Skip to content
SavaSync
← All legal documents

Privacy Policy

Effective 2026-09-10 · v1.13

Effective: September 10, 2026

1. Introduction

This Privacy Policy describes how Tricky Labs LLC, a New Hampshire limited liability company doing business as SavaSync ("SavaSync," "we," "our," or "us"), collects, uses, discloses, and protects information about you when you use the SavaSync platform — including our website at savasync.com, our web application, our mobile apps once released, and the embeddable booking widget (collectively, the "Platform").

This Policy applies to information collected directly from you, automatically from your devices, and from third parties (such as Stripe for payment processing). It is incorporated into our Terms of Service by reference.

SavaSync is operated from and primarily directed at users in the United States. If you access the Platform from outside the U.S., you consent to your information being transferred to and processed in the United States, as described in Section 9.

By using the Platform, you agree to this Policy. If you do not agree, please do not use the Platform.

2. Information We Collect

2.1 Information you provide directly

When you create an account or use the Platform, you give us:

  • Account information: your name, email address, password (which we store only as a salted hash via Supabase Auth, not in plain text), and account type (Instructor, Studio, or Student). If you sign in with a social provider (currently Google), we receive your name, email address, and profile photo from that provider instead of a password.
  • Profile information: your display name, bio, profile photo, logo, brand colors, font preferences, business address, contact email and phone, timezone, social-media links, and any other information you add to your studio or instructor profile.
  • Account settings: if you own an account, the operational settings for an account you own — for example its cancellation policy and window, how much of the schedule is public, and the wording you prefer for class terminology.
  • Subscription: your SavaSync subscription tier and its status, including any trial end date.
  • Class and booking information: the Classes you create, edit, or book; attendance and check-in status; class capacity and pricing; recurrence rules; instructor assignments; per-class location data; the waitlist places you take and the offers you are made; and check-ins recorded when you arrive at a facility.
  • Payment information: when you accept payments as a Studio, you connect a Stripe account, which handles all card processing. We never see or store card numbers, CVCs, expiry dates — or even the last four digits or brand of a payment card. We keep the Stripe customer and connected-account IDs, and the Stripe identifiers attached to each transaction (payment intents, transfers and transfer groups, subscriptions and prices, the latest invoice and its PDF link, a booking's receipt link, and platform-fee references). Each is a reference we hand back to Stripe, never a way to charge a card. Opening your payout settings asks Stripe for the bank account it pays out to and shows its name and last four digits; that answer is not stored.
  • Membership and class-pack information: subscription plans you create, memberships you purchase, class packs you own, the status of each (active, canceled, paused, past due), and a record of each time a membership or class-pack credit was spent.
  • Waivers and intake responses: when you create a waiver as a Studio, we store the waiver text and version. When you sign a waiver as a Student, we store your typed name, the IP address from which you signed, your user-agent string, the timestamp, and a snapshot of the exact waiver text you signed. This is a legal record of consent.
  • Intake-form responses: Studios may attach custom intake forms to their Classes. Depending on the questions the Studio asks, your answers may include health-related information (injuries, medical conditions, pregnancy, equipment needs) and may include a signature image you draw. SavaSync stores these responses on the Studio's behalf — the Studio decides what to ask and how to use the answers; signature images are kept in private storage. When a form carries any question the Studio has marked sensitive, your whole response to it — and any signature image with it — is readable only by you and by the owner of the account that took the booking, not by the Studio's other staff. Where a form carries such a question, we also keep the record of the consent you gave for it: the timestamp, the wording version you were shown, and the IP address and user-agent at that moment — so a consent taken in your name can be checked.
  • Notes Studios keep about you: Instructors and Studios can record private free-text notes about their clients (for example, progress notes or preferences). These notes are visible to the Studio's staff, not to other Students, and are personal data about you that SavaSync stores on the Studio's behalf.
