Legal

Privacy Policy

This describes what SlotCue actually stores, where it lives, and who else touches it. It was written from our own database schema and code — not adapted from a template — so everything below is a description of the running system.

Effective 19 August 2026 · Last updated 20 August 2026

1. Who we are

SlotCue is a scheduling and booking platform published by Joaico. In this policy, “SlotCue”, “we”, and “us” mean Joaico operating the SlotCue service at slotcue.com and book.slotcue.com.

You can reach a human at privacy@ramsford.ai for anything on this page, or support@ramsford.ai for account and billing questions. These are monitored mailboxes operated by our team.

2. Two different roles — please read this one

SlotCue handles two categories of people, and our responsibilities differ for each.

If you booked an appointment and want your details corrected or removed, the fastest route is to contact the business you booked with. You can also write to us at privacy@ramsford.ai and we will pass the request to them and help action it.

3. What we collect

3.1 When a business creates a SlotCue account

DataDetail
Business profileBusiness name, booking-page address (slug), time zone, and your branding choices (colours, logo URL, page copy).
Account & sign-inEmail address, your role on the account (owner, admin, manager, staff, viewer), and a one-way hash of your password. We never store your password itself and cannot recover it.
Two-factor authenticationIf you turn on TOTP two-factor, the shared secret is stored encrypted, never in plain text.
Sign-in security recordsSession records with creation, expiry and last-seen timestamps, plus the IP address and browser user-agent of the session, and counters for failed sign-in attempts and lockouts. This is how you can review and revoke your own active sessions, and how we stop password-guessing.
Team membersName and email of staff you add, and invitation records for people you invite.
ConfigurationServices and prices you publish, working hours, locations, time off, and scheduling rules.
Billing referencesYour plan tier and status, and the Stripe customer and subscription identifiers for your subscription. See §3.4.
How you found usFirst-touch acquisition details recorded once when you first arrive: the channel, any UTM parameters, the referring site, and the page you landed on. See §4.
Activity logAn audit record of significant actions on your account (booking created, appointment cancelled, configuration changed) with the actor and a timestamp.

3.2 When someone books through a business's booking page

The booking page asks for a name and an email address, and optionally a phone number and a note. We store those together with the service chosen, the appointment start and end time, and the booking status (booked, completed, cancelled, no-show). We also store short-lived “holds” that reserve a slot while a booking is being completed, and they expire on their own.

This data belongs to the business you booked with (see §2). Email is required because that is where the booking confirmation and any appointment reminder are sent.

3.3 Product analytics

We record first-party product events — for example a landing-page visit, a signup step completed, a trial started — with an event type, a random anonymous visitor identifier, a marketing channel label, and the event's own properties. We use this only to understand which parts of the funnel work. We do not use a third-party analytics provider, and there are no advertising or social-media tracking pixels anywhere on SlotCue.

3.4 Payments

Subscription payments for SlotCue are handled by Stripe. Card details are entered on Stripe's own payment pages and go directly to Stripe. We never receive, see, or store your card number. What we store on our side is your Stripe customer identifier, your subscription identifier, your plan tier and subscription status, and the acquisition tags we attach to a subscription so we can tell which marketing channel it came from.

3.5 Mailing list

If you subscribe from one of our blog posts or resources, we store your email address, the segment you tell us you're in if you tell us, which post you subscribed from, the acquisition details in §3.1, and a one-click unsubscribe token. Every email we send you carries a working unsubscribe link, and unsubscribing takes effect immediately.

4. Cookies and local storage

We use no advertising cookies and no cross-site tracking cookies. The complete list is:

NameWherePurpose
bs_sessbook.slotcue.comYour signed-in session. Strictly necessary — you cannot use the app without it. Holds a random token only; it expires and you can revoke it yourself from your security settings.
bs_wizbook.slotcue.comRemembers your progress through the signup wizard so you don't lose your answers between steps.
sc_attrbook.slotcue.comFirst-touch marketing attribution — the channel, UTM parameters, referrer, landing page and a random visitor identifier, written once and kept for one year. It is never overwritten by later visits and contains nothing that identifies you personally.
sc_ftslotcue.com
(browser local storage, not a cookie)
The same first-touch marketing parameters, held in your browser so that when you click through to sign up, we can attribute the signup to the right channel.

Our marketing pages load web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Making that request means Google receives your IP address and browser user-agent, as it does for any site using their font service. No font cookie is set and we send Google nothing else about you.

5. Why we use it

We do not use your data, or your clients' data, to train machine-learning models.

6. Who else processes it

This is the complete list of third parties that handle SlotCue data. Each one processes it only to provide the service listed.

ProviderWhat they do
VercelHosts and serves the SlotCue website and application.
SupabaseHosts the PostgreSQL database where account, configuration, booking and analytics data is stored.
StripeProcesses subscription payments and stores payment-method details. See §3.4.
ResendDelivers our transactional email — booking confirmations, appointment reminders, sign-in and password emails, and mailing-list messages.
Google FontsServes the typefaces on our marketing pages. See §4.

We do not sell personal information, and we do not share it with advertisers or data brokers. We may disclose information if we are legally required to, or to protect the security of the service, and we would tell you unless we were legally prevented from doing so. If the business is ever sold or merged, account data would transfer with it and we would notify you first.

7. Where it is stored

Our database is hosted in the United States (Supabase, US West region). Our application and website are served from Vercel's global network. Stripe and Resend are US-based providers and process data on their own infrastructure. If you use SlotCue from outside the United States, your information will be transferred to and stored in the United States.

8. How it is protected

No system is perfectly secure, and we will not tell you otherwise. If we ever discover a breach affecting your data, we will contact you directly and tell you what happened.

9. How long we keep it

We keep account data, configuration and booking history for as long as the account exists, because the account is a business record its owner relies on. Cancelling a subscription revokes access to paid features but deliberately preserves the data so the account can be reactivated — it does not delete anything.

To have data actually deleted, ask us. Write to privacy@ramsford.ai from the account's email address and we will delete the account and its associated data within 30 days, other than records we must keep for accounting or legal reasons (for example, payment records held by Stripe). Expired booking holds are swept automatically. Mailing-list unsubscribes take effect immediately, and we keep the record of the unsubscribe so that we do not email you again by mistake.

To be plain about it: we do not currently run an automated retention or purge schedule. Deletion happens when you ask for it or when you delete the account.

10. Your choices and rights

Whatever jurisdiction you are in, you can ask us to:

Send requests to privacy@ramsford.ai. We handle these by hand and will respond within 30 days. We may need to confirm you control the account's email address before we act, so that someone else cannot use this process to reach your data.

SlotCue is a product for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child's information reached us, write to us and we will remove it.

11. What we do not do

Stating these plainly is more useful than a list of assurances:

An honest note about this document. This policy was written in-house from our own schema and source code so that it is accurate. It has not been reviewed by a lawyer. We chose an accurate, self-authored policy over having none at all, and over publishing boilerplate that describes a system we don't run. If something here is unclear or you need a specific contractual assurance, write to privacy@ramsford.ai and we will answer directly.

12. Changes and contact

When we change this policy we will update the “last updated” date at the top. If a change materially affects how we handle your data — a new processor, a new category of data, a new integration — we will email account holders before it takes effect rather than relying on you to re-read this page.

Privacy and data requests: privacy@ramsford.ai
Account, billing and support: support@ramsford.ai
Our terms of service: slotcue.com/terms