Privacy Policy
Version 1.3 · Last updated 2026-09-06
*SummaBooking is a product of SummaCore LLC.*
Version: 1.3 Effective date: 2026-09-06 Last updated: 2026-09-06
---
1. Who We Are
SummaCore LLC ("SummaCore", "we", "us") is a Texas limited liability company. We operate SummaBooking, a software-as-a-service room and resource booking platform available at app.summabooking.com (the "Service"). This Privacy Policy also covers the public demonstration environment available at `/demo` (the "Demo Environment"), which is described separately in Section 13.
This Privacy Policy describes how we handle personal information in connection with the Service, the Demo Environment, and our public website. It should be read together with the SummaBooking Subscription Terms and, for the Demo Environment, the Demo Terms. This Policy is a notice describing our practices. It is not a contract, although the Subscription Terms and the Demo Terms refer to it.
Questions: see Section 15.
2. Our Posture — Two Roles
We hold two different roles, depending on what data is at issue:
(a) Account Data, Site and Demo Data, and our own operations. For your account data (your sign-in identity and profile — Section 3.1), for information about your use of our public website and the Demo Environment (Section 13), and for our own operational processing (for example, server logs, Section 3.5), SummaCore is the business responsible for that data. You sign in with your own email address, and you act as yourself when you use these parts of the Service.
(b) Workspace Records. Bookings, room and resource configurations, and the content within them (Sections 3.2 and 3.7) are Workspace Records — they are owned by the organization that runs your Workspace, under the Subscription Terms' Section 5.1 ownership provision. SummaCore processes Workspace Records to provide the Service; your organization administers the Workspace those records live in and is responsible for decisions about them, including who in the Workspace can see or manage a given record.
Most personal data in the Service is submitted by the individual it concerns, with limited exceptions — for example, a free-text booking title may mention someone else's name; see Section 3.2.
If your organization's Workspace admin manages your membership, some requests — for example, removing you from a Workspace, or changing your role — may need to go through your organization rather than directly through us, because your organization controls who belongs to its Workspace and administers the Workspace Records within it. See Section 10.
3. Information We Process
3.1 Account data
- Your email address and display name, as verified and held by our identity provider and refreshed in our database each time you sign in, together with your status within each Workspace you belong to and a last-seen timestamp.
- Your role (member, admin, or owner) within each Workspace. Roles are stored and administered in our own database, not with our identity provider: a role is set when you create a Workspace (owner), when you accept an invitation (the role the inviting admin chose), or when a Workspace admin changes it. This stored role is the value the Service's access-control decisions are made against. Our identity provider holds no role or Workspace information for the Service.
- Your identity-provider user ID, which links your sign-in identity to your Workspace membership records. Workspaces are identified by an internal Workspace key; the Service does not use organization objects from the identity provider.
- Sign-in is handled entirely by our identity provider (see Section 7), using passwordless email-code authentication. Our identity provider sends the sign-in code email itself; the application sends no sign-in or authentication email of its own. The only email the application itself sends is the Workspace invitation email described in Section 3.8, delivered through our transactional email service. This describes the technical design — it does not limit SummaCore the company from sending you other notices (for example, under Section 8 or Section 14) through other channels, such as email to the address on your account, in-Service notice, or notice through your organization.
- If you are removed from a Workspace, your mirrored account row is marked inactive (deactivated) in our database rather than being immediately and permanently erased. See Section 9 for how long a deactivated row is kept before deletion.
3.2 Booking data
Your booking's title and details are visible to you. Other members of your Workspace see only that a time slot is busy — the Service's availability views deliberately do not show them your booking's title or your identity. Workspace admins can manage bookings within the Workspace (for example, cancel one). Booking records, including titles, are part of your organization's Workspace Records — see Section 2(b).
- Reservation title, attendee count, start and end times, and a link to the account that made the booking.
- The reservation title is a free-text field you write yourself, and it is the one field in this category that can carry personal or sensitive content — everything else is structured (times, counts, an account link).