  • Legal-document acceptances: when you accept these Terms or our Privacy Policy at signup or when we publish a new version, we record the document slug, version, your IP address, your user-agent, and the acceptance timestamp.
  • Communications: the contents of emails Studios send you through the Platform, support requests you send us, and any other text you submit through the Platform. We also keep your notification and reminder preferences, and a record of the email types you have unsubscribed from.
  • Promotions: promotional codes you create as a Studio, and the codes you redeem as a Student, with the discount applied.
  • Client roster and tags: Studios keep a roster of the clients they work with, and their own labels ("tags") for people on it. If a Studio adds you, we store the roster entry, how you came to be on it, and any tags applied to you.
  • Staff roles and invitations: if you are invited to teach at a business, we store the invitation email address, the role offered, whether the invitation has been accepted, and the dates the engagement runs between — a guest appearance can be given an end date so the roster closes itself.
  • Hours you record at work: if a business you work for turns on the time clock, we store the hours you record — when each stretch of work started and ended, what it was for (teaching, prep, admin, meetings, training, travel, cleaning, front desk), the business's timezone, whether you clocked yourself or a manager entered it for you, and whether an end time was typed in or stamped by the clock. We also keep the full history of every change to an entry: the values before and after, who made the change, the role they held at the time, and — for a change somebody made to another person's record — the reason they gave. Times are stored exactly as recorded and are never rounded. You can always read your own hours and their full change history, including changes a business made. SavaSync records these hours; it does not calculate wages, overtime, premiums or deductions, and it does not determine whether anyone is complying with any law.
  • What you are paid: if you teach at a business on SavaSync, the business records the rate it pays you for the sessions you provide — a fixed amount per session, an amount per attendee, a share of what was collected, or a combination. SavaSync calculates from those rates and does not pay you; the business does.
  • Cash payments recorded at the door: when you pay a Studio in cash rather than through the Platform, a member of its staff marks the booking or appointment paid. We record every one of those marks and every un-marking: what the payment status was before and after, the time payment was recorded, the time an un-marking removed, who made the change, and when. A cash payment has no card receipt behind it, so this record is the only account of it either of you can point to — which is why you can always read the history of marks made on your own bookings, not only the Studio. Un-marking a payment clears the recorded payment time from the booking itself, so that the booking never claims money the Studio does not have; the history above is what keeps the earlier claim visible.
  • Pay reports we email: when a business schedules a pay report, we record the address it was sent to and when it went.
  • Teaching transfers: a business can ask you to bring your teaching with you when you join it. If it does, we store whether it asked for your clients, whether it asked for your classes, the classes you agreed to move, the date you chose for them to change hands, which person at the business made the request, and the number of bookings you refunded to bring that date forward. Nothing moves on the strength of the request alone: taking one account's classes and clients into another needs both sides to have agreed, and the record is how that stays checkable afterwards.
  • Connected Zoom accounts: if you connect Zoom for meeting links, we store the Zoom account identifier and its email address, and the tokens Zoom issues us (Sections 2.3 and 4).
  • On-demand video library (Premier tier): a Studio's uploads are stored as objects in Cloudflare R2 — the original, the streaming renditions we transcode from it, and a poster image — with the title, description and running order in our database. Anyone signed in can see that metadata once a video has finished processing; watching one requires an active membership, checked when the playback link is issued. Where a video shows a person, that footage is personal data about them, and the Studio decides what to record and publish.
  • Privacy requests: when you exercise a right under Section 5, we log its type, the email address it came from, when it arrived, when it is due, and how it was resolved — the register is how we can show a request was answered.
  • Device tokens for push notifications: if you enable push notifications on a mobile device, your device registers an Expo Push token with us so we can deliver notifications.

2.2 Information collected automatically

When you use the Platform, our servers and the third-party services we rely on automatically collect:

