Privacy Policy
Last updated: June 15, 2026 • Version 1.2.0
At Onpage Scheduler, we prioritize the secure processing, integrity, and privacy of both your registered business attributes and the contact details submitted by your customers during client-side booking events.
1. Information We Collect
We process minimal data parameters required to coordinate stateless scheduling calendars:
- Merchant Workspace Attributes: Custom links, contact emails, working hours, primary hex colors, and media asset URLs.
- Client Booking Data: Customer full names, active emails, phone records, custom notes, and slot coordinates.
- Payment Gateways Credentials: We only store merchant Stripe Public/Secret keys and PayPal Client IDs securely inside encrypted database fields. Actual transactions are processed directly on gateway host servers.
2. Data Security & Storage Architecture
Your information is stored securely in databases hosted on cloud environments.
3. Webhook and Asynchronous Processing
Transactional client checkout tokens or platform subscription charges are verified asynchronously. We enforce webhook validation to confirm that only legitimate Stripe-signed event payloads can trigger plan tier modifications or write transaction auditing rows.
4. Zero External Selling of Data
We never monetize, share, sell, or distribute any email records, client metadata, or business analytics to third-party advertising companies. All stored arrays remain strictly isolated to the multitenant tenant scope of your customized links.
5. Cookies usage
We utilize stateless cookie sessions strictly to keep merchants securely authenticated to their dashboard panels (`sessionToken`). These are marked as `HttpOnly`, `SameSite=Lax`, and expire automatically.
Questions or GDPR deletion requests?
Connect directly with our security handlers via privacy@onpagescheduler.com.