Please avoid putting sensitive personal information about yourself or others in a booking title or other free-text field. Booking titles are stored in your organization's Workspace Records, and another person's name in a title becomes personal data about them — treat a booking title the way you would treat something posted on a shared office calendar.
3.3 Provisioned but not currently offered
The Service's database includes provision for two features that are not currently offered in the product:
- Organization join requests — a record that could hold your email address if you requested to join a Workspace before you had an account.
- Booking check-ins — a record associated with checking in to a booking.
Neither feature is currently offered in the product, and no such data is collected today. If either feature ships, this Policy will be updated first to describe what is collected and how it is retained.
3.4 Cookies and similar technologies
The application sets no cookies of its own. Our identity provider's session cookies keep you signed in; a third-party bot-protection widget used in the sign-up flow may set its own cookies or use device signals; and our content delivery and network security provider may set operational security cookies as traffic passes through it. We set no advertising or analytics cookies of any kind. Because we do not track you across other websites or services, browser "Do Not Track" and Global Privacy Control signals have no effect on how the Service operates; we treat every user as if they were set.
3.5 Server logs
- Our hosting server's application error logs may capture technical details of failed requests (for example, error type, timestamp, and request path) for operational troubleshooting. We do not perform any request-level logging of user activity — there is no feature in the Service today that records a running log of what a given user did.
- We have not completed an audit of whether error-log payloads can incidentally capture personal data (for example, an email address embedded in a failed request). We do not represent that these logs are free of personal data; we retain them for operations and troubleshooting as described in Section 9.
3.6 What we do not collect
- Payment card details. We never see or store your card number, expiry, security code, or bank details. They are entered directly into pages served by our payment processor, and are held by our payment processor under its own privacy policy. What we do keep about billing is described in Section 3.9.
- No data used for or generated by any AI feature. The Service does not currently have any AI-assisted feature.
3.7 Room and resource configuration data
Names, descriptions, capacities, amenity details, and photos or photo links for bookable rooms and resources, provided by your organization's Workspace admins. Photos could include images of identifiable people if an admin uploads one that shows a person. Like booking data, room and resource configuration data is part of your organization's Workspace Records — see Section 2(b). Retention: the life of the Workspace; the Subscription Terms' Section 16.2 clocks apply on termination.
3.8 Workspace invitations
Workspace admins add people to their Workspace by invitation. When an admin enters an email address, the Service stores an invitation record and sends one email to that address, at the admin's request, through our transactional email service (Section 7).
- What an invitation record holds: the invited email address, the role the admin chose (member or admin), which admin sent it (their display name or email address, which also appears in the email so the recipient knows who asked for them to be added), when it was sent, when it expires (14 days after sending), and whether and when it was accepted or revoked. The one-time link in the email is stored only as a cryptographic hash; the link itself is never stored, logged, or shown anywhere after the email is sent.
- What the email is, and is not: it is a transactional message sent at a named admin's request, naming the Workspace and the admin, with one link to accept. It contains no marketing, no tracking pixel, and no tracked links (open and click tracking are switched off for the Service's sending domain), and it is not followed by reminders. Nothing happens unless the recipient accepts. A recipient who does not want invitations from SummaBooking can reply to the email and we will stop sending to that address.
- If you receive an invitation and never accept it: your email address stays in the invitation record until the retention period in Section 9 ends and is then deleted. You never become a User, no account is created for you, and no other information about you is collected.
- Accepting: an invitation can only be accepted by signing in with an email address verified by our identity provider that matches the invited address. Accepting creates your membership record in that Workspace (Section 3.1) and marks the invitation accepted.
- Who can see invitations: the Workspace's admins and owners (pending, expired, and revoked invitations, with the invited address and role). Invitation records are part of the organization's Workspace Records (Section 2(b)); the tenant audit log (Section 9) records that an invitation was sent, re-sent, revoked, or accepted, and records membership and role changes.
3.9 Billing data
Billing is per Workspace and is managed by the Workspace's admins or owners through the Billing page. When an admin subscribes, they are sent to a checkout page served by our payment processor (Section 7), where they enter the payment card and confirm the recurring charge.