  • Server logs: the requests your device makes to our servers (pages and API endpoints, timestamps, response status), your IP address, and your browser's user-agent string. We also collect sampled performance telemetry (page-load and API timing) through our monitoring service (Sentry) to keep the Platform fast; this telemetry is used only for operations and debugging, never for advertising or cross-site profiling.
  • Aggregate site metrics: our marketing site uses Cloudflare Web Analytics, a cookieless tool that gives us aggregate page-view and performance metrics without identifying or profiling individual visitors. It sits in the consent banner's "Analytics & diagnostics" category, and whether it starts before you have chosen depends on where you are: outside the United States the script is not sent to your browser at all unless you have allowed that category, and in the United States it runs unless you turn it off or your browser sends Global Privacy Control. Either way it stops the moment you decline. See Section 6.
  • Error reports and diagnostic logs: when something breaks, an error report is sent to our error-tracking service (Sentry) so we can fix it. A report can include your IP address, user-agent, and technical context about what the app was doing (such as internal record identifiers); we do not send passwords or payment data. We also send diagnostic log lines to Sentry to give errors context. These are genuinely automatic: they store nothing in your browser, and we rely on them under our legitimate interest in keeping the Platform secure and working (Section 3).
  • Error-triggered session replay, in the dashboard (and the mobile apps once released) onlyand always yours to switch off: while the consent banner's "Analytics & diagnostics" category is on for you, an error in the SavaSync dashboard (app.savasync.com) — or, once they are released, the mobile apps — may additionally capture a short replay of the screens involved so we can reproduce the problem. Replays are captured only when an error occurs, never continuously, and text you type and images are masked or blocked before anything leaves your browser. Whether it starts before you have chosen depends on where you are, exactly as the previous bullet describes: outside the United States nothing is recorded until you allow that category, and in the United States a masked replay may be captured unless you turn it off or your browser sends Global Privacy Control. If you decline, no replay is ever recorded and any recording in progress stops. Our savasync.com marketing site records no session replays at any time, allowed or not. See Section 6.
  • The country you signed up from: at signup, our edge network reports which country the request came from — Cloudflare derives it from your IP address; we do not ask you for it and you do not type it in. We store that two-letter country code on your profile because SavaSync is offered only in the United States, and it is included in a copy of your data if you ask for one. It is a country, never a precise location, and it is not used for advertising.
  • Cookies and similar technologies: see our Cookie Policy for the full item-by-item list. Your login session is not a cookie — it is a token in your browser's localStorage (or, in the mobile apps once released, the app's own on-device storage). The only cookies we set ourselves are sv_authed, a credential-free signed-in indicator, and sv_consent, which records your answer to the consent banner. We set no CSRF-token cookie, and do not need one: the app attaches your session token explicitly, so a browser never sends it automatically the way it sends cookies. There are two consent categories and only two — Essential, which is always on, and Analytics & diagnostics, which is yours to decide and which the Cookie Policy explains the defaults for. There is no functional, advertising, or marketing category. We do not use advertising cookies. Our marketing site uses Google Analytics 4, which sets two measurement cookies (_ga and _ga_<measurement-id>) and is described in Section 6 and in the Cookie Policy; it is configured for measurement only — Google Signals off, no data shared with Google for its own ad personalisation or targeting, no advertising account linked — so it is not used to profile you, to target advertising, or to track you across other websites, and it does not run in the dashboard at all. Our error and performance monitoring (Sentry) is used solely for diagnostics and is not used to build advertising or marketing profiles.
  • Audit data for legal-record events: when you sign a waiver, accept a legal document, or unsubscribe from emails, we capture your IP address and user-agent at the moment of the action. This is necessary to maintain a legally defensible audit trail.

2.3 Information from third parties

  • Stripe: payment status, payout status, dispute and chargeback information, and connected-account status for Studios.
  • Resend (transactional and marketing email provider): the immediate result of each send request — whether Resend accepted the message and, if it refused, the error — and, from the effective date of this version, two later events about messages we send you: a hard bounce (the address does not exist, or permanently refused the message) and a spam complaint (you marked one of our messages as junk). Those two, and nothing else: we do not run open tracking or click tracking, there is no tracking pixel in our email (see the Cookie Policy §1), and we do not receive open or click events. We use a bounce or complaint for one purpose — adding that address to a suppression list so we stop sending to it, which is how we honor a spam complaint and how one dead address stops damaging email delivery for everyone else on the Platform. The list holds the address, which of the two events it was, and when.
  • Twilio (SMS provider for Premier-tier accounts where SMS reminders are enabled): the immediate result of each send request — whether Twilio accepted the message. We do not subscribe to Twilio status callbacks, so we do not receive later delivery or failure events.
  • Expo Push Service: the ticket Expo returns when we hand it a notification, which says whether Expo accepted it and reports a token that has become invalid so we can stop using it. We do not poll Expo for final delivery receipts.
  • Google (if you sign in with Google): your name, email address, and profile photo from your Google account.
  • Zoom (only for a Studio or Instructor who connects a Zoom account to create meeting links for online Classes): the Zoom account identifier and the email address on that Zoom account. Nothing is received from Zoom for anyone else.

