Privacy Policy
Last updated: August 2026
Who this covers
This policy explains how Sessions handles personal information across our websites, apps, embeds, and API.
We handle information in two roles. For people who hold a Sessions account — business owners, staff, and customers with their own account — we decide how that information is used, and this policy applies directly. For the information a business collects about its own customers through Sessions, that business decides how it is used and we process it on their behalf; their privacy policy applies, and requests are best sent to them. We always help a business answer a request.
What we collect
Account information. Your name, email address, and the sign-in method you use. Sessions is passwordless, so there is no password to store. If you sign in with Google or Apple we receive your name and email address from them, and nothing else.
Business and activity data. Schedules, activities, bookings, attendance, memberships, passes, scores, waivers, and the customer records a business enters or uploads. This is stored so a business can run its operation and its customers can manage their bookings.
Purchase and payment information. What was bought, when, for how much, and the receipts and payout records that follow. Card details go directly to Stripe — we never see or store a full card number, only what Stripe returns to us, such as the card brand and last four digits.
Messages and support. The confirmations, reminders, and marketing messages sent through Sessions, whether they were delivered and opened, and anything you send us when you ask for help.
Technical and usage data. Basic request logs (IP address, user agent, URL) retained for up to 30 days for security and debugging, plus error reports. We do not use third-party analytics or advertising trackers.
How we use it
We use personal information to run Sessions: to provide the service and the bookings made through it, to process payments and issue receipts, to send service messages such as confirmations, reminders, and security notices, to provide support, to keep the service secure and prevent fraud and abuse, and to meet our legal obligations.
Where the law requires a lawful basis, ours is performing our agreement with you, our legitimate interest in operating and securing the service, your consent where we ask for it, and compliance with legal obligations. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it to train advertising or third-party AI models.
Marketing messages
We send marketing email only with consent or where our relationship with you allows it, and every marketing message carries a one-click unsubscribe. Service messages — receipts, security alerts, and notices about your account — are part of the service and continue while your account is open.
How long we keep it
Account and business data is kept while the account is open. Request logs are kept for up to 30 days. When you delete your account or your data we remove it from the live service within 30 days and from backups within 90, except records we are required to keep — transaction and tax records, for example — and anything a business must retain, such as a signed waiver.
How we protect it
Data is encrypted in transit, access is limited to the people who need it, and sign-in is passwordless, so there is no password to steal. No service can promise perfect security, but if a breach affects your personal information we will notify you and the relevant regulator as the law requires.
Where your data is processed
Sessions runs on Cloudflare’s global network, and our providers process data in Canada, the United States, and the European Union. Where information crosses a border we rely on the contractual protections our providers offer, including standard contractual clauses, so it stays protected to the standard described here.
Your rights
You can access, correct, export, or delete your information, and withdraw consent you have given, at any time from your account settings or by writing to us at privacy@sessions.website. We respond within the timelines the law sets, and we will not treat you differently for exercising a right.
If your information is held by a business using Sessions, send your request to that business — they decide what happens to it, and we help them act on it. If our response does not satisfy you, you can complain to your privacy regulator, including the Office of the Privacy Commissioner of Canada or your provincial or state authority.
Children
Sessions is not directed to children under 13 and we do not knowingly collect their information for accounts of their own. A parent or guardian can add a child to their own account so they can book activities for the child; the adult stays in control of that profile and can remove it at any time.
Changes to this policy
We update this policy as the service changes, and the date above always reflects the current version. When a change is material we tell account holders by email before it takes effect.
Contact
Sessions has a designated privacy officer. Questions, requests, or complaints about this policy can be sent to privacy@sessions.website, and we respond within 30 days.