Privacy Policy
Last updated 30 Sep 2026
This policy explains how RightSchedule handles personal data of business owners who use the service and visitors of our website. If you booked an appointment with a business, see that business's privacy notice on its booking page instead.
1. Who we are
[Company legal name] ("RightSchedule", "we"), [Registered address, Portugal], tax ID [NIF / VAT number], is the controller of the data described in this policy. Contact: privacy@rightschedule.example.
2. Our two roles
For your account data (email, password, business profile) we are the controller.
For the data of your own customers (names, phones, emails, notes, bookings, quote requests) each business is the controller and RightSchedule is the processor. That processing is governed by our Data Processing Agreement.
3. Data we collect and why
- Account data: email, password hash, date and version of the Terms you accepted. Purpose: create and run your account. Basis: contract (Art. 6(1)(b) GDPR).
- Business data you enter: business profile, staff, services, working hours. Purpose: provide the booking service. Basis: contract.
- Technical data: IP address, request identifiers and security logs. Purpose: security, abuse and rate-limit protection. Basis: legitimate interest (Art. 6(1)(f)).
- Service emails (booking notifications, reminders): necessary to provide the service. We send no marketing emails without a separate opt-in.
4. Cookies
We use only strictly necessary cookies: a session cookie that keeps you signed in and a language preference cookie. We use no analytics or advertising trackers, so no cookie banner is required. If that changes, we will ask for your consent first.
5. Who receives data
Only our sub-processors (hosting, database and email delivery), listed on the sub-processors page, and authorities when legally required. We do not sell personal data.
6. International transfers
We host data in the EU/EEA where possible. Where a provider transfers data outside the EEA, we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.
7. How long we keep data
- Account and business data: while your account is active; deleted when you delete your account.
- Bookings: anonymized 24 months after the appointment. Quote requests: deleted 12 months after receipt.
- Security logs: kept for a short period (up to 30 days) and then deleted.
- Backups: deleted data ages out of backups within [backup retention period].
8. Your rights
You can access, correct, export and erase your data, and object to or restrict processing. Use Settings > Privacy in the app to export or delete your account, or write to us. You may lodge a complaint with the Portuguese data protection authority, CNPD (www.cnpd.pt), or your local authority.
9. Security
We use encryption in transit, hashed passwords, HttpOnly session cookies, per-business data separation and rate limiting. No system is perfectly secure; we will notify affected parties of breaches as the law requires.
10. Changes
We will post changes here and notify account owners of material changes.