Last updated 17 June 2026
This policy explains how CalyPad handles personal data across our marketing site and our booking, loyalty, and messaging platform. CalyPad is a product of Number Pii.
CalyPad is operated by Number Pii. For our marketing site and platform account data we act as the data controller. For the customer data a business (a tenant) manages through CalyPad, that business is the controller and CalyPad acts as its processor. You can reach us about privacy at privacy@calypad.com.
CalyPad sends three categories of text message: one-time passcodes for login, transactional messages about a booking you made (such as confirmations and reminders), and marketing or loyalty messages where you have given consent. Consent for marketing messages is collected through a clear opt-in during the booking flow, and we record the time and IP address of that consent.
Message frequency varies based on your activity. Message and data rates may apply. You can opt out of messages at any time by replying STOP, or by using the opt-out link or account setting where a reply is not supported. Reply HELP for help, or contact support@calypad.com.
We do not share mobile information with third parties or affiliates for marketing or promotional purposes. We share the minimum data necessary with our messaging provider solely to deliver the messages you receive. Text messaging originator opt-in data and consent are not shared with any third party for marketing purposes.
Where UK GDPR or EU GDPR applies, we rely on: performance of a contract (to provide the service and transactional messages), consent (for marketing messages and certain cookies), and legitimate interests (to secure and improve the service). You may withdraw consent at any time.
We use service providers that process data on our behalf under contract, including Stripe for payments, our SMS provider for message delivery, and Supabase for hosting and database services. We do not sell personal data.
We keep personal data only as long as needed for the purposes above or as required by law. Guest booking data is deleted automatically after a per-business retention window. Legal acceptance records are kept as long as needed to evidence consent and resolve disputes. Message logs are kept for up to 24 months to support delivery monitoring and dispute resolution, then deleted automatically.
Depending on your location you may have rights to access, correct, delete, or restrict the use of your data, to object to processing, and to data portability. You can opt out of marketing at any time. To exercise a right, contact privacy@calypad.com. You may also complain to your local data protection authority, such as the UK Information Commissioner's Office.
Where data is transferred outside the UK or EEA, we use appropriate safeguards such as standard contractual clauses.
We use technical and organisational measures to protect personal data, including encryption in transit, access controls, and tenant data isolation.
We may update this policy and will revise the date above when we do. Questions can be sent to privacy@calypad.com. See also our Terms of Service and SMS Policy.