Privacy Policy
Last updated: August 22, 2026
This policy explains how Moolah Technologies LTD ( "we", "us", "Cyntree") collects, uses, and protects your personal data when you use our platform. We are committed to handling your data responsibly and in accordance with UK GDPR and the Data Protection Act 2018.
For account, billing, support, platform security, and product analytics data, Cyntree acts as a data controller. For client information a business collects inside its workspace, including booking forms and uploaded documents/images, the business usually decides why that data is needed and Cyntree provides the platform that stores and processes it on the business's behalf.
Information We Collect
We collect information in the following ways:
- Account data — name, email address, password (hashed), and business details when you register. If you sign in with Apple, we receive your Apple user identifier and, if you choose to share it, your email address.
- Booking data — appointment times, service details, client records, and notes created through the platform.
- Booking image data — where enabled by a business, client-uploaded booking images and related metadata (file type, size, storage path, booking linkage).
- Booking form data — where enabled by a business, information requested before or after a booking, including typed answers, yes/no or choice answers, consent statements and acceptance records, signature text or signature files, requested documents or images, filenames, file type, file size, secure storage paths, submission status, reminder activity, review status, and retention/deletion metadata.
- Client portal account data — if you choose to create a Cyntree client portal account when making a booking, we store your email address, hashed password, and display name. This account is optional and lets you view all your bookings across any Cyntree business in one place at cyntree.com/portal. Your historical bookings (matched by email address) are accessible once the account is created. You can request deletion of your portal account at any time by contacting us.
- Payment data — payment amounts, tips, and transaction references. Full card numbers are handled directly by our payment processors (Stripe or Paystack, depending on your region) and are never stored on our servers. For in-person card payments taken via Tap to Pay on iPhone, we store limited card metadata returned after a transaction (such as card brand, the last four digits, card network, funding type, country of issue, the authorisation code, and the cardholder verification method) to produce receipts and to support reconciliation, refunds, and dispute handling.
- Location data (in-person payments) — if a business uses Tap to Pay on iPhone to accept in-person card payments, our payment processor (Stripe) requires the device's approximate geographic location at the time of each transaction for fraud prevention and regulatory compliance. We request location permission when in-person payments are set up, and the location is attached to the charge by Stripe. You can decline, but in-person card acceptance will not work without it. We do not use this location for advertising or to track you outside of taking a payment.
- In-app purchase data — for subscriptions or add-ons bought in the mobile app, we receive purchase receipts, transaction IDs, product identifiers, subscription status, and renewal/expiry dates from Apple App Store and Google Play (via our subscription infrastructure provider). We do not receive your full card number or bank details from Apple or Google.
- Usage data — pages visited, features used, device type, browser, and IP address for platform analytics and security.
- Business setup and account health data — where you create or manage a business workspace, we may use limited account, business profile, subscription, onboarding, verification, readiness, booking-page, and app/website visit signals to understand whether the workspace is set up correctly, whether you may need help using the platform, and whether previous support or outreach has already happened. This does not include client booking notes, booking-form answers, uploaded client documents, or full payment details for Cyntree's own outreach.
- Communications — messages you send to our support team and any feedback you submit through the platform (including your name, email, and message content).
- Support and outreach records — records of Cyntree support or onboarding messages we prepare or send, including the recipient, subject, short body preview, reason for contact, internal notes, whether a message draft was generated or copied, whether a compose window was opened, whether contact was marked as completed, and any suppression or opt-out request.
- Push notification tokens — if you enable push notifications in the mobile app, we store a device token so we can deliver booking alerts and reminders to your device. You can disable notifications at any time in your device settings.
- Calendar sync data — if you connect Google Calendar or Microsoft Outlook, we store encrypted OAuth tokens and connection metadata (e.g. account email, calendar IDs you select for availability and for receiving bookings). We use this only to sync Cyntree bookings to your chosen calendar and to read busy/availability when you enable it. We do not store the contents of your calendar events on our servers beyond what is needed for that sync.
- Team member data (Cyntree Teams) — for businesses on a Teams plan, the name, email address, optional phone number, profile details, assigned role and permissions, working hours and availability, and time-off requests of the team members a business owner invites to their workspace.
- Invitation data — the email address of a person a business owner invites to join their workspace, which we process to deliver and manage the invitation until it is accepted, declined, or expires.
- Activity records — for businesses on a Teams plan, a log of certain actions taken in the workspace (such as changes to bookings, clients, team membership, and settings), recording which team member took the action and when, used for security and accountability.
- Earnings data — where enabled, service earnings, tips, and commission figures attributed to individual team members for the business's own reporting. These figures are estimates derived from booking and payment data and are not a payroll or tax record.
