Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how ScheduleSorter ("we", "us") collects, uses, and protects personal data when you use our scheduling software and website. We act as a data controller for account holder data, and as a data processor for the attendee data that account holders manage on our platform.
Who we are
ScheduleSorter is operated by [LEGAL NAME] ([COMPANY NUMBER, if applicable]), registered at [BUSINESS ADDRESS]. We are the data controller for the purposes of UK GDPR and, where applicable, EU GDPR.
Information we collect
- Account data: your name, email address, organisation name, and a hashed password.
- Attendee data: names and (optional) email addresses that organisers add directly or that attendees submit through a public enrollment link, plus the events they enrol in.
- Usage & technical data: IP address, browser type, and log data used for security, rate limiting, and debugging.
- Billing data: processed by our payment provider; we store only a subscription reference and status, never card numbers.
Cookies and tracking
ScheduleSorter does not use advertising or analytics cookies. We only set the strictly necessary cookies required to keep you signed in and to maintain a secure session — these cannot be disabled without breaking login functionality. We do not use Google Analytics, ad pixels, or other third-party trackers, and we do not track you across other websites. If this changes in future, we'll update this section and, where legally required, ask for your consent first.
Legal basis for processing (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the account and scheduling service | Performance of a contract with you |
| Security, fraud prevention, rate limiting | Legitimate interests |
| Billing and tax records | Legal obligation / contract |
| Processing attendee data on an organiser's behalf | Performance of the organiser's contract with their attendees (we act as processor) |
How we use it
- To provide scheduling, enrollment, and notification features.
- To send transactional email (password resets, team invitations, and published-schedule notifications).
- To secure the service (authentication, abuse prevention, rate limiting).
- To process subscriptions and comply with legal obligations.
We do not send marketing emails unless you opt in, and we do not sell personal data.
Children's privacy
ScheduleSorter is not directed at, and may not be used by, individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@schedulesorter.com and we will delete it.
Third-party processors (sub-processors)
We share data with the following sub-processors only as needed to run the service. We'll update this list as it changes.
- Paddle — payments and subscription management.
- Resend — transactional email delivery.
- Anthropic — powers the in-app help assistant (chat messages you send to it).
- Our cloud hosting and database provider.
International data transfers
Because we serve customers globally, your data may be transferred to and processed in countries outside the UK or European Economic Area, including the United States, where some of our sub-processors are based. Where this happens, we rely on appropriate safeguards recognised under UK GDPR and EU GDPR, such as Standard Contractual Clauses or the UK International Data Transfer Addendum, or the sub-processor's own adequacy certifications.
Data retention
We keep account and attendee data for as long as the account is active. When you delete your organisation, all associated projects, attendees, events, schedules, and team members are permanently removed from live systems, and purged from rolling backups within 7 days.
Data breaches
If a data breach occurs that's likely to result in a risk to your rights and freedoms, we will notify affected customers and, where legally required, the relevant supervisory authority, without undue delay and in line with our obligations under UK GDPR / EU GDPR.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data.
- UK / EU (GDPR): Account holders can export all organisation data as JSON and permanently delete their organisation from Settings → Account inside the app. Attendees who enrolled via a public link should contact the organiser, or email us and we will assist. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local EU supervisory authority — though we'd appreciate the chance to resolve any concerns directly first.
- California (CCPA/CPRA): California residents have the right to know what personal information we collect, request deletion or correction, and opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioural advertising. To exercise these rights, email privacy@schedulesorter.com.
Security
Passwords are stored using bcrypt hashing, sessions are token-based with expiry, and access to an organisation's data is restricted to its members. No method of transmission is perfectly secure, but we take reasonable measures to protect your data.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the service or by email. Continued use after changes take effect constitutes acceptance.
Contact
Questions or requests about this policy or your data: privacy@schedulesorter.com.