Privacy Policy
Effective date: 2026-08-16
Version: 1.5
Amendment (2026-08-16, v1.5): corrected every description of Marketplace guest accounts to match what is actually built. PeasyBooking does not offer consumer accounts: a guest books by providing the contact details for that booking, and there is no guest login, password, stored sign-in credential, or self-serve profile to manage or close. The Sections that described such an account (1, 2, 3, 4, 12, and 15) now describe the guest-first Marketplace as built, and state how a guest exercises access, correction, and deletion in its absence.
Amendment (2026-08-02, v1.4): named and activated the Marketplace's browser-direct OpenFreeMap tile service disclosure, including its operator, ordinary and incident logging, Cloudflare processing, and the non-map fallback.
Amendment (2026-07-29, v1.3): the public Privacy Policy page now renders this master text exactly (LEGAL-002 — one canonical body drives the page, the registered hash, and the acceptance record). No substantive policy change.
Amendment (2026-07-29): added the Language statement — the English version governs; translations are for convenience only.
Amendment (2026-07-21): clinical/health-data clauses removed following the medical de-scope; PeasyBooking no longer offers clinical features.
This Privacy Policy explains how PeasyBooking Technologies Inc. (operating as "PeasyBooking", "we", "us", or "our") handles personal information. PeasyBooking is a federal Canadian corporation with its registered office at 150 Evergreen Mount SW, Calgary, AB T2Y 0L8.
This Policy is written to align with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's Personal Information Protection Act (PIPA), Quebec's Act respecting the protection of personal information in the private sector (as amended by the Act to modernize legislative provisions as regards the protection of personal information, "Law 25"), and other applicable provincial privacy laws. For individuals in the United States, Section 11A describes rights under the CCPA/CPRA and comparable state laws. Our Privacy Officer (Section 16) is also the person in charge of the protection of personal information for the purposes of Law 25.
PeasyBooking offers two distinct services under one platform, and our privacy responsibilities differ across them:
- Business-management software for salons, spas, wellness and fitness studios, and other service businesses (booking, scheduling, client management, payments, messaging, marketing, reminders, reporting, and related features); and
- A guest-first consumer Marketplace where members of the public can discover providers, book and pay for appointments, leave reviews, and cancel — without holding a provider account.
Because these services involve different relationships, this Policy is organized around who is responsible for which information. Please read Section 1 first; it determines which other parts of this Policy apply to you.
---
1. Who is responsible for which information
Privacy law distinguishes between an organization that determines why and how personal information is handled and an organization that merely handles information on another's behalf and under its instructions. The table below sets out, for each category of information, who is the responsible organization and where to direct questions.
| Information | Whose information | Responsible organization | Governed by |
|---|---|---|---|
| Account holder and staff data (the people who sign up for and use a PeasyBooking business account — names, emails, login activity, roles) | Our business customers and their personnel | PeasyBooking | This Policy |
| Marketplace guest data (people who use the consumer Marketplace — the booking details a guest provides, searches, bookings, reviews, marketplace communications, marketing preferences; there is no guest account — see Section 4) | Members of the public who book through PeasyBooking | PeasyBooking | This Policy (see Section 4) |
| Business client records (the clients and customers of a business that uses PeasyBooking — appointment records, contact details, notes, and form responses) | The business's own clients | The business (PeasyBooking processes this information only on the business's documented instructions) | The business's own privacy policy, plus our Data Processing Agreement (see Section 5) |
| Payment-card details | Whoever pays (a business paying its subscription, or a client/guest paying for a service) | Stripe, under its own terms (PeasyBooking does not store full card numbers) | Stripe's privacy policy; see Section 7 |
| Email and SMS reminders/confirmations sent to a business's clients | The business's clients | The business controls the purpose; PeasyBooking delivers the messages on the business's instructions | The business's own policies, plus our Data Processing Agreement; see Sections 7 and 8 |
Plain-language summary.
- If you are an account holder, staff member, or Marketplace guest, PeasyBooking is the organization responsible for your information, and this Policy governs how we handle it.
- If you are a client of a salon, spa, or other business that uses PeasyBooking, that business — not PeasyBooking — is responsible for your information. We handle it only to operate the service for that business. Please direct access, correction, and privacy questions about those records to the business that serves you. Our handling on their behalf is governed by our Data Processing Agreement.
---
2. Information we collect (where PeasyBooking is responsible)
This Section describes information for which PeasyBooking is the responsible organization — that is, information about account holders, staff, and Marketplace guests.
From account holders and staff:
- Account and business data: name, email, phone number, business name and details, role, seat assignments, and preferences.
- Subscription and billing data: plan, subscription status, billing history, and tax information. Card details are handled directly by Stripe; we do not store full card numbers.
- Usage and device data: log data, IP address, browser and device type, and actions taken, used to operate, secure, and improve the service.
- Support communications: messages you send us and our records of them.
From Marketplace guests (see Section 4 for detail):
- Guest booking details: the name, email, and phone number you provide in order to make a booking. We do not collect guest sign-in credentials, because the Marketplace does not offer consumer accounts — there is no guest login or password (see Section 4).
- Booking and transaction data: the providers and services you search for, appointments you request or book, cancellations, and your booking history.
- Reviews and content: reviews, ratings, and other content you submit.
- Marketplace communications: confirmations, reminders, and messages relating to your bookings, and (where you consent) marketing messages.
We also receive limited information from our service providers in the course of operating the service (for example, payment status from Stripe and delivery status from our email and SMS providers).
---
3. Why we use information, and consent
Where PeasyBooking is the responsible organization, we collect, use, and disclose personal information for the following purposes:
- to create and administer business accounts, and to take and manage Marketplace bookings;
- to provide, maintain, secure, and improve the service;
- to process subscriptions, billing, and (for Marketplace bookings) to facilitate payment through Stripe;
- to facilitate and confirm Marketplace bookings, cancellations, and reviews;
- to send transactional and service messages (such as booking confirmations, reminders, password resets, and account notices);
- to send marketing messages where we have consent (see Section 8 on Canada's Anti-Spam Legislation);
- to detect, prevent, and address fraud, abuse, and security incidents; and
- to comply with legal obligations.
Consent at a glance
Different activities have different responsible parties and consent approaches:
| Activity | Responsible party | Consent approach |
|---|---|---|
| Appointment booking & reminders | Provider/clinic | Service-delivery notice; the provider controls the purpose |
| Marketplace account, searches, rankings | PeasyBooking | Marketplace privacy notice at collection |
| PeasyBooking promotions | PeasyBooking | Separate marketing consent (CASL) |
| Provider promotions | Provider | Separate provider marketing consent (CASL) |
| SMS reminders | Provider purpose / PeasyBooking delivery | Express SMS opt-in + STOP handling |
| Marketplace attribution | PeasyBooking | Prominent disclosure in the booking flow and this Policy |
For every consent we rely on, we preserve evidence — date/time, method, the wording/version shown, channel, sender, the email or phone given, the source page, and any later withdrawal.
Consistent with PIPEDA and Alberta PIPA, we collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances, and we obtain consent where required. You may withdraw consent subject to legal and contractual limits, though withdrawing certain consents may mean we can no longer provide part or all of the service to you.
We do not sell personal information.
---
4. Marketplace guests
This Section applies to people who use the consumer Marketplace to discover providers and book appointments. For Marketplace guests, PeasyBooking is the organization responsible for the guest's searches, bookings, reviews, and marketplace communications. The Marketplace is guest-first: you book without creating an account, and PeasyBooking does not issue guest logins or hold guest passwords. Your use of the Marketplace is also governed by our Marketplace Guest Terms.
Minimum age and consent. The consumer Marketplace is intended for adults. You must be at least the age of majority in your province or territory (18 or 19, depending on the province or territory) to book a service through the Marketplace without the involvement of a parent or legal guardian. A person under the age of majority may use the Marketplace only with the consent and under the supervision of a parent or guardian who agrees to these terms on the minor's behalf and is responsible for the booking. Consistent with the position of the Office of the Privacy Commissioner of Canada that consent from a minor generally cannot be presumed valid, we do not knowingly take bookings from, or rely on the independent consent of, individuals below the age of valid consent. If we learn that we have collected personal information from a person under the age of majority without the required parental or guardian consent, we will take reasonable steps to delete it or to obtain valid consent. To report such a case, contact our Privacy Officer (see Section 16).