How We Use Information
We use your data to:
- Operate, maintain, and improve the Cyntree platform.
- Process bookings, send confirmation and reminder emails, and manage scheduling.
- Store, secure, and display client-uploaded booking images to the relevant business for appointment delivery.
- Send, track, review, and retain booking forms requested by a business, including sending completion reminders, notifying the business when a form is submitted, generating business PDF exports, and applying the business's configured retention settings.
- Process payments and handle refunds via Stripe or Paystack (depending on your region).
- Send push notifications about booking updates, reminders, and account activity when you have opted in via the mobile app.
- Sync your Cyntree bookings to your connected calendar (Google or Outlook) and use your calendar's availability when you enable calendar sync.
- Generate AI-assisted website drafts, power Cyntree Assist, and check AI feature inputs for abuse and security risks.
- Provide customer support and respond to your requests.
- Provide proactive onboarding support and product guidance for business account holders, for example helping you verify your account, finish setup, switch from test mode to live mode, share your booking page, or understand a relevant feature.
- Keep a limited contact history so we know whether we have already contacted you, why we contacted you, and whether you have asked us not to contact you for marketing or manual outreach.
- Detect and prevent fraud, abuse, and security incidents.
- Power your optional client portal — if you create a portal account, we use your email address to retrieve and display all bookings you have made across any Cyntree business so you can manage your history in one place.
- Comply with our legal obligations under UK law.
AI features currently use a third-party provider (OpenAI) for website generation, Cyntree Assist, content-safety moderation, and limited internal support drafting. Cyntree Assist questions are sent to the provider to create a product-guidance answer. For internal support drafting, we may send limited business/account context such as business name, setup state, verification state, readiness blockers, subscription tier, and recent platform activity signals so a Cyntree admin can review and edit a support message. We do not use client booking content, booking-form answers, uploaded client documents/images, or full payment details for Cyntree support or marketing drafts. If an AI input is flagged by automated safety checks, its status, safety categories, and a redacted excerpt may be retained and an internal alert may be emailed to Cyntree support for human review. A safety alert does not by itself suspend an account or produce another legal or similarly significant decision. Recent Cyntree Assist questions and answers may also be kept locally on the user's device for up to 30 days and can be cleared in the app. We do not share personal data with the AI provider except for the limited information needed to provide the requested AI feature, support drafting, and safety moderation.
We may contact business account holders with service, account, or onboarding messages that are needed to provide or improve the service you signed up for. We may also send limited product guidance or marketing messages where permitted by law. Marketing emails are treated separately from essential service messages: you can opt out of marketing at any time, and we will still send transactional, security, billing, booking, or account messages where they are necessary to operate the platform.
Our legal basis for processing is primarily contract performance (to provide the service you signed up for), legitimate interests (platform security, service improvement, customer support, onboarding guidance, and limited direct marketing where PECR allows it), consent where required for electronic marketing or optional analytics, and legal obligation where applicable. Where a business asks its client to provide booking form information, that business is responsible for identifying and explaining its lawful basis for collecting the requested information.
Sharing of Information
We do not sell your personal data. We share data only with trusted sub-processors required to operate the service:
- Supabase — database hosting and authentication (EU region).
- Stripe — online and in-person payment processing (PCI-DSS compliant), including Tap to Pay on iPhone via Stripe Terminal. For in-person payments, Stripe receives the device's approximate location at the time of the transaction for fraud prevention and compliance.
- Paystack — payment processing for supported African regions.
- Apple App Store — mobile in-app purchase processing and subscription management for iOS users.
- Google Play — mobile in-app purchase processing and subscription management for Android users.
- RevenueCat — in-app purchase receipt validation and subscription status infrastructure.
- Resend — transactional email delivery.
- Vercel — web hosting and edge delivery.
- OpenAI — AI website generation, Cyntree Assist, safety moderation of AI inputs, and limited internal support drafting using privacy-minimised account/business context.
- Google — when you use Calendar Sync, we use Google's APIs (e.g. Google Calendar) under Google's privacy and API terms. We do not sell or share your calendar data with other third parties.
- Microsoft — when you use Calendar Sync with Outlook, we use Microsoft Graph under Microsoft's privacy and terms. We do not sell or share your calendar data with other third parties.
All sub-processors are contractually bound to process data only on our instructions and in accordance with applicable data protection law.
Business owners and authorised workspace members can access the booking, client, image, document, and form data connected to their workspace. For businesses on a Teams plan, the owner may grant access to additional team members, and what each member can see is governed by the role and permissions the owner assigns them. Data is only made available within the business's own workspace; Cyntree does not share one business's data with another business. If a business downloads a PDF, document, image, or other export from Cyntree, that exported copy is controlled by the business and is no longer governed by Cyntree's in-platform retention settings.
