Privacy Policy
Last updated: April 4, 2026
1. Information We Collect
We collect information you provide directly to us when you create an account, set up your operator profile, or contact support. This includes your name, email address, business name, address, timezone, and currency preferences. When guests make bookings through operator pages, we collect their name, email, phone number, and any additional information required by the operator (such as waiver signatures or dietary requirements). We also collect usage data automatically, including pages visited, features used, browser type, device information, and IP address. We use essential cookies for authentication and session management. Optional analytics cookies are only set with your explicit consent.
2. How We Use Information
We use the information we collect to provide, maintain, and improve the Service; to process bookings and payments; to send transactional communications such as booking confirmations, payment receipts, and session reminders; to provide customer support; to analyze usage patterns and improve the platform experience; and to detect, investigate, and prevent fraudulent transactions or unauthorized access. We do not use guest data for our own marketing purposes. Transactional emails (confirmations, reminders, receipts) are sent automatically as part of the booking service and cannot be disabled.
3. Data Sharing
We share data with third-party service providers only as necessary to operate the Service. Stripe processes payments and receives guest payment information directly — Stokely never stores credit card numbers or bank account details. Postmark delivers transactional and marketing emails on behalf of operators. Twilio sends SMS notifications when enabled by operators. We use Supabase for database hosting and authentication. We do not sell, rent, or trade personal information to third parties for their marketing purposes. We may disclose information when required by law, such as in response to a subpoena, court order, or government request.
4. Operator vs. Guest Data
Operators who use Stokely are data controllers for the guest information collected through their booking pages. Stokely acts as a data processor, processing guest data on behalf of operators in accordance with their instructions and applicable data protection laws. Operators determine the purposes for which guest data is collected and are responsible for ensuring they have a lawful basis for processing, including obtaining consent for marketing communications (email and SMS). Guests who wish to exercise their data rights should contact the operator who collected their information in the first instance.
5. Data Retention
Booking data is retained in accordance with the operator's account settings and applicable legal requirements. Operators may configure their own data retention preferences through the dashboard. Platform analytics data (aggregated, non-personal) is retained for 12 months and then automatically purged. Upon account termination, operators may request a full export of their data within 30 days. After 30 days, Stokely will delete operator and associated guest data from active systems, though backup copies may persist for up to 90 days before being permanently removed.
6. Your Rights
Depending on your location, you may have certain rights regarding your personal data. Under the General Data Protection Regulation (GDPR), European residents have the right to access, rectify, erase, restrict processing of, and port their personal data, as well as the right to object to processing. Under the California Consumer Privacy Act (CCPA), California residents have the right to know what personal information is collected, to request deletion, and to opt out of the sale of personal information. Stokely does not sell personal information. To exercise any of these rights, please contact us at privacy@stokely.io. We will respond to all legitimate requests within 30 days.
7. Security
We implement industry-standard security measures to protect your data. All data is encrypted in transit using TLS 1.2 or higher. Database access is controlled through row-level security (RLS) policies that enforce tenant isolation, ensuring operators can only access their own data. Authentication tokens are managed through secure, httpOnly cookies. Access to production systems is restricted to authorized personnel with multi-factor authentication. We conduct regular security reviews of our codebase and infrastructure. While we strive to protect your information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
8. Cookies
Stokely uses essential cookies that are strictly necessary for the Service to function. These include authentication session cookies and CSRF protection tokens. These cookies cannot be disabled without breaking core functionality. We also support optional analytics cookies (such as Google Analytics) that operators may enable on their booking pages. These cookies are only set after the guest provides explicit consent through a cookie banner. No tracking cookies are set by default. Operators who enable third-party analytics tools (GA4, Meta Pixel) are responsible for their own cookie consent compliance.
9. Children
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@stokely.io.
10. International Transfers
Stokely is based in the United States and data is primarily processed on servers located in the US. If you are accessing the Service from outside the United States, your information will be transferred to, stored, and processed in the US. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of personal data from the European Economic Area. By using the Service, you acknowledge that your data may be processed in a jurisdiction with different data protection laws than your own.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify operators of material changes by email at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at privacy@stokely.io.
Stokely, Inc.