Privacy Policy
Last updated: 1 September 2026
This policy explains how IdeaZone collects, uses, stores and shares personal data, including through our website at ideazone.co and through Zeplicity, our booking and scheduling platform for practitioners. It also explains, in its own section below, exactly how we handle Google and Microsoft calendar data when you choose to connect a calendar to Zeplicity.
1. Who we are
IdeaZone ("IdeaZone", "we", "us", "our") builds and operates this website and Zeplicity, a booking and scheduling platform used by practitioners such as coaches, therapists and consultants to take client bookings. Zeplicity is a trading name (a registered DBA) of IdeaZone, not a separate company, so this policy governs both.
Our full legal entity name is IDEAZONE Operations LLC, a limited liability company formed in the State of Texas, United States, whose registered office is 1401 Art Dilly Drive, Unit 269, Austin, TX 78702, United States. Our filing number with the Texas Secretary of State is 806665376.
2. Scope of this policy
This policy covers two kinds of personal data, and treats them differently:
- Practitioner data. Information about you, if you are a practitioner with a Zeplicity account, or a visitor enquiring through our website. For this data, IdeaZone is the data controller.
- Client data.Information a practitioner stores in Zeplicity about their own clients, such as names, contact details, booking history, session notes, consent records and assessment responses. For this data, the practitioner is the data controller and IdeaZone is the data processor, acting only on the practitioner's instructions. See our Terms of Service for more on this distinction.
If you are a client of a practitioner who uses Zeplicity and you have a question about your own data, please contact that practitioner directly in the first instance, since they control your data and are best placed to action your request.
3. What data we collect, and why
Practitioner account data: name, email address, phone number, business details, calendar connection status, and billing information (handled by Stripe, see Sub-processors below). We use this to create and run your account, provide the scheduling service, process payment, and communicate with you about your account.
Client data, held on a practitioner's behalf:a client's name, email address, phone number, booking history, session notes, consent records and assessment responses, as entered by the practitioner. We store and process this data only to run the scheduling and record-keeping features the practitioner uses.
Website and usage data: pages viewed, device and browser information, and how you interact with our site and product, collected through the analytics tools described in Cookies below. We use this to understand how our site and product are used, to keep them secure, and to improve them.
Calendar data: if you connect a Google or Microsoft calendar, we access a limited set of calendar information as set out in the Google and Microsoft sections below.
4. Our lawful bases for processing
Under UK GDPR, we rely on the following lawful bases:
- Contract: to create your account and provide the Zeplicity service you have signed up for, including calendar sync and payment processing.
- Legitimate interests: to keep our website and product secure and working correctly, to prevent abuse, to understand and improve how our site and product are used, and to respond to enquiries.
- Consent: for optional analytics and advertising cookies, and for marketing communications where consent is required.
- Legal obligation: to meet our tax, accounting and other legal record-keeping requirements.
For client data processed on a practitioner's behalf, the lawful basis is determined by the practitioner as data controller. Our role is limited to processing that data as instructed.
5. Google user data (Calendar integration)
If a practitioner connects their Google Calendar to Zeplicity, we request the following Google API scopes, and use each one only as described here:
- Calendar events (
calendar.events). Write access only. We use this to create, update and delete the calendar events that correspond to bookings the practitioner accepts through Zeplicity, so their calendar stays in sync with their bookings. - Free/busy (
calendar.freebusy). Read-only access to the free and busy time ranges on the connected calendar. We use this only to avoid offering a booking slot the practitioner is not actually free for. This scope does not let us read event titles, descriptions, attendees, locations, or any other event content, only whether a time range is marked busy or free. - Email address (
userinfo.email). Used only to identify which Google account was connected, so Zeplicity reads and writes to the correct calendar.
How we use, store and share this data. We use Google Calendar data solely to provide the scheduling feature to the practitioner who connected their account: keeping their calendar and their Zeplicity bookings in sync and avoiding double-booking. We do not sell Google user data, we do not use it for advertising, and we do not use it to train any artificial intelligence or machine-learning model. We do not transfer Google user data to anyone except as needed to provide this feature (for example, the infrastructure providers listed in Sub-processors below, who process it on our behalf under contract), or where required by law. Access and refresh tokens are stored securely and used only to make the calendar API calls described above.