- What our payment processor processes for us: the card and any billing address it collects, the subscribing admin's email address, invoices, receipts, and payment events. Our payment processor acts on our instructions for these purposes; its own privacy policy also applies to data it collects directly on its pages.
- What we store: our payment processor's identifiers for the Workspace's customer and subscription records, the subscription's status (for example active, past due, canceled), the billing email address (the admin who subscribed), the current billing period's end date, and whether cancellation at the end of the period has been requested. We also record, in the Workspace's audit log, that a checkout was started, that the recurring-charge consent was given (with the checkout session identifier), and that a payment failed. We store no card numbers.
- Room counts: the number of active rooms in a Workspace is sent to our payment processor as a quantity so the subscription reflects the price model (Subscription Terms Section 3.2). No room names or booking data are sent.
- Who sees it: the Workspace's admins and owners, on the Billing page and in the billing portal our payment processor hosts (invoices, card on file). Members do not see billing data.
- Emails about billing: our payment processor sends receipts and failed-payment notices to the billing email address at our direction; these are transactional messages about your subscription, not marketing.
4. Why We Process Information
We process personal information only to:
- Provide, operate, secure, and support the Service, including account creation, sign-in, and booking creation, modification, and cancellation;
- Show Workspace members when rooms and resources are busy or available, as the Service is designed to do (without showing them another member's booking title or identity — Section 3.2);
- Operate the Demo Environment as described in Section 13;
- Maintain the security and reliability of the Service, including troubleshooting failed requests;
- Operate, secure, and improve the Service, where "improve" uses only the aggregated, de-identified usage statistics described in Section 5; and
- Comply with legal obligations.
5. What We Do NOT Do
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use personal information for advertising of any kind.
- We do not use any first-party or third-party analytics or tracking technology. This does not prevent SummaCore from generating aggregated, de-identified usage statistics to operate, secure, and improve the Service (Section 4); such statistics never identify Customer, its Workspace, or any individual, consistent with the Subscription Terms' Section 5.4.
- We do not collect payment card data ourselves — our payment processor does, on pages it serves; see Sections 3.6 and 3.9.
- The Service has no AI features, and SummaCore does not use personal data or Customer Data to train, tune, or improve any AI model, and does not permit any third party to do so — this mirrors the Subscription Terms' Section 5.3 commitment exactly, and applies regardless of whether an AI feature is ever added.
6. How We Disclose Information
We disclose personal information only to:
- Service providers listed in Section 7, strictly to provide the Service;
- Other members of your Workspace, who see only that a room or resource is busy at a given time — not your booking's title or your identity (Section 3.2) — and whose Workspace admins can manage membership and bookings as described in Section 2;
- Other demo visitors, for content entered in the public demo, as the Demo Terms explain — see Section 13;
- Professional advisers (lawyers, accountants) under confidentiality obligations, where necessary;
- Authorities or litigants when required by law, subpoena, or court order — we will challenge overbroad demands where reasonable;
- A successor entity in a merger, acquisition, or sale of assets, subject to this Policy's commitments continuing to apply.
7. Service Providers
All Service hosting is in the United States. We use the following categories of service providers (sometimes called "subprocessors") to help us operate the Service:
| Category | What it does | Region |
|---|---|---|
| Identity provider | Authentication, session management, and delivery of sign-in code emails | US |
| Cloud hosting provider | Cloud hosting of the application and database | US |
| Content delivery and network security provider | Network routing and security in front of the application — traffic transits through our network provider; no data is stored at rest there | US |
| Bot-protection / CAPTCHA service | A third-party bot-protection service mounted in the sign-up flow | US |
| Transactional email service | Delivery of Workspace invitation emails (Section 3.8). Processes the recipient address and the message content in order to deliver it; open and click tracking are switched off | US |
| Payment processor | Payment processing, subscription billing, invoices and receipts, and the self-serve billing portal (Section 3.9). Card details are entered on, and held by, our payment processor | US |
| Cloud backup storage | Encrypted backup copies of Service data, encrypted before they leave our systems, with keys we hold | North America (US-based providers) |
There are no AI service providers. The Service has no AI features (Section 5).
