In short
- We collect what we need to run your workspace, and nothing for advertising.
- We don’t sell personal data, and we don’t use cookies to track you.
- Card details stay with Stripe. Your access keys are stored only in hashed form.
- You can ask us for a copy of your data, or to delete it, at [email protected].
Who we are
The controller of your personal data is MindCache LTD, a private company limited by shares, registered in England and Wales with company number 16468302. Our registered office is Office 12, Initial Business Centre, Wilson Business Park, Manchester, M40 8WN, United Kingdom.
This policy covers this website, the schedule-bit console, the live playground and the schedule-bit API. For anything about your personal data, email [email protected].
Your data and your customers’ data
We handle personal data in two roles:
- As controller, for the data about you as our customer: your account, keys, usage and billing. This policy describes that.
- As processor, for personal data you put into your schedules, such as the names of the people you book. You decide what goes in and why, and we process it only to run the service for you, under our Terms of Service. If you are booked through a business that uses schedule-bit, please ask that business about your data first.
What we collect, why, and our legal basis
| What | Why | Legal basis |
|---|---|---|
| Your sign-up email address and workspace name | To create and run your workspace, send the sign-up link, and tell you about your account, billing and changes to the service. | Contract |
| Access keys | To check that each request comes from your workspace. We keep keys only in hashed form (a one-way fingerprint), so we cannot read them back. A key is shown once, when it is made. | Contract; legitimate interests (keeping the service secure) |
| The schedules you create: calendars, resources, bookings, labels and the history of changes | To provide the service. This is your data; we use it only to run the service for you. | Contract |
| Usage counts: requests, bookings and changes, resources and assistant runs each month | To apply your plan’s limits and show you your usage. | Contract |
| Billing references: your Stripe customer and subscription ids, your plan, and the subscription’s status and dates | To match payments to your workspace and set your plan. Card details are collected and kept by Stripe; we never see or store them. | Contract; legal obligation (keeping accounting records) |
| Notification (webhook) addresses you register, and their signing secrets | To send your systems notifications when something changes, signed so that you can check they came from us. | Contract |
| Request logs: the IP address a request came from, the time, the address requested, the result, and the workspace | To keep the service secure, stop abuse, and find and fix faults. | Legitimate interests (security and reliability) |
| The sign-up check: signals from your browser, read by Cloudflare’s check that you are a person | To stop automated sign-ups. | Legitimate interests (preventing abuse) |
| Emails you send us | To answer you, and to keep a record of what we agreed. | Legitimate interests; contract where it concerns your account |
“Contract” means we need the data to provide the service you signed up for. “Legitimate interests” means we use it for a reasonable purpose of ours, such as security, that does not override your rights; you can object to it, as your rights explain.
On this website we run no analytics and no advertising. The service-status line on our pages asks our own service whether it is running, and sends nothing about you. Our pages, the console and the playground load their fonts from Google Fonts, so your browser connects to Google, which receives your IP address and browser details to deliver them.
We don’t sell personal data, and we don’t make decisions about you by automated means that have legal or similarly significant effects.
The AI assistant
The assistant is optional. Only when you run it, we send Anthropic your prompt and the schedule data that the run reads, so that its model can answer. Our logs of a run keep its id, your workspace, its steps, the number of tokens, why it stopped and whose key it used; never your prompt.
If you give the assistant your own Anthropic key, we use it for that run only. It is sent to Anthropic as the run’s key and nowhere else, and we never store or log it.
Cookies and storage in your browser
We don’t set cookies on this website, the console or the playground, and we use no tracking or advertising tools. Some features keep small items in your browser’s own storage, which stays on your device and is not sent to us:
- This website remembers your light or dark theme choice.
- The console keeps your access key for the browser tab you are using, and forgets it when the tab closes. It remembers the address of the service you connected to.
- The playground keeps your access key, and your own Anthropic key if you give one, for the browser tab only; disconnecting or closing the tab removes them. It remembers your display preferences (such as theme and sound), the name and colour others see, and the examples you save.
These items exist only to do what you asked for, so we don’t ask for consent with a banner. You can clear them at any time in your browser’s settings.
Cloudflare, which hosts our services, may set a strictly necessary security cookie if it needs to check that traffic is not automated. The sign-up check runs only on the sign-up screen.
International transfers
Some of our sub-processors are in, or reach data from, countries outside the UK, mainly the United States. When personal data leaves the UK, we make sure it is protected by one of the safeguards UK law allows: UK adequacy regulations where they apply, or the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum. Email us for more detail on the safeguard for a given transfer.
How long we keep it
| Data | How long |
|---|---|
| Your workspace, schedules, usage counts, webhooks and key records | While your workspace is open. When you ask us to close it, we delete them within 30 days. |
| Billing records (invoices, payments and the references that link them to you) | Six years after the end of the financial year they relate to, as UK tax and company law requires. |
| Request logs | Up to 30 days. |
| An unfinished sign-up | The link expires after 30 minutes; an unused request is not kept as a workspace. |
| Emails with us | Up to two years after our last exchange, unless we need them longer for a legal claim. |
Deleting on request
You can revoke access keys and remove notification addresses yourself, in the console or through the API. Deleting a calendar, a resource or a whole workspace isn’t yet possible in the API, so do that on request: email [email protected] from your sign-up address, say what you want deleted, and we will delete it within 30 days. We keep only what the law requires us to keep, such as billing records.
Security
We protect your data with measures that fit a service like ours:
- Every connection to the service is encrypted (HTTPS).
- Access keys are stored only in hashed form, and each key is shown once, when it is made.
- Every request is checked against its key, and one workspace cannot read or change another’s data unless it was given access.
- Each schedule’s history is chained, so a change to its past can be detected.
- Notifications to your systems are signed, so you can check that they came from us.
- Card details never reach our systems, and your own Anthropic key is never stored.
- Rate limits protect the service from overload and abuse.
- Only the people who run the service can reach its production systems.
No system is perfectly secure. If a breach puts your personal data at risk, we will tell the Information Commissioner’s Office within 72 hours where the law requires it, and tell you without undue delay.
Your rights
Under UK data protection law, you have the right to:
- get a copy of your personal data (access);
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use it;
- object to our use of it based on legitimate interests;
- receive data you gave us in a machine-readable form, or have it sent to another provider (portability).
To use any of these rights, email [email protected], ideally from your sign-up address. We may need to confirm who you are. We answer within one month, and it is free in most cases.
Complaints
If you are unhappy with how we handle your data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator: ico.org.uk/make-a-complaint, or 0303 123 1113. If you live in the EU, you can also complain to the data protection authority in your country.
Children
schedule-bit is a service for businesses and developers and is not meant for anyone under 16. We don’t knowingly collect personal data from children. If you think a child has given us personal data, email [email protected] and we will delete it.
Changes to this policy
We may update this policy when the service or the law changes. The date at the top shows when it last changed. If a change materially affects how we use your personal data, we will email you before it takes effect.
Contact
Privacy questions and data requests: [email protected]. Anything else: [email protected]. By post:
MindCache LTDOffice 12, Initial Business Centre
Wilson Business Park
Manchester
M40 8WN
United Kingdom