Privacy Policy
Please read this privacy notice carefully before using our services
This policy explains what personal data Calenzy Pte. Ltd. ("Calenzy", "we", "us") collects, why, who sees it, where it is kept and what your rights are. Calenzy is registered in Singapore at 160 Robinson Road, Singapore 068914.
It covers the website calenzy.com, the dashboard at calenzy.app, the public pages we host for our customers (booking pages, digital menus and websites), our APIs, and the Calenzy and Uptime mobile apps. Our consumer apps Currenzy and Smoky have their own privacy notices, published inside the apps and on their store pages.
Data Protection Officer: Jerome Seidita, dpo@calenzy.com.
Representative in the European Union (article 27 GDPR): Marine Larmier, 11 avenue des Moulins, 06670 Saint-Martin-du-Var, France, marine@calenzy.com.
Last updated: 5 September 2026. The English text governs; the French and Chinese versions are translations for convenience.
Contents
- Who this policy is for
- Data we process for our customers
- What we collect
- Why we use it
- Emails we send you
- Who we share it with
- Where your data is kept and international transfers
- Cookies
- How long we keep it
- Security
- Your rights
- Children
- Automated decisions and Do Not Track
- Changes to this policy
- Contact
1. Who this policy is for
- Visitors of calenzy.com and of the public pages we host.
- Customers: the businesses that hold a Calenzy account, and the people who use it (owners and team members).
- Clients of our customers: people who book, order, pay or receive messages through a page or feature a customer runs on Calenzy. Section 2 explains our role towards you.
- Users of the Calenzy and Uptime apps.
2. Data we process for our customers
Our customers use Calenzy to run their business: they record their clients' appointments, bookings, contact details, notes, invoices and messages, and they publish booking pages and websites. For that data, the customer is the controller (in Singapore, the organisation responsible) and we are its processor (in Singapore, a data intermediary): we act on the customer's instructions under our Data Processing Agreement, we keep the data secure, we do not use it for our own purposes, and we delete it when the customer asks or leaves.
If you are a client of one of our customers and want to see, correct or delete what they hold about you, or to stop receiving their messages, contact that business first; they decide, and we help them carry it out. If you cannot reach them, write to dpo@calenzy.com and we will pass your request on and make sure it is handled.
The rest of this policy describes the data for which we are the controller: visitors of our site, our customers' accounts, and app users.
3. What we collect
When you visit calenzy.com
- Server logs: IP address, browser and device type, pages requested, time and referring page. Kept 14 days for security and troubleshooting.
- Statistics: we measure visits with Calenzy Analytics, our own tool, which uses no cookies and does not identify you. It records the page, the country derived from the IP address, the device type and the referrer, in aggregate.
- Your language choice, kept in a cookie for 30 days.
- An approximate location (country and city) derived from your IP address by our own service, used to show prices in your currency and the site in your language.
- The contact form: your name, email address and message, together with your IP address and the result of our spam filter. Sent to us by email and kept as long as the conversation needs.
- The chat: nothing is loaded until you open it. If you do, Crisp, our chat provider, receives what you write and technical data about your browser under its own privacy policy.
- If you write to us on WhatsApp, your number and messages are held in WhatsApp and on our phones.
When you have a Calenzy account
- Account data: business name, your first and last name, email address, password (stored hashed, never readable), phone number, language, time zone, country and currency, and if you sign in with Google or Apple, the identifier and profile photo they give us.
- Billing data: billing contact and address, invoices, and the brand, last four digits and expiry of your payment card. The card itself is held by Stripe.
- Everything you put into the dashboard: your services, clients, bookings, invoices, campaigns, menus, files, website and its texts and images. You control this content; where it is about your own clients, section 2 applies.
- Onboarding data: what you tell us about your business, and if you pick your business from Google, the public listing Google returns (address, hours, phone, photos and reviews).
- Data from services you connect: Google Business Profile, Meta, Stripe, Xero and others, as the feature describes.
- AI chats: your messages to our AI assistants and their answers, and images you attach, so you can go back to them and so we can improve the assistants.
- Usage data: when you sign in, which parts of the dashboard you use, milestones you reach (first booking, site published), and your session. We use it to support you, to understand what works and to send the emails described in section 5.
- How you found us: the campaign or page that led to your signup, when a link carries that information.
