Skip to main content
timeslot.ie
Home Features Pricing Demo About Help
Login Start free
Home Features Pricing Demo About Help Login Start free
Privacy

Privacy Policy

Last updated: 23 February 2026

1. Data Controller

timeslot.ie (“we”, “us”, “our”) is the data controller for personal data collected through the timeslot.ie platform and website (timeslot.ie). We are an Irish company and subject to the General Data Protection Regulation (GDPR) as implemented by the Data Protection Act 2018.

Registered address
Dublin, Ireland
Email
privacy@timeslot.ie

2. Categories of Personal Data Collected

We collect and process the following categories of personal data:

  • Account data — name, email address, phone number, business name, and billing address when you create an account.
  • Booking data — appointment details, service selections, scheduling preferences, and customer notes submitted through booking pages.
  • Payment data — payment card details are processed directly by Stripe and are never stored on our servers. We retain transaction references, amounts, and invoice records.
  • Usage data — IP address, browser type, pages visited, and feature usage for analytics and service improvement.
  • Communication data — email and SMS content sent through our notification system, and support correspondence.

3. Purpose and Lawful Basis

Purpose Lawful basis
Providing the booking and scheduling service Performance of contract (Art. 6(1)(b))
Processing payments and issuing invoices Performance of contract (Art. 6(1)(b))
Sending booking confirmations and reminders Performance of contract (Art. 6(1)(b))
Fraud prevention and security Legitimate interest (Art. 6(1)(f))
Service improvement and analytics Legitimate interest (Art. 6(1)(f))
Marketing communications Consent (Art. 6(1)(a))
Compliance with tax and legal obligations Legal obligation (Art. 6(1)(c))

4. Data Retention

  • Account data — retained for the duration of your account, plus 30 days after deletion.
  • Booking data — retained for 3 years after the booking date for business reporting purposes.
  • Financial records — retained for 6 years as required by Irish Revenue for tax compliance.
  • Usage logs — retained for 90 days, then aggregated and anonymised.
  • Support correspondence — retained for 2 years after the last interaction.

5. Sub-processors

We share personal data with the following categories of sub-processors:

  • Stripe (payments) — Stripe, Inc., USA. Processes payment card data under their own controllership. Stripe Privacy Policy.
  • Email delivery provider — for sending transactional emails (booking confirmations, reminders, invoices).
  • SMS delivery provider — for sending SMS reminders to end customers.
  • Hosting provider — infrastructure hosting for the timeslot.ie platform and database.

A complete list of sub-processors with their locations is available upon request by contacting privacy@timeslot.ie.

6. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions by the European Commission for the recipient country.
  • Binding Corporate Rules where applicable.

7. Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of your personal data.
  • Right to rectification — request correction of inaccurate data.
  • Right to erasure — request deletion of your data (“right to be forgotten”).
  • Right to restriction — request limited processing of your data.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interest.
  • Right to withdraw consent — withdraw consent at any time where processing is based on consent.

To exercise any of these rights, submit a Data Subject Access Request (DSAR) by emailing privacy@timeslot.ie. We will respond within 30 days.

8. Security Measures

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access controls and least-privilege principles.
  • Regular security audits and vulnerability assessments.
  • Secure password hashing (bcrypt).
  • Automated threat detection and rate limiting.

9. Contact

For privacy-related enquiries or to submit a DSAR:

Email
privacy@timeslot.ie
Data Protection Officer
Contact our DPO

You also have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority for data protection.

timeslot.ie

Online booking pages with built-in payments for Irish service businesses. Create your page, share your link, and get booked.

Product

  • Features
  • Pricing
  • Integrations
  • Demo

Support

  • Help centre
  • Contact us
  • System status
  • Security

Company

  • About timeslot.ie
  • Blog
  • Privacy policy
  • Terms of service
ISO 27001compatible SOC 2aligned GDPRaligned PCI DSSSAQ-A WCAG 2.2 AAEAA
© 2026 timeslot.ie
Cookie policy · Refunds · Accessibility · DPA