Privacy Policy
Overview
At Ordinus, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our scheduling service.
Information We Collect
Account Information
- Name and email address
- Password (encrypted and hashed)
- Profile information you choose to provide
- Billing and payment information (processed by Stripe)
Appointment Data
- Client names and email addresses
- Appointment dates, times, and durations
- Appointment types and settings
- Calendar availability preferences
- Payment transaction details
Usage Information
- Device information (browser type, OS, IP address)
- Log data (access times, pages viewed, errors)
- Analytics data (pageviews, feature usage)
How We Use Your Information
We use your information to:
- Provide and maintain our scheduling service
- Process appointments and payments
- Send appointment confirmations and reminders
- Communicate with you about your account
- Improve our service and develop new features
- Detect and prevent fraud and abuse
- Comply with legal obligations
Our Role: Controller and Processor
Ordinus handles two kinds of personal data, and our legal role differs between them. This policy describes the data we control ourselves. The data you process inside your workspace is governed by the Data Processing Agreement, not by this policy.
Data we control
We act as the controller for your user account itself - your login identity, credentials, authentication and two-factor state, and account security records - for the contract, payment, and invoicing data behind your Ordinus subscription, and for platform-level security, fraud-prevention, and network logs. Your account belongs to you, works across workspaces run by different organisations, and you can delete it yourself.
Data we process on your behalf
Everything inside a workspace - bookings and the client details attached to them, contacts, event types, routing forms, workflows, availability, workspace membership and roles, and workspace audit records - is processed on the instruction of whoever runs that workspace. For that data they are the controller and we are their processor. If you booked an appointment through an Ordinus page, the business you booked with is the controller, and requests about that data should go to them.
Data Sharing and Processors
We do not sell your personal information. We share data only with trusted service providers who help us operate our service:
Third-Party Processors
- Hosting
- Email service providers - Transactional emails and notifications
- Sms
- Ai
- Umami Analytics (self-hosted by us) - Cookieless usage statistics, processed only after consent; no data is shared with a third-party analytics provider
All processors are contractually required to protect your data and use it only for the purposes we specify.
Payments (Stripe)
Stripe is not one of our subprocessors. For your own Ordinus subscription, Stripe and Ordinus each act as independent controllers for the payment and invoicing data involved. For paid bookings, you connect your own Stripe account and hold your own agreement with Stripe: charges are created directly on that account and the funds go straight to you. We never receive or store card data.
International Data Transfers
Personal data is stored and primarily processed in Germany. Our application, database, and backups run at Hetzner Cloud in the EU, and nothing about hosting or storage leaves the EU.
Three optional or supporting services involve transfers from the EEA to the United States: Google Cloud EMEA (transactional email delivery), Twilio Ireland (SMS, only where SMS is enabled) and OpenAI Ireland (AI features, only where they are enabled). Each of these transfers is covered by the EU Standard Contractual Clauses under Art. 46 GDPR, supplemented by the provider's own safeguards where applicable, and we assess each transfer before we rely on it.
Where you connect a third-party service to Ordinus yourself, such as Google Calendar, Microsoft Outlook, Zoom, Slack, or a CRM, data is transmitted to that provider on your instruction and under your own agreement with them. Any transfer outside the EEA that results is governed by that relationship.
How we use Google user data
When you connect your Google Calendar to Ordinus, we request three narrowly-scoped permissions: create a separate "Ordinus" calendar and manage only the events on that calendar (calendar.app.created), read busy/free intervals - start and end times only (calendar.freebusy), and read the list of your calendars so we can check all of them for conflicts (calendar.calendarlist.readonly). We deliberately do not request the broader calendar.events or calendar.readonly scopes, which would let us read or change the events on your own calendars - we never need that and never want it. We use the access we do have solely to provide Ordinus's scheduling features, never for advertising and never to build a profile of you.
What we access, and why
- Availability: to prevent double-booking, we read only the start and end times of events across all of your Google calendars via Google's freebusy API. That API only returns busy/free intervals - by design, it never returns titles, descriptions, attendees, locations, attachments, or notes. The "we only see start and end" promise is enforced at the API layer by Google itself, not just by us discarding fields.
- Calendar list: we read the names and identifiers of your calendars so Ordinus can check all of them for scheduling conflicts. We do not read the events on those calendars through this permission.
- Bookings: when an appointment is booked through Ordinus, we create a corresponding event on a separate "Ordinus" calendar that we create in your account - never on your existing personal or work calendars.
- Reschedules and cancellations: if an Ordinus booking is rescheduled we update that same Ordinus-created event on the Ordinus calendar; if it is cancelled we delete that event. We only ever delete events Ordinus created.
What we never do
- We never modify or delete calendar events that Ordinus did not create. Ordinus only ever writes to events it created itself; events you or others created are out of reach for any modification.
- We never read or use the contents of calendar events Ordinus did not create - titles, descriptions, attendees, locations, attachments, and notes from your other events are never looked at, stored, logged, shared, or used to train any model.
- External events are queried in real time only to extract start and end times, and discarded immediately after conflict-checking. We keep no persistent copy, summary, or index of your other calendar data.
- We do not use Google user data for advertising purposes, and we do not sell it or transfer it to data brokers.
- We do not allow humans to read your Google data, except with your explicit consent (for example, to resolve a support request), where necessary for security or to comply with applicable law, or where the data has been aggregated and anonymized.
Ordinus's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Security
We implement industry-standard security measures:
- TLS/HTTPS encryption for data in transit
- Encryption at rest for sensitive data
- Secure password hashing (bcrypt)
- Regular security audits and updates
- Access controls and authentication
- Daily automated backups
Your Rights (GDPR)
If you are in the European Union, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Portability: Export your data (JSON/CSV)
- Restriction: Limit how we process your data
- Objection: Object to data processing
To exercise these rights, contact us at dpa@ordinus.io
Data Retention
We retain your data for as long as your account is active or as needed to provide our services. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.
Platform-level security, fraud-prevention and abuse-prevention records that are not tied to a single workspace are kept for a maximum of 12 months and then erased. Session records are deleted on logout, on a deletion request, or automatically within 7 days of expiry. Backups are retained for a maximum of 30 days and are then overwritten.
Data inside a workspace is retained on the instruction of whoever runs that workspace and is erased when the workspace is deleted. Those retention rules are set out in the Data Processing Agreement, not in this policy.
Cookies
We use essential cookies to maintain your session and authentication. We do not use advertising or tracking cookies without your consent.
Children's Privacy
Our service is not intended for children under 16. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our service.
Contact Us
If you have questions about this Privacy Policy, contact us at:
Email: dpa@ordinus.io