Marketplace tracking and attribution. When you use the Marketplace, we record how a booking begins — for example, whether you started it from a Marketplace listing or from a provider's own direct link or website — along with related activity such as searches and listings viewed, and the basic device and browser signals needed to operate and secure the service. We use this booking-source and attribution information to run, measure, secure, and improve the Marketplace, to rank and present results, to prevent abuse and fraud, and to report to providers how the Marketplace contributes to their business. This information is generated and controlled by PeasyBooking; we do not use it to charge guests any fee. Our Marketplace Guest Terms describe the Marketplace further.
Marketplace maps. Marketplace pages can display an interactive map using the public OpenFreeMap tile service operated by Hyperknot Software Kft. (Hungary). Your browser, not PeasyBooking's server, requests the map style and tiles directly. The service therefore receives your IP address and standard technical request data under its own privacy policy; PeasyBooking does not send it your name, account, booking, payment, or business-client records. OpenFreeMap states that it does not ordinarily log IP addresses, but may temporarily retain IP logs for up to 30 days when investigating technical or security incidents, and that Cloudflare may process requests as part of delivery and abuse protection. If map tiles are unavailable or blocked, Marketplace search remains usable through the accessible provider-list view.
What this means:
- Your booking details, and the absence of an account. There is no guest account to create, manage, or close: the Marketplace takes bookings from guests directly, using the contact details you provide for the booking. PeasyBooking holds and is responsible for the marketplace-side record — your searches, bookings, reviews, and communications with us — and you can request access to, correction of, or deletion of that information from us directly (see Section 11), without needing an account to do it. If we introduce guest accounts in future, this Policy will be updated before they are offered.
- Searches and bookings. We use your searches and booking details to show relevant providers, facilitate your booking, send you confirmations and reminders, and process your payment through Stripe (the provider is the merchant of record for the service — see Section 7).
- Reviews and content. Reviews you submit are handled by PeasyBooking under our review-moderation and anti-fake-review practices described in the Marketplace Guest Terms. Reviews you choose to publish are visible to others.
- Marketplace communications and marketing. We send you transactional messages about your bookings. We will send you marketing messages (for example, promotions or recommendations) only where we have the consent required by Canada's Anti-Spam Legislation (CASL), and every commercial electronic message includes sender identification and an unsubscribe mechanism. You can withdraw marketing consent at any time without affecting the transactional messages necessary to manage your bookings. See Section 8.
- The provider relationship. The provider you book delivers the service and is responsible for the quality, licensing, availability, pricing, cancellation, and professional care relating to that service. The provider may also receive the information necessary to fulfil your booking, and that provider becomes responsible for the information it holds about you as its own client. PeasyBooking is the platform, not the service provider.
---
5. Business client records (PeasyBooking processes under instruction)
When a salon, spa, or other business uses PeasyBooking to manage its own clients — including appointment records, contact details, notes, and form responses — the business is the responsible organization. PeasyBooking processes that information only on the business's documented instructions and does not use it for its own purposes.
In particular, PeasyBooking does not use identifiable client records for advertising, profiling, independent analytics, artificial-intelligence training, or product development.
Our handling of this information is governed by our Data Processing Agreement, which addresses permitted uses, security safeguards, incident notification, and record export and retention.
Individuals with questions about their own records held by a business that uses PeasyBooking should contact that business directly. PeasyBooking will refer such requests to the responsible business.
---
6. Service providers (subprocessors) and disclosures
We share personal information with vetted service providers (subprocessors) only as needed to operate the service, under contracts that limit their use of it. Our principal subprocessors are:
- Google Cloud Platform (Google) — application hosting, PostgreSQL database, and file storage. Core customer and client data is hosted in the northamerica-northeast1 (Montréal, Canada) region; the automated database backups and point-in-time-recovery copies of that data are stored in Google Cloud's
usmulti-region (United States). - Google Identity Platform / Firebase Authentication (Google, United States / global) — account sign-in and authentication.
