Privacy policy
Last updated 5 October 2026
This policy explains what personal data TimetableOS ("we", "us") handles when you use TimetableOS, why, who sees it, and what you can ask us to do about it. TimetableOS is software that studios, gyms and wellness businesses ("studios") use to run their business and to serve their members.
Who is responsible for your data
There are two roles, and which one applies depends on who you are.
- If you are a member or customer of a studio (you book classes, buy a membership, sign a waiver), the studio decides what to collect and why. The studio is the controller of that data and we process it on the studio's behalf. Questions about your membership data, and requests to see or delete it, are best sent to the studio first. We will help the studio answer you.
- If you run a studio or work for one (you hold a TimetableOS account), and for visitors to this website, we are the controller of the data described under "Account holders and visitors" below.
What we collect
On behalf of studios (members and customers)
- Identity and contact details: name, email address, phone number, date of birth, address, photo.
- Membership and booking records: plans, passes, bookings, waitlists, check-ins and attendance, course enrolments, appointments.
- Payment records: what was charged, refunded or is owed, the last digits and brand of a card, and receipts and invoices. Full card numbers are handled by our payment processor and never stored by us.
- Forms and waivers a member has completed or signed, including any health or emergency information a studio chooses to ask for.
- Messages sent through the product: campaign and notification emails, texts and push notifications, and whether they were delivered or opened.
- Feedback, ratings and reviews a member chooses to leave, and referral and gift card activity.
- Notes a studio's team writes about a member.
Account holders and visitors
- Account details: name, email address, phone number, password (stored only as a one-way hash), role and permissions, and the studio or business you belong to.
- Billing details for studios' own use of TimetableOS.
- Security and usage records: sign-in times, IP address, browser type, and an audit log of important actions in the product.
- What you send us when you contact us or enquire through a form.
Why we use it, and our legal basis
- To provide the service: taking bookings, billing, checking people in, sending the messages a studio asks us to send. (Performance of a contract.)
- To keep the service secure, prevent fraud and abuse, and fix problems. (Our legitimate interests.)
- To meet tax, accounting and other legal obligations. (Legal obligation.)
- To send marketing emails or texts where you have agreed, or where the law allows it. You can unsubscribe from any campaign email with the link at its foot. (Consent or legitimate interests.)
We do not sell personal data, and we do not use members' data to advertise to them.
Who we share it with
- The studio you deal with, and the people it gives access to.
- Service providers that help us run the product, under contracts that limit them to doing so: a payment processor, email, text message and push notification providers, cloud hosting and file storage, error monitoring, and a CAPTCHA service that protects sign-up forms from automated abuse.
- Authorities and advisers where the law requires it, or to protect rights, safety and property.
- A buyer if our business is sold or merged, with this policy continuing to apply.
Some providers are based outside your country. Where personal data leaves the UK or the European Economic Area we rely on an approved transfer mechanism, such as standard contractual clauses.
Cookies
We use only the cookies needed to run the service: a session cookie that keeps you signed in and protects forms, and a sign-in cookie for the studio's pages and portal. We do not use advertising cookies. Fonts are loaded from a font provider, which may see your IP address, and sign-up forms load a CAPTCHA that may set its own cookies.
How long we keep it
We keep studio and member data while the studio's account is active, and for a limited time afterwards so it can be recovered or exported. Records we must keep for tax and accounting are kept for the period the law requires. Security logs are kept for a limited time. When data is no longer needed it is deleted or anonymised. A studio can delete or anonymise a member's record, and a member can ask for this.
Your rights
Depending on where you live, you can ask to see the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent you have given. If you are a member of a studio, we may pass your request to the studio. You also have the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office, and in the EU it is your national authority. California residents have the rights described in the CCPA, including the right not to be discriminated against for using them. We do not sell or share personal data as those laws define.
Security
We protect data with encryption in transit, hashed passwords, access controls by role, mandatory two-factor sign-in for our own staff, and audit logging. No system is perfectly secure. If a breach affects your data we will tell the studio and, where the law requires, the authorities and you, without undue delay.
Children
Studios may register children as members, for example for kids' classes, usually through a parent or guardian's account. We process that data on the studio's behalf and expect the studio to have the guardian's permission. TimetableOS is not intended for children to use on their own.
Changes
We will update this page when our practices change and change the date above. For significant changes we will tell account holders by email.
Contact
Use the contact details on our website. This policy is issued by TimetableOS.