Your information, explained
Privacy policy
Updated October 5, 2026 · Private pilot
Post My Openings helps independent stylists manage appointment requests, schedules, and Instagram availability updates. This policy describes information used by the Post My Openings pilot. The studio you book with also uses your information to provide its services; contact that studio about its appointment policies and records.
Information we use
- Optional GlossGenius calendar connection: the private subscription link you provide, stored encrypted, sync status, and busy start/end times. The feed may include client names, services, and addresses; we read it to calculate busy periods and discard those client details rather than saving them or adding them to Stories.
- Optional Google Calendar connection: your verified Google email, account identifier, selected calendar identifiers and names displayed during selection, encrypted authorization credentials, sync status, and busy start/end times. We do not request event titles, descriptions, attendees, or private client notes. This permission is separate from Google sign-in and Gmail sending.
- Optional Gmail connection: your verified sending email address, Google account identifier, encrypted authorization credentials, and records of booking emails sent through Gmail. This is separate from Google sign-in.
- Studio details: the owner’s sign-in email and account identifier, studio name, services, prices, hours, and booking policies.
- Booking details: your name, email, optional phone number, selected service and time, booking source, and appointment status.
- Private client notes: preferences and appointment details recorded by your studio, with creation and edit dates. These help the stylist prepare for future appointments.
- Instagram information: the connected professional account’s username, identifiers, authorization token and expiration, plus booking messages, participant identifiers, timestamps, and conversation state provided to the integration.
- Operational information: availability artwork, publication and delivery records, processing errors, request logs, and optional pilot feedback.
We use this information to authenticate studio owners, process booking requests, manage appointments, respond to inquiries, publish authorized availability updates, troubleshoot problems, and evaluate the pilot. Email notifications use appointment and contact details when enabled. The pilot does not process payments or send automated SMS.
Who can access information
The relevant studio owner can access that studio’s appointments, customer contact details, private client notes, and booking conversations. Post My Openings’s operator may access records to support the pilot and handle requests. Public availability pages do not show other customers’ details.
Private notes are not included in customer booking pages, appointment-management links, automated messages, emails, or Instagram Stories.
Selected Google Calendar busy times help exclude occupied periods from availability and Instagram Stories. Post My Openings reads these times and does not create or edit Google events. Calendar data is not sold, used for advertising targeting, or used to train AI models. Google Calendar data is used only to provide the calendar and availability features you authorize. You can disconnect in Calendar sync to remove the connection and imported busy times; appointments created in Post My Openings remain.
Connecting a GlossGenius subscription lets Post My Openings read its busy periods for availability and Stories. We do not create or edit GlossGenius appointments. Disconnecting in Calendar sync removes the saved subscription link and imported busy times; your GlossGenius account and Post My Openings appointments remain unchanged.
We use Supabase for authentication, database records, and Story artwork storage; Vercel for hosting and processing; and Meta for connected Instagram features. Google processes appointment emails when a studio connects Gmail; Resend processes them when a platform sender is configured. These providers receive information needed to supply those services.
Availability artwork is accessible through a public asset URL and may be published to Instagram. It shows services and openings, not customer names or contact details. Updating a booking does not edit or remove a Story already published. Keep your appointment-management link private: it allows access to the appointment and its available actions.
Cookies, storage, and security
Cookies maintain owner sign-in and temporary authorization state. The app uses an IP-derived hash to limit repeated requests; hosting providers also process network request information. Demo data is stored in your browser and can be accessed by others using that browser profile. Use sample information in demo mode.
Studio records have owner access controls, and stored Instagram, Gmail, and calendar credentials are encrypted. The pilot has no automatic record-expiration or account-deletion feature. Records remain stored unless removed manually; provider logs and backups have their own retention cycles. Contact us to discuss removal of your information.
Gmail permissions and your choices
Connecting Gmail authorizes Post My Openings to send appointment requests, confirmations, changes, cancellations, and reminders on your behalf. We request send-only Gmail access and verified account identity; we do not request access to read your inbox. Replies and delivery notices stay in Gmail. We store the outgoing booking email and send receipt to diagnose failures and avoid duplicate sends.
Disconnect Gmail in Settings → Booking emails to delete the saved Gmail credentials and stop future sends. An email already sending may still arrive. You may also remove the app’s authorization in your Google Account. Disconnecting does not delete appointment or delivery records; contact us to request their deletion.
Post My Openings’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this access only to provide the booking email feature. Google user data is not sold, used for advertising, or used to train general-purpose AI models.
Access, correction, and deletion
Contact the Post My Openings pilot through its current support account, @booked.ez, to ask about your information or request access, correction, or deletion. Include the studio name and the email or Instagram username you used. Do not send passwords, access tokens, or your private appointment-management link.
Requests are handled manually. We verify that the request relates to your account before changing records and explain the removal scope, including any records that must be retained. Revoking access in Instagram stops subsequent authorized API access; it does not automatically delete information already stored in Post My Openings.
Policy updates
We update this page as the pilot changes and revise the date above. Contact @booked.ez with questions about this policy.