← Back to Stund

Privacy Policy

Last updated: 12 July 2026

Stund is booking and scheduling software provided by Sagen Software AS, org.nr 931 235 362, Høymyrmarka 85, 1391 Vollen, Norway (“Stund”, “we”, “us”). This policy explains what personal data we process, why, who we share it with, how long we keep it, and the rights you have under the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

Two roles: controller and processor

Stund serves two kinds of people, and our role differs for each:

  • Organizers — the businesses and people who sign up to run bookings. For their account and platform-usage data, Stund is the data controller.
  • Bookers & customers — the people who book, buy a package, or borrow equipment through an organizer. For that data, the organizer is the controller and Stund is a processor acting on their instructions. If you booked with a specific business, that business decides how your data is used; contact them first, and we will support them (and you) in handling the request.

Data we process

  • Organizer accounts: name, email, password (stored only as a bcrypt hash), profile image, locale, and — for social login — Google account identifiers and OAuth tokens. Sessions store IP address and browser user-agent for security.
  • Organization & billing: organization details, contact email, subscription/plan, and payment-processor account identifiers. We do not store card numbers.
  • Bookers & customers: name, email, phone number (if provided), booking details, notes, answers to any custom questions the organizer configures, attendee counts, terms-acceptance records, equipment-checkout details, and payment status. Card and wallet payment details are handled directly by our payment processors and are never stored by us.
  • Communications: a log of the confirmations, reminders, and other notifications we send you (recipient, type, delivery status, timestamps).
  • AI assistant: if you use the booking chat assistant, the messages you send are processed by Google’s Gemini models to generate a reply (see Subprocessors).
  • Usage data: product analytics via PostHog, collected server-side. We remove direct identifiers such as names, notes, and emails from the event details before sending, but each event carries a distinct identifier so a person’s activity can be correlated — for booking-related events this identifier is the booker’s email address.

Why we process it (legal bases)

  • To perform the contract (GDPR Art. 6(1)(b)): operating bookings, processing payments, syncing calendars, and sending transactional messages such as confirmations, reminders, cancellations, and payment receipts.
  • Legal obligation (Art. 6(1)(c)): keeping accounting and tax records for payments.
  • Legitimate interests (Art. 6(1)(f)): securing accounts, preventing fraud and abuse, and improving the product through minimized analytics.
  • Consent (Art. 6(1)(a)) where required, e.g. optional SMS notifications. You can withdraw consent at any time.

We do not sell personal data, and we do not use it for third-party advertising.

Subprocessors

We share data only with service providers needed to run Stund, each bound by a data processing agreement:

  • Stripe — card payments and platform subscription billing.
  • Vipps MobilePay — wallet payments and booker sign-in.
  • Twilio — SMS notifications (only when an organizer enables them).
  • Resend — transactional and account emails.
  • Google — sign-in for organizers, two-way Google Calendar sync (when connected), and the Gemini AI models that power the assistant.
  • Vercel — application hosting and file/image storage (Vercel Blob).
  • Neon — managed PostgreSQL database.
  • PostHog — minimized product analytics.

International transfers

Some subprocessors (for example Stripe, Twilio, Google, and PostHog) may process data outside the EU/EEA, including in the United States. Where they do, transfers are covered by the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

Cookies

We use only first-party, strictly necessary and functional cookies: a secure session cookie to keep you signed in, and preference cookies that remember your language and currency. We do not use third-party advertising or cross-site tracking cookies, so no consent banner is required.

Retention

We keep account, booking, and payment records for as long as needed to provide the service and to meet legal and accounting obligations (payment records are typically retained for the statutory bookkeeping period). After that, data is deleted or anonymized. Notification and audit logs are kept for a limited period for security and support.

Your rights

You have the right to access, correct, export (data portability), and delete your personal data, to restrict or object to processing, and to withdraw consent. To exercise any of these — including a booker asking to delete their booking data — email privacy@stund.net. We respond within 30 days. Where an organizer is the controller of your booking data, we will forward your request to them and assist as their processor.

You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or your local EU/EEA supervisory authority.

Changes

We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above.

Contact

Privacy questions or requests: privacy@stund.net. General support: support@stund.net.