Privacy Policy
Last updated: April 10, 2026. This policy describes how Schedulaa collects, uses, stores, and shares personal data when you use our website, applications, and connected billing services.
Data we collect
- Account profile data, organization details, and workspace configuration.
- Operational product data such as bookings, schedules, and service activity.
- Billing and payment metadata from payment providers (for example Stripe IDs, invoice state, and card attributes).
- Security and anti-fraud signals such as IP address, request timestamps, user agent, and risk events.
- Punch-location evidence, if enabled by a company, such as employee/device location captured when an employee taps Clock In or Clock Out.
How we use data
- Provide and secure Schedulaa services.
- Process subscriptions, invoices, and payments.
- Detect abuse, prevent fraud, and investigate suspicious billing behavior.
- Support attendance verification, manager review, operational security, and timekeeping review.
- Respond to payment disputes and legal/regulatory requests.
Punch location evidence
If a company enables punch-location evidence, Schedulaa may collect employee/device location only when an employee taps Clock In or Clock Out. This evidence is used for attendance verification, manager review, operational security, and timekeeping review. Location data is collected only when the employee initiates a clock-in or clock-out action.
Schedulaa does not use this feature for background location tracking or continuous location monitoring. If location is unavailable, denied, unsupported, or times out, employees may still be able to clock in or out depending on the product flow. Punch-location evidence is advisory for manager review and is not continuous surveillance.
Fraud prevention controls
To reduce card abuse and account takeover risk, Schedulaa may apply risk-based controls including attempt limits, 3D Secure challenges, prepaid-card restrictions for subscriptions, and temporary billing review holds.
We may retain fraud-attempt and fraud-event records for limited periods to support operational security, dispute response, and compliance.
Data sharing
We share data with trusted subprocessors only as needed to operate the platform (for example payments, infrastructure, email delivery, and security tooling). Payment data is handled by PCI-compliant payment providers.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict certain personal data. To submit a request, contact us through support.
