Legal
Privacy Policy
This policy explains what Pasco Labs LLC collects, why, and what we will and will not do with it.
Effective August 8, 2026
Pasco Labs LLC (“Pasco Labs”, “we”, “us”) builds and operates software for small businesses. This policy covers our website at pascolabs.com and the products we run, including Kalendaryo.
Who the data belongs to
We handle two kinds of personal information, and the distinction matters for your rights:
- Our customers. Businesses that sign up to use our products, and the staff they invite. We are the controller of this information.
- Their customers. People who book appointments with a business using our software. That business decides what happens with this information; we process it on their behalf and under their instruction.
What we collect
- Account information — name, business name, email address, phone number, and a hashed password. We never store passwords in a readable form.
- Booking information — appointment times, the service requested, the staff member, and the contact details a customer provides in order to be booked and reminded.
- Enquiry information — where a business uses our software to handle its contact form, website chat, or missed calls, the contact details and message you submitted, so the enquiry can be answered and followed up.
- Conversation content — messages exchanged with our scheduling agent, kept so that a booking can be reconstructed and disputes resolved.
- Technical information — IP address, browser type, and pages requested, collected in server logs for security and diagnostics.
We do not collect payment card numbers. Where payments are supported, they are handled by a third-party payment processor and the card details never reach our systems.
Text messaging and mobile information
No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
Mobile numbers collected for appointment messaging are used only to send messages relating to the appointment the person made — confirmations, reminders, and changes — and only for the business they booked with. A number given to one business is never used to send messages on behalf of another.
Text messaging is off by default. An account holder turns it on themselves, and we record when and how that permission was given. People who book as guests, without an account, are contacted by email only — we do not text a number that was typed into a booking form by someone we cannot verify. Replying STOP withdraws permission everywhere at once, across every kind of message we send on that business's behalf.
Where we handle enquiries for a business, a mobile number is treated as textable only if the person used it to contact the business themselves, or gave express permission on the form they submitted. A number that merely appeared in a form is answered by email. This distinction is enforced in our software rather than left to judgement.
We share mobile numbers with our telecommunications provider solely to deliver those messages. That provider is contractually restricted to processing the data for delivery and may not use it for its own purposes. This is a service-delivery necessity, not a sale or a marketing share.
Consent can be withdrawn at any time by replying STOP to any message. Full details are in our Messaging Terms.
How we use information
- To provide the service — creating, changing, and confirming bookings.
- To send transactional messages about an appointment or an account.
- To keep accounts secure and investigate abuse.
- To diagnose faults and improve reliability.
- To meet legal and tax obligations.
We do not sell personal information. We do not use customer conversation content to train general-purpose AI models.
Who we share it with
We share personal information only with service providers who need it to run the product — cloud hosting, our messaging provider, our AI model provider for the duration of a request, and error monitoring. Each is bound by contract to use it only for that purpose. We may also disclose information where the law requires it, or to protect our rights or someone's safety.
How long we keep it
Account information is kept while the account is open and for a reasonable period afterwards to meet legal and accounting obligations. Booking records are retained per the business's own settings. Server logs are retained for a limited diagnostic window and then discarded. Deletion requests are honoured as described below.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. Write to allan@pascolabs.com and we will respond within the period the law requires.
If you booked an appointment with a business that uses our software, that business controls your record. We will pass your request to them and assist them in fulfilling it.
Security
Data is encrypted in transit. Access to production systems is restricted to the people who need it. Passwords are stored hashed. No system is perfectly secure, and we will notify affected users and regulators of a breach where the law requires it.
Children
Our products are not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
Changes
We will update this page when our practices change and revise the effective date at the top. Material changes will be communicated to account holders directly.
Questions about this document? Write to allan@pascolabs.com. Postal correspondence for Pasco Labs LLC can be arranged by email — we'll provide a mailing address on request.