- Stripe (Stripe, Inc., United States / global) — PeasyBooking subscription billing, and — where a business enables the optional online-payments feature — processing of client/guest payments via direct charges on the business's own Stripe connected account (the business is the merchant of record).
- Resend (Resend, United States) — transactional email delivery (for example, confirmations, reminders, password-reset, and verification messages).
- Twilio (Twilio Inc., United States / global) — delivery of text-message (SMS) reminders, confirmations, and two-way replies for the optional SMS add-on, where enabled. Processes mobile numbers and message content solely to deliver the messages.
A current, public list of subprocessors — including each provider's processing region and purpose — is maintained in our Subprocessor List.
The Marketplace also uses OpenFreeMap, operated by Hyperknot Software Kft. (Hungary), as a browser-direct public map service. It receives a visitor's IP address and standard request data directly from the visitor rather than receiving Customer Data from PeasyBooking. It operates under its own public terms and privacy policy and is identified separately in the Subprocessor List so it is not misrepresented as a contracted Customer Data subprocessor.
We may also disclose personal information where required or permitted by law, to enforce our agreements, or to protect the rights, property, or safety of PeasyBooking, our customers, or others. We do not sell personal information.
---
7. Payments
PeasyBooking does not store full payment-card numbers. Stripe handles card details directly under its own terms.
- Subscription payments (a business paying PeasyBooking): PeasyBooking is the merchant for its own subscription fees and bills the business through Stripe, adding applicable GST/HST.
- Client and guest payments to a business (for example, paying for a facial, haircut, or massage): online payment collection is an optional feature, disabled by default. A business may enable it only by connecting and maintaining its own Stripe account; payments are then processed directly by Stripe on the business's connected account (Stripe direct charges). The business is the merchant of record and receives settlement directly from Stripe. PeasyBooking does not receive, hold, control, settle, transmit, or take title to those funds, and charges no commission or per-transaction fee on them. PeasyBooking receives only limited transaction-status information (such as paid/deposit/failed status, amount, and a Stripe reference) needed to operate booking, confirmation, refund-status, reconciliation, and support. The business is responsible for its own refunds, chargebacks, sales tax, tips, deposits, memberships, and cancellation fees.
For privacy purposes, this means card details are governed by Stripe's privacy practices, and we receive only limited payment-status information needed to operate the service. Further detail on the payments model appears in our Business SaaS Terms and Marketplace Guest Terms.
---
8. Email and SMS messages, and CASL
PeasyBooking sends two broad kinds of electronic messages: transactional/service messages (such as booking confirmations, appointment reminders, password resets, and account notices) and, where consent exists, marketing messages.
- Reminders and confirmations a business sends to its clients. When a business uses PeasyBooking to send email or SMS reminders and confirmations to its own clients, the business controls the purpose and audience of those messages, and PeasyBooking delivers them on the business's instructions. The business is responsible for obtaining and keeping proof of the consent its clients require. PeasyBooking provides the tools that support compliance with Canada's Anti-Spam Legislation (CASL), including sender identification, an unsubscribe mechanism, suppression lists, consent records, and message logs. Appointment reminders are generally service messages; campaigns, review requests, promotions, reactivation messages, membership offers, and referrals are generally commercial messages requiring consent.
- SMS text messages (the optional SMS add-on). Where a business enables the SMS add-on, texts are sent from a dedicated mobile number assigned to that business and delivered through our SMS subprocessor, Twilio Inc. (United States; see Section 6 and the Subprocessor List). SMS is opt-in: a recipient's express consent is captured — for example, by choosing "Text me appointment reminders" at booking — and recorded with a timestamp. Every text identifies the business and tells recipients they can reply STOP to opt out at any time (and HELP for help); a STOP reply unsubscribes that number immediately, and replies are honoured before any further message is sent. Two-way reminder texts also let a recipient reply to confirm or cancel their appointment. Mobile numbers and message content are processed only to deliver these messages.