Cookies & Tracking
We use essential cookies required for authentication and platform functionality.
- Essential cookies are always active and are required for sign-in, account security, and booking flows.
- Optional analytics cookies (Google Tag Manager, Vercel Analytics, Vercel Speed Insights, and Microsoft Clarity) are only enabled after you provide consent through our cookie banner/settings. Microsoft Clarity may record anonymised session interactions (clicks, scrolls, mouse movements) to help us improve the site; recordings are masked by default and we do not use them for advertising.
We do not use advertising cookies or cross-site profiling cookies. You can withdraw or update your analytics preference at any time.
In our mobile app, browser cookies are not used. The app uses essential device storage/session data to keep you signed in and secure.
Data Retention
We retain your data for as long as your account is active or as needed to provide the service. If you close your account, we will delete or anonymise your personal data within 90 days, except where we are required to retain it for legal, tax, or dispute-resolution purposes (typically up to 6 years under UK law).
Client-uploaded booking images and booking-form documents, images, signatures, and responses may also be deleted under the relevant business retention settings, account controls, policy enforcement, or legal/takedown obligations.
For booking forms, businesses can configure retention periods for uploaded documents/images/signatures, form answers, and abandoned uploads. If a business does not change the default settings, Cyntree is designed to retain submitted form files for 90 days, form answers for 1 year, and abandoned form uploads for 48 hours, subject to operational, legal, security, or dispute-resolution needs.
When form files are deleted under retention settings, Cyntree may keep a minimal audit record, such as filename, file type, size, deletion timestamp, and deletion reason, unless the business has chosen not to keep that audit record. Once form answers or uploads have been deleted under the retention process, they may not be recoverable from the platform.
For businesses on a Teams plan, pending invitations are retained until they are accepted, declined, or expire; records of team members who leave or are deactivated are retained while needed to keep an accurate workspace history; and workspace activity records are retained for security and accountability. Activity records may be retained under our legitimate interests even after other records relating to the same person have been deleted.
Internal support and outreach records are kept only for as long as needed to understand previous contact, avoid duplicate outreach, respect suppression or opt-out requests, handle complaints, and demonstrate compliance. Suppression and opt-out records may be kept for longer than ordinary contact history so that we can continue to honour your request not to receive marketing or manual outreach.
Backups, logs, and security records may persist for a limited period after deletion from the live service where this is needed for resilience, audit, fraud prevention, or legal compliance. Access to those records is restricted. Cyntree Assist usage and safety records are kept only while needed to operate rate limits, investigate abuse or security incidents, and meet applicable legal obligations.
Security
We implement appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS), hashed passwords, and restricted access controls. However, no method of internet transmission or electronic storage is 100% secure, and we cannot guarantee absolute security.
Booking-form uploads are stored privately and are accessed through time-limited secure links for authorised users. Businesses should still treat any downloaded documents, images, signatures, or PDF exports as confidential and store them securely outside Cyntree.
Your Rights (UK & EEA)
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Marketing opt-out — object to or opt out of direct marketing at any time. We will stop using your information for direct marketing when you object, while still sending essential service, security, billing, booking, or account communications where needed.
The fastest way to exercise these rights is from the Cyntree mobile app: open Settings > Account > Danger zone > Request your data. You can choose which kind of request to make, narrow it to specific categories of data, and tell us where to send the response. You can also contact us at support@cyntree.com. We will respond within 30 days of receiving the request.
If your request concerns information you gave to a business, such as a booking form response or uploaded document/image, you may also need to contact that business directly because it decides why the information was requested. We will assist businesses with platform records where required by applicable data protection law.
Third-Party Services
Our platform may contain links to third-party websites or integrate with external services. We are not responsible for the privacy practices of those third parties and recommend reviewing their policies independently.
If you connect Google Calendar or Microsoft Outlook for calendar sync, those providers' privacy policies and terms also apply to the data they receive. You can disconnect your calendar from Cyntree at any time in your dashboard or app settings; we will stop syncing and you may revoke access in your Google or Microsoft account settings.
Children's Privacy
Cyntree is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.
Changes to this Policy
We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. The "Last updated" date at the top of this page will always reflect the most recent revision. Continued use of Cyntree after changes constitutes acceptance of the updated policy.
Contact & Complaints
For privacy-related questions or to exercise your rights, the quickest route is the in-app Settings > Account > Danger zone > Request your data screen, which creates a tracked request our privacy team will respond to within 30 days. You can also email us at support@cyntree.com.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Moolah Technologies LTD is the platform operator. Registered in England & Wales, Company No. 16892355. Registered office: 14 Smith Close, Armthorpe, Doncaster.
