1. Introduction
1001368444 Ontario Inc. ("BusyTimes," "we," "us," or "our") operates the BusyTimes platform at busytimes.co and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our Service.
BusyTimes is a software-as-a-service (SaaS) booking and scheduling platform that enables businesses ("Companies") to accept online bookings from their clients ("Clients"). This policy applies to both Companies and their Clients who interact with our platform.
We are committed to compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation in Canada.
2. Information We Collect
2.1 From Companies (Business Administrators and Staff)
- Account information: business name, contact name, email address, phone number, website URL, business type, and password (stored in hashed form)
- Staff information: staff names, email addresses, phone numbers, and role/access level within your organization
- Service and scheduling data: services offered, pricing, durations, descriptions, availability schedules, blocked times, and booking settings
- Branding and customization data: logos, color schemes, custom CSS, and other visual customization settings
- Payment integration data: Stripe Connect account identifiers and onboarding status (we do not store raw payment card data — this is handled by Stripe)
- Calendar integration data: Google Calendar and/or Microsoft (Outlook) OAuth access and refresh tokens and calendar identifiers necessary to sync appointments (we request only the minimum scopes required to read availability and write appointment events). Tokens are stored in encrypted form.
- Communication preferences: SMTP settings (if configured), email template customizations
2.4 Document and E-Signature Data
Companies using our E-Signatures feature, and the individuals they send documents to ("Signers," who may or may not otherwise be Clients), provide additional information:
- Document content: PDF documents and document templates uploaded by a Company, and the field values a Signer enters
- Signature data: the signature and initials a Signer draws (captured as an image), and any typed name, date, or checkbox responses
- Signer identity and audit data: Signer name and email address, IP address, browser/user-agent, and the timestamps at which the document was viewed and signed
- Consent and integrity records: the Signer's acceptance of electronic-signing consent, plus a verification code and a SHA-256 cryptographic fingerprint of the completed document used to confirm it has not been altered
2.2 From Clients (Booking Clients)
- Contact information: full name, email address, and optionally phone number
- Appointment data: services booked, dates and times, assigned staff, special notes or requests
- Payment data: deposit amounts paid (processed through Stripe — we do not store card numbers)
- Communication preferences: consent to receive appointment-related emails and optionally SMS reminders
2.3 Automatically Collected Information
- Log data: IP addresses, browser type, operating system, pages visited, and timestamps
- Session data: authentication tokens stored in secure HTTP-only cookies
- Usage data: feature usage patterns to improve the Service (may be aggregated and de-identified)
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the BusyTimes platform
- Process and manage appointment bookings
- Send appointment confirmations, reminders, and receipts to Clients on behalf of Companies
- Notify Companies and their staff of new bookings, cancellations, and changes
- Process payments and deposits through Stripe
- Sync appointment data with Google Calendar or Microsoft (Outlook) Calendar (when authorized)
- Send SMS appointment reminders (when authorized by Clients)
- Create, send, complete, store, and cryptographically verify electronically-signed documents on behalf of Companies (E-Signatures feature)
- Authenticate users and maintain secure sessions
- Provide customer support
- Send service-related administrative notices
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal information. We do not use Client data collected through booking forms for our own marketing purposes without explicit consent.
4. How We Share Your Information
4.1 With Companies
When a Client books an appointment, their contact details and booking information are shared with the Company that operates the booking portal. Clients booking through a Company's portal are subject to that Company's own privacy practices in addition to this policy.
4.2 Service Providers
We engage third-party service providers who assist in operating our platform. These providers access information only to perform services on our behalf and are bound by confidentiality obligations:
- Stripe: Payment processing and Stripe Connect for managing Company payment accounts. Stripe's privacy policy applies to payment data. (stripe.com/privacy)
- Google: Google Calendar integration for Companies who authorize calendar sync. Google's privacy policy applies to OAuth-accessed calendar data. (policies.google.com/privacy) BusyTimes's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data only to provide the calendar-sync feature you request; we do not use it for advertising, do not sell it, do not use it to train generalized AI/ML models, and do not transfer it except to provide or improve this feature, comply with law, or as part of a merger where the receiving party honours this policy.
- Microsoft: Microsoft (Outlook / Microsoft 365) Calendar integration for Companies who authorize it. Microsoft's privacy statement applies to OAuth-accessed calendar data. (privacy.microsoft.com) Microsoft calendar data is used only to provide the calendar-sync feature you request.