- Marketing messages PeasyBooking sends in its own right (for example, to Marketplace guests or to account holders about our own products). We send these only with the consent CASL requires, and every commercial electronic message identifies the sender and includes an unsubscribe mechanism. You can withdraw consent at any time.
---
9. Where your information is stored, and cross-border processing
Core customer and client data — including the PostgreSQL database and file storage — is hosted in Canada, in Google Cloud's northamerica-northeast1 (Montréal) region.
Backups are stored in the United States. The automated daily database backups and point-in-time-recovery copies described in our Data Retention Schedule are held in Google Cloud's us multi-region (United States). They exist for disaster recovery only, are not used for analytics or day-to-day access, and age out on the rolling schedule set out in that document. This applies to every customer, including customers in Canada.
However, not all other data stays in Canada either. Certain service providers process limited personal information outside Canada to deliver their services:
- authentication (Google Identity Platform / Firebase) — United States / global;
- payments (Stripe) — United States / global;
- transactional email (Resend) — United States; and
- SMS (Twilio Inc.) — United States / global.
Marketplace map requests are made directly by a visitor's browser to OpenFreeMap (operator in Hungary, with Cloudflare's global delivery/security network). This direct request contains the visitor's IP address and standard technical request data but no name, account, booking, payment, or business-client record sent by PeasyBooking.
While information is stored or processed outside Canada, it may be accessible to courts, law enforcement, and regulatory authorities in those jurisdictions under their laws. Consistent with PIPEDA's accountability principle, we engage service providers that are contractually bound to provide a level of protection comparable to that required under applicable Canadian privacy law — that is, comparable to the protection PeasyBooking is itself required to provide — and we limit the information shared with each provider to what is needed for its function. Our Subprocessor List sets out each provider's processing region.
Customers and individuals outside Canada. If you are located outside Canada (for example, in the United States), your personal information is processed and stored in Canada as described above, and backed up in the United States. Business customers acknowledge this cross-border hosting at signup, and that acknowledgment is recorded with its date and version. By using the service you acknowledge this cross-border transfer.
Quebec. Our primary hosting region is located in Quebec (Montréal). Where personal information about individuals in Quebec is communicated outside Quebec — including to the United States as backups, and to the service providers listed above — we do so in accordance with Law 25, including assessing the factors Law 25 requires before such communication.
---
10. How we protect information
We use technical and organizational safeguards appropriate to the sensitivity of the information, including:
- encryption in transit (TLS) and encryption at rest;
- network isolation, role-based access controls, and access/audit logging; and
- backup and recovery controls.
No method of transmission or storage is perfectly secure. PeasyBooking does not claim HIPAA compliance or a SOC 2 attestation. We describe only the security measures we actually employ.
---
11. Your rights — access, correction, and consent
Subject to applicable law, where PeasyBooking is the responsible organization (account holders, staff, and Marketplace guests), you may:
- request access to the personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- where Quebec's Law 25 applies to you, request that computerized personal information you provided to us be communicated to you (or, at your request, to a person or body authorized by law to collect it) in a structured, commonly used technological format (data portability); and
- withdraw consent, subject to legal and contractual limits.
Response timeframes. We will respond within the timeframes the law requires. Under Alberta PIPA, we will generally respond to access and correction requests within 45 days (with extensions permitted in limited circumstances); under Quebec's private-sector act we will respond within 30 days; and we will meet the response obligations that PIPEDA imposes for requests it governs. Response timeframes for US state-privacy requests are described in Section 11A.
To exercise these rights, contact our Privacy Officer using the details in Section 16. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your applicable provincial privacy commissioner (for example, the Office of the Information and Privacy Commissioner of Alberta, or, for Quebec, the Commission d'accès à l'information du Québec).
