Aviso de Privacidad / Privacy Policy
Este aviso se publica y rige en inglés. Si reservaste una cita con un negocio que usa Plaza, el Aviso al cliente resume en español lo que más te afecta, y la lista de subprocesadores está en /subprocessors.
Audience: everyone — the businesses that subscribe to Plaza, the clients of those businesses, and anyone who visits our website or a booking page we host.
This Policy is a notice. It is not part of the Platform Terms of Service and updating it does not amend that contract (see Platform Terms of Service §1.5).
Read this first if you booked an appointment. If you gave your information to a salon, barbershop, auto shop or other business that uses Plaza, that business decides what happens to your information — not us. We run the software it uses. Section 1 explains the difference, and Section 11 explains who to contact. A short Spanish-first version of this is shown to you on the booking page itself (Customer Notice).
1. Who we are, and the two different roles we play
Techne Studios LLC, a New Jersey single-member limited liability company at 59 2nd Ave, Unit 374, Raritan, NJ 08869, operates Plaza (also called "Techne Studios CRM") at crm.technestudios.net.
We handle personal information in two distinct roles, and almost every question about your rights depends on which one applies.
| Tenant Account Data | Customer Data | |
|---|---|---|
| Whose information | The business that subscribes to Plaza, and the person who signs it up | The business's own clients, and its staff |
| Our role | Controller ("business" under California law) | Processor ("service provider") |
| Who decides what happens to it | We do | The business does |
| Governed by | This Policy | This Policy plus our Data Processing Addendum (Data Processing Addendum) and the business's own privacy notice |
| Who you contact about rights | privacy@technestudios.net | The business. We will forward and assist — Section 11.4 |
We call the subscribing business a Business below, and its client an End Customer.
We are not a marketplace and we do not have consumers of our own. We do not operate a consumer-facing app, we do not build a cross-business profile of any End Customer, and an End Customer does not have a Plaza account with us. A booking-page visitor's information belongs to the Business whose page they visited.
2. What information we handle
2.1 As controller — Tenant Account Data
- Business identity and contact: business name, legal entity name, address, phone, email, business type, and time zone.
- Account and login: the account owner's name and email, authentication records, and session information.
- Subscription and billing: plan, subscription state, payment status, invoices, and the last four digits and expiry of the card used to pay us (held by Stripe; we never receive the full number).
- Support and correspondence: what you write to us, and our replies.
- Operational logs: IP address, browser and device information, timestamps, error and audit records, and rate-limiting records generated when you use the Service. We treat these as ours, generated by our own infrastructure to keep the Service running and secure.
2.2 As processor — Customer Data
We process, on the Business's instructions, whatever the Business collects:
- Client records: name, phone number, email, appointment history, service preferences, and free-text notes the Business writes.
- Booking information: requested service, staff member, date and time, and anything typed into the booking form.
- Consent records: the exact wording shown, how consent was given, when, and by which method (Section 6).
- Message records: the appointment and marketing messages sent, delivery status, and inbound replies including STOP and HELP.
- Commercial records: sales, tickets, tips, deposits, refunds, gift-card issuance and redemption, and loyalty balances.
- Staff records: the Business's staff names, contact details, roles and capabilities, and schedules.
- Custom form content. A Business can build its own intake or consent forms. We do not control, review, or restrict what a Business asks in its own form. Depending on the Business's questions, those fields may contain health-adjacent or otherwise sensitive free text. That is the Business's choice, the Business's responsibility, and the Business's data (Platform Terms of Service §9.4).
3. Why we process information
As controller (Tenant Account Data): to create and operate accounts; to charge subscription fees and manage billing; to provide support; to secure the Service, prevent abuse and fraud, and enforce our Terms and Acceptable Use Policy; to send service and administrative messages; to comply with law; and to establish, exercise or defend legal claims.
As processor (Customer Data): only to provide the Service to the Business — running its booking page, calendar, client records, checkout, deposits, gift cards, receipts and messaging; keeping the data secure and backed up; providing support at the Business's request; and complying with law.