- Support: the requests you open in the dashboard, the emails you send us, and our replies.
- Technical data: IP address and approximate location at signup and sign in, browser and device.
When you use a public page a customer runs on Calenzy
- What you enter to book, order or pay: name, email address, phone number, the service or dates chosen, your answers to the business's questions, and notes. This is the business's data (section 2).
- Your IP address and browser, kept with the booking for security and fraud prevention.
- If you pay, your card is handled by Stripe on the business's own Stripe account; we never see the card number. If you choose to keep a card on file with that business, Stripe stores it and we store only a reference.
- These pages carry no advertising and no cross site tracking. A business may add its own analytics to its website; its own notice tells you.
When you use the Calenzy or Uptime app
- The same account data as above. Uptime accounts and Calenzy accounts are one account, matched by email address.
- Device data: model, operating system, app version, language, and a push notification token if you allow notifications (delivered through OneSignal and Firebase).
- Crash and performance reports (Firebase Crashlytics), without your name.
- In Uptime: the domains, sites and certificates you ask it to watch, and the alerts sent.
- If you subscribe inside an app, the purchase is handled by Apple or Google under their terms; we receive a confirmation, not your payment details.
- The apps use no advertising and no tracking across other apps. Camera, contacts and biometric access are used only for the feature you trigger and only with your permission.
We do not ask for sensitive data (health, beliefs, biometrics used to identify you) and we do not want it in our own records. Our customers may need to note such things about their own clients (a spa noting an allergy, for example); that data is theirs and section 2 applies.
4. Why we use it
- To provide the Services you asked for: run your account, serve your pages, send your messages, bill you, support you. Basis: our contract with you.
- To keep the Services secure and honest: prevent abuse, spam and fraud, investigate incidents, keep logs. Basis: our legitimate interest in running a safe service.
- To improve the Services: understand which features are used and where people get stuck, from usage data and support requests. Basis: our legitimate interest in improving what we sell; we look at patterns, not at individuals, unless we are helping you.
- To tell you about the Services: the emails in section 5. Basis: our contract for service messages; our legitimate interest, or your consent where the law requires it, for the rest, with an opt out every time.
- To meet legal duties: keep accounting records, answer lawful requests from authorities, handle disputes. Basis: legal obligation and legitimate interest.
- With your consent where we ask for it, for example to use your testimonial. You can withdraw consent at any time.
We do not sell personal data, do not use it for advertising, and do not use your content or your clients' data to train artificial intelligence models.
5. Emails we send you
As a customer you receive service emails we cannot switch off: invoices and receipts, renewal and payment notices, security alerts, changes to our terms, and answers to your requests. During your trial and after it we also send a short series of emails that explain the features and tell you when the trial ends. We may send occasional product news. You can stop the trial series and the news from your profile or with the link in each email; service emails continue as long as you have an account.
6. Who we share it with
We share personal data only with the providers we need to run the Services, each under a contract that binds them to protect it and to use it only for us. The current list, with what each one does and where it processes data, is kept on our subprocessors page. In short: Amazon Web Services (hosting, storage, email delivery, backups), Stripe (payments), OpenAI (AI features), Google and Apple (sign in, business listing, notifications), OneSignal and Firebase (app notifications and crash reports), NETIM and OVH (domain names and mailboxes), ImprovMX (email forwarding), Microsoft (licences we buy for you), Xero and Meta (when you connect them), Crisp (chat, when you open it), and Tiny (the text editor in the dashboard).
Customers who ask us to process their clients' data are told by email at least 30 days before we add a provider to that list, and may object.
We may also share data with our accountants and lawyers under confidentiality, with authorities when the law requires it, and with a buyer or successor if our business is sold or reorganised, who takes it over under this policy.
7. Where your data is kept and international transfers
Our servers run on Amazon Web Services in Singapore and in Paris. A customer account is created in Paris when it signs up in French and in Singapore otherwise; files are stored in the same region as the account. Emails sent by the Services leave from Singapore. Backups stay in the region of the data. Mailboxes we provide are hosted in France. Our team works from Taiwan and Singapore and accesses the Services from there.
