Privacy Policy
Last updated August 24, 2026
This Privacy Policy explains how Rezzy, operated by Tiny Labs LLC (“we”, “us”), collects, uses, and protects personal information when you use letsrezzy.com and the Rezzy booking software (the “Service”). We keep it plain and collect only what we need to run the Service.
Two kinds of people, two roles
Rezzy sits between two groups:
- Studio owners who sign up for a Rezzy account. For their account data, Rezzy is the data controller.
- Clients who book appointments with a studio through Rezzy. For that booking data, the studio is the controller and Rezzy is its processor: we handle it on the studio’s behalf. If you’re a client with a question about your data, please contact the studio you booked with.
What we collect
- Account information: your name, email address, password (stored hashed), business name, and the settings you enter.
- Booking information: when a client books, we store the details they provide: name, email, phone number, chosen service, and appointment time, so the studio can serve them and we can send confirmations and reminders.
- Marketing opt-ins: the booking form offers an optional, never pre-ticked box to hear about offers from that studio. Ticking it records the exact wording shown, a timestamp, and the IP address, because a studio asked to prove consent needs to show what someone actually agreed to. Leaving it alone means the studio can only send you booking email. Every marketing email carries an unsubscribe link that works instantly, without a login, and never expires.
- How you reached the booking page: we record whether a booking came through the studio's Rezzy booking page or the booking widget on their own website, and the site that referred you (for example Instagram or Google), so the studio can tell where their clients find them. It is the referring website only, never your browsing history, and it is not used for advertising.
- Cancellation reasons: when an appointment is cancelled we record who cancelled it. A client may also be offered an optional reason afterwards, from a short preset list, with an optional sentence of their own. It is always optional, never asked before the cancellation goes through, and it is only ever shown to the studio. We deliberately keep the choices coarse and never ask about health or symptoms.
- Client records studios add: studios may add or import client details from their previous systems (names, contact details, visit history, notes, and any consent status carried over). We process these on the studio’s behalf.
- Payment information: paid plans are processed by Stripe. We don’t see or store full card numbers; Stripe handles payment data under its own privacy policy. We keep a customer and subscription identifier and your plan status.
- Consent records: when a client opts in to text messages from a studio, we record the consent itself (the wording shown, a timestamp, the page it happened on, and the IP address) because studios are legally required to be able to prove it. Opt-outs are recorded the same way and are never deleted. When a studio requires a card on file, the client’s agreement to the studio’s cancellation policy is recorded the same way.
- Push notification subscriptions: if a studio user turns on phone notifications, we store the delivery address the browser issues for that device (an opaque endpoint URL and its encryption keys) plus the browser type, so we can send that device short notices such as "New booking". One record per device, tied to that device's sign-in: signing out or removing the device in Settings deletes it. Notification content travels encrypted end to end; Apple, Google, or Mozilla relay it without being able to read it.
- Technical information: basic logs such as IP address, browser type, and timestamps, used for security and to keep the Service running.
- Cookies: a small number of essential cookies, for example to keep you signed in. One more, on our marketing pages only, remembers which page or link brought you to us, so we know which of our own pages are worth writing. It holds a website name and a page path, never your name or anything about you, and it lasts 30 days. We don’t use advertising trackers, and we don’t sell or share anything for advertising.
- Website analytics: our public marketing pages (the homepage, solutions, guides, blog, and legal pages) use Google Analytics to count visits and see which pages people find useful. It records things like the pages viewed, approximate location, device and browser, and how you arrived, and it sets its own cookies to do so. We use it only to improve the site. It does not run on studio booking pages, so a studio’s own clients are never measured by us when they book. Signed-in areas of the app are not tracked this way either.
How we use information
We use personal information to:
- Provide and operate the Service, including creating booking pages and managing appointments.
- Send transactional email on a studio’s behalf: booking confirmations, reminders, reschedule and cancellation notices, and calendar invites. These are not marketing emails.
- Send, on a studio’s behalf, a post-visit review request about the client’s own appointment, one follow-up three days after a cancelled appointment if the client has not rebooked, and, only to clients who have consented, marketing email. Every one of these emails carries an unsubscribe link that works instantly, without a login, and never expires; unsubscribing stops review requests too.
