Privacy Policy
Last updated: September 10, 2026
This Privacy Policy explains how Guidly Booking Inc. ("Guidly", "we", "us", or "our") collects, uses, and shares information when you use Guidly's coaching scheduling platform at guidly.ca and the Guidly mobile apps (the "Service"). By using the Service, you agree to the practices described here.
About payments: Coaches (providers) pay Guidly a subscription fee to use the platform. In addition, providers may set a price on certain session types; when a client books a paid session, Guidly facilitates that payment through Stripe on the provider's behalf. Guidly does not store full card numbers — Stripe processes and stores card data on its PCI-compliant infrastructure. Guidly retains transaction records (amount, date, card last four digits, session) for accounting, tax, and dispute-resolution purposes.
1. Information we collect
Information you provide directly
- Account information: name, email address, phone number, password (stored hashed), profile photo, and for coaches: specialty, hourly rate, availability schedule, meeting preferences.
- Booking information: session date, time, duration, meeting mode (Zoom or in-person), and any topic or notes you add.
- Subscription information (coaches only): we use Stripe to process coach subscription payments to Guidly. We do not store full card numbers; Stripe stores those on PCI-compliant infrastructure. We retain transaction records (amount, date, last four digits, plan tier) for accounting and tax purposes.
- Communications: messages you send to coaches or clients through the platform, and support requests you send to us.
Information collected automatically
- Usage data: pages viewed, actions taken, and timestamps. Used to operate and improve the Service.
- Device and connection data: IP address, browser type, operating system, and approximate location (derived from IP).
- Cookies and local storage: we use session tokens stored in your browser's local storage to keep you signed in. Advertising and analytics cookies are covered in section 2 below, and are set only if you consent.
- Mobile app data: in the Guidly mobile apps, your sign-in token is stored securely on your device (Apple Keychain / Android Keystore). If you enable notifications, we store a device push token so we can send you booking-related notifications (confirmations, reminders). No business data is cached on the device.
Information from connected services
If you connect your Google Calendar or Zoom account, we receive the OAuth tokens and limited account information necessary to operate those integrations:
- Google Calendar: we read your calendar's busy times to prevent double-booking, and create/update/delete events for Guidly bookings on your calendar. We do not read or store the content of events we did not create.
- Zoom: we read your display name and email at connect time, and create/delete unique meeting URLs for confirmed Guidly bookings. We do not access meeting recordings, transcripts, participant lists, or chat logs.
Google user data and the Limited Use requirements
Guidly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Calendar API is used only to:
- read the busy times on your calendars, so that Guidly offers clients only the times you are genuinely free; and
- create, update and delete the calendar events that correspond to your Guidly bookings.
We do not transfer Google user data to third parties except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition. We do not use it to serve advertisements, and we do not use it to develop, improve or train generalized artificial intelligence or machine learning models. We do not allow humans to read it, except with your explicit consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
You can disconnect Google Calendar at any time from Settings → Integrations inside Guidly. Disconnecting deletes the OAuth tokens we hold for you and stops all further calendar access. You can also revoke Guidly's access from your Google Account permissions page, which immediately invalidates those tokens at Google's end; disconnecting inside Guidly afterwards removes them from our records as well. Calendar events already created for past bookings stay on your calendar and are yours to keep or delete.
2. Cookies, analytics and advertising
Guidly uses a small number of cookies and similar technologies. They fall into two groups, and only one of them needs your permission.
Strictly necessary (always on)
Your sign-in token is stored in your browser's local storage so you stay signed in as you move between pages. It is not a tracking technology, it is never shared with anyone, and the Service cannot work without it. In the Guidly mobile apps the equivalent token is held in the Apple Keychain or Android Keystore.
Measurement and advertising
Guidly advertises on Google and on Meta's platforms (Facebook and Instagram) to reach coaches, instructors, tutors and other providers. Subject to your choice below, we use the Google tag (Google Ads, and Google Analytics where enabled) and the Meta Pixel to understand which advertisements lead people to create an account, so we can stop paying for advertising that does not work.
- What it records: that a visit or a sign-up followed an advertisement, together with the page, timestamp, device and browser type, and approximate location derived from your IP address.
- What it is not used for: we do not use it to build a profile of you, and Guidly does not sell personal information to anyone.
- Who receives it: Google LLC and Meta Platforms, Inc., each acting as an independent controller for its own advertising purposes under Google's Privacy Policy and Meta's Privacy Policy.