- Email service providers: We use third-party email infrastructure to deliver transactional emails (appointment confirmations, reminders, receipts, and e-signature requests and completed-document notices)
- SMS providers: When Companies enable SMS reminders and Clients opt in, SMS messages are delivered via a third-party SMS gateway
- Hosting and infrastructure providers: Our platform, including uploaded and signed documents, is hosted on cloud infrastructure providers who process data on our behalf
4.3 Legal Requirements
We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency), or to protect the rights, property, or safety of BusyTimes, our users, or others.
4.4 Business Transfers
If BusyTimes is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
4.5 E-Signature Documents and Public Verification
When a document is completed through the E-Signatures feature, the completed PDF (including drawn signatures, entered values, and an audit certificate) is available to the Company that sent it and to the Signers involved. BusyTimes also provides a public verification page so that anyone holding a document's verification code, or the completed PDF file, can confirm the document is authentic and unaltered. The public verification page discloses only limited metadata — the document title, the Company (business) name, the completion date, and each signer's name, role, signing time, and a partially-masked email address. It never exposes the document's contents, the stored PDF file, download links, or any internal identifiers. Signed and source documents are stored on our infrastructure and are served only through authenticated, non-public links.
4.6 International Data Transfers
BusyTimes is operated from Canada. Some of our service providers (including Stripe, Google, Microsoft, and our email, SMS, and hosting providers) may store or process information on servers located outside your province or country, including in the United States. Where information is transferred across borders, it remains subject to this Privacy Policy and to contractual and legal safeguards, and it may be accessible to courts, law enforcement, and authorities in those jurisdictions under their laws.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements:
- Account and business data: retained for the duration of the account plus 90 days after account deletion
- Appointment and client records: retained for 7 years to support tax record-keeping and legal compliance
- Payment records: retained as required by applicable financial regulations (typically 7 years)
- Signed documents and e-signature audit records: retained for the life of the Company's account (and for the period the Company requires them for their own record-keeping) unless deleted earlier at the Company's request; the audit trail and integrity fingerprint are retained with the document
- Calendar OAuth tokens: retained only while the integration remains connected, and deleted when you disconnect the integration or delete your account
- Log data: retained for up to 90 days
- Consent records: retained permanently as evidence of consent
You may request earlier deletion of your data — see Section 8 (Your Rights).
6. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain secure authentication sessions (HTTP-only session cookies)
- Remember user preferences
- Ensure platform security and prevent fraud
We use only essential cookies required for the platform to function. We do not use advertising cookies or track users across unrelated websites. Blocking essential cookies may prevent you from using certain features of the Service.
7. Security
We implement industry-standard security measures to protect your personal information, including:
- TLS/HTTPS encryption for all data in transit
- Encrypted storage for passwords (bcrypt hashing) and sensitive tokens
- Access controls limiting who can access personal data, scoped so that each Company can access only its own data
- Envelope encryption for sensitive stored credentials and integration tokens
- Uploaded and signed documents stored outside the public web root and served only through authenticated links; completed documents protected by a SHA-256 integrity fingerprint
- Rate limiting to prevent brute-force attacks
- Regular security monitoring
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we take reasonable precautions to protect your information.
8. Your Rights (PIPEDA)
Under PIPEDA and applicable Canadian privacy laws, you have the right to:
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate or incomplete information
- Withdrawal of consent: withdraw consent to certain uses of your information (note: this may limit your ability to use certain features)
- Deletion: request deletion of your personal information, subject to legal retention requirements
- Complaint: lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca)
To exercise these rights, contact us at privacy@busytimes.co. We will respond within 30 days.
Google and Microsoft calendar data: You may disconnect a calendar integration at any time from your BusyTimes account settings. Disconnecting immediately revokes our access and deletes the stored OAuth tokens. You may also revoke BusyTimes's access directly from your Google Account permissions or Microsoft account. We do not retain a copy of your calendar contents.
Clients and Signers: Booking records and signed documents are controlled by the Company on whose account they were created. To access or delete this data, contact that business directly. We will assist Companies in fulfilling such requests and will honour verified deletion requests we receive, subject to legal retention requirements.
9. Children's Privacy
The BusyTimes platform is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or by posting a notice on the platform. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
1001368444 Ontario Inc.
Privacy inquiries: privacy@busytimes.co
General support: support@busytimes.co
Jurisdiction: Ontario, Canada