- Send account email to you, the studio: sign-in confirmation, password resets, and, whenever someone asks to change the email address you sign in with, a link to the new address and a notice to the old one.
- Process payments and manage subscriptions.
- Provide support, prevent abuse, and keep the Service secure.
We do not sell personal information, and we don’t use client booking data for our own marketing.
Who we share it with
We share information only with service providers that help us run Rezzy, under agreements that require them to protect it:
- Stripe: subscription billing for Rezzy plans.
- Stripe or Square, the studio’s own account: if a studio turns on client payments, deposits and payments are processed by the studio’s own payment account under that provider’s terms. When a studio requires a card on file, the card is saved and stored by Stripe or Square on the studio’s own account; Rezzy stores only a reference to it. Card details are entered directly into the payment provider’s own secure fields and go straight to that provider. Rezzy never sees or stores card numbers and never holds the money.
- Resend: sending email.
- Telegram: internal alerts to Rezzy’s own team, for example that a studio signed up or that our email delivery has failed. These carry the studio’s name, the owner’s email address, and totals. No client information is sent.
- Our SMS provider: if a studio enables text messaging, delivering those texts (and the carrier registrations US messaging requires).
- Google: if a studio connects Google Calendar, we sync bookings to and read busy times from their calendar, with their permission and only while connected. Rezzy’s use of information from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- Our hosting provider: to run the servers and store data, including encrypted off-site backups that expire on a rolling schedule.
We may also disclose information if required by law or to protect people’s rights and safety.
Client-facing email
A studio’s booking confirmations and reminders to their own clients are always available regardless of plan. We never gate client-facing email. These messages are transactional, not marketing.
Text messages (SMS)
Studios can invite their clients to receive text updates about appointments and openings, including a booking confirmation and a reminder the day before. These texts are strictly opt-in: a client only receives them after checking an unchecked box on the booking page, confirming through an emailed opt-in link, or telling the studio yes when they book over the phone. A client can opt out at any time by replying STOP to any text. An opt-out is permanent: it is never undone by a box on a later booking. Messages may be automated and AI-assisted, and message frequency varies; message and data rates may apply. Consent is never a condition of booking.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers and opt-in data are used only to send the messages the client agreed to receive from their studio.
Data retention
We keep your data while your account is active. Downgrading a plan never deletes data. If you close your account or ask us to delete your data, we’ll remove it within a reasonable period, except where we must keep records to meet legal or accounting obligations.
If you connect an AI assistant through our MCP connector, we log each request your assistant makes: which tool it called, the arguments (which can include client names and search terms), how many rows came back, and when. These logs exist so you can always see what your assistant was shown. They are kept for 90 days and then deleted automatically. Connecting by sign-in also stores which assistant you connected and when; both it and any unused sign-in credentials expire after 90 days, and you can disconnect at any time from Settings → Profile.
Deleting your account
You can delete your account yourself at any time from Settings → Business. Deletion is immediate and permanent: your bookings, clients, notes, email history, and reports are removed from our live systems right away, upcoming appointments are cancelled with an email to each affected client, and your subscription is cancelled. Encrypted database backups age out on a rolling schedule and are never used to restore a deleted account. Stripe retains subscription invoice records on their systems as required for tax and accounting purposes; any Stripe, Square, or Google account you connected belongs to you and is untouched.
Security
We protect data with encryption in transit (HTTPS), encrypt sensitive stored credentials, and limit access to what’s needed to operate the Service. No system is perfectly secure, but we work to keep your information safe.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to certain processing. To exercise these rights for your Rezzy account, email hello@letsrezzy.com. If you’re a client of a studio, contact that studio, which controls your booking data.
Children
Rezzy is for businesses and isn’t directed to children under 18. We don’t knowingly collect data from children.
Where data is stored
Rezzy is operated from the United States, and information is processed and stored there. If you access the Service from elsewhere, you understand your information will be transferred to the US.
Changes to this policy
We may update this policy from time to time. We’ll change the date above and, for material changes, take reasonable steps to let you know.
Contact
Questions about privacy? Email hello@letsrezzy.com.