3. How We Use Your Information

We use the information described above to:

  • Provide the Platform. Create and authenticate your account, host and display your Classes, process Bookings, route payments through Stripe, send transactional notifications (booking confirmations, class reminders, cancellation notices, waitlist offers, membership renewals).
  • Operate the business model. Calculate platform fees, process subscription billing, and produce reports for Studios (revenue, attendance, retention, and what each instructor is owed for the sessions they taught — a report the Studio acts on itself; SavaSync does not pay instructors).
  • Communicate with you. Send service communications about your bookings and account: booking confirmations, cancellation notices, class reminders, waitlist offers, membership updates, payment-failure alerts, security alerts, policy updates, and support responses. You can opt out of most of these individually (see Section 6.1); a small core — security alerts, payment-failure notices, membership renewal and cancellation notices, the notice we send when a Studio ends your membership, and legal or policy notices — is essential to operating your account and is always sent while your account is active. Studios you book with may also send marketing email through the Platform (announcements and custom email campaigns they write). Every marketing email includes an unsubscribe link, and SavaSync honors a global marketing opt-out across all Studios.
  • Maintain security and prevent fraud. Detect suspicious account activity, enforce our Acceptable Use Policy, prevent abuse, and respond to security incidents.
  • Comply with legal obligations. Maintain tax records, respond to subpoenas and lawful requests, and preserve legal-record evidence (waiver signatures, legal acceptances, payment records).
  • Improve the Platform. Diagnose problems, debug errors, and develop new features. Where we use aggregate or de-identified data for product analytics, the data cannot be tied back to an individual user.

4. How We Share Your Information

We share your information only in the specific circumstances listed below. We do not sell or rent your personal information to anyone.

  • With Studios and Instructors you book with: when you book a Class, we share your name, email, phone (if you provided it), and booking details with the Studio so the Studio can deliver the Class, run check-in, and contact you about the Class. The Studio's use of that information is governed by the Studio's own privacy policy, not ours.

  • With Students who book your Classes (if you are a Studio): we share Students' booking information with you for the Classes you operate.

  • With our service providers (data processors), each bound by data-processing agreements with us:

    • Stripe for payment processing, payouts, and chargeback handling
    • Supabase for database, authentication, and file storage
    • Resend for transactional and marketing email delivery
    • Twilio for SMS reminders (Premier-tier accounts where SMS reminders are enabled)
    • Expo Push Service for mobile push notifications
    • Sentry for error tracking, performance monitoring, and diagnostic logs across the whole Platform: when an error occurs, the report can include your IP address, user-agent, and technical context (such as internal record identifiers). In the dashboard (app.savasync.com) (and the mobile apps once released) — and only for people whose "Analytics & diagnostics" category is on, which Section 6 explains the defaults for — a report may also include an error-triggered session replay of the affected screens, with typed text and media masked or blocked by default. Reports from the savasync.com marketing site never include a replay, because that site does not run the recorder. Sentry data is retained for about 30 days and is used only to diagnose and fix problems.
    • Google Analytics 4 for measuring the savasync.com marketing site only — which pages are read and which sources send visitors — and never in the dashboard at app.savasync.com. It runs only for people whose "Analytics & diagnostics" category is on, which Section 6 explains the defaults for. Google truncates your IP address before storing it and we never receive it; we do not send names, email addresses or any account data. Google Signals is off, we do not share this data with Google for its own ad personalisation or targeting, and no advertising account is linked to it. Data is retained for 14 months.
    • Google Maps Platform for turning Studio business addresses into map coordinates and time zones (Geocoding and Time Zone APIs), and for address autocomplete while a Studio owner types a business address (Places API). Student addresses are not sent to Google — SavaSync does not collect them.
    • Zoom Video Communications, Inc. for creating the meeting link attached to an online Class, and only for accounts that connect a Zoom account. If a Studio or Instructor connects Zoom, we store that person's Zoom account identifier, the email address on their Zoom account, and the access and refresh tokens Zoom issues us. The only Class information we send to Zoom is the Class title: the meeting we create is a permanent recurring meeting with no scheduled time, so no Class date, time, or schedule ever reaches Zoom. Most accounts never connect Zoom, and nothing is sent to Zoom for those accounts. Student information is not sent to Zoom. Disconnecting Zoom stops this.
    • Cloudflare for hosting our web applications (Cloudflare Workers for the marketing site, the dashboard, and the embeddable widget), for DNS, CDN, and TLS termination on our domains, for cookieless aggregate site analytics (Cloudflare Web Analytics) on the marketing site, and for object storage (Cloudflare R2) holding uploaded video files and the streaming renditions and poster images we generate from them. Cloudflare processes user requests as our hosting provider.