What we never do with Customer Data: we do not sell it; we do not share it for cross-context behavioral advertising; we do not use it to build profiles for our own purposes; we do not use it to train artificial-intelligence models; and we do not use it for any purpose outside the Business's instructions and our legal obligations (Platform Terms of Service §9.5).
4. Who we share information with — our subprocessors
We use a small number of vendors to run the Service. Each is bound to process personal information only for us, and each is listed here because naming them is more useful than a category list. Our current list is also published, with dates, at crm.technestudios.net/subprocessors.
| Vendor | What it does for us | What it handles |
|---|---|---|
| Stripe | Payment processing and subscription billing; Connect accounts for Businesses | Payment and card data (held by Stripe, not by us), payer identifiers, transaction records |
| Supabase | Database, authentication and file storage | Substantially all Tenant Account Data and Customer Data |
| Twilio | SMS sending and receiving over a toll-free number | Phone numbers, message contents, delivery and opt-out records |
| Google Workspace | Business email and the service account used to send transactional mail and receipts | Email addresses and message contents |
| Resend | Transactional email delivery | Email addresses and message contents |
| Cloudflare | Hosting, content delivery, scheduled jobs, and network protection | Network traffic, IP addresses, request metadata |
| Anthropic | The in-app and booking-page AI assistant | The text a user types into the assistant, including text typed by an End Customer (Section 9) |
Optional, only if a Business connects them: QuickBooks Online (accounting export) and Google Calendar (calendar synchronization). These run only where the Business has authorized them and only for the data the Business directs.
We also disclose information to professional advisers under confidentiality; to a party in a merger, acquisition or sale of assets (with notice, and subject to this Policy); and where required by law, legal process, or to protect rights and safety. We do not sell personal information, and we do not share it for cross-context behavioral advertising, in any jurisdiction, under any definition.
Advance notice of new subprocessors. Before we add a new subprocessor that processes Customer Data, we will update the subprocessors page and email the Business's account address, and we will do so at least 30 days before the new vendor begins processing, except where a change is required urgently for security or continuity — in which case we will notify as soon as we reasonably can. A Business's objection rights are in Data Processing Addendum §3.
5. Email
We send email to Businesses (account, billing and service notices, and support replies) and, on a Business's behalf, to its End Customers (appointment confirmations, changes, reminders, receipts, and portal sign-in links). Transactional email to End Customers is sent because the Business asked us to send it as part of the transaction the customer entered into. Any promotional email a Business sends is that Business's own program, and the Business is responsible for CAN-SPAM compliance including a working unsubscribe.
6. Text messages (SMS) and consent records
Full detail is in Messaging Program Terms. The essentials:
6.1 Two separate consents, neither pre-checked, and marketing never required. On a Business's booking page, a customer sees two separate checkboxes, both unchecked by default:
- transactional messages about the appointment itself (confirmations, changes, reminders) — optional, and offered at booking because they are about the appointment itself; leaving the box unchecked does not prevent you from booking; and
- marketing messages (offers and promotions) — entirely optional, never required, and never bundled with the first. Consent to marketing is never a condition of booking or of any service.
6.2 We keep an exact record of what you agreed to. Consent is stored as an append-only event log. Each event records the exact wording shown on screen, how consent was given, and when. Records are never edited in place; the current state is the most recent event. This is deliberate: it is the evidence that a message sent to you was one you asked for.
6.3 Stopping messages. Reply STOP (or STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE, OPTOUT) to any message and we stop. Reply HELP (or INFO, AYUDA) for contact information. Because the toll-free number is shared across all businesses that use Plaza, a STOP sent to it stops both appointment and marketing messages from every business that texts you from that number. You will receive one confirmation of the stop.
6.4 Starting again is deliberately narrow. Replying START (or UNSTOP, YES, UNPAUSE, RESUME) resumes appointment messages only. It does not restore marketing consent. Marketing consent can be granted only at the booking-form checkbox, which carries the full disclosure and is tied to the phone number itself. The "Mis citas" customer portal is revoke-only: you can turn marketing off there, but not back on. That is a design decision, not a limitation we intend to remove.
