname, and basic device/browser diagnostics. SchedMate’s first-party growth analytics table does not store IP addresses or full referring URLs.
- Billing information: subscription status and payment metadata from our payment provider (we do not store full card details).
- Support communications: messages you send to support (and related technical details needed to help you).
2. How We Use Information
We use your information to:
- Provide and operate SchedMate features (scheduling, client management, invoices, payments, reporting).
- Authenticate users, maintain security, and prevent fraud/abuse.
- Improve performance, reliability, and user experience.
- Provide customer support and respond to requests.
- Process subscriptions and billing (when applicable).
- Comply with legal obligations and enforce our Terms.
3. Cookies, Local Storage & Analytics
SchedMate uses local storage and similar browser storage to keep you signed in, remember settings, maintain a random analytics session identifier, preserve first-touch campaign attribution, and help the product work correctly. Our first-party growth analytics does not use advertising cookies or browser fingerprinting.
First-Party Product Analytics
We collect limited events such as homepage views, trial-button clicks, signup progress, dashboard visits, first service or booking creation, booking-link publication, upgrade attempts, and system error codes. This helps us understand where users need help and whether the product is working. We do not place client names, client emails, phone numbers, booking notes, invoice contents, passwords, payment details, IP addresses, or full referring URLs in the growth analytics event table.
Campaign parameters such as utm_source and utm_campaign may be retained with the first visit.
Only the hostname of an external referring site may be stored. Analytics events are automatically removed after approximately
180 days, and account-linked events are removed when the associated SchedMate account is permanently deleted.
Infrastructure Analytics and Security Logs
Hosting, authentication, database, and security providers may process network information such as IP addresses in their own operational logs to deliver and protect the service. SchedMate does not copy those addresses into its first-party growth analytics table. Cloudflare Web Analytics may also provide aggregate traffic and performance measurements.
Advertising Measurement
We may enable advertising measurement tools, such as Meta conversion measurement, for a specific campaign in the future. When such a tool is enabled, we will operate it subject to its provider’s policies and any consent requirements that apply. SchedMate does not currently rely on an advertising pixel for the first-party funnel described above, and we do not sell personal information.
Your Choices
You can clear site storage using your browser controls. Doing so may sign you out, reset preferences, and create a new anonymous analytics session. Blocking storage does not prevent core pages from loading, although some preferences may not persist.
4. Sharing & Service Providers
We may share information with trusted service providers who help us run SchedMate (for example: hosting, authentication, analytics, email delivery, and payment processing). These providers are only permitted to process data for the services they provide to us.
Google Sign-In
SchedMate offers Google Sign-In as an optional way to create an account and sign in. The sign-in flow is handled by Supabase Auth, which is our authentication provider.
- When you choose Google Sign-In, SchedMate receives only the basic account information you authorize during the Google consent step — your email address and basic profile information such as your name.
- The Google Sign-In flow does not request access to your Gmail messages or your Google Calendar, and SchedMate does not read, write, or store data from those services.
- SchedMate does not currently offer a Google Calendar integration. Bookings you create live in your SchedMate workspace only.
- Google Sign-In is optional. You can create an account with an email address and password instead, and you can stop using Google Sign-In at any time by revoking SchedMate's access in your Google account settings.
Third Parties We Work With
- Google: optional sign-in (authentication only, through Supabase Auth). No Gmail or Google Calendar access is requested.
- Cloudflare: website delivery, security, and aggregate performance analytics.
- Meta (Facebook/Instagram): advertising measurement only when expressly enabled for a campaign.
- Payment providers (e.g., PayPal): subscription billing and transaction processing.
- Infrastructure/auth providers (e.g., Supabase): authentication, database, and hosting services.
- Email/support tools: sending service-related messages and support replies.
- Analytics tools (if enabled): product and website analytics to improve performance.
5. Data Retention
We retain information for as long as necessary to provide the service and for legitimate business purposes (such as security, dispute resolution, and compliance). First-party growth analytics events are retained for approximately 180 days. Account-linked analytics is removed when the associated SchedMate account is permanently deleted. You may request deletion of your account, subject to legal and operational limits.
6. Your Rights
- You can update certain account information within your workspace settings (when available).
- You may request deletion of your account by contacting us (see Contact below).
- You may request access/correction of your information where applicable.
- You may opt out of marketing emails at any time (if we send them) using the unsubscribe link or by contacting us.
7. Client Data Responsibility
If you store information about your clients, you are responsible for having permission to store and use that data. You should not store sensitive data unless required for your business and allowed by law.
8. Data Security
We use reasonable administrative, technical, and organizational measures to protect your information. No system is 100% secure, but we work to keep your data safe with access controls and modern hosting practices.
9. International Use
If you access SchedMate from outside your country, your information may be processed in locations where our service providers operate. We take reasonable steps to protect information consistent with this policy.
10. Children’s Privacy
SchedMate is not intended for children under 13. If you believe a child has provided personal information, contact us and we will take appropriate steps.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we may provide notice on the site or in the product. Continued use means you accept the updated policy.
12. Contact
For privacy questions or requests, contact us at: support@getschedmate.com