Privacy Policy
Effective date: July 14, 2026
Citafy ("Citafy", "we", "our", "us") is a scheduling platform operated by TriExpert Services LLC, a limited liability company organized in the State of Florida, United States. This policy explains what personal information we handle, why, where it lives, and the choices you have. Questions: support@citafy.me.
1. Two different roles
Citafy handles two distinct kinds of personal information, and our role differs for each:
- Your account information — the data of the business or professional who signs up. Here we act as the controller: we decide why and how it is processed.
- Your customers' booking information — the people who book appointments with you. Here you are the controller and Citafy is a processor: we handle that data only on your instructions, to run the scheduling service you asked for. You are responsible for having a lawful basis to collect it and for what you ask your customers in your intake forms.
2. Information we collect
Account information (you)
- Name, email address and time zone.
- Password — stored only as a one-way hash. We never store or can read your password.
- Organization name, slug, branding (logo, colors) and preferences.
- If you enable two-factor authentication: your TOTP secret and recovery codes, encrypted at rest.
- Team membership and role.
Booking information (your customers)
- Attendee name, email address and, optionally, phone number.
- Appointment date, time, duration, host and status.
- Notes and the answers to any intake questions you choose to ask on your booking form.
Technical information
- IP address and browser user-agent, recorded with your login sessions.
- IP address recorded on security-relevant actions in our audit log.
- Aggregate counts of API requests per day (volume and response class only — no request contents).
- Application logs.
Payment information
Citafy never sees or stores card numbers. Online payment collection is an optional feature that is not currently enabled on the platform. If and when you enable it, card data is handled directly by our payment processor (Stripe) and only a payment reference, amount, currency and status are stored by us.
3. How we use information
- To provide scheduling: compute availability, create and manage bookings, prevent double-booking.
- To authenticate you and keep your account secure.
- To send transactional email (booking confirmations, cancellations, reminders) from
noreply@citafy.me. - To deliver the events you subscribe to, to the endpoints you configure (see §5).
- To maintain a tamper-evident audit trail of security-relevant actions.
- To operate, secure, debug and improve the service, and to comply with law.
We do not sell personal information, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models.
4. Google user data
Connecting a Google Calendar account is optional. If you never connect one, this section does not apply to you.
Scopes we request and why
| Scope | Why we need it |
|---|---|
.../auth/calendar.readonly |
To read your calendar list and your busy time ranges, so Citafy never offers a slot when you are already busy. |
.../auth/calendar.events |
To create, update and delete the calendar events that correspond to your Citafy bookings. |
We request no other Google scopes.
What we store
- OAuth access and refresh tokens — encrypted at rest.
- The identifiers of the calendars you select.
- For availability only: the start and end times of busy periods, and the identifiers of events Citafy created.
We do not read, store or index the titles, descriptions, attendees or contents of calendar events that Citafy did not create. We only need to know when you are busy, not why.
Limited Use
Citafy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we do not:
- transfer Google user data to third parties, except as necessary to provide or improve the feature you requested, to comply with applicable law, or as part of a merger or acquisition;
- use Google user data for advertising;
- allow humans to read Google user data, unless we have your affirmative consent for specific messages, it is necessary for security purposes or to comply with applicable law, or the data is aggregated and anonymized;
- use Google user data to develop, improve or train generalized AI or machine-learning models.
Revoking access
You can disconnect at any time from your Citafy account settings, or at myaccount.google.com/permissions. When you disconnect, we delete the stored tokens and the cached busy-time data.
5. Who receives information
We do not sell personal information. Information is shared only in these cases:
- Endpoints you configure (webhooks). If you register a webhook, Citafy transmits the booking events you subscribed to — including attendee name and email — to the URL you specify, signed with a secret. You choose that destination and are responsible for it. You can delete a webhook at any time to stop delivery.
- Google. Only if you connect a calendar, and only as described in §4.
- Infrastructure providers. We rent servers from hosting providers in the United States (see §6). They provide compute and network capacity; they do not process your data for their own purposes.
- Payment processor. Only if online payments are enabled for your account (not currently enabled platform-wide).
- Legal authorities, when required by valid legal process.
We do not use third-party advertising networks, and we do not send your data to an external email delivery service — outbound email is sent from mail infrastructure we operate ourselves.
6. Where your information is stored
All information is processed and stored in the United States:
| What | Where |
|---|---|
| Application database (accounts, bookings, all customer data) | Florida, United States — on infrastructure we operate |
| Outbound email server | Virginia, United States |
| Web edge / TLS termination | New York, United States |
If you access Citafy from outside the United States, you understand that your information will be transferred to and processed in the United States.
7. How long we keep it
- Account and booking data: while your account is active.
- API idempotency records (which may briefly contain a copy of an API response): about 24 hours.
- Webhook delivery records (which contain the event payload sent to your endpoint): retained for troubleshooting and replay.
- Audit logs: append-only and tamper-evident; retained for security and dispute resolution.
- Backups: retained for a limited period according to our retention setting.
After account deletion, data may persist for a limited period in backups and in records we must keep for legal, tax, fraud-prevention or dispute-resolution purposes, after which it is deleted or anonymized.
8. Security
- Tenant isolation is enforced by the database itself. Every tenant table carries a row-level security policy that fails closed, so one organization's queries cannot return another organization's rows — not only in the application, but at the database level.
- The application connects to the database with a non-privileged role that cannot bypass those policies.
- Traffic is encrypted in transit (HTTPS), and the application-to-database connection requires TLS.
- Passwords are hashed. API keys are stored only as a SHA-256 hash — the key itself is shown once and never stored. Webhook signing secrets, OAuth tokens and two-factor secrets are encrypted at rest.
- Security-relevant actions are recorded on a hash-chained audit trail.
No system can be guaranteed completely secure, and we cannot guarantee absolute security.
9. Cookies
We use cookies that are strictly necessary to run the service: to keep you signed in, to protect forms against cross-site request forgery, and to remember your interface preferences (such as light or dark theme). We do not use advertising or third-party tracking cookies. Blocking essential cookies will prevent you from signing in.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, restrict or object to the processing of your personal information. To exercise these rights, contact support@citafy.me.
If you are an attendee who booked an appointment through Citafy and want your information changed or deleted, please contact the business you booked with — they control that data. If you contact us, we will refer your request to them.
California (CCPA/CPRA)
California residents may have the right to know what personal information we collect, to delete it, to correct it, and to opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined by California law. We will not discriminate against you for exercising these rights.
European Economic Area, United Kingdom and Switzerland (GDPR)
If you are located in these regions you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority. Where we act as a processor for your customers' data (§1), we process it only on your documented instructions.
11. Children
Citafy is a business tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
12. Changes
We may update this policy. Material changes will be reflected by a new effective date at the top of this page, and continued use of the service after an update constitutes acceptance.
13. Contact
TriExpert Services LLC — Florida, United States
support@citafy.me
Citafy is a service of TriExpert Services LLC (Florida, United States). Questions: support@citafy.me