Privacy Policy

Last Updated: August 17, 2026

This Privacy Policy explains how Maelo App Inc. ("Maelo", "we", "us"), a federal corporation (Corporations Canada No. 1736630-2) based in Vancouver, British Columbia, Canada, collects, uses, discloses, and protects personal information through the Maelo platform at maelo.app and its apps (the "Service"). We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), Canada's Anti-Spam Legislation (CASL), and, for users in the EU/EEA and UK, the GDPR / UK GDPR. By using the Service you consent to the practices described here.

1. Roles: Who Controls Your Data

Maelo plays two roles depending on the data:

  • As a controller, for information we collect to run the platform (account data, billing, technical logs, our own communications with you).
  • As a service provider for Artists, when an Artist uses Maelo to manage their own Clients. The Artist controls their Client list; Maelo processes that data on the Artist's behalf. Artists are independently responsible for handling Client information lawfully.

2. Information We Collect

  • Account information (Artists): name, preferred name, email, username, auth credentials, profile and avatar images, business/studio details, timezone, settings, and branding.
  • Booking information (Clients): name, email, optional phone, the details you submit in a booking request (description, placement, size, reference images, budget, preferred dates), and messages with the Artist.
  • Sensitive information: waivers and details that may be sensitive (e.g., tattoo placement, any health-related answers a waiver collects). We treat this with a higher standard of consent and protection: your handwritten signature is encrypted at rest with a dedicated key, and the rest of the submission is sent over an encrypted connection and held in an access-controlled database. We collect it only with your express consent.
  • Payment information: processed by Stripe. We do not store full card numbers; we retain limited transaction metadata needed to operate bookings and payouts.
  • Technical information: IP address, browser/user-agent, device data, and usage/diagnostic logs used for security, fraud prevention, and reliability.
  • AI feature inputs: what you choose to submit to an optional AI feature, such as a receipt image you upload for expense scanning, or a short text prompt describing a page you want to build. We do not store embeddings of your messages. See Section 12.

3. How We Use Your Information

We use personal information to:

  • Provide, operate, and maintain the Service (accounts, bookings, messaging, payments, calendars, notifications)
  • Send transactional communications (booking confirmations, reminders, receipts, security notices)
  • Send marketing or product-update emails only with your consent (CASL), with an unsubscribe link in every such message
  • Prevent fraud and abuse and keep the Service secure
  • Comply with legal obligations
  • Improve the Service using aggregated, de-identified analytics

We collect only what is needed for these purposes (data minimization) and do not use personal information for materially new purposes without appropriate consent.

4. Legal Basis and Consent

  • PIPEDA / BC PIPA: we rely on your consent (express for sensitive information; implied for routine processing necessary to deliver a service you requested), and on other lawful bases where permitted.
  • CASL: we obtain consent before sending commercial electronic messages and honour withdrawal of consent.
  • GDPR / UK GDPR: our lawful bases are performance of a contract (Art. 6(1)(b)), consent (Art. 6(1)(a)), legitimate interests (Art. 6(1)(f)), and legal obligation (Art. 6(1)(c)). For sensitive data we rely on explicit consent (Art. 9(2)(a)).

You may withdraw consent at any time (subject to legal or contractual restrictions) by contacting us or using in-product controls.

5. How We Disclose Information: Service Providers

We do not sell or rent your personal information. We share it only:

  • With the Artist / Client you are transacting with, as needed to fulfil a booking
  • With service providers who process data on our behalf under contractual and technical safeguards: Stripe (payments); Cloudflare (hosting, storage, security/Turnstile, edge AI); Hetzner (managed database hosting); Apple / Google (calendar sync and maps when you connect them, and delivery of push notifications to your device); and Resend (delivery of transactional email such as booking confirmations and sign-in links)
  • When required by law: to comply with a valid legal request or to protect the rights, safety, or property of Maelo, our users, or the public

Our error monitoring and product analytics run on our own servers, not on a third-party service, so that data is not shared with anyone.

Google user data (Calendar)

If you choose to connect a Google Calendar, Maelo requests two narrowly scoped permissions: calendar.readonly (to see the calendars you choose and the times you are already busy) and calendar.events. We use them for exactly two purposes, both of which you initiate: reading your existing events, so that times you are already busy are blocked out and clients cannot book them; and writing your Maelo bookings into your calendar, so a confirmed appointment appears alongside the rest of your day.

We access only the calendars you select in Settings → Scheduling. Event titles and details are used solely to compute your availability and to create or update the events for your own bookings; you may hide event titles from the Maelo interface at any time.

Maelo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data, do not use it for advertising, do not use it to train any AI or machine-learning model, and do not transfer it to others except as needed to provide the Service, comply with applicable law, or with your explicit consent.