6.5 Consent records are never sold or shared. Mobile opt-in information, phone numbers collected for SMS, and consent records are never sold, rented, or shared with any third party for marketing purposes, and are never disclosed to any third party except the subprocessors in Section 4 that are strictly necessary to deliver the message. We treat consent records as evidence, and we protect them accordingly.
6.6 Carriers. Messages are delivered by Twilio and by wireless carriers we do not control. Carriers may delay, filter or fail to deliver messages and are not liable for it. Message and data rates may apply.
7. How long we keep information, and what deletion actually does
7.1 While the account is open. We keep Customer Data for as long as the Business keeps it, because the Business decides. We keep Tenant Account Data for as long as the account is open and afterward as described below.
7.2 Account deletion by a Business. The Service includes a deletion function that a Business's owner can run on its own account. When it runs:
- Day 0 — hard erasure of personal information. Names, contact details, notes, message contents, and stored third-party integration tokens for the Business's customers and staff are erased immediately. This is deletion, not flagging.
- Seven years — de-identified financial and tax records. Sales, refunds, payouts, gift-card and loyalty ledgers, and deposit charges are retained in de-identified form, because tax and financial-record obligations require them. A daily scheduled job hard-purges them once the seven-year period expires.
- Consent records survive. Records of SMS and messaging consent are deliberately excluded from erasure and are retained after the rest is gone. We keep them because they are the proof that a message sent to a person was lawfully sent to that person, and destroying that proof would leave both the Business and us unable to answer a complaint. They are protected by an append-only control that the deletion path must explicitly bypass.
7.3 Deletion is irreversible. We cannot restore a deleted account.
7.4 Sign-in credentials and tokens. Separately from account deletion, a scheduled job purges credential records — the booking-page recognition token, customer portal sessions, portal sign-in rate records, calendar-feed tokens, and other portal tokens — 30 days after each record becomes dead (expired, revoked, or used up, depending on the record). This runs continuously in the background.
7.5 Our own records. We keep Tenant Account Data, billing records and correspondence for as long as needed for the account, then for the period required by tax, accounting, and limitations law, and to establish or defend legal claims.
8. Payments
Payments run on Stripe. Each Business connects and controls its own Stripe account, and every charge, deposit, refund and payout for that Business's customers happens on that account. The Business — not Techne — is the merchant of record for those transactions (Platform Terms of Service §6).
Card details are entered into Stripe's own payment form and go to Stripe. Full card numbers never reach Plaza's servers and are never stored by us. We see identifiers, amounts, status, and the last four digits. Stripe processes payment information as its own controller under Stripe's privacy policy, and Stripe's own anti-fraud tools run on its payment form.
We do not claim PCI-DSS, SOC 2, HIPAA, or ISO certification. The statement above is a description of how the system is built, not a certification.
9. AI-assisted features
The Service includes an AI assistant, available inside the application and on booking pages. Text a person types into the assistant — including text an End Customer types on a booking page — is sent to Anthropic to generate a reply. Anthropic processes it as our subprocessor, and under our agreement with Anthropic that input is not used to train models.
Do not type payment card numbers, government identifiers, or medical detail into the assistant. AI-generated replies can be wrong; prices, availability, and policy statements should be confirmed with the business directly.
10. Cookies and similar technologies
We do not use advertising cookies, analytics cookies, session-replay tools, or social-media tracking cookies, and we have no advertising or analytics tracker on any Plaza surface. That is why there is no cookie banner: there is nothing here to consent to. It is also why the table below says, for each cookie, what it actually does rather than calling all of them "strictly necessary." Most are necessary to sign you in or take a payment. Two are not: they are a convenience for a returning customer, and everything works without them.
