Privacy policy
Last updated October 11, 2026
Draft, not yet reviewed by a lawyer. It describes how [PRODUCT NAME] works today and will be checked before launch.
Who we are
[PRODUCT NAME] is run by [COMPANY LEGAL NAME], [COMPANY ADDRESS], [BUSINESS / VAT NUMBER] (“we”). Questions about privacy: [CONTACT EMAIL].
Our role
For the accounts of businesses and their staff, and for this website, we decide what happens with the data: we are the controller. The details of a business's own customers (who book through its booking page) belong to that business: it is the controller and we process them on its behalf, only to run the service.
What we collect
Only what the service needs:
- Account: name, email address, password (stored as a hash), two-step verification settings (secrets encrypted), language and time zone.
- Work set-up: departure address, working hours and appointment types.
- Customers and bookings: name, email address, phone number, address and its map position, booking times, notes and the language of the booking.
- Calendar, only if you connect Google Calendar: your busy times and the events we create. Access tokens are stored encrypted.
- Billing: your plan and subscription status. Payments are handled by Stripe; we never see or store card numbers.
- Technical: IP address and browser in server logs, and your push subscription if you turn notifications on.
Why and on what basis
To provide the service you signed up for (performance of a contract): bookings, routes, calendar sync, confirmations and reminders. To keep accounts and the service secure (legitimate interest). To keep invoices and accounting records (legal obligation). We don't sell data and don't use it for advertising.
Who receives data
Only these services, each for its own part of the work:
- Hosting: [HOSTING PROVIDER], with the data stored in [DATA LOCATION].
- Email delivery: [EMAIL PROVIDER].
- Payments: Stripe.
- Google, only if you connect Google Calendar.
- Address search: Photon by komoot receives the address text you type.
- Maps: OpenFreeMap serves the map tiles, so it sees your IP address when a map loads.
- Notifications: the push service of your browser (for example Apple, Google or Mozilla) delivers them in encrypted form.
How long we keep it
Account and customer data are kept while the account exists and deleted after it is closed. Invoicing records are kept as long as accounting law requires. Server logs are kept for a limited time, for security.
Your rights
You can ask to see, correct or delete your data, to limit or object to its use, and to receive it in a usable format. Email [CONTACT EMAIL]. Customers of a business that uses [PRODUCT NAME] can best contact that business first. You can also complain to the Belgian Data Protection Authority (www.dataprotectionauthority.be).
Security
Connections use HTTPS, staff accounts can use two-step verification, and calendar tokens and verification secrets are stored encrypted.
Changes
When this policy changes, we update the date at the top and tell account owners by email about important changes.