Privacy

Last updated September 27, 2026

Written in plain English on purpose. This is a small product run by one person; if something here is unclear, ask and we will fix the wording.

What we store

For you: your email, display name, timezone, policy text, weekly booking hours, a usual meeting place, and billing status. We also store the Stripe customer id for your $29/mo subscription, and your Stripe Connect account id once you connect, so client pack payments can land in your account. If you connect Google Calendar, we store an encrypted token so we can add and remove session events and read busy times. Disconnect deletes that token.

If you leave the check-in emails on, we store whether you unsubscribed, whether you opted into the newsletter, and a pause date if you asked us to wait.

For your clients: whatever you type in — name, and optionally email, phone and notes — plus their packs, sessions, payments, and booked times. A booked time can carry a place the client sees on their link. A person who uses your unlisted booking link types their own name and a phone or email. We do not email clients.

Google Calendar

Connecting Google Calendar is optional. If you connect it, PacksLeft requests three permissions only: create and change events on the calendar you choose, see whether that calendar is busy, and read the email address of that Google account.

We use them to keep bookings in step with that calendar. Booking a session adds one event titled “Session · [client]” with the start, the end, and the place. Moving the time updates that same event. Cancelling deletes it. We do not read, edit, or delete events we did not create. Busy or free time is used only to hide hours that are already taken. We do not store the titles of your other events. The Google email address is shown on Booking settings so you can see which account is connected.

Security procedures are in place to protect that data. Traffic between your browser, PacksLeft, and Google is encrypted in transit (HTTPS). The refresh token Google issues is encrypted before it is stored, with AES-256-GCM, and the key stays on our server. The browser is not given a key that can read it. We do not send the token in email or put it in the page.

We do not sell Google user data. We do not transfer or disclose it for advertising. We do not use it to train AI or machine learning models. The only companies that handle it are the ones that run PacksLeft: Supabase stores the encrypted token and the connected email address, and Vercel hosts the app. Google keeps the events on your own calendar.

We keep the token only while Calendar stays connected. Disconnect deletes our copy and revokes the token with Google, so PacksLeft can no longer act on that account. If you ask us to delete your account, we delete the token then too. Write to support@packsleft.com.

How you sign in

Sign-in is a magic link. There is no password. Supabase sends the link and keeps the session in a cookie. The key the browser is allowed to hold cannot read your ledger. Only our server can.

What your clients see

A client’s link shows only that client’s sessions remaining, their last five sessions, a booked time and the place when one is set, your policy text, and buy buttons for packs you have priced. It never shows their email, phone, your notes, or any other client. From that same link they can add their booked times to their own calendar. That calendar lists only their times and the place. It is not your Google Calendar. The link is unguessable and you can rotate it at any time, which immediately kills the old one, including that calendar. These pages are not indexed by search engines.

Email

We email you. We do not email your clients.

Pack alerts (running low, or expiring) come from alerts@. Optional welcome and check-in mail comes from hello@, and you can turn that off. Unsubscribing uses the one-click control in the email. Opening the link in a browser goes to preferences instead, so a mail scanner that fetches every link cannot unsubscribe you. Turning off check-ins does not turn off pack alerts.

Alert emails say your client was not emailed.

Card payments

There are two Stripe relationships, and they are not the same money.

Your clients pay into your own Stripe account. Card numbers never touch PacksLeft’s servers — we only store which pack was bought and that it was paid. PacksLeft takes 0% of those charges. Stripe’s own fees still apply.

Your $29/mo subscription is a separate charge on PacksLeft’s Stripe account.

What we measure

We record seven first-time events about your account only: sign-up, first client, first log, Stripe connected, first checkout, first time a client opens their link, and trial converted. A portal open is recorded as you, never as your client. No client information is sent to analytics, and we do not run session replay.

The public site and the trainer app load the Meta pixel, so we can see whether an ad led to a trial or to a download of the free session tracker. It records a page view, one event when a trial starts, and one event when that sheet is downloaded. It does not load on a client’s private link, a booking link, or a payment short link. Those addresses are the credential, and they are not sent to Meta. We do not send Meta your email or your clients’ names.

The public site (the homepage, the sign-in page, and the articles) also loads an OpenAI measurement pixel so we can see whether a ChatGPT ad led to a trial. It records which page was opened and, when a trial starts, that the trial started. It may store two cookies in this browser, named __oppref and __obref, to tie that visit to the ad. If you type your email on the sign-in page, the pixel may include a hashed copy so the trial can be matched to the ad. Inside the app it loads once, on the first screen after a new account is created, which has no clients on it yet. It does not load on a client link or a booking link.

Who else handles data

Vercel hosts the app. Supabase holds the database and sign-in. Stripe processes cards. Resend sends email. Google Calendar holds session events only if you connect it. Meta receives the page views described above, from the public site and the trainer app only. OpenAI receives the ad-measurement events described above. We do not sell your data.

On this browser

The client portal may store one flag in this browser so the “save this link” nudge stays dismissed. That flag stays on the device. It is not an account.

Your data is yours

Export your clients, packs, sessions and payments as CSV from Settings at any time, including after your subscription ends. Ask us to delete your account and we will remove your data.

Contact

Questions or a deletion request: support@packsleft.com.