Disconnecting.A practitioner can disconnect their Google Calendar from Zeplicity at any time from within their account settings. Doing so deletes their stored access and refresh tokens from our systems, and Zeplicity makes no further calls to their Google Calendar. A practitioner can also revoke Zeplicity's access directly from Google at myaccount.google.com/permissions.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Microsoft user data (Calendar integration)
Microsoft calendar integration works the same way, for practitioners who connect an Outlook or Microsoft 365 calendar instead. We request the Calendars.ReadWrite, User.Read and offline_accessscopes: the first to keep calendar events in sync with bookings, the second to identify the connected account, and the third so the connection does not require the practitioner to sign in again every time. The same commitments above apply: this data is used only to provide the scheduling feature to the practitioner who connected their account, is never sold or used for advertising or AI training, and is not shared except as needed to provide the feature or where required by law. A practitioner can disconnect at any time from their Zeplicity account settings, which deletes the stored tokens, or by removing Zeplicity's access from their Microsoft account's app permissions settings.
7. Sub-processors and other services we use
We use the following third-party services to run our website and Zeplicity. Each processes personal data on our behalf, under contract, only for the purpose described:
- Vercel: hosts our website and application.
- Supabase: our database and file storage.
- Stripe: processes payments. We do not store full card details ourselves.
- Resend: delivers transactional email, such as booking confirmations and account notices.
- Google and Microsoft: calendar integration, only when a practitioner chooses to connect a calendar (see above).
- Upstash: rate limiting, to protect the service against abuse.
We do not sell personal data to anyone.
8. International data transfers
Some of the providers listed above process data outside the United Kingdom, including in the United States. Where personal data is transferred outside the UK, we take steps to ensure it stays protected, such as relying on the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an equivalent safeguard offered by the provider.
9. How long we keep data
We keep client records, such as booking history, session notes, consent records and assessment responses, for seven years. This is a deliberate choice: the ordinary UK limitation period for bringing a legal claim is six years, and we keep records for a further year beyond that so they remain available for as long as they could genuinely be needed.
We keep practitioner account data for as long as the account is active, and for a reasonable period afterwards to meet our legal, accounting and tax obligations. We delete or anonymise personal data once it is no longer needed for the purpose it was collected for, subject to the retention period above.
10. Security
We apply technical and organisational measures to protect personal data, including encryption of data in transit, restricted and role-based access to our systems, and database-level access rules that limit which data any given request can reach. No system is completely secure, and we cannot guarantee absolute security, but we work to reduce risk and to respond quickly if a problem is found.
11. Your rights under UK GDPR
Subject to certain conditions and exemptions, you have the right to:
- be told how your data is used;
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, in certain circumstances;
- restrict or object to certain processing;
- receive your data in a portable format, in certain circumstances; and
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights over data we control directly (see Scope above), contact us using the details in Contact us below. If your request relates to client data held by a practitioner on Zeplicity, we will where appropriate direct you to that practitioner, since they control that data.
12. How to complain
We hope we can resolve any concern directly, so please contact us first. If you are in the United Kingdom you also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO), at any time. If you are elsewhere in Europe, you may complain to your own national data protection authority. You can reach the ICO at ico.org.uk or by calling their helpline.
13. Cookies and similar technologies
Our website at ideazone.co uses cookies and similar technologies for:
- Essential functionality, needed for the site to work.
- Analytics, to understand how the site is used, through tools including Vercel Analytics and Google Analytics.
- Advertising and retargeting, through the Meta Pixel and the LinkedIn Insight Tag, to measure and improve our marketing.
The analytics and advertising technologies above do not run until you agree to them. When you first visit the site we ask, and nothing in those two categories loads unless you choose "Accept". Choosing "Reject" is equally easy and leaves the site working exactly the same. You can change your mind at any time using the Cookie settings link in the footer of every page, and withdrawing agreement stops those technologies immediately.
Vercel Analytics is listed above for completeness but is treated as essential: it is cookieless, stores nothing on your device and does not track you between sites, so it is not covered by the choice above. You can also control or delete cookies through your browser settings; blocking some cookies may affect how our website works. Zeplicity, the product itself, uses its own strictly necessary session cookies to keep you signed in, which are not part of the marketing tools above.
14. Children's privacy
Our website and Zeplicity are intended for business use by adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to remove it.
15. Changes to this policy
We may update this policy from time to time, for example as our product, vendors or legal obligations change. We will update the "Last updated" date at the top of this page when we do, and for material changes we will take reasonable steps to let you know directly.
16. Contact us
If you have a question about this policy or how we handle personal data, including a request to exercise any of the rights above, contact us at support@ideazone.co. You can also write to us at the registered office given in section 1.