We describe our providers by category here; the named list is available to Workspace owners and prospective customers on request by email to privacy@summacore.com (Section 15). We will update this Policy before adding a category of provider that handles personal information.
No provider in this table sends email on the Service's behalf other than our identity provider's own authentication email (Section 3.1), our transactional email service's delivery of Workspace invitation emails (Section 3.8), and our payment processor's receipts and payment notices to the billing email address (Section 3.9).
8. Security
We maintain the following with respect to the Service, matching the Subscription Terms' Section 15 description exactly: tenant isolation enforced at the database layer through row-level security tied to each Workspace, so that one Workspace cannot read or write another Workspace's data through the application; encrypted transport (TLS) for data in transit; hosting on infrastructure SummaCore manages and controls; and a least-privilege application account for the Service's database access. SummaCore does not claim any third-party security certification for the Service.
No system is perfectly secure. If we determine that a breach of system security has affected personal information we hold, we will notify affected Customers without unreasonable delay, consistent with the Subscription Terms' Section 6.4, and, where required by law, affected individuals directly — using the most effective available channel, which may include email to the address on your account, in-Service notice, or notice through your organization — consistent with Tex. Bus. & Com. Code § 521.053 and other applicable breach-notification law.
9. Retention and Deletion
- Account rows: after your Workspace membership is deactivated (Section 3.1), we hard-purge your mirrored account row after 12 months, or, if earlier, the Subscription Terms' Section 16.2 termination clocks — on Workspace termination, those clocks control everything.
- Booking records: retained for the life of the Workspace, because they are the shared scheduling record other Workspace members rely on (busy/free status), even though the title and identity behind a booking are not shown to them (Section 3.2).
- Provisioned-but-unused features: no data is currently collected for the join-request or check-in provisions described in Section 3.3. If join requests ship, a JoinRequest row will be retained for 90 days after the request is decided or abandoned; check-in retention will be defined when that feature ships.
- Workspace invitation records (Section 3.8): a pending invitation expires 14 days after it is sent. An invitation that was accepted, revoked, or expired without being accepted is deleted 90 days after that event, on the same nightly clock as the tenant audit log below. Deleting the invitation record removes the invited email address from our database unless that person has since become a User.
- Billing records (Section 3.9): our payment processor's identifiers, subscription status, and billing email are kept for the life of the Workspace. Invoices, receipts, and payment records — held by our payment processor, and our copies of the related audit entries — are retained for seven (7) years after the transaction, as tax and accounting law requires, and are not subject to the Section 16.2 deletion schedule in the Subscription Terms.
- Server error logs: retained for 90 days, or, if earlier, the Subscription Terms' Section 16.2 termination clocks where applicable, for operations and troubleshooting (Section 3.5).
- Tenant audit log: actions taken within a Workspace (for example, a booking change or a membership change) are recorded in an internal audit log retained for 90 days. This 90-day clock does not apply to the Terms/Policy acceptance record described below, which is retained separately and for longer.
- Terms and Policy acceptance records: a workspace-level record of who accepted these Terms or this Policy, which version, and when, is retained for the life of the Workspace, plus four years after termination — distinct from the 90-day tenant audit log above and from the Demo Environment's acceptance record, which follows the demo's nightly wipe and backup-rotation schedule described in Section 13.
- Room and resource configuration records: retained for the life of the Workspace (Section 3.7).
- On Workspace termination: deletion follows the Subscription Terms' Section 16.2 schedule exactly — we will delete Customer Data from the production Service in accordance with its deletion schedule after the later of (a) 60 days following termination or expiration and (b) completion of any export request submitted within that 60-day period, and will delete Customer Data from backups within up to 40 additional days as backup media rotate, except for data we are required by law to retain. This Policy does not restate different numbers; the Subscription Terms control.