Where they live. Every cookie in the table is stored under this site's own address (first-party), except the last two rows, which are set on other companies' domains inside Stripe's payment form.
| Cookie | Set by | What it does, and whether it is necessary | Approximate life |
|---|---|---|---|
plz_rec | Plaza; HTTP-only, so no script can read it | Convenience, not necessary. Recognizes a returning customer on one specific business's booking page so they do not retype their details. Scoped to that business's page path. Booking works without it. | ~180 days |
plz_rec_m | Plaza; readable by the page's own scripts | Convenience, not necessary. A content-free marker whose entire value is the character 1, telling the page that a recognition cookie exists. Holds no personal information. | ~180 days |
plz_sess | Plaza; HTTP-only | Necessary. Keeps a customer signed in to the "Mis citas" portal after a sign-in link. Path-scoped per business. Its life is fixed at sign-in and is not extended by continued use. | 90 days |
plz_mfa_dev | Plaza; HTTP-only | Necessary. Set only when a signed-in owner or staff member chooses "remember this device" after entering an emailed verification code, so that browser can skip the code next time. Its life is fixed at the moment it is set and is not extended by use. It is cleared when they turn email verification off or reset their password. | 30 days |
sb-…-auth-token | Supabase | Necessary. Keeps a Business's owner or staff signed in to the application. It is a persistent cookie, not a browser-session one: it survives closing the browser, and the application's own scripts in your browser can read it, which is how the app restores your session. | Up to ~400 days (about 13 months) |
__stripe_mid | Stripe's script, stored under this site's address | Necessary for payment. Stripe's fraud prevention on the payment form. First-party and host-only — your browser files it under this site's address, not under stripe.com. | ~1 year |
__stripe_sid | Stripe's script, stored under this site's address | Necessary for payment. The same fraud prevention, for the current payment session. First-party and host-only. | ~30 minutes |
m | Stripe, on m.stripe.com | Necessary for payment. Stripe's own fraud-prevention identifier, set on Stripe's domain. | Set by Stripe |
__cf_bm | Cloudflare, on .hcaptcha.com, for hCaptcha (Intuition Machines, Inc.) | Necessary for payment. Cloudflare Bot Management for the invisible anti-bot check that Stripe's payment form loads inside its own frame. We do not send them anything; they see only what Stripe's fraud check collects there. | Set by those providers |
Stripe's cookies and its embedded anti-bot check load only at the payment step of a booking — not when the booking page opens, and not before. A customer who books without paying a deposit never loads them, and the last four rows above never exist for that customer.
A cookie for one sign-in. When an owner or staff member signs in with Google, or opens an emailed sign-in link that was issued the older way, the browser stores a sb-…-code-verifier cookie that exists only to finish that one sign-in. It is deleted when that sign-in completes. If a sign-in is abandoned — the Google screen closed, the emailed link never opened — nothing deletes it at that moment: it simply sits there unused, holding no session and signing nobody in, until the next sign-in attempt replaces it or it expires, on the same schedule as the sb-…-auth-token row above (up to ~400 days).
Similar technologies — what stays on your device
The application also keeps three small preferences in your browser's own storage. These are not cookies: they are never sent to us, they never leave your device, and they hold no personal information. All three exist only inside the staff-and-owner application, never on a booking page.
| Key | Stored in | What it holds |
|---|---|---|
plaza-theme | localStorage | Light, dark, or "match my system" appearance. |
plaza-locale | localStorage | Spanish or English for the application's own interface. |
plaza.mfaNudgeDismissed | sessionStorage | That a reminder to turn on two-step sign-in was dismissed for this browser session. |
We use no other browser storage: no IndexedDB, no local database, no device fingerprinting, and no session recording or replay.
Do Not Track and Global Privacy Control. We do not track you across other websites, we set no advertising or analytics cookie anywhere, and we do not sell personal information or share it for cross-context behavioral advertising. Because of that, a browser's Do Not Track (DNT) header or a Global Privacy Control (GPC) signal does not change how this site behaves — not because we ignore it, but because the behavior it asks us to stop is behavior we never perform. If we ever introduce a tracker that would make such a signal meaningful, we will honor the signal, and we will update this Policy before introducing it.
11. Your privacy rights
11.1 If you are a Business (our subscriber). Contact privacy@technestudios.net to access, correct, delete, or receive a copy of your Tenant Account Data, or to object to or restrict processing. We will verify your identity as the account owner and respond within the period required by applicable law.
