Privacy Policy

Last updated: July 13, 2026

This Privacy Policy explains how Aotoz (“we”, “us”, or “our”) collects, uses, stores, and shares information when you use our scheduling platform and services at https://aotoz.com.

1. Overview

Aotoz is a multi-tenant scheduling SaaS platform used by businesses (“Operators”) to offer appointment booking to their own customers (“End Users”). This policy covers both relationships.

We act as a data processor for Operators and as a data controller for information we collect about Operators and their account users. Operators are responsible for the privacy rights of their own End Users.

By using Aotoz, you agree to the collection and use of information as described in this policy.

2. Information We Collect

Account & operator information

  • Name, email address, and password when you create an account
  • Organization name, industry, timezone, and branding preferences
  • Billing information (processed securely by our payment provider — we do not store full card numbers)
  • IP addresses and browser/device information for security and fraud prevention

Booking & scheduling data (processed on behalf of Operators)

  • Customer names, email addresses, and phone numbers entered by Operators or End Users
  • Appointment dates, times, services, and notes
  • Responses to intake forms created by Operators
  • Payment amounts, coupon codes, and transaction status

Usage & technical data

  • Pages visited, features used, and time spent on the platform
  • API requests, response times, and error logs
  • Cookie identifiers and session tokens

Third-party integrations (when you connect them)

  • Google Calendar: event data and free/busy information (only when you connect your Google account)
  • Email providers: delivery status and open rates for notifications

3. How We Use Information

We use information we collect to:

  • Provide, operate, and improve the Aotoz platform
  • Send transactional emails (booking confirmations, reminders, password resets)
  • Process payments and prevent fraud
  • Respond to support requests and communicate about your account
  • Generate aggregated analytics to improve the product
  • Comply with legal obligations
  • Send product updates and marketing communications (you may opt out at any time)

We do not sell your personal data or your customers’ data to third parties. We do not use your booking data for advertising purposes.

4. Sharing & Disclosure

We share information only in the following circumstances:

  • Service providers: Trusted vendors who process data on our behalf (email delivery, payment processing, cloud hosting, error monitoring). These providers are bound by data processing agreements.
  • Operators: If you are an End User, your booking information is shared with the Operator whose booking page you used. Their privacy policy governs that relationship.
  • Legal requirements: We may disclose information if required by law, court order, or to protect the rights, property, or safety of Aotoz, our users, or the public.
  • Business transfers: If Aotoz is acquired or merged, user information may be transferred as part of that transaction. You will be notified in advance.
  • With your consent: For any other purpose with your explicit consent.

5. Data Retention

We retain data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.

  • Account data: Retained until account deletion, then deleted within 90 days
  • Booking records: Retained for 7 years for financial compliance purposes unless you request earlier deletion
  • Audit logs: Retained for 2 years
  • Session and security logs: Retained for 90 days

You may request deletion of your account and data at any time by contacting privacy@aotoz.com. Some data may be retained where required by law.

6. Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Tenant isolation — each workspace’s data is logically separated
  • Granular role-based access controls
  • Immutable audit logs for all sensitive operations
  • Regular security reviews and dependency updates
  • Bcrypt password hashing — we never store plain-text passwords

No system is completely secure. If you discover a security vulnerability, please report it responsibly to security@aotoz.com.

7. Healthcare Data (HIPAA)

Aotoz provides technical controls that healthcare organizations can use to support HIPAA compliance, including PHI access logging, audit trails, role-based permissions, and retention controls.

Important: These controls do not make Aotoz automatically HIPAA-compliant for your organization. HIPAA compliance also requires your organization to:

  • Execute a Business Associate Agreement (BAA) with Aotoz
  • Maintain appropriate internal policies and staff training
  • Conduct a risk assessment
  • Implement required administrative and physical safeguards

To request a BAA, contact privacy@aotoz.com. BAAs are available on Business and Enterprise plans.

Protected Health Information (PHI) entered into Aotoz is processed on behalf of the covered entity Operator. Aotoz acts as a Business Associate under HIPAA when processing PHI.

8. Cookies & Tracking

We use the following types of cookies:

  • Essential cookies: Session tokens required for authentication. Cannot be disabled.
  • Preference cookies: Store your UI preferences (e.g. sidebar state). Can be cleared in your browser settings.
  • Analytics cookies: Aggregate usage data to help us improve the product. We use privacy-respecting analytics and do not track across third-party sites.

We do not use advertising cookies or share cookie data with ad networks.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (right to erasure)
  • Portability: Receive your data in a machine-readable format
  • Restriction: Request that we restrict processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

EU/EEA and UK residents have these rights under GDPR/UK GDPR. California residents have rights under CCPA/CPRA. To exercise any right, contact privacy@aotoz.com.

We will respond to rights requests within 30 days. We may ask you to verify your identity before processing requests.

10. Children's Privacy

Aotoz is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@aotoz.com and we will delete it promptly.

11. International Data Transfers

Aotoz is operated from servers in the European Union and the United States. If you are located outside these regions, your data may be transferred to and processed in countries with different data protection laws.

For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or other lawful transfer mechanisms. For transfers from the UK, we use the UK International Data Transfer Agreement (IDTA) or equivalent mechanisms.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a prominent notice on the platform at least 30 days before the change takes effect.

Continued use of Aotoz after the effective date constitutes acceptance of the updated policy. If you do not agree with the changes, you may close your account before the effective date.

13. Contact Us

For privacy-related questions, requests, or complaints, contact us at:

If you are an EU/EEA resident and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.