10. Your Privacy Rights and Requests
You may have rights to access, correct, or delete your personal information, depending on where you live. We do not currently have self-serve tooling for these requests — the same honest posture as the Subscription Terms' Section 16 for Customer Data generally. To make a request, contact us using the information in Section 15.
A request is subject to your Workspace relationship. A booking is a shared record that belongs to your Workspace, not solely to you — other members rely on it to know a room or resource is unavailable, even though they cannot see its title or your identity (Section 3.2). Leaving or being removed from a Workspace deactivates your account membership (Section 3.1), but Workspace Records your organization's Workspace owns (Section 2(b)) may persist under that organization's control, the same way records on a shared office calendar would.
Response timeframe. We will respond to a privacy request within a reasonable time, generally no more than 45 days after we receive it. If we need longer, we will tell you why and when to expect a response.
Verification. We verify a request using the email address on your account (or another reasonable method if you do not have an account). We may decline a request we cannot verify.
11. State Privacy Laws
11.1 California (CCPA/CPRA)
SummaCore likely does not meet the CCPA's threshold to be a covered "business" at the Service's current scale. Regardless of whether the CCPA applies to us, we do not sell or share personal information, and we do not use it for cross-context behavioral advertising — that commitment is unconditional and does not depend on CCPA coverage.
Regardless of CCPA coverage, we offer every user of the Service the following rights, consistent with CCPA-style practice: the right to know what personal information we hold about you and how we use it; the right to access a copy of it; the right to correct inaccurate personal information; the right to delete it, subject to Section 10's Workspace-relationship limits; the right to be free from discrimination for exercising these rights; and the right to have an authorized agent make a request on your behalf, subject to the verification described in Section 10.
11.2 Texas (TDPSA)
SummaCore likely qualifies for the Texas Data Privacy and Security Act's small-business treatment at the Service's current scale. Regardless of that status, we offer TDPSA-consistent commitments — including never selling personal data — to every user of the Service.
11.3 Texas breach notification
Tex. Bus. & Com. Code § 521.053 applies to the data we hold. We will notify affected users of a breach of system security without unreasonable delay, consistent with applicable law, as described in Section 8.
11.4 Other jurisdictions
The Service is offered in the United States and is not directed to individuals in the European Union, European Economic Area, or United Kingdom.
12. Children
The Service is for users 18 and older and is not directed to children, matching the Subscription Terms' Section 1.3 and the Demo Terms. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
13. The Public Demo
The Demo Environment at `/demo` works differently from the rest of the Service, and this section describes it on its own. It should be read together with the Demo Terms, which govern your use of the Demo Environment and control if there is any conflict with this section.
- Other than a record that you accepted the Demo Terms (a timestamp, the Demo Terms version shown, and a technical session identifier), using the demo creates no account and no per-visitor record of your demo activity. Every demo visitor is signed in as the same shared demo identity, in the same shared demo Workspace.
- Your IP address is not written to disk or to any database by the demo's rate limiter, which uses it only transiently, in memory, to enforce rate limits on demo use. Like any web request, technical details, including your IP address, may appear transiently in network-infrastructure logs and server error logs — see Section 3.5.
- The demo is wiped every night, with backup copies rotating out within about 40 days, matching the Demo Terms exactly: the demo Workspace is wiped and reloaded with fresh sample data nightly, and routine backups taken before a nightly wipe may retain a copy of what a visitor entered for up to about 40 days before those backups, too, rotate out.
- Because the demo is shared and not private, do not enter real names, real business information, or anything confidential into it — see the Demo Terms for the full statement of what you agree not to do.
14. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy at this address with a new "Last updated" date and, for significant changes, take reasonable steps to notify Workspace administrators.
This Section does not apply to the Demo Environment. The version of this Policy — and of the Demo Terms — posted at the demo gate at the time you use the demo governs your use of the demo, as the Demo Terms describe.
15. Contact
SummaCore LLC 5900 Balcones Drive, Ste 100 Austin, Texas 78731 Email: privacy@summacore.com
If you are a member of an organization's Workspace, see Section 2 — some requests may need to go through your organization.
---
*SummaBooking is a product of SummaCore LLC.*