Your choice, and where we ask first
If you are visiting from the United Kingdom, the European Economic Area, Switzerland or Quebec, we ask before setting anything in the second group. A banner appears on your first visit, with Accept and Reject given equal prominence. Until you choose, advertising and analytics storage stays switched off: we implement Google Consent Mode, so Google sets no advertising cookies and receives no advertising identifiers from your device. Choosing "Reject" keeps it that way permanently.
Elsewhere, including the rest of Canada and the United States, advertising measurement is enabled by default — which is what this policy discloses — and you can switch it off whenever you like. We will remember that you did.
Either way, nothing about the Service stops working if you decline. The only storage we never gate is the sign-in token described above, because without it you cannot stay signed in.
You can change your mind at any time — reopen your cookie choices. Clearing your browser's site data also resets the decision.
3. How we use information
- To operate the Service: create accounts, manage bookings, send confirmations and reminders, sync calendars.
- To process coach subscription payments through Stripe.
- To communicate with you: confirmations, reminders, security alerts, occasional product updates. You can opt out of non-essential email and SMS at any time.
- To prevent fraud, abuse, and security incidents.
- To improve the Service through aggregated, non-identifying analytics.
- To measure which of our advertisements lead people to sign up, subject to your cookie choices in section 2.
- To comply with legal obligations.
4. How we share information
We do not sell your personal information. We share it only as follows:
Between coaches and clients
When a client books a session through Guidly, the coach and client see each other's name, email, and any session-related information needed to conduct the booking. Coaches additionally see clients' phone numbers if provided.
Service providers (sub-processors)
We use third-party services to operate Guidly. Each receives only the data needed for their specific function:
- Supabase — hosted PostgreSQL database (account and booking data, encrypted at rest).
- Render — application hosting.
- Netlify — frontend hosting.
- SendGrid (Twilio) — transactional email delivery.
- Twilio — SMS delivery.
- Stripe — coach subscription payment processing.
- Google — OAuth sign-in, Calendar API, and, subject to your cookie choices in section 2, advertising measurement through Google Ads.
- Meta Platforms — subject to your cookie choices in section 2, advertising measurement through the Meta Pixel on Facebook and Instagram.
- Zoom — meeting creation API.
These providers are bound by their own privacy policies and contractual data protection obligations.
Legal and safety
We may disclose information if required by law, court order, or to protect the rights, safety, or property of Guidly, our users, or others.
Business transfers
If Guidly is acquired or merged, your information may be transferred to the successor entity, subject to this Privacy Policy.
5. How long we keep information
We retain your personal information while your account is active and for a reasonable period after closure to fulfill legal, accounting, and dispute-resolution obligations (typically up to 7 years for financial records). You can request deletion sooner — see "Your rights" below.
Booking records and associated communications are retained for the duration of any active dispute or until expiration of the applicable limitation period in Ontario.
6. How we protect information
We use industry-standard security measures including:
- HTTPS encryption for all data in transit.
- Encryption at rest for our database (Supabase, AES-256).
- Hashed password storage using bcrypt.
- Token-based authentication with short-lived sessions.
- Access controls and audit logging on our backend systems.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to protect your information using commercially reasonable practices.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information (most fields are editable in your account settings).
- Delete your account and personal information, subject to legal retention requirements.
- Export your data in a portable format.
- Withdraw consent for non-essential processing.
- Object to specific processing or lodge a complaint with a privacy regulator (in Canada, the Office of the Privacy Commissioner).
If you are in the United Kingdom or the European Economic Area, you may also lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. Our lawful bases are: performance of our contract with you, to operate the Service; legitimate interests, for security and fraud prevention; and your consent, for advertising measurement, which you can withdraw at any time without affecting anything else. If you are in Quebec, you may also contact the Commission d'accès à l'information du Québec.
To exercise these rights, email support@guidly.ca. We respond within 30 days.
8. International transfers
Guidly is operated from Canada, but our service providers may process data in the United States and other countries. By using the Service, you consent to your information being processed in these locations, which may have different privacy laws than your jurisdiction.
9. Children
Guidly is not intended for users under 16. We do not knowingly collect information from children under 16. If you believe a child has created an account, contact us and we will remove it.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice at least 14 days before taking effect. Continued use of the Service after changes take effect constitutes acceptance.