Privacy Policy
Tase Tech LLC — booking software for service businesses
Effective date: August 24, 2026
English
Looking for a specific business's policy? Each business that
takes bookings through Tase Booking publishes its own privacy policy at
tasebooking.com/b/<business>/privacy. This page covers
Tase Tech LLC as the software provider.
1. Two different roles
Tase Tech LLC provides the booking software. How your data is
handled depends on which relationship you are in:
- If you booked an appointment with a business that uses our
software, that business decides what is collected and why. It is the data
controller; we process the data on its behalf. Its own privacy policy applies.
- If you are a business using our software, we are the controller
for your account information, and this page applies.
2. Information we hold about business accounts
- Account details: name, email address, password (stored only as a hash).
- Business profile: trading name, contact details, address, timezone, services and availability.
- Where a business connects Google Calendar, the access credentials for that connection, encrypted at rest.
- Operational logs needed to run and debug the service.
3. Appointment data
Appointment records belong to the business that took the booking. We
store and process them so the software works, and we do not use them for
our own marketing, do not sell them, and do not share them between
businesses.
4. Sub-processors
- Hostinger International Ltd. — hosting and database.
- Twilio Inc. — SMS delivery.
- Google LLC — calendar and video-meeting integration, when a business enables it.
- Cloudflare, Inc. — bot protection on public booking forms.
5. Google user data
A business may connect its Google account so that video appointments get
a calendar event and a Google Meet link automatically. This section
describes exactly what that connection does, because it is the only part of
the service that touches data held in a Google account.
- Scopes we request.
https://www.googleapis.com/auth/calendar.events — to create,
update and delete the calendar events for appointments booked through
this software, and nothing else.
https://www.googleapis.com/auth/userinfo.email — to display
which Google account is connected, so the owner can confirm they linked
the right one.
- What we access. Only events this application created.
We do not read, index, or analyse the rest of the calendar.
- How we use it. When a customer books a video
appointment we create one calendar event, attach a Google Meet link, and
add the customer as a guest so Google sends them the invitation. When the
appointment is rescheduled we move that event; when it is cancelled we
delete it.
- What we store. The OAuth access and refresh tokens,
encrypted at rest with AES-256-GCM; the identifier of each event we
created; and the Meet link for the booking. We do not copy calendar
contents into our database.
- What we never do. We do not sell or transfer Google
user data, do not use it for advertising, do not use it to train
generalised models, and do not allow humans to read it except where
required for security, to comply with the law, or with the account
owner's explicit permission.
- Revoking access. Disconnect at any time from
Integrations in the admin panel, or from
Google Account
permissions. On disconnect we delete the stored tokens and revoke
them with Google. Calendar events already created stay on the calendar
and can be deleted there.
Our use of information received from Google APIs adheres to the
Google
API Services User Data Policy, including the Limited Use requirements.
6. Security
Passwords are hashed, calendar credentials are encrypted at rest, and
access to production data is limited to what is needed to operate the
service. No system is perfectly secure, and we do not claim otherwise.
7. Retention and deletion
We keep account and appointment data for as long as the account is
active. A business may request export or deletion of its data by writing to
the address below.
8. Contact
contact@tasetech.com
Español
¿Buscas la política de un negocio en particular? Cada negocio
que recibe reservas con Tase Booking publica la suya en
tasebooking.com/b/<negocio>/privacy. Esta página se refiere a
Tase Tech LLC como proveedor del software.
1. Dos roles distintos
- Si reservaste una cita con un negocio que usa nuestro software,
ese negocio decide qué se recoge y para qué. Él es el responsable de los datos y
nosotros los procesamos por su cuenta. Aplica la política de ese negocio.
- Si eres un negocio que usa el software, somos responsables de los
datos de tu cuenta y aplica esta página.
2. Información de las cuentas de negocio
- Datos de la cuenta: nombre, correo y contraseña (guardada sólo como hash).
- Perfil del negocio: nombre comercial, contacto, dirección, zona horaria, servicios y disponibilidad.
- Si el negocio conecta Google Calendar, las credenciales de esa conexión, cifradas.
- Registros operativos necesarios para operar y depurar el servicio.
3. Datos de las citas
Los registros de citas pertenecen al negocio que recibió la reserva. Los
almacenamos y procesamos para que el software funcione; no los usamos para
marketing propio, no los vendemos y no los compartimos entre negocios.
4. Subprocesadores
- Hostinger International Ltd., alojamiento y base de datos.
- Twilio Inc., entrega de SMS.
- Google LLC, integración de calendario y videollamadas cuando el negocio la activa.
- Cloudflare, Inc., protección antibots en los formularios públicos.
5. Datos de usuario de Google
Un negocio puede conectar su cuenta de Google para que las citas por
videollamada generen automáticamente un evento de calendario y un enlace de
Google Meet. Esta sección detalla exactamente qué hace esa conexión, porque
es la única parte del servicio que toca datos de una cuenta de Google.
- Permisos que pedimos.
https://www.googleapis.com/auth/calendar.events, para crear,
actualizar y borrar los eventos de las citas reservadas con este
software, y nada más.
https://www.googleapis.com/auth/userinfo.email, para mostrar
qué cuenta quedó conectada y que la dueña confirme que enlazó la correcta.
- A qué accedemos. Sólo a los eventos que esta
aplicación creó. No leemos, indexamos ni analizamos el resto del calendario.
- Cómo lo usamos. Cuando alguien reserva una videollamada
creamos un evento, le adjuntamos un enlace de Google Meet y agregamos al
cliente como invitado para que Google le envíe la invitación. Si la cita
se reprograma movemos ese evento; si se cancela, lo borramos.
- Qué guardamos. Los tokens de acceso y actualización,
cifrados con AES-256-GCM; el identificador de cada evento que creamos; y
el enlace de Meet de la reserva. No copiamos el contenido del calendario
a nuestra base de datos.
- Qué nunca hacemos. No vendemos ni transferimos datos de
usuario de Google, no los usamos para publicidad, no los usamos para
entrenar modelos generalizados y no permitimos que personas los lean,
salvo por seguridad, obligación legal o permiso explícito de la dueña
de la cuenta.
- Revocar el acceso. Se puede desconectar en cualquier
momento desde Integraciones en el panel, o desde los
permisos de tu cuenta
de Google. Al desconectar borramos los tokens guardados y los
revocamos ante Google. Los eventos ya creados permanecen en el calendario
y se pueden borrar desde ahí.
El uso que hacemos de la información recibida de las APIs de Google se
ajusta a la Política
de Datos de Usuario de los Servicios de API de Google, incluidos los
requisitos de Uso Limitado.
6. Seguridad
Las contraseñas se guardan como hash, las credenciales de calendario van
cifradas y el acceso a datos de producción se limita a lo necesario para
operar. Ningún sistema es perfectamente seguro y no afirmamos lo contrario.
7. Conservación y borrado
Conservamos los datos mientras la cuenta esté activa. Un negocio puede
pedir la exportación o el borrado de sus datos escribiendo a la dirección de abajo.
8. Contacto
contact@tasetech.com