Some providers process data in other countries, mainly the United States (Stripe, OpenAI, Google, Apple, OneSignal, ImprovMX, Microsoft). For customers in the European Economic Area, transfers out of the EEA, including to us in Singapore, rest on the European Commission's standard contractual clauses, which are part of our Data Processing Agreement, and on the equivalent clauses our providers offer. For data we hold as a Singapore organisation, we transfer it only to recipients bound by contract to a standard of protection comparable to the Personal Data Protection Act.
8. Cookies
We use no advertising or analytics cookies. The cookies we set are needed for the site and the dashboard to work:
- Session cookie on calenzy.com and on the public booking pages: keeps your language and your steps while you browse. Ends when you close the browser.
- language on calenzy.com: your chosen language, 30 days.
- Dashboard session cookie on calenzy.app: keeps you signed in for 30 days after your last visit.
- Sign in state cookies used for a few minutes during Google and Apple sign in.
- Crisp sets its own cookies only if you open the chat on calenzy.com.
Because these cookies are strictly necessary, we do not ask for consent for them. You can delete them in your browser; the site will forget your language and the dashboard will sign you out.
9. How long we keep it
- Your account and its content: as long as the account is active. When a subscription or trial ends, the account locks and its data stays intact for at least 12 months; after that we may delete it, after emailing the Owner twice. An Owner can ask us to delete the account at any time; we do so within 30 days.
- Invoices and payment records: 5 years after the year of the transaction, as accounting law requires, longer where your country's law requires it of us.
- Backups: 7 days, then overwritten.
- Server logs: 14 days.
- Statistics from Calenzy Analytics: raw, unidentified events 90 days; aggregated figures 12 months.
- Sessions: dashboard sessions 30 days after the last visit; app sign ins 90 days.
- Contact form and support emails: as long as needed to answer, then up to 3 years in case a question returns.
- Data we process for a customer: for as long as the customer keeps it; deleted when the customer deletes it or when the customer's account is deleted.
10. Security
Connections to the Services are encrypted. Passwords are stored hashed. Secret keys you give us, such as your Stripe key, are stored encrypted. Access to an account is controlled by membership and by the permissions its Owner sets, and our staff open an account only to support you or to keep the Services secure. Card details never reach our servers. Our servers are kept updated, protected by firewalls and monitored, and backed up daily. No system is perfectly secure; if we learn of a breach that affects your data we will tell you and the authorities as the law requires, and for data we process for a customer we tell the customer without undue delay.
11. Your rights
Wherever you are, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, object to a use of it, and withdraw a consent you gave. Write to dpo@calenzy.com from the email address on your account, or by post to the address below. We answer within 30 days. We may ask you to confirm your identity first.
- Singapore. Under the Personal Data Protection Act you have the rights of access and correction, the right to withdraw consent, and the right not to receive marketing messages on a number listed on the Do Not Call Registry. You can complain to the Personal Data Protection Commission (pdpc.gov.sg).
- European Economic Area, United Kingdom, Switzerland. Under the GDPR and equivalent laws you also have the rights to restrict processing, to data portability, and not to be subject to a decision based solely on automated processing. You can complain to your data protection authority; in France that is the CNIL (cnil.fr). You may also contact our representative in the EU named at the top of this policy.
- Taiwan. Under the Personal Data Protection Act you may ask to review, copy, supplement, correct or delete your data and to stop its collection or use.
- Thailand. Under the Personal Data Protection Act you have rights of access, portability, objection, deletion, restriction and correction, and may complain to the Personal Data Protection Committee.
If your data sits in a customer's account (section 2), we forward your request to that customer and help them answer it.
12. Children
The Services are for businesses and their adult clients. We do not knowingly collect data from anyone under 18 for our own purposes. If you believe a child has given us data, write to dpo@calenzy.com and we will delete it.
13. Automated decisions and Do Not Track
We make no decisions about you by automated means that have legal or similarly significant effects. Our site does not track you across other sites, so a browser's Do Not Track setting changes nothing.
14. Changes to this policy
We update this policy when the Services or the law change. The date at the top tells you when. For changes that matter to you we email customers before they take effect.
15. Contact
Calenzy Pte. Ltd.
160 Robinson Road
Singapore 068914
Data Protection Officer: dpo@calenzy.com
General enquiries: support@calenzy.com
Representative in the EU: Marine Larmier, 11 avenue des Moulins, 06670 Saint-Martin-du-Var, France, marine@calenzy.com