    We will update this list when we add or replace material sub-processors. The current list is maintained in this Policy; check the Effective Date at the top to see when it was last revised.

  • Publicly, for Studio and Instructor business profiles: if you operate a Studio or Instructor account, your business profile — display name, bio, logo and gallery photos, business address and location, class schedule, prices, and cancellation policy — is published on your public SavaSync profile page and through the embeddable widget. That is the point of the profile; don't put anything in those fields you don't want public. Student profiles are never public.

  • In response to lawful requests: subpoenas, court orders, search warrants, or other legal process. We will give you notice when allowed by law.

  • To protect rights and safety: when we reasonably believe disclosure is necessary to enforce our Terms, investigate fraud, protect the rights or safety of users or the public, or comply with applicable law.

  • In a corporate transaction: if SavaSync is acquired, merged, or sold, your information may be transferred to the acquirer, subject to this Privacy Policy (or a similar one).

5. Your Rights and Choices

You have the rights described below, and there are two ways to exercise them.

In the app. Signed in, from Account settings → Your data, you can download a copy of everything we hold about you without asking us first. The download is a machine-readable archive (an export.json file, a spreadsheet copy of every section, your profile picture and any intake-form signatures you drew) together with a plain-language README.txt that lists anything left out and the reason for it. It includes the private notes a Studio has written about you, though not which member of Studio staff wrote them, and it never contains live credentials such as payment-processor identifiers or connected-app access tokens. One export per day; the download link is private to you and expires after five minutes. From your account settings you can also correct your profile and delete your account.

By email. You can always email us at legal@savasync.com with the request and the email address associated with your account — and you should, for anything the in-app tools do not cover, or if you cannot sign in. We will respond within 30 days (or, for residents of states with longer mandated response windows, within the period required by your state's law — typically 45 to 60 days); if your request is complex, we may extend by an additional 30 days and will tell you.

We keep a register of the requests we receive, with a response clock on each one. Requests you make through the in-app tools are logged in the same register.

This section is organized so you can find the rights that apply to you: Section 5.1 covers rights we extend to every user. Section 5.2 covers California rights under CCPA/CPRA. Sections 5.3 through 5.5 cover Virginia, Utah, and Texas rights. Section 5.6 covers other U.S. state privacy laws that share the same structural rights.

5.1 Rights for all users

  • Access: download a copy of the personal information we hold about you from Account settings → Your data, or request one by email.
  • Correction: request that we correct inaccurate information. You can update most profile information yourself from your account settings.
  • Deletion: delete your account yourself from your account settings, or ask us to. We will honor this within 30 days, except for information we are legally required to retain (see Section 7) and waiver signatures that are kept as a legal record.
  • Marketing opt-out: unsubscribe from marketing emails using the link at the bottom of any marketing message, or by adjusting notification preferences in your account.

5.2 Additional rights for California users (CCPA / CPRA)

California residents have the right to:

  • Know what categories of personal information we collect, the sources, the purposes, and the categories of third parties we share with — all of which are described in this Policy.
  • Delete their personal information, subject to legal-retention exceptions.
  • Correct inaccurate personal information.
  • Limit the use of sensitive personal information. We do not use sensitive personal information for purposes other than those listed in this Policy.
  • Non-discrimination: we will not deny service, charge different prices, or provide a lower-quality experience because you exercise these rights.

We do not sell or share your personal information as those terms are defined in the CCPA/CPRA. If that ever changes, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" link.

We honour the Global Privacy Control signal even though, because we neither sell nor share, there is nothing it is legally required to opt you out of. A browser that sends it is treated as having declined the "Analytics & diagnostics" category described in Section 6, and nothing in that category is switched on for you. See the Cookie Policy §4.2.

