Legal

Privacy Policy

This policy explains what Tymbook handles when studios manage calendars, customers book, and account holders use payments, Agent tools or connected channels.

Last updated: 13 July 2026

Controller and contact

For Tymbook's own account, support, security and product-usage processing, the controller is Viktor Laszlo Vincze, a sole proprietor trading as Tymbook at Buchwies 17, 54426 Büdlich, Germany.

Privacy questions and data requests can be sent to info@tymbook.com.

Who this policy covers

Tymbook provides calendars, booking pages and related tools to service businesses. When a studio chooses what customer details to collect and how to use them, that studio is responsible for those choices and Tymbook processes the details to provide the service. We are responsible for the account, support, security and product-usage data we collect for our own operations.

If you book with a studio, contact the studio first about its booking records or business practices. You can also contact us when your question concerns Tymbook itself.

Data we collect

  • Account and workspace data: name, email, sign-in method, hashed password, language, business profile, plan, team memberships, calendars, services, availability, booking rules and settings.
  • Booking and customer data: names, contact details, appointments, intake answers, notes, status, reminders and deposit or refund references. Tymbook Quick also stores the event details and email addresses needed to arrange a one-off appointment.
  • Content and communications: profile images, support requests, feedback, Agent conversations, confirmation choices, emails and messages exchanged through connected channels.
  • Integration data: connected-provider identifiers, encrypted credentials where required, API-token and webhook configuration, delivery status, custom domains and subdomains.
  • Technical and usage data: session and preference cookies, IP and request logs, browser or device information, security events, and analytics about visits and product use.

How we use data

  • Provide accounts, calendars, booking pages, reminders, payments, support, APIs, Agent features and connected channels.
  • Authenticate users, keep workspaces separated, prevent abuse, troubleshoot failures and protect the service.
  • Process plan billing, deposit status and refunds, and keep the records needed to reconcile those transactions.
  • Understand performance and product use, improve Tymbook, and communicate important service or account information.

We do not sell account data or studio customer data, and we do not use it for cross-site advertising.

AI and connected services

Agent Chat and AI onboarding send the prompt and the relevant studio context to OpenRouter and the model provider selected for that request. Agent conversations can include calendar, service, team, appointment and customer details. Agent write actions require confirmation in Tymbook before they are applied, but AI output can still be incomplete or wrong.

If you connect Telegram, Discord, Slack, WhatsApp, Messenger or Instagram, messages and provider identifiers pass through that provider and Tymbook so the Agent can reply. Google handles Google sign-in; Stripe handles subscriptions and connected-account deposits; Telnyx handles enabled SMS reminders; Google Analytics measures use of the main Tymbook production site. API, MCP, WebMCP, webhook and custom-domain features send data to the tools and destinations the studio chooses.

Support attachments are forwarded through email. Uploaded profile images are stored for the workspace and served from a hard-to-guess public file address, so do not upload confidential images.

Those providers process data under their own terms and privacy policies. Disconnecting a channel removes its Tymbook connection, but does not erase copies already retained by that provider or the account's shared Agent history.

Cookies and analytics

Tymbook uses necessary cookies for sign-in, security, language, active calendar, navigation and interface preferences. A theme preference may also be stored in your browser.

Google Analytics loads only on tymbook.com and www.tymbook.com, not on staging or a studio's custom booking domain. It may set measurement cookies and receive device, page and interaction information. We use this to understand aggregate product and site performance, not for cross-site advertising.

When data is shared

We share data only as needed with authorized workspace members, the studio and its bookers, the service providers described above, and infrastructure or email providers that help us operate Tymbook. We may also disclose information when required by law, to protect people or the service, to investigate abuse, or as part of a business transfer subject to appropriate safeguards.

Retention and deletion

We keep account and workspace records while they are needed to provide Tymbook. Different records follow different schedules: short-lived verification and linking codes expire; cancelled or completed Tymbook Quick events are purged after their operational window; security, billing, deposit, refund, delivery and backup records may remain longer where needed for reliability, fraud prevention, accounting or legal obligations.

Removing an avatar, revoking an API token or disconnecting a channel removes that item from active use. It does not automatically delete related booking records, shared Agent history, provider copies or rolling backups.

Your choices and requests

Account holders can update much of their profile and workspace data in Tymbook, remove images, revoke tokens and disconnect channels. To request access, correction, a portable copy or deletion of other data, email info@tymbook.com from the account address and tell us which account or booking the request concerns. We may need to verify your identity and may retain records where the law or a legitimate operational need requires it.

If a studio collected your information as its customer, contact the studio first. We will help the studio respond when Tymbook holds the relevant data for it.

Security and international processing

We use safeguards including encrypted connections, hashed passwords, scoped access controls and encryption for provider credentials. No online service can guarantee absolute security. Tymbook and its providers may process data in countries other than yours, subject to the protections required for that processing.

Children and policy changes

Tymbook accounts are for adults using the service for lawful business purposes. Studios are responsible for having an appropriate basis and any required permission before entering information about a child or offering services to one.

We may update this policy as Tymbook changes. We will update the date above and provide additional notice when a change materially affects how we handle data.

Contact

Privacy questions and data requests: info@tymbook.com.