Data portability — how to request it and what you receive. To make a data-portability request, send it to our Privacy Officer using the contact details in Section 16 and identify it as a "data portability request." After we verify your identity, we will provide the computerized personal information you provided to us in a structured, commonly used, machine-readable format (for example, CSV or JSON) — or, at your request and where it is technically feasible for us, transmit that information directly to a person or body authorized by law to collect it. We provide it within the response timeframes set out above, at no charge in the ordinary case.
Records held by a business that uses PeasyBooking. If you are a client of a salon, spa, or other business that uses PeasyBooking, please direct access and correction requests about those records to that business, which is the responsible organization. We will refer such requests to it.
---
11A. Your U.S. state privacy rights (CCPA/CPRA)
This Section applies if you are a California resident — and, where comparable state laws apply, a resident of another U.S. state — and PeasyBooking is the organization responsible for your information (see Section 1).
- Notice at collection. In the past 12 months we have collected the categories of personal information described in Section 2: identifiers (such as name, email, and IP address), commercial information (such as subscription and payment activity), internet and network activity (such as log and usage data), and the content you choose to submit. We collect it for the business purposes described in this Policy and retain it as described in Section 12.
- No sale or sharing. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding 12 months, including with respect to the personal information of consumers under 16.
- Sensitive personal information. We use any sensitive personal information only as necessary to provide the service and for purposes permitted by the CCPA/CPRA; we do not use or disclose it to infer characteristics about you.
- Your rights. Subject to verification, you may request to: know the categories and specific pieces of personal information we hold about you and how we collect, use, and disclose it; delete personal information we have collected, subject to legal exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information (noting we do not sell or share it); and not receive discriminatory treatment for exercising your rights.
- How to exercise your rights. Submit a request using the contact details in Section 16 or the "Do Not Sell or Share My Personal Information" link on our website. We will verify your request against information associated with your account and respond within 45 days (extendable by a further 45 days where permitted). You may use an authorized agent to submit a request on your behalf with proof of authorization.
- Do Not Sell or Share My Personal Information. PeasyBooking does not sell or share personal information as those terms are defined by the CCPA/CPRA, so no opt-out is required. If this ever changes, we will provide a working opt-out and honor opt-out preference signals such as Global Privacy Control (GPC).
- Shine the Light (California Civil Code §1798.83). We do not disclose personal information to third parties for those parties' own direct marketing purposes.
Client records held for a business. Where PeasyBooking processes your information on behalf of a business you patronize (Section 1), PeasyBooking acts as a "service provider" under the CCPA/CPRA, and requests should be directed to that business; the service-provider commitments appear in our Data Processing Agreement.
---
12. Retention and deletion
We retain personal information for as long as needed to provide the service and to meet legal, tax, and security obligations. Our full retention periods — including database, backup, billing, email/SMS, and log retention — are set out in our Data Retention Schedule.
Account holders and Marketplace guests (information PeasyBooking is responsible for). When a business account is closed, access to the service ends and a grace period applies, after which we delete the associated account data on the timelines in the Data Retention Schedule. Because the Marketplace does not offer consumer accounts, a guest has no profile to close; a guest may instead ask us at any time to delete the marketplace-side information we hold about them, using the contact details in Section 16, and we respond within the timeframes described in Section 11.
Business client records (processed under instruction). A single standard applies: when a business closes its account, its client records follow the standard account-closure process — a grace period (currently approximately 30 days), then permanent deletion — on the timelines in the Data Retention Schedule. A business may instruct earlier deletion; before we act on such an instruction, the business must confirm that its own retention, preservation, and legal-hold obligations have been satisfied.
The specifics — including export before closure, active-system recoverability, backup retention windows, and legal holds — are set out in our Data Processing Agreement and Data Retention Schedule.
Information that may remain elsewhere. Even after deletion from the active system, limited information may persist for a period in encrypted backups (which age out on a rolling basis), in our service providers' systems (for example, Stripe payment records, and email/SMS delivery logs), and in our invoices, security records, and audit logs, to the extent required for legal, tax, accounting, dispute-resolution, and security purposes, or where a legal hold, payment dispute, complaint, or regulatory investigation applies.