5.3 Additional rights for Virginia users (VCDPA)

If you are a Virginia resident, the Virginia Consumer Data Protection Act ("VCDPA") gives you the right to:

  • Confirm whether we process your personal data and access the personal data we hold about you.
  • Correct inaccuracies in your personal data, taking into account the nature of the data and the purposes of processing.
  • Delete personal data we have about you, subject to the legal-retention exceptions in Section 7.
  • Obtain a copy of your personal data in a portable, readily usable format that allows you to transmit it to another controller without hindrance, where technically feasible. The in-app download described at the top of this Section is that copy; you can also request one by email.
  • Opt out of (a) the sale of your personal data, (b) targeted advertising, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, conduct targeted advertising, or profile users for significant decisions, so there is currently nothing for you to opt out of; if that ever changes, we will provide a clear opt-out mechanism.

For "sensitive data" under the VCDPA (defined to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, precise geolocation, and personal data collected from a known child), we will obtain your opt-in consent before processing such data for any purpose not strictly necessary to deliver the service. SavaSync does not itself ask for sensitive data; however, Studios may collect health-related information from you through intake forms (see Section 2.1), which SavaSync stores on the Studio's behalf and uses for no other purpose. You choose what to disclose in an intake form, and the Studio is responsible for the questions it asks.

If we deny your request, you may appeal by emailing legal@savasync.com with "VCDPA Appeal" in the subject line. We will respond to the appeal within 60 days. If we deny the appeal, you may submit a complaint to the Virginia Attorney General at https://www.oag.state.va.us/.

5.4 Additional rights for Utah users (UCPA)

If you are a Utah resident, the Utah Consumer Privacy Act ("UCPA") gives you the right to:

  • Confirm whether we process your personal data and access that data.
  • Delete personal data you provided to us.
  • Obtain a copy of your personal data in a portable, readily usable format.
  • Opt out of (a) the sale of personal data and (b) targeted advertising. As stated above, we currently do neither.

The UCPA does not include a right to correct or a right to opt out of profiling. For "sensitive data" under the UCPA, we will give you clear notice and an opportunity to opt out before processing it. SavaSync does not itself ask for sensitive data; health-related information you choose to provide in a Studio's intake form (Section 2.1) is stored on the Studio's behalf and used for no other purpose.

To exercise your rights, email legal@savasync.com. We will respond within 45 days; if the request is complex, we may extend by 45 additional days and tell you.

5.5 Additional rights for Texas users (TDPSA)

If you are a Texas resident, the Texas Data Privacy and Security Act ("TDPSA") gives you the right to:

  • Confirm whether we process your personal data and access the personal data.
  • Correct inaccuracies.
  • Delete personal data.
  • Obtain a copy of your personal data in a portable format.
  • Opt out of (a) sale of personal data, (b) targeted advertising, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. We currently do none of these.

The TDPSA defines "sensitive data" to include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data processed to uniquely identify a person, precise geolocation, and personal data of a known child. We will not process sensitive data without obtaining your opt-in consent, and we will provide a clear notice if we ever begin doing so. SavaSync does not itself ask for sensitive data; health-related information you choose to provide in a Studio's intake form (Section 2.1) is stored on the Studio's behalf and used for no other purpose.

A specific Texas-required notice: If we ever begin to sell sensitive personal data, we will post a clear notice in this Privacy Policy stating "NOTICE: We may sell your sensitive personal data." As of the effective date of this Policy, we do not.

You may appeal a denied request by emailing legal@savasync.com with "TDPSA Appeal" in the subject. We will respond within 60 days. If the appeal is denied, you may complain to the Texas Attorney General at https://www.texasattorneygeneral.gov/.

5.6 A note on other state privacy laws

Several other U.S. states have enacted privacy laws that share structural elements with the laws above (Colorado's CPA, Connecticut's CTDPA, Oregon's OCPA, Delaware's DPDPA, Indiana's INCDPA, Iowa's ICDPA, Montana's MCDPA, New Hampshire, New Jersey, Tennessee's TIPA, and others). The rights granted by these laws are substantially the same as those described in Sections 5.3 through 5.5 (access, correct, delete, portability, opt-out of sale/targeted advertising/profiling). If you are a resident of one of these states, we will honor your rights under your state's law on the same terms described above, even if your state is not separately named. To exercise your rights, email legal@savasync.com.

