Privacy Policy
Last updated: February 23, 2026
1. Introduction
Slotbase (“we,” “us,” or “our”) operates the Slotbase platform at www.slotbase.cloud (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account data: Name, email address, phone number, date of birth, and role (player, parent, coach, facility admin).
- Facility data: Facility name, address, operating hours, resources, sport types, and logo.
- Booking data: Session dates, times, participants, notes, and payment information.
- Payment data: Billing details processed through Stripe. We do not store full credit card numbers on our servers. For enrollment auto-pay subscriptions, Stripe provides us with limited payment method metadata (card brand and last four digits) to display subscription status. This information is fetched from Stripe in real time and is not stored in our database.
- Communications: Messages you send through the platform, support requests, and feedback.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, actions taken, timestamps, and session duration.
- Device data: Browser type, operating system, IP address, and device identifiers.
- Cookies: We use essential cookies for authentication and session management. See Section 7 for details.
2.3 Information from Third-Party Services
- Authentication (Clerk): We use Clerk for authentication. When you sign up or sign in, Clerk provides us with your name, email, and profile image.
- Payments (Stripe): Stripe processes payments and provides us with transaction status, amounts, payment method type, card brand, and last four digits (not full card details). For recurring enrollment subscriptions, Stripe also provides subscription status and next billing date.
- Google Calendar: If a facility connects Google Calendar, we access calendar event data (event titles, times, attendees) to sync with facility schedules. See Section 6 for full details.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service (bookings, payments, enrollments, scheduling).
- Authenticate your identity and manage your account.
- Process payments, generate invoices, and manage recurring enrollment billing (auto-pay subscriptions).
- Send transactional notifications (booking confirmations, reminders, payment receipts).
- Enable facility admins to manage their resources, coaches, players, and events.
- Sync calendar data between Slotbase and connected third-party calendars.
- Improve the Service through analytics and error tracking (Sentry).
- Respond to support requests and communicate with you about the Service.
- Comply with legal obligations and enforce our Terms of Service.
4. How We Share Your Information
We do not sell your personal information. We share information only in these circumstances:
- With your facility: When you join a facility, the facility admin can see your name, email, phone, booking history, and payment status (including enrollment subscription status, card brand, last four digits, and next billing date for auto-pay enrollments). This is necessary to manage your bookings, enrollments, and billing.
- With service providers: We use third-party services (Clerk for auth, Stripe for payments, Resend for email, Vercel for hosting, Sentry for error tracking) that process data on our behalf under contractual data processing agreements.
- With coaches: Coaches affiliated with a facility can see student names, session schedules, and attendance for their assigned sessions.
- For legal compliance: We may disclose information if required by law, regulation, legal process, or governmental request.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained until you delete your account.
- Booking and payment records: Retained for 7 years after creation for legal and financial compliance.
- Usage logs: Retained for 90 days for security and debugging purposes.
- Google Calendar data: Cached temporarily during sync. Calendar data is not permanently stored beyond what is displayed in the facility schedule. When a facility disconnects Google Calendar, all cached calendar data is deleted.
When you request account deletion, we remove your personal data within 30 days, except where retention is required by law.
6. Google API Services — Limited Use Disclosure
Slotbase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6.1 What Google Data We Access
When a facility admin connects their Google Calendar to Slotbase, we request access to:
- Calendar list (read): To display available calendars for selection.
- Calendar events (read): To import event titles, start/end times, and attendee information into the facility schedule view.
6.2 How We Use Google Data
- Display imported calendar events alongside Slotbase bookings in the facility schedule.
- Prevent scheduling conflicts by showing occupied time slots.
- Sync session attendance data with calendar events (when enabled by the facility admin).
6.3 Limited Use Compliance
We comply with Google's Limited Use requirements:
- We only use Google Calendar data to provide and improve the calendar sync feature within Slotbase.
- We do not use Google Calendar data for advertising, marketing, or selling to third parties.
- We do not transfer Google Calendar data to third parties except as necessary to provide the Service (e.g., displaying events in the facility dashboard).
- We do not allow humans to read your Google Calendar data unless: (a) you give explicit consent, (b) it is necessary for security purposes, or (c) it is required by law.
- Google Calendar data is not cached permanently. Data is fetched on-demand during sync and displayed in real-time. Cached data is refreshed on each sync and deleted when the integration is disconnected.
6.4 Revoking Access
A facility admin can disconnect Google Calendar at any time from Facility Settings → Google Calendar. Disconnecting immediately revokes Slotbase's access to your Google Calendar data and deletes all cached calendar information. You can also revoke access directly from your Google Account permissions page.
7. Cookies and Tracking
We use the following types of cookies:
- Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
- Analytics cookies: Used to understand usage patterns and improve the Service. These are anonymized.
We do not use advertising cookies or sell tracking data. We do not use cookies for cross-site tracking.
8. Data Security
We implement appropriate security measures including:
- Encryption in transit (TLS/HTTPS) for all data transmission.
- Encryption at rest for sensitive data stored in our database.
- Authentication via Clerk with support for multi-factor authentication.
- Role-based access control for all application data.
- Rate limiting and audit logging on all API endpoints.
- Regular security reviews and dependency updates.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data (subject to legal retention requirements).
- Export your data in a portable format.
- Withdraw consent for optional data processing (e.g., disconnect Google Calendar).
- Object to processing of your data for specific purposes.
To exercise any of these rights, contact us at privacy@slotbase.cloud. We will respond within 30 days.
10. Children's Privacy
Slotbase is used by sports facilities that may serve minors (under 18). Account creation requires users to be 18 or older. Minors are managed through their parent's account:
- Parents add children to their account with name and date of birth.
- Parents manage bookings and enrollments on behalf of their children.
- Children do not have independent login access unless enabled by the facility admin when they reach the minimum age.
- We do not knowingly collect personal information directly from children under 13 without parental consent.
11. International Data Transfers
Your data may be processed in countries other than your own. Our hosting infrastructure (Vercel, Render) operates primarily in the United States. By using the Service, you consent to the transfer of your data to the United States and other countries where our service providers operate.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
- Email: privacy@slotbase.cloud
- Support: support@slotbase.cloud
- Website: www.slotbase.cloud