Privacy Policy

Effective date: 29 May 2026

Last updated: 5 July 2026

1. Introduction

MyYoga.Guru is an all-in-one scheduling and business platform for solopreneurs and small teams. We are operated by Crafted XP Pty Ltd ("we", "us", "our"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights in relation to it.

By using MyYoga.Guru — whether as a tenant (a business owner who runs their practice on our platform) or as a visitor booking an appointment or interacting with a tenant's public pages — you agree to the practices described in this policy.

2. Information we collect

Account data. When you sign up as a tenant, we collect your name, email address, and a hashed password (managed through AWS Cognito). If you sign in with Google, we receive your Google account name, email, and a profile photo.

Business and booking data. Tenants provide information about their offerings, availability calendars, and customer-facing content. When visitors make bookings, we collect the visitor's name, email address, and the details of the appointment (date, time, service type). This data is stored in DynamoDB on behalf of the tenant and is logically isolated per tenant.

Payment information. Payments are processed entirely by Stripe. MyYoga.Guru does not store full card numbers or CVVs. We receive confirmation of payment outcomes (e.g. successful, failed) and Stripe customer/payment-method identifiers for record-keeping.

Google Calendar connection. When a tenant connects their Google Calendar, we receive OAuth tokens, the email address of the connected Google account, and calendar event data from Google. This Google user data is handled exclusively as described in Section 3 (Google User Data) below.

Zoom connection. When a tenant connects their Zoom account, we receive OAuth tokens and the email address of the connected Zoom account. These are encrypted using AWS KMS and used solely to create Zoom meeting links for the tenant's events and bookings.

Outlook Calendar connection. When a tenant connects their Microsoft Outlook Calendar, we receive OAuth tokens — including a refresh token — the email address and profile of the connected Microsoft account, and calendar event data from Microsoft Graph. We request the Microsoft Graph scopes Calendars.ReadWrite (read and write the tenant's calendar events, for two-way sync), User.Read (read the account profile and email, to show which account is connected), and offline_access (the refresh token that keeps the connection working). These tokens are encrypted using AWS KMS and used solely to sync the tenant's calendar events. This connection is calendar-sync only — it grants no access to meetings, recordings, chat, or mail. Outlook data is never used for advertising, analytics, or AI/ML training.

Social-platform tokens. When a tenant connects a social media account (e.g. Meta/Facebook, Instagram) through MyYoga.Guru's social publishing feature, we receive and store OAuth access tokens and page/profile identifiers. These social-platform tokens are encrypted at rest using AWS KMS and used solely to publish content on the tenant's behalf.

Technical data. We collect standard server and application logs including IP addresses, browser user-agent strings, request timestamps, and error traces. This data helps us diagnose issues and protect the service.

3. Google User Data (Google Calendar Integration)

When a tenant connects their Google Calendar to MyYoga.Guru, we access Google user data through Google APIs with the tenant's explicit consent. This section describes exactly what we access, how we use it, how we protect it, and how you can revoke our access at any time.

What we access. We request two OAuth scopes: https://www.googleapis.com/auth/calendar.events (view and edit events on your calendar — we do not request broad access to your calendar) and https://www.googleapis.com/auth/userinfo.email (used solely to read and display the email address of the connected Google account). Through the calendar events scope we read event titles, descriptions, dates and times, locations, attendee email addresses, and conferencing details (such as Google Meet links).

How we use it. We use Google Calendar data only for the following user-facing features:

  • Displaying your Google Calendar events inside the MyYoga.Guru in-app calendar.
  • Two-way sync — pushing events you create, update, or delete in MyYoga.Guru to your Google Calendar.
  • Blocking time slots that are already busy in your Google Calendar from being booked online.
  • Creating Google Meet conference links on events when you request it (per event or per setting).
  • Showing you which Google account is connected.

If you actively use MyYoga.Guru's AI assistant features and your request involves your calendar, calendar data (including Google-sourced events) may be passed transiently to our AI provider (OpenAI) solely to answer your request. This is a user-facing feature only — Google user data is never used to train AI or machine-learning models, never used for advertising or analytics, and never sold or transferred to data brokers. We do not use Google user data for any other purpose.

Storage and protection. Events we read from your Google Calendar are processed transiently in memory to render your calendar and check availability — they are not stored in our database. The only Google-derived data we store is (1) the Google event ID of events we created in your Google Calendar (so that sync, updates, and deletions work) and (2) the Google Meet link generated for an event — both stored on your own MyYoga.Guru calendar-event records. Your Google OAuth access and refresh tokens are encrypted using AWS KMS and stored in our AWS DynamoDB database in the AWS Sydney (ap-southeast-2) region, which is additionally protected by AWS's encryption at rest. All Google user data is transmitted only over HTTPS/TLS. Access to Google user data is restricted to the systems and personnel needed to operate the integration.

Sharing. We do not sell, rent, or transfer Google user data to third parties, data brokers, or advertisers. Google user data is shared only with the infrastructure subprocessors needed to run the service — AWS (hosting and database), Vercel (application hosting), and our AI provider only in the user-initiated case described above — and where required by law.

Retention and deletion. We keep your Google OAuth tokens only while your Google Calendar remains connected. You can disconnect at any time from Settings → Google in the app; on disconnect we revoke our access with Google and immediately delete the stored tokens and connection settings. You can also revoke MyYoga.Guru's access from your Google Account security settings. Stored Google event IDs and Meet links on your own MyYoga.Guru events remain part of your app data and are deleted along with that data (see Section 6, Data retention — account deletion purges data within 30 