You can disconnect at any time in Settings → Scheduling, or revoke Maelo’s access directly at myaccount.google.com/permissions. Disconnecting stops all further access; calendar tokens are deleted and imported event data is removed within 30 days.

6. Where Your Data Is Stored (Cross-Border Transfers)

Maelo operates globally and uses providers located outside Canada. Your personal information may be stored or processed in the European Union (database hosting), the United States, and other countries via our providers' global infrastructure. While in another country, data may be accessible to that country's courts, law enforcement, and regulators under its laws. We use contractual and technical safeguards (including, where applicable, GDPR Standard Contractual Clauses) to require comparable protection for personal information transferred outside Canada, consistent with PIPEDA and BC PIPA.

7. Data Retention

  • Account and booking data: for the life of your account plus a reasonable period for legal, tax, accounting, and dispute-resolution purposes
  • Payment/transaction records: as required by financial and tax law
  • Technical logs: a limited period for security and diagnostics
  • On account deletion we remove or de-identify personal data across our systems (see data deletion status), except records we must retain by law

8. Security

We protect personal information with administrative, technical, and physical safeguards, including encryption in transit (TLS), encryption at rest for sensitive fields (waiver signatures and calendar tokens), role-based database access, scoped tenant isolation, and bot/abuse protection. No system is perfectly secure, but we work to protect your data and respond quickly if an issue arises.

9. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Withdraw consent to processing or marketing
  • Delete your account and associated personal data
  • Port your data in a portable format
  • Object to / restrict certain processing (GDPR)

We respond to access and correction requests within 30 days (PIPEDA / BC PIPA). To exercise any right, contact our Privacy Officer (Section 14). You may also complain to:

  • the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
  • the Office of the Privacy Commissioner of Canada (OPC)
  • your EU/EEA Data Protection Authority
  • the UK Information Commissioner's Office (ICO)

10. Marketing and Unsubscribe (CASL)

Every marketing email includes an unsubscribe link. You can also email privacy@maelo.app with "Unsubscribe" in the subject. We process opt-outs promptly (within 10 business days as required by CASL). Transactional messages necessary to a booking are not marketing and may still be sent.

11. Cookies and Analytics

We use strictly necessary cookies for authentication and security, and privacy-respecting analytics to understand and improve the Service. We use Cloudflare Turnstile for bot protection. Where required, we obtain consent for non-essential cookies/analytics.

12. Artificial Intelligence

Maelo includes a small number of optional AI features. Every one of them runs on Cloudflare Workers AI, the AI service built into our hosting provider. We do not send your data to OpenAI, Anthropic, Google, or any other third-party AI provider, and we do not route AI requests through any aggregator, gateway, or model hub.

No Google user data is used with AI

Data obtained from the Google Calendar API is used only to calculate your availability and to write your Maelo bookings into your calendar. It is never sent to an AI model, never included in an AI prompt, and never used to develop, improve, or train any AI or machine-learning model, whether ours, our providers’, or a third party’s.

We do not train models on your data

Cloudflare Workers AI does not retain the inputs we send it and does not use them to train its models. Nothing you enter into Maelo is used to create, improve, or fine-tune any AI or machine-learning model.

Receipt Scanning (OCR)

When an Artist uploads a receipt image for expense tracking, we use a vision AI model on Cloudflare Workers AI (Llama 3.2 Vision) to extract details such as vendor, date, amount, and line items. The image and extracted data are stored in the Artist’s own account.

Page Building Assistance

When an Artist describes the page they want to build, a text model on Cloudflare Workers AI suggests which page components to use, and can generate a background configuration (colours and gradients) from a short text prompt you provide. The only input is the Artist’s own description. No Client information and no calendar data is involved.

Automated Decision-Making (GDPR Article 22)

Our AI features provide suggestions and extracted data only. They do not make automated decisions producing legal or similarly significant effects; all final decisions remain with you.

Retired Features

Maelo previously offered an AI Draft Assistant that suggested replies to Client messages using per-user embeddings of your past messages. This feature was removed in July 2026, together with the stored embeddings and the vector indexes that held them. Maelo no longer creates or stores embeddings of your messages.

13. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

14. Privacy Officer and Contact

We have designated a Privacy Officer at Maelo App Inc. responsible for compliance with this policy and applicable privacy law (PIPEDA / BC PIPA). Contact: privacy@maelo.app (response time: within 30 days).

15. Breach Notification

If a privacy breach occurs that creates a real risk of significant harm, we will notify affected individuals and the OIPC BC / OPC (and applicable EU/UK authorities) as required by law, and keep records of breaches as required.

16. Changes to This Policy

We may update this policy. If we make material changes we will update the "Last Updated" date and, where appropriate or required, notify you by email or in-app, and seek new consent where needed.


© 2026 Maelo. All rights reserved. | Back to Home | Terms of Service