6. Cookies and Tracking

Your dashboard login session is a token stored in your browser's localStorage (or, in the mobile apps once released, in the app's own on-device storage) — it is strictly necessary and identifies your account. One cookie (sv_authed, a credential-free signed-in indicator for the marketing site) is set when you log in, and one (sv_consent) records your answer to the consent banner. The dashboard also keeps a few interface-state entries — which account you last had open, light or dark, whether the sidebar was collapsed, and the signup choices carried across an OAuth redirect. All of these are essential and always on, and the Cookie Policy names every one of them.

Three things are governed by the "Analytics & diagnostics" answer rather than being essential, and they sit on different surfaces. On the savasync.com marketing site, that is Cloudflare Web Analytics, our aggregate page-view counter, and Google Analytics 4, which sets the two measurement cookies named in the Cookie Policy and is configured for measurement only, with Google Signals off and no advertising account linked; the marketing site runs no session replay at all. In the dashboard (and the mobile apps once released), it is Sentry session replay, which stores a browser sessionStorage entry while a masked, error-triggered recording is being made. Both are governed by the same "Analytics & diagnostics" answer, so one choice covers both places. Whether they start before you have answered depends on where you are: outside the United States none of them run until you allow the category, and in the United States they all run unless you turn them off — no United States privacy law requires us to ask first for aggregate measurement and masked, error-triggered diagnostics, and we neither sell nor share personal information. If your browser sends a Global Privacy Control signal we treat that as a no and start neither, without asking; an explicit yes you give afterwards is a more specific choice and we follow it. Declining means the analytics script is never sent to your browser and no replay is recorded; withdrawing later stops any recording in progress and deletes its stored entry. You can change your answer at any time from the Cookie settings link in the footer of savasync.com, or from Account settings → Analytics and diagnostics in the dashboard.

Sentry's error reports, performance traces and diagnostic logs are separate from that category and are not switched off by declining it: they store nothing in your browser, and we rely on them under our legitimate interest in keeping the Platform secure and working (§3). We do not use advertising cookies, cross-site tracking, or device fingerprinting, and we do not use analytics to build individual profiles of you: the measurement described above is configured so that Google cannot use it for its own ad personalisation or targeting. See our Cookie Policy for the complete item-by-item list and for instructions on managing your choices.

6.1 Marketing communications

Studios you book with may send you marketing email through the Platform (announcements and custom email campaigns they write). Every message includes an unsubscribe link in the footer; clicking it removes you from Studio marketing email immediately, globally across all Studios.

Service emails are also under your control, per type: you can unsubscribe from class reminders, booking confirmations, cancellation notices, membership updates, and waitlist offers individually, using the unsubscribe link in the footer of any of those emails or the notification preferences in your account settings. A small core of messages — security alerts, payment-failure notices, membership renewal and cancellation notices, the notice we send when a Studio ends your membership, and legal or policy notices — is essential to operating your account and cannot be opted out of while your account is active. Opting out of membership updates therefore stops the optional ones, such as the welcome message when a membership starts; it does not stop the renewal and cancellation notices, which are billing disclosures we are required to send for as long as you hold a membership, and it does not stop the notice we send when a Studio ends your membership, which is how you find out that access you were paying for is ending. Messages in that core carry no unsubscribe link, because the link would offer a choice that does not apply to them. If you have any trouble unsubscribing, email us at legal@savasync.com.

7. Data Retention

We retain your information for as long as your account is active. After you close your account:

  • Personal account data (profile information, booking history, notification preferences, intake-form responses, notes Studios kept about you): retained for 30 days, during which you may restore your account. Closing an account suspends its sign-in for the whole recovery window, so logging back in will not restore it — use the restore page, which emails a link to the address on the account. Restoring brings back your profile, your schedule and your history; it does not undo what closing the account did. Upcoming bookings and appointments were cancelled, and client memberships and any SavaSync subscription were cancelled with our payment processor — none of which we can reinstate, so those bookings and subscriptions have to be made again. Closing an account cancels; it does not refund. Money you have already paid for an upcoming booking is not returned automatically, so if you are owed a refund, request it from the Studio before you close your account. After 30 days, your personal data is permanently deleted from active systems on a rolling automated schedule.
  • Waiver signatures: retained for the longer of seven (7) years or the period required by applicable law, in immutable, append-only form. Waiver signatures are a legal record of consent to liability terms and cannot be deleted on account closure.
  • Payment records and tax-related records: retained for seven (7) years per IRS recordkeeping rules.
  • Records of hours worked: where a Studio used the Platform to record your working time as its staff member, those entries are the Studio's employment record. They are retained for the period that applies to employment records, are not removed when you close your account, and a profile that holds them is not permanently deleted after 30 days. SavaSync records hours; it does not calculate wages, overtime, premiums or deductions, and it does not determine whether anyone is complying with any law.
  • Legal-document acceptances (Terms, Privacy Policy, and other versioned documents you accepted): retained for seven (7) years as a record of the version of the Terms you agreed to.
  • IP addresses used transiently for rate-limiting and abuse prevention: deleted by an automatic hourly sweep once the record is more than 36 hours old. The rate-limit windows themselves are much shorter — a minute to an hour — but the same records also hold a daily send counter that resets at midnight UTC, so the sweep waits out a full day plus a margin rather than cutting at the longest rate-limit window. IP/user-agent data attached to legal-record events (waiver signatures, legal acceptances, unsubscribe records) follows the retention periods above for those records. Error reports, diagnostic logs, performance telemetry, and error-triggered session replays are retained by Sentry per our plan's standard retention (currently about 30 days). Google Analytics measurement data for the savasync.com marketing site is retained for 14 months.
  • Aggregated and de-identified data used for product analytics: retained indefinitely, as it cannot be linked back to you.
  • Backups: data within rolling encrypted backups is purged on the backup-rotation schedule, typically within 35 days after the backup containing that data is rotated out of the live retention window.

If you ask us to delete your account, we delete account-linked data within the periods above, except where the law requires longer retention (such as a litigation hold, subpoena, or other legal process).

8. Children's Privacy

The Platform is intended only for adults. You must be at least 18 years old to create an account, and we do not knowingly collect personal information directly from anyone under 18 as an account holder or direct user. If you believe someone under 18 has created an account, or that we have inadvertently collected personal information directly from a minor, contact us at legal@savasync.com and we will delete it promptly.

Some Studios offer Classes to minors (for example, youth or children's programs). In those cases an adult account holder — a parent or legal guardian, or the Studio — provides and manages any information about the minor participant (a booking, an intake response, or a waiver signed on the minor's behalf). SavaSync stores that information on the Studio's behalf as described in this Policy, and the Studio is responsible for obtaining any parental or guardian consents required by law.

9. International Data Transfers

SavaSync is operated from the United States. If you are accessing the Platform from outside the United States, your information will be transferred to and processed in the United States or other countries where our service providers operate, and by using the Platform you consent to that transfer.

10. Security

We protect your information with industry-standard safeguards:

  • All Platform traffic is encrypted in transit using TLS 1.2 or higher.
  • All data at rest in our database and file storage is encrypted using AES-256 (provided by Supabase).
  • Passwords are stored only as bcrypt-style salted hashes (managed by Supabase Auth); we never see plain-text passwords.
  • Payment-card data is handled exclusively by Stripe and never touches our servers.
  • We restrict access to personal data to employees and contractors who need it to do their jobs, under written confidentiality obligations.
  • We log and monitor administrative access for anomalies.

No security program is perfect. If we discover a personal-data breach that affects you, we will notify you without undue delay and within the timeline required by the breach-notification law applicable in your jurisdiction. Our notice will include the categories of data affected, the steps we have taken in response, and recommended steps you can take to protect yourself.

11. Changes to This Policy

We may update this Policy from time to time. Changes take effect when we post them, and we will note the new effective date at the top. If we make a material change, we will notify you by email and by an in-app notice at or before the time it takes effect, and we will not begin any new collection or use of your information that the change describes until that notice has gone out. Material changes include any change to the categories of data we collect, the purposes we use it for, the categories of third parties we share with, or your rights.

If you continue to use the Platform after a material change takes effect, you accept the updated Policy.

12. Contact Us

If you have questions, concerns, or requests about this Policy or about your personal information:

  • Email: legal@savasync.com
  • Mail: Tricky Labs LLC, 221 Main St Ste N, Nashua, NH 03060, USA

We aim to respond to all privacy inquiries within 30 days.