Privacy Policy

Last updated 3 August 2026

This policy explains what personal information Zeitlup collects, how it is used, and your choices. It covers both people who book through a business's page and businesses that run their scheduling on the Service.

Who we are

Zeitlup is provided by Magnifecent Dragon LTD. For data about people who book through a business's page, that business decides how the data is used (the controller) and we process it on their behalf (the processor). For a business's own account data, we are the controller.

What we collect

When you book a session or sign up for a class, we collect your first and last name, email address, phone number (if you provide one), time zone, the session you booked, and any message you add.

When a business creates an account, we collect their name and email, business details (such as business name, time zone, and booking handle), login and security information, and payment-related identifiers from our payment processor (we do not see or store full card numbers).

If you contact us through our website — the contact form or an enterprise demo request — we collect what you enter: your name, email address, and message, plus company name and phone number (if provided) for demo requests, so we can respond. If you subscribe to product updates, we collect your email address.

Why we use it and our legal basis

We use booking data to schedule and confirm sessions, send confirmation and reminder emails, and let you and the business manage, reschedule, or cancel a booking. We use account data to provide, secure, and bill the Service. We do not sell personal information or use it for advertising.

Where required by law, our bases for processing are performance of a contract, our legitimate interests in running the Service securely, and consent (for example, for optional marketing emails, which you can withdraw at any time).

Messages sent through our website are used only to respond to you. A newsletter signup is used only to send you product updates, and every such email includes a way to unsubscribe.

Who it is shared with

Booking details are visible to the business you booked with. To deliver the Service we also use a small set of service providers (sub-processors) — for example for hosting, our database, email delivery, and payments. If a business has connected Google Calendar, your session is added to it as an event that includes your name and email.

A current list of our sub-processors is available at /subprocessors. These providers handle data only to provide the Service to us.

Google Calendar

Connecting Google Calendar is optional and is always started by the business. On Google's consent screen they grant Zeitlup permission to view calendar events and to create and manage events on their Google account. That permission is wider than what we use it for, so to be exact: we read free/busy times only, to work out when the business is already occupied so that a client cannot book a slot that is not really free, and we create, update, and delete only the events that Zeitlup itself added for a booking. We do not list, search, read, change, or store the contents of any other event.

To keep the connection working we store the access keys Google issues (encrypted), the identifier of the connected calendar, when that access expires, and the technical details we need in order to tell a business when their connection has stopped working. A business can disconnect at any time from its settings: we delete those stored keys immediately, and at the same time ask Google to revoke the access. If that revoke request does not get through, the disconnect still completes on our side — so anyone who wants to be certain the grant is gone should also remove Zeitlup from the connected-apps page of their Google Account. Bookings already added to the calendar stay there.

Zeitlup's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this information, use it for advertising, or use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.

How long we keep it

We keep booking and account data for as long as the account is active and as needed to provide the Service and keep records of sessions. After an account is closed, we delete or anonymize personal data within a reasonable period, except where we must keep certain records (such as transaction records) to meet legal, tax, or accounting obligations.

Website inquiries and demo requests are kept only as long as needed to handle them. A newsletter address is kept until you unsubscribe.

Cookies

When you start a booking, we store one small functional cookie to hold your selected time slot while you complete the form. Businesses signing in use secure session cookies to stay logged in. These are not used for tracking or advertising.

Public forms (booking, purchases, and our website's contact, demo, and newsletter forms) are protected by Cloudflare Turnstile, a bot-check that may set its own functional cookie while it verifies you. If you switch our website between light and dark mode, that preference is saved in your browser and is not sent to us.

Payments

Payments are processed by Stripe. Card details are entered directly with Stripe and are never stored on our servers; we keep only the identifiers needed to reconcile a payment.

Where your data is processed

Our hosting and database providers process data in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards as required by applicable law.

Security

We protect data with measures such as encryption in transit, hashed passwords, access controls, and optional two-factor authentication for business accounts. No system is perfectly secure, but we work to protect your information.

Your rights and choices

You can ask to see, correct, delete, or receive a copy of the personal data we hold about you. If your request is about data you provided when booking with a business, please contact that business — we will help them respond. For account data, or to reach us directly, email support@zeitlup.com.

Your privacy contact

Magnifecent Dragon LTD is responsible for the personal information described here. Our Privacy Officer is Viktor Zaharov. To ask a question, make a request about your data, or raise a concern, email support@zeitlup.com or write to Viktor Zaharov, Privacy Officer, Magnifecent Dragon LTD, #213, 9-6975 Meadowvale Town Center Cir., Mississauga, ON, Canada, L5N 2V7.

If you are in Canada

We handle personal information in line with Canada's federal privacy law (PIPEDA). You can ask to see the information we hold about you, ask us to correct it, and ask how it has been used or shared. Viktor Zaharov, our Privacy Officer, is your contact for any of this.

If you are in Quebec, Law 25 gives you additional rights, including the right to ask us to stop sharing your information, to have it de-indexed in certain cases, and to receive a copy in a structured, commonly used format. Viktor Zaharov is the person responsible for protecting personal information under Law 25. If a privacy incident ever creates a risk of serious harm to you, we will notify you and the Commission d'accès à l'information as the law requires, and we keep a record of incidents.

If you are in the EEA or the UK

Under the GDPR and UK GDPR you have the right to access, correct, delete, restrict, or object to our use of your personal data, and the right to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. You also have the right to complain to your local data-protection authority.

Some of our service providers are in the United States. When we transfer personal data internationally, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — as required by law. If a data breach is likely to put your rights at risk, we will notify the relevant authority without undue delay and, where required, within 72 hours of becoming aware of it.

If you are a US state resident

Depending on your state, you may have the right to know what personal information we collect, to access or delete it, to correct it, and to opt out of its sale or of "sharing" for targeted advertising. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of — but you can still exercise your other rights by emailing support@zeitlup.com. We will not discriminate against you for doing so.

We honor the Global Privacy Control (GPC). If your browser or a browser extension sends a GPC signal, we treat it as a valid request to opt out of any sale or sharing of your personal information for that browser.

Changes and contact

We may update this policy from time to time and will change the date above when we do. Questions about this policy or your data? Email support@zeitlup.com.