11.2 If you are an End Customer. The business you booked with decides what happens to your information. Contact that business. It is the controller. Its name, address and contact details are on its booking page and on any message or receipt you received.
11.3 What you can do yourself, right now. Regardless of who the controller is, you can, from any message or from the "Mis citas" portal: stop messages by replying STOP; turn marketing off in the portal's consent preferences; view and manage your appointments; and use the portal's account-deletion function where the business has enabled it.
11.4 If you contact us instead. If an End Customer sends us a rights request, we will not act on it as a controller, because we are not one for that data. We will promptly forward it to the business and give the business the tools and assistance it needs to answer it, as required by Data Processing Addendum §5. We will tell you we have done so.
11.5 California (CCPA/CPRA). For Customer Data we act as a service provider and process it only under the Business's written instructions and only for the business purposes specified in our Data Processing Addendum. We do not sell or share personal information and have not in the preceding 12 months. We do not use or retain personal information for any purpose other than performing the services, and not outside our direct relationship with the Business. Where we are a business (Tenant Account Data), a California subscriber may exercise rights of access, deletion, correction, portability, and non-discrimination by writing to privacy@technestudios.net.
11.6 New Jersey (NJDPA) and other state privacy laws. New Jersey residents, and residents of other states with comprehensive privacy laws, have rights to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sell personal data, or profile individuals for decisions producing legal or similarly significant effects. For Tenant Account Data, write to privacy@technestudios.net; if we deny a request you may appeal by replying to our decision, and we will respond to the appeal, and you may complain to the New Jersey Division of Consumer Affairs. For Customer Data, contact the business (Section 11.2). Sensitive data — including health-adjacent information a business may collect in its own custom forms — is processed only on the business's instruction; the business is responsible for obtaining any required consent.
11.7 No discrimination. We do not deny service, charge a different price, or provide a different quality of service because a person exercised a privacy right.
12. Security, honestly stated
We use measures appropriate to a service of our size: encryption of data in transit; row-level access controls in the database so one business's data is not reachable by another; capability-gated permissions inside each account; hashed and short-lived sign-in tokens; scheduled purging of dead credentials; append-only ledgers for consent and gift-card value; and card handling delegated entirely to Stripe so card numbers never reach our systems.
What we will not say: we do not hold any security certification, we do not describe our security as "bank-level" or "military-grade," and we do not represent that the Service cannot be breached. No system is secure against every attack.
If a security incident affects personal information, we will notify affected Businesses without undue delay and as required by applicable law, with what we know at the time and what we are doing about it. We deliberately do not promise a fixed number of hours: Plaza is operated by one person, and a deadline we could not reliably meet would be a promise worth less than the honest statement.
13. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from a child under 13, and a Business must not use the Service to collect information from children under 13 without the consent required by law. If we learn we hold such information without a lawful basis, we will delete it. A Business that serves minors is responsible for parental consent and for the record of it.
14. Where information is processed
Techne Studios LLC is in the United States, and our vendors process information in the United States and, for some vendors, in other countries where they operate. We do not currently offer the Service in the European Economic Area or the United Kingdom and do not rely on Standard Contractual Clauses. If that changes, we will implement an appropriate transfer mechanism and update this Policy before doing so.
15. Changes to this Policy, and how to reach us
We may update this Policy. The version and "Last updated" date at the top always reflect the current version. If we make a material change, we will notify Businesses by email to the account address before it takes effect. Because this Policy is a notice and not a contract term, an update does not amend the Platform Terms of Service.
Techne Studios LLC — operator of "Plaza"
59 2nd Ave, Unit 374, Raritan, NJ 08869, United States
Privacy and data rights: privacy@technestudios.net
Legal notices: legal@technestudios.net · Abuse: abuse@technestudios.net · Support: soporte@technestudios.net
Related: Platform Terms of Service (the contract) · Data Processing Addendum (our processor obligations) · Messaging Program Terms (messaging in full) · Customer Notice (the short Spanish-first notice shown at booking).