Skip to content

Privacy Policy

Last updated: August 2026

Who this covers

This policy explains how Sessions handles personal information across our websites, apps, embeds, and API.

We handle information in two roles. For people who hold a Sessions account — business owners, staff, and customers with their own account — we decide how that information is used, and this policy applies directly. For the information a business collects about its own customers through Sessions, that business decides how it is used and we process it on their behalf; their privacy policy applies, and requests are best sent to them. We always help a business answer a request.

What we collect

Account information. Your name, email address, and the sign-in method you use. Sessions is passwordless, so there is no password to store. If you sign in with Google or Apple we receive your name and email address from them, and nothing else.

Business and activity data. Schedules, activities, bookings, attendance, memberships, passes, scores, waivers, and the customer records a business enters or uploads. This is stored so a business can run its operation and its customers can manage their bookings.

Purchase and payment information. What was bought, when, for how much, and the receipts and payout records that follow. Card details go directly to Stripe — we never see or store a full card number, only what Stripe returns to us, such as the card brand and last four digits.

Messages and support. The confirmations, reminders, and marketing messages sent through Sessions, whether they were delivered and opened, and anything you send us when you ask for help.

Technical and usage data. Basic request logs (IP address, user agent, URL) retained for up to 30 days for security and debugging, plus error reports. We do not use third-party analytics or advertising trackers.

How we use it

We use personal information to run Sessions: to provide the service and the bookings made through it, to process payments and issue receipts, to send service messages such as confirmations, reminders, and security notices, to provide support, to keep the service secure and prevent fraud and abuse, and to meet our legal obligations.

Where the law requires a lawful basis, ours is performing our agreement with you, our legitimate interest in operating and securing the service, your consent where we ask for it, and compliance with legal obligations. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it to train advertising or third-party AI models.

Sharing

We share personal information with the providers that operate the service on our behalf, under contracts limiting what they may do with it: Cloudflare (hosting, infrastructure, and bot protection), Stripe (payment processing), and Resend (email delivery).

A business using Sessions sees the information its own customers give it. Public schedule and activity links are visible to anyone with the URL, and a business can unpublish them at any time to remove public access.

We also disclose information where the law requires it, where it is needed to protect the rights and safety of people or of the service, and to a successor if the business is sold — in which case this policy continues to apply until you are told otherwise.

Marketing messages

We send marketing email only with consent or where our relationship with you allows it, and every marketing message carries a one-click unsubscribe. Service messages — receipts, security alerts, and notices about your account — are part of the service and continue while your account is open.

Cookies

We use a session cookie to keep you signed in, small preference cookies to remember choices such as language and theme, and Cloudflare Turnstile to tell people from bots on public forms. We do not use advertising or cross-site tracking cookies.

How long we keep it

Account and business data is kept while the account is open. Request logs are kept for up to 30 days. When you delete your account or your data we remove it from the live service within 30 days and from backups within 90, except records we are required to keep — transaction and tax records, for example — and anything a business must retain, such as a signed waiver.

How we protect it

Data is encrypted in transit, access is limited to the people who need it, and sign-in is passwordless, so there is no password to steal. No service can promise perfect security, but if a breach affects your personal information we will notify you and the relevant regulator as the law requires.

Where your data is processed

Sessions runs on Cloudflare’s global network, and our providers process data in Canada, the United States, and the European Union. Where information crosses a border we rely on the contractual protections our providers offer, including standard contractual clauses, so it stays protected to the standard described here.

Your rights

You can access, correct, export, or delete your information, and withdraw consent you have given, at any time from your account settings or by writing to us at privacy@sessions.website. We respond within the timelines the law sets, and we will not treat you differently for exercising a right.

If your information is held by a business using Sessions, send your request to that business — they decide what happens to it, and we help them act on it. If our response does not satisfy you, you can complain to your privacy regulator, including the Office of the Privacy Commissioner of Canada or your provincial or state authority.

Children

Sessions is not directed to children under 13 and we do not knowingly collect their information for accounts of their own. A parent or guardian can add a child to their own account so they can book activities for the child; the adult stays in control of that profile and can remove it at any time.

Changes to this policy

We update this policy as the service changes, and the date above always reflects the current version. When a change is material we tell account holders by email before it takes effect.

Contact

Sessions has a designated privacy officer. Questions, requests, or complaints about this policy can be sent to privacy@sessions.website, and we respond within 30 days.