Privacy Policy
Version 1 · Last updated Jul 11, 2026Last updated: 2026-07-06
This Privacy Policy explains how Vinta Software Studio LLC ("Vinta Schedule", "we", "us", or "our") collects, uses, discloses, and safeguards your information when you use the Vinta Schedule scheduling and calendar platform, our websites, and related applications and APIs (collectively, the "Service").
Vinta Schedule is a business-to-business scheduling platform. In most cases your organization (your employer, provider, or the reseller that offers you the Service) is the controller of the personal data processed about you, and we act as a processor / service provider on that organization's behalf and instructions. Where that is the case, your organization's own privacy notice may also apply, and requests about your data may need to be directed to that organization.
1. Who this policy covers
This policy applies to:
- Account users — people who register for and sign in to Vinta Schedule (for example, staff, providers, and administrators at an organization).
- Booking participants — people whose availability is scheduled, or who book time or resources through the Service.
- Visitors — people who visit our marketing website or public pages.
If your access to Vinta Schedule is provided through a reseller or white-label partner, that partner may display its own name, logo, and support contact. The data practices described here still apply to the underlying Service.
2. Information we collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Account and profile | First name, last name, email address, password (stored only as a secure hash), profile picture, organization name |
| Phone number | The mobile phone number you provide for account security and phone verification (see the SMS Policy) |
| Authentication data | Multi-factor authentication (TOTP) enrollment, passkeys/WebAuthn credentials, and recovery codes |
| Organization data | Team membership, roles, invitations, and organization settings you configure |
| Support and communications | Information you include when you contact support or send us messages |
2.2 Calendar and scheduling data
To provide the Service we process calendars, events, availability windows, bookings, booking policies, bundles, resources (such as rooms), change requests, and related scheduling metadata. This may include event titles, times, participants, and notes that you or your organization choose to store in or sync to the Service.
Depending on your organization's use of the Service, calendar and scheduling data may include health-related or other sensitive information (for example, appointment context in a healthcare setting). Your organization is responsible for determining what data it places in the Service and for any additional agreements (such as a Business Associate Agreement) required for that use.
2.3 Information from connected services
If you or your organization connect an external calendar or identity provider, we receive information from that provider to operate the integration:
- Calendar providers — Google Calendar, Microsoft/Outlook, Apple, and iCalendar (ICS) feeds. For organization-wide room and resource sync, an administrator may configure a Google Workspace service account with domain-wide delegation; in that case we access calendar and directory data within the scope your administrator grants.
- Sign-in providers — Google, Apple, and Facebook, when you choose to sign in with them. We receive basic profile identifiers needed to create and authenticate your account.
2.4 Information collected automatically
When you use the Service we automatically collect technical information needed to operate and secure it, such as IP address, device and browser information, and log/usage data (including, for consent records, the IP address and user agent captured at the time you gave consent).
3. How we use information
We use personal data to:
- Provide, operate, and maintain the Service and its scheduling, calendar, and booking features;
- Create and manage accounts, organizations, teams, and invitations;
- Authenticate you and protect account security, including multi-factor authentication and sending one-time verification codes by SMS (see the SMS Policy);
- Synchronize calendars and resources with the providers you connect;
- Send transactional communications (such as verification codes, security alerts, and branded transactional email) and respond to your requests;
- Maintain records of policy and SMS consent as required by law;
- Detect, prevent, and address fraud, abuse, security incidents, and technical issues; and
- Comply with legal obligations.
We do not sell your personal information, and we do not use the phone number you provide for verification to send you marketing messages.
4. Legal bases for processing (where applicable)
Where data protection law (such as the GDPR) applies, we rely on: performance of a contract (to provide the Service to you or your organization); legitimate interests (to secure and improve the Service); consent (for example, SMS messaging consent); and compliance with legal obligations. Where we act as a processor, our processing is governed by our agreement with your organization.
5. How we share information
We share personal data only as needed to operate the Service:
- Within your organization — with administrators and members according to roles and the features your organization enables.
- Service providers (sub-processors) — vendors that help us run the Service, including:
- Twilio — to deliver SMS verification codes;
- Amazon Web Services (AWS) — hosting and storage, including profile pictures stored in Amazon S3;
- Calendar and identity providers — Google, Microsoft, and Apple, to operate the integrations you connect.
- Legal and safety — when required by law, legal process, or to protect the rights, safety, and security of users, the public, or the Service.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
We require service providers to protect personal data and to use it only to provide services to us.
6. Data retention
We retain personal data for as long as your account or your organization's account is active, as needed to provide the Service, and as required to comply with legal, tax, accounting, and security obligations. Consent records are retained as long as necessary to evidence consent. When data is no longer needed, we take reasonable steps to delete or de-identify it.
[Confirm retention specifics with the backend/compliance team and complete this section — e.g. concrete retention windows and deletion timelines.]
7. Your choices and rights
Depending on where you live and applicable law, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing or withdraw consent.
- Profile information — you can view and update your name and profile picture in your account settings.
- SMS consent — you can opt out of SMS at any time as described in the SMS Policy.
- Account changes — some actions (such as account deactivation) are performed by your organization's administrators. If we act as a processor for your organization, we will refer your request to that organization or act on its instructions.
To exercise a right, contact us at contact@vintasoftware.com (or your organization's designated support contact). We may need to verify your identity before acting on a request.
8. Security
We use technical and organizational measures designed to protect personal data, including: authentication through a secure back-end-for-frontend proxy with HTTP-only session and token cookies; support for multi-factor authentication (TOTP), passkeys/WebAuthn, and recovery codes; email and phone verification; strong-password requirements; and re-authentication for sensitive actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International data transfers
We and our service providers may process personal data in countries other than your own. Where required, we use appropriate safeguards for such transfers.
10. Children's privacy
The Service is intended for use by organizations and their authorized users and is not directed to children. We do not knowingly collect personal data from children in a manner that violates applicable law. If you believe a child has provided us personal data, contact us at contact@vintasoftware.com.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
12. Contact us
If you have questions about this Privacy Policy or our data practices, contact:
Vinta Software Studio LLC 1110 Brickell Ave, 200, Miami, FL 33131 Email: contact@vintasoftware.com
If your access is provided by a reseller or your organization, you may also contact your organization's designated support address.