SummaBooking

Privacy Policy

Version 1.3 · Last updated 2026-09-06

*SummaBooking is a product of SummaCore LLC.*

Version: 1.3 Effective date: 2026-09-06 Last updated: 2026-09-06

---

1. Who We Are

SummaCore LLC ("SummaCore", "we", "us") is a Texas limited liability company. We operate SummaBooking, a software-as-a-service room and resource booking platform available at app.summabooking.com (the "Service"). This Privacy Policy also covers the public demonstration environment available at `/demo` (the "Demo Environment"), which is described separately in Section 13.

This Privacy Policy describes how we handle personal information in connection with the Service, the Demo Environment, and our public website. It should be read together with the SummaBooking Subscription Terms and, for the Demo Environment, the Demo Terms. This Policy is a notice describing our practices. It is not a contract, although the Subscription Terms and the Demo Terms refer to it.

Questions: see Section 15.

2. Our Posture — Two Roles

We hold two different roles, depending on what data is at issue:

(a) Account Data, Site and Demo Data, and our own operations. For your account data (your sign-in identity and profile — Section 3.1), for information about your use of our public website and the Demo Environment (Section 13), and for our own operational processing (for example, server logs, Section 3.5), SummaCore is the business responsible for that data. You sign in with your own email address, and you act as yourself when you use these parts of the Service.

(b) Workspace Records. Bookings, room and resource configurations, and the content within them (Sections 3.2 and 3.7) are Workspace Records — they are owned by the organization that runs your Workspace, under the Subscription Terms' Section 5.1 ownership provision. SummaCore processes Workspace Records to provide the Service; your organization administers the Workspace those records live in and is responsible for decisions about them, including who in the Workspace can see or manage a given record.

Most personal data in the Service is submitted by the individual it concerns, with limited exceptions — for example, a free-text booking title may mention someone else's name; see Section 3.2.

If your organization's Workspace admin manages your membership, some requests — for example, removing you from a Workspace, or changing your role — may need to go through your organization rather than directly through us, because your organization controls who belongs to its Workspace and administers the Workspace Records within it. See Section 10.

3. Information We Process

3.1 Account data

3.2 Booking data

Your booking's title and details are visible to you. Other members of your Workspace see only that a time slot is busy — the Service's availability views deliberately do not show them your booking's title or your identity. Workspace admins can manage bookings within the Workspace (for example, cancel one). Booking records, including titles, are part of your organization's Workspace Records — see Section 2(b).

Please avoid putting sensitive personal information about yourself or others in a booking title or other free-text field. Booking titles are stored in your organization's Workspace Records, and another person's name in a title becomes personal data about them — treat a booking title the way you would treat something posted on a shared office calendar.

3.3 Provisioned but not currently offered

The Service's database includes provision for two features that are not currently offered in the product:

Neither feature is currently offered in the product, and no such data is collected today. If either feature ships, this Policy will be updated first to describe what is collected and how it is retained.

3.4 Cookies and similar technologies

The application sets no cookies of its own. Our identity provider's session cookies keep you signed in; a third-party bot-protection widget used in the sign-up flow may set its own cookies or use device signals; and our content delivery and network security provider may set operational security cookies as traffic passes through it. We set no advertising or analytics cookies of any kind. Because we do not track you across other websites or services, browser "Do Not Track" and Global Privacy Control signals have no effect on how the Service operates; we treat every user as if they were set.

3.5 Server logs

3.6 What we do not collect

3.7 Room and resource configuration data

Names, descriptions, capacities, amenity details, and photos or photo links for bookable rooms and resources, provided by your organization's Workspace admins. Photos could include images of identifiable people if an admin uploads one that shows a person. Like booking data, room and resource configuration data is part of your organization's Workspace Records — see Section 2(b). Retention: the life of the Workspace; the Subscription Terms' Section 16.2 clocks apply on termination.

3.8 Workspace invitations

Workspace admins add people to their Workspace by invitation. When an admin enters an email address, the Service stores an invitation record and sends one email to that address, at the admin's request, through our transactional email service (Section 7).

3.9 Billing data

Billing is per Workspace and is managed by the Workspace's admins or owners through the Billing page. When an admin subscribes, they are sent to a checkout page served by our payment processor (Section 7), where they enter the payment card and confirm the recurring charge.

4. Why We Process Information

We process personal information only to:

  1. Provide, operate, secure, and support the Service, including account creation, sign-in, and booking creation, modification, and cancellation;
  2. Show Workspace members when rooms and resources are busy or available, as the Service is designed to do (without showing them another member's booking title or identity — Section 3.2);
  3. Operate the Demo Environment as described in Section 13;
  4. Maintain the security and reliability of the Service, including troubleshooting failed requests;
  5. Operate, secure, and improve the Service, where "improve" uses only the aggregated, de-identified usage statistics described in Section 5; and
  6. Comply with legal obligations.

