Privacy Policy
In short
ProtoSync is an online booking service: an owner publishes a schedule and visitors take free time slots. That needs a minimum of data, and we try not to collect anything beyond it.
- We do not sell your data and do not share it with ad networks.
- A schedule reaches search engines ONLY if its owner turned the corresponding switch on.
- Participant lists, who booked which slot, phone numbers, email addresses and Telegram usernames are never published.
Who processes your data
ProtoSync (protosync.co) is run by a private individual — its owner and developer. There is no company behind the service.
For any question about this data, including a request to export or delete it, write to support@protosync.co. This is the main and fastest channel.
Full controller details are provided on a justified request — to you or to a data protection authority.
Division of roles. We are responsible for your account data and for running the service. The owner of the schedule you book with decides what to ask visitors in their own fields and what to do with it — in that part they act as an independent controller and we merely provide the tool. Questions about data you left with a particular owner go to that owner; if they do not answer, write to us.
What we collect
Account data, depending on how you sign in:
- Telegram: numeric account id, name, username and a link to your profile photo if it is public.
- Google: a permanent account identifier, email address, name and a link to your profile photo.
- Email and password: your email address, the name you provide and an irreversible transformation of the password. The password itself is never stored and cannot be recovered — only replaced.
Service usage data: schedules you create and their settings, slots and bookings, participants, reviews and ratings, chat messages, the schedule activity log, and messages to the administration.
Technical data: IP address (to limit request rates and resist password guessing), your browser push subscription endpoint and the mobile push token, plus internal error records.
Location: precise coordinates are requested ONLY when you press the «detect location» button while filling in a schedule address. There is no background tracking.
Storage in your browser. We use no advertising or analytics cookies. Local storage and the service worker cache hold only what the app needs to run: your session tokens, the chosen language and theme, and the schedules loaded last so the app opens without a network. All of it is cleared by signing out and by clearing site data in the browser.
Why, and on what legal basis
- Performance of our contract with you — bookings, schedules, chats and notifications: without this data the service cannot work.
- Legitimate interest — security: rate limiting, protection against password guessing and abuse, moderation.
- Your consent — publishing a schedule to search engines, location detection, push notifications. Each is enabled separately and can be withdrawn at any time.
- Legal obligation — records of subscription payments.
Is providing data mandatory. Some of it is inherent to the service: without an account and a booking record we can neither hold the time for you nor remind you of the visit. Declining means declining that feature, not the service as a whole — public schedule pages are open without signing in. Location detection, push notifications and search visibility are entirely optional.
We make no automated decisions producing legal effects for you and we do no profiling. Only technical checks run automatically: rate limiting and abuse protection.
Who we share data with
We use third-party services only where they are necessary. Each receives only what its task requires:
- Telegram — notification delivery and sign-in with Telegram.
- Google — sign-in with Google, push notifications in the mobile app and Google Play subscription processing.
- Cloudflare — the «not a robot» check on sign-in and registration; it receives your IP address.
- Mail server — delivery of address confirmation and password reset messages.
- Browser push services (Google, Mozilla, Apple) — delivery of browser notifications.
- BigDataCloud — resolving country and city from coordinates when you press the address auto-detect button. Coordinates are sent.
We do not sell data and do not share it for advertising or profiling.
Transfers outside your country
Some of the recipients above operate outside your country, including outside the European Economic Area. Only what a given feature needs is transferred, and only while that feature is being used.
Such transfers rely on the mechanisms provided by data protection law: an adequacy decision, or the standard contractual clauses of the provider in question. Where no mechanism applies, the feature is not used.
Publishing a schedule to search engines
Every schedule has a «Show in search» switch. It is OFF by default. While it is off, no public page exists and nothing reaches search engines.
If the owner turns it on, a page is published with the title, description, city, category, average rating and the text of visible reviews. Each review shows its author name — the same name that is visible inside the app.
Never published: the participant list, who booked which time, phone numbers, email addresses, Telegram usernames.
The switch can be turned off at any time and the page stops being served immediately. Note that a search engine may keep showing it from its own cache for a while, which is outside our control.
How long we keep data
Account and schedule data is kept while the account exists. The rest has its own periods:
- past slots and the records attached to them — 180 days after the slot date, then the automatic archive cleanup removes them;
- read notifications in the inbox — 180 days; unread ones stay until they are read;
- device push tokens — 90 days after the device last contacted the service;
- schedule chat messages — while the schedule itself exists: the conversation is the record of what both sides agreed;
- subscription payment records — for the period required by the law on keeping payment records.
⚠ Important about account deletion. When you delete an account we erase the profile but KEEP the link to the Telegram or Google identifier you signed in with. This prevents duplicates on a repeat sign-in and stops a block from being bypassed by simply deleting the account. Practical consequence: signing in again the same way brings the account back as a new one — without your previous schedules and bookings.
If you need complete deletion including that link, write to support@protosync.co and we will remove the record entirely.
Your rights
- Obtain a copy of your data and learn how it is processed.
- Receive that data in a machine-readable form and pass it on to another service.
- Correct inaccurate data — name and photo are editable in profile.
- Delete your account — the button in profile; complete deletion on request by email.
- Withdraw consent: turn off search visibility, disable notifications, revoke location access in your browser or phone.
- Object to processing and request its restriction.
- Lodge a complaint with the data protection authority of your country.
Requests sent to support@protosync.co are handled within 30 days.
Requests are free of charge. So as not to hand your data to a stranger, we may ask you to confirm that the request comes from the account owner — for example by writing from the email address linked to it. If a request is manifestly unfounded or excessively repetitive, we may ask for clarification or refuse, stating the reason.
Security
Traffic is protected with TLS. Passwords are stored only as a salted, irreversible transformation. Schedule data is accessible to its owner, the administrators they appoint and its participants — to the extent set by the privacy settings of that schedule.
No protection is absolute, so avoid putting anything into titles, descriptions and chats that you are not prepared to show to strangers.
Should a breach occur that is likely to pose a serious risk to your rights, we will notify the supervisory authority and you, within the time and in the manner the law prescribes.
Children
The service is not intended for children under 16. If you learn that a child registered without parental consent, write to us and we will delete the account.
Changes to this policy
We may update this policy. The date of the last change is shown at the top of the page. We will try to announce material changes in advance with an in-app notification.
Previous versions are available on request at support@protosync.co.