---
13. Breach of security safeguards
How we handle a privacy or security breach depends on who is the responsible organization for the affected information. This Section is consistent with, and should be read together with, our Data Processing Agreement.
Information PeasyBooking is responsible for (account holders, staff, and Marketplace guests). If a breach of security safeguards involving information for which PeasyBooking is responsible occurs, we assess whether it creates a real risk of significant harm and make the notifications applicable law requires, reporting to and notifying the applicable privacy commissioner(s) where the threshold is met. Because PeasyBooking is an Alberta-resident organization:
- Where Alberta PIPA applies, we will report the incident to the Office of the Information and Privacy Commissioner of Alberta under PIPA's mandatory breach-notification provisions (section 34.1) where there is a real risk of significant harm to an individual, and we will notify affected individuals as directed by the Alberta Commissioner.
- Where PIPEDA applies, we will report to the Office of the Privacy Commissioner of Canada and notify affected individuals where the real-risk-of-significant-harm threshold is met.
- Where Quebec's Law 25 applies, we will notify the Commission d'accès à l'information du Québec and the affected individuals of any confidentiality incident that presents a risk of serious injury, take reasonable measures to reduce the risk of injury and prevent recurrence, and maintain a register of confidentiality incidents.
Neither commissioner is the sole regulator; we will make the report(s) and notifications required by the privacy law(s) applicable to the affected information, and where more than one regime applies we will meet each of their requirements. We keep records of all breaches as the law requires.
Information a business is responsible for (its clients). Where a breach affects client information that PeasyBooking processes on a business's instructions, the business (as the responsible organization) decides whether and how to notify affected individuals and regulators. PeasyBooking's role is to promptly notify the affected business, contain the incident, support the investigation, and provide the facts the business needs to make its decisions. Our specific commitments — including the initial-notice timing target, the required contents of that notice, ongoing updates, containment steps, preservation of evidence and logs, and who communicates with individuals and regulators — are defined in our Data Processing Agreement.
---
14. Cookies and similar technologies
We use technologies that are necessary to keep you signed in and to operate and secure the service, including those used by our authentication provider, Google Identity Platform / Firebase Authentication, to establish and maintain your session (see Sections 6 and 9). We do not use cookies or similar technologies for third-party advertising. The Marketplace map feature causes your browser to request map imagery directly from OpenFreeMap, identified in our Subprocessor List; that service receives your IP address and standard technical request data under its own privacy policy. PeasyBooking does not send it your name, account, booking, payment, or business-client details. The provider-list view remains available without map tiles.
---
15. Children
PeasyBooking's business tools are not directed to children. The consumer Marketplace is for adults: you must be the age of majority in your province or territory to book, as stated in the Marketplace Guest Terms, and we do not knowingly collect personal information from minors through the Marketplace. Where a business records information about minor clients (for example, a salon serving a minor client with parental consent), it does so under its own authority and responsibility as the organization responsible for those records — not through the Marketplace.
---
16. Changes to this Policy, and how to contact us
We may update this Policy from time to time and will post the new effective date above. Material changes will be communicated as required by law. Our governance policies and practices with respect to personal information — including who our person in charge of the protection of personal information is (our Privacy Officer, who approves these policies), the retention and destruction framework in the Data Retention Schedule, the roles and responsibilities of our personnel throughout the information life cycle, and our process for handling privacy complaints — are published on our website in simple and clear terms, as required by Quebec's Law 25, at peasybooking.com/privacy-governance.
Privacy questions, requests, or complaints may be directed to our Privacy Officer:
PeasyBooking Technologies Inc.
Attn: Privacy Officer
150 Evergreen Mount SW, Calgary, AB T2Y 0L8, Canada
Email: info@peasybooking.com (support: support@peasybooking.com)
This Policy is governed by the laws of the Province of Alberta and the federal laws of Canada applicable therein.
Language. This Policy is drafted in English. The English version is the only authoritative version and governs for all purposes; any translation we may provide is for convenience only.
Related documents: Business SaaS Terms · Marketplace Guest Terms · Provider Marketplace Agreement · Data Processing Agreement · Subprocessor List · Data Retention Schedule.