5. What We Do NOT Do

6. How We Disclose Information

We disclose personal information only to:

7. Service Providers

All Service hosting is in the United States. We use the following categories of service providers (sometimes called "subprocessors") to help us operate the Service:

CategoryWhat it doesRegion
Identity providerAuthentication, session management, and delivery of sign-in code emailsUS
Cloud hosting providerCloud hosting of the application and databaseUS
Content delivery and network security providerNetwork routing and security in front of the application — traffic transits through our network provider; no data is stored at rest thereUS
Bot-protection / CAPTCHA serviceA third-party bot-protection service mounted in the sign-up flowUS
Transactional email serviceDelivery of Workspace invitation emails (Section 3.8). Processes the recipient address and the message content in order to deliver it; open and click tracking are switched offUS
Payment processorPayment processing, subscription billing, invoices and receipts, and the self-serve billing portal (Section 3.9). Card details are entered on, and held by, our payment processorUS
Cloud backup storageEncrypted backup copies of Service data, encrypted before they leave our systems, with keys we holdNorth America (US-based providers)

There are no AI service providers. The Service has no AI features (Section 5).

We describe our providers by category here; the named list is available to Workspace owners and prospective customers on request by email to privacy@summacore.com (Section 15). We will update this Policy before adding a category of provider that handles personal information.

No provider in this table sends email on the Service's behalf other than our identity provider's own authentication email (Section 3.1), our transactional email service's delivery of Workspace invitation emails (Section 3.8), and our payment processor's receipts and payment notices to the billing email address (Section 3.9).

8. Security

We maintain the following with respect to the Service, matching the Subscription Terms' Section 15 description exactly: tenant isolation enforced at the database layer through row-level security tied to each Workspace, so that one Workspace cannot read or write another Workspace's data through the application; encrypted transport (TLS) for data in transit; hosting on infrastructure SummaCore manages and controls; and a least-privilege application account for the Service's database access. SummaCore does not claim any third-party security certification for the Service.

No system is perfectly secure. If we determine that a breach of system security has affected personal information we hold, we will notify affected Customers without unreasonable delay, consistent with the Subscription Terms' Section 6.4, and, where required by law, affected individuals directly — using the most effective available channel, which may include email to the address on your account, in-Service notice, or notice through your organization — consistent with Tex. Bus. & Com. Code § 521.053 and other applicable breach-notification law.

9. Retention and Deletion

10. Your Privacy Rights and Requests

You may have rights to access, correct, or delete your personal information, depending on where you live. We do not currently have self-serve tooling for these requests — the same honest posture as the Subscription Terms' Section 16 for Customer Data generally. To make a request, contact us using the information in Section 15.

A request is subject to your Workspace relationship. A booking is a shared record that belongs to your Workspace, not solely to you — other members rely on it to know a room or resource is unavailable, even though they cannot see its title or your identity (Section 3.2). Leaving or being removed from a Workspace deactivates your account membership (Section 3.1), but Workspace Records your organization's Workspace owns (Section 2(b)) may persist under that organization's control, the same way records on a shared office calendar would.

Response timeframe. We will respond to a privacy request within a reasonable time, generally no more than 45 days after we receive it. If we need longer, we will tell you why and when to expect a response.

Verification. We verify a request using the email address on your account (or another reasonable method if you do not have an account). We may decline a request we cannot verify.

11. State Privacy Laws

11.1 California (CCPA/CPRA)

SummaCore likely does not meet the CCPA's threshold to be a covered "business" at the Service's current scale. Regardless of whether the CCPA applies to us, we do not sell or share personal information, and we do not use it for cross-context behavioral advertising — that commitment is unconditional and does not depend on CCPA coverage.

Regardless of CCPA coverage, we offer every user of the Service the following rights, consistent with CCPA-style practice: the right to know what personal information we hold about you and how we use it; the right to access a copy of it; the right to correct inaccurate personal information; the right to delete it, subject to Section 10's Workspace-relationship limits; the right to be free from discrimination for exercising these rights; and the right to have an authorized agent make a request on your behalf, subject to the verification described in Section 10.

11.2 Texas (TDPSA)

SummaCore likely qualifies for the Texas Data Privacy and Security Act's small-business treatment at the Service's current scale. Regardless of that status, we offer TDPSA-consistent commitments — including never selling personal data — to every user of the Service.

11.3 Texas breach notification

Tex. Bus. & Com. Code § 521.053 applies to the data we hold. We will notify affected users of a breach of system security without unreasonable delay, consistent with applicable law, as described in Section 8.

11.4 Other jurisdictions

The Service is offered in the United States and is not directed to individuals in the European Union, European Economic Area, or United Kingdom.

12. Children

The Service is for users 18 and older and is not directed to children, matching the Subscription Terms' Section 1.3 and the Demo Terms. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

13. The Public Demo

The Demo Environment at `/demo` works differently from the rest of the Service, and this section describes it on its own. It should be read together with the Demo Terms, which govern your use of the Demo Environment and control if there is any conflict with this section.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy at this address with a new "Last updated" date and, for significant changes, take reasonable steps to notify Workspace administrators.

This Section does not apply to the Demo Environment. The version of this Policy — and of the Demo Terms — posted at the demo gate at the time you use the demo governs your use of the demo, as the Demo Terms describe.

15. Contact

SummaCore LLC 5900 Balcones Drive, Ste 100 Austin, Texas 78731 Email: privacy@summacore.com

If you are a member of an organization's Workspace, see Section 2 — some requests may need to go through your organization.

---

*SummaBooking is a product of SummaCore LLC.*