Last Updated: August 17, 2026
This Privacy Policy explains how Maelo App Inc. ("Maelo", "we", "us"), a federal corporation (Corporations Canada No. 1736630-2) based in Vancouver, British Columbia, Canada, collects, uses, discloses, and protects personal information through the Maelo platform at maelo.app and its apps (the "Service"). We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), Canada's Anti-Spam Legislation (CASL), and, for users in the EU/EEA and UK, the GDPR / UK GDPR. By using the Service you consent to the practices described here.
Maelo plays two roles depending on the data:
We use personal information to:
We collect only what is needed for these purposes (data minimization) and do not use personal information for materially new purposes without appropriate consent.
You may withdraw consent at any time (subject to legal or contractual restrictions) by contacting us or using in-product controls.
We do not sell or rent your personal information. We share it only:
Our error monitoring and product analytics run on our own servers, not on a third-party service, so that data is not shared with anyone.
If you choose to connect a Google Calendar, Maelo requests two narrowly scoped permissions: calendar.readonly (to see the calendars you choose and the times you are already busy) and calendar.events. We use them for exactly two purposes, both of which you initiate: reading your existing events, so that times you are already busy are blocked out and clients cannot book them; and writing your Maelo bookings into your calendar, so a confirmed appointment appears alongside the rest of your day.
We access only the calendars you select in Settings → Scheduling. Event titles and details are used solely to compute your availability and to create or update the events for your own bookings; you may hide event titles from the Maelo interface at any time.
Maelo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data, do not use it for advertising, do not use it to train any AI or machine-learning model, and do not transfer it to others except as needed to provide the Service, comply with applicable law, or with your explicit consent.
You can disconnect at any time in Settings → Scheduling, or revoke Maelo’s access directly at myaccount.google.com/permissions. Disconnecting stops all further access; calendar tokens are deleted and imported event data is removed within 30 days.
Maelo operates globally and uses providers located outside Canada. Your personal information may be stored or processed in the European Union (database hosting), the United States, and other countries via our providers' global infrastructure. While in another country, data may be accessible to that country's courts, law enforcement, and regulators under its laws. We use contractual and technical safeguards (including, where applicable, GDPR Standard Contractual Clauses) to require comparable protection for personal information transferred outside Canada, consistent with PIPEDA and BC PIPA.
We protect personal information with administrative, technical, and physical safeguards, including encryption in transit (TLS), encryption at rest for sensitive fields (waiver signatures and calendar tokens), role-based database access, scoped tenant isolation, and bot/abuse protection. No system is perfectly secure, but we work to protect your data and respond quickly if an issue arises.
Subject to applicable law, you have the right to:
We respond to access and correction requests within 30 days (PIPEDA / BC PIPA). To exercise any right, contact our Privacy Officer (Section 14). You may also complain to:
Every marketing email includes an unsubscribe link. You can also email privacy@maelo.app with "Unsubscribe" in the subject. We process opt-outs promptly (within 10 business days as required by CASL). Transactional messages necessary to a booking are not marketing and may still be sent.
We use strictly necessary cookies for authentication and security, and privacy-respecting analytics to understand and improve the Service. We use Cloudflare Turnstile for bot protection. Where required, we obtain consent for non-essential cookies/analytics.
Maelo includes a small number of optional AI features. Every one of them runs on Cloudflare Workers AI, the AI service built into our hosting provider. We do not send your data to OpenAI, Anthropic, Google, or any other third-party AI provider, and we do not route AI requests through any aggregator, gateway, or model hub.
Data obtained from the Google Calendar API is used only to calculate your availability and to write your Maelo bookings into your calendar. It is never sent to an AI model, never included in an AI prompt, and never used to develop, improve, or train any AI or machine-learning model, whether ours, our providers’, or a third party’s.
Cloudflare Workers AI does not retain the inputs we send it and does not use them to train its models. Nothing you enter into Maelo is used to create, improve, or fine-tune any AI or machine-learning model.
When an Artist uploads a receipt image for expense tracking, we use a vision AI model on Cloudflare Workers AI (Llama 3.2 Vision) to extract details such as vendor, date, amount, and line items. The image and extracted data are stored in the Artist’s own account.
When an Artist describes the page they want to build, a text model on Cloudflare Workers AI suggests which page components to use, and can generate a background configuration (colours and gradients) from a short text prompt you provide. The only input is the Artist’s own description. No Client information and no calendar data is involved.
Our AI features provide suggestions and extracted data only. They do not make automated decisions producing legal or similarly significant effects; all final decisions remain with you.
Maelo previously offered an AI Draft Assistant that suggested replies to Client messages using per-user embeddings of your past messages. This feature was removed in July 2026, together with the stored embeddings and the vector indexes that held them. Maelo no longer creates or stores embeddings of your messages.
The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
We have designated a Privacy Officer at Maelo App Inc. responsible for compliance with this policy and applicable privacy law (PIPEDA / BC PIPA). Contact: privacy@maelo.app (response time: within 30 days).
If a privacy breach occurs that creates a real risk of significant harm, we will notify affected individuals and the OIPC BC / OPC (and applicable EU/UK authorities) as required by law, and keep records of breaches as required.
We may update this policy. If we make material changes we will update the "Last Updated" date and, where appropriate or required, notify you by email or in-app, and seek new consent where needed.
© 2026 Maelo. All rights reserved. | Back to Home | Terms of Service