Privacy Policy
Last updated: February 3, 2025
Schedesk ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our desk booking and workplace management platform ("Service").
This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
1. Data Controller
Schedesk acts as the data controller for personal data collected through the Service. For company-managed accounts, your employer may also act as a data controller or joint controller for employee data processed through the platform.
For data protection inquiries, contact us at schedesk@gmail.com.
2. Personal Data We Collect
2.1 Data You Provide
- Account information: name, email address, and password when you create an account
- Profile information: profile picture, job title, and department
- Company information: company name and workspace settings provided by administrators
- Payment information: billing details processed securely through Stripe (we do not store full payment card details)
2.2 Data Generated Through Use
- Booking data: desk reservations, check-in/check-out times, and workspace preferences
- Attendance data: office attendance records and work-from-home status
- Vacation data: leave requests, PTO balances, and approval history
- Lunch orders: meal selections and dietary preferences
2.3 Automatically Collected Data
- Device information: browser type, operating system, and device identifiers
- Usage data: pages visited, features used, and interaction patterns
- Log data: IP address, access times, and referring URLs
- Cookies: essential cookies for authentication and session management (see Section 8)
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract performance: processing necessary to provide the Service you have subscribed to
- Legitimate interests: improving our Service, ensuring security, and preventing fraud
- Consent: where you have given explicit consent, such as for optional analytics cookies or marketing communications
- Legal obligation: compliance with applicable laws and regulations
4. How We Use Your Data
We use your personal data to:
- Provide, maintain, and improve the Service
- Process desk bookings, attendance, and vacation management
- Authenticate your identity and secure your account
- Process payments and manage subscriptions
- Send transactional notifications (e.g., booking confirmations, reminders)
- Provide customer support
- Generate aggregated, anonymized analytics for administrators
- Comply with legal obligations
5. Data Sharing and Third Parties
We share personal data only as necessary:
- Stripe: payment processing (Stripe Privacy Policy)
- Slack: workspace integration, if enabled by your administrator (Slack Privacy Policy)
- Google: OAuth authentication, if you choose to sign in with Google (Google Privacy Policy)
- Resend: transactional email delivery
- Your employer: administrators in your organization can access booking, attendance, and leave data as part of workplace management
We do not sell your personal data to third parties. We do not share your data for advertising purposes.
6. Data Retention
We retain your personal data for as long as:
- Your account remains active
- Necessary to provide the Service
- Required by applicable law (e.g., tax and accounting records)
When you or your administrator deletes an account, we will delete or anonymize associated personal data within 30 days, unless retention is required by law. Aggregated, anonymized data that cannot identify you may be retained indefinitely.
7. Your Rights
Depending on your location, you have the following rights regarding your personal data:
Under GDPR (EEA/UK residents)
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your data ("right to be forgotten")
- Portability: receive your data in a structured, machine-readable format
- Restriction: request limitation of processing in certain circumstances
- Objection: object to processing based on legitimate interests
- Withdraw consent: withdraw consent at any time where processing is based on consent
Under CCPA (California residents)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell data)
- Right to non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at schedesk@gmail.com. We will respond to requests within 30 days.
8. Cookies
We use the following types of cookies:
- Essential cookies: required for authentication, session management, and security (CSRF protection). These cannot be disabled as they are necessary for the Service to function.
- Functional cookies: remember your preferences such as theme settings and language
- Analytics cookies: help us understand how the Service is used (only with your consent)
You can manage your cookie preferences through the cookie consent banner or your browser settings.
9. Data Security
We implement industry-standard security measures to protect your data:
- AES-256 encryption for sensitive data at rest
- TLS/HTTPS encryption for data in transit
- Secure password hashing (bcrypt)
- CSRF protection on all forms
- Regular security audits and vulnerability assessments
- Role-based access control
While we take reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your data.
10. International Data Transfers
Your data may be processed in countries outside your country of residence. When transferring data outside the EEA/UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
11. Children's Privacy
The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If we discover that a child has provided us with personal data, we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also notify you via email.
13. Contact Us
For privacy-related questions, data requests, or complaints, contact us at:
- Email: schedesk@gmail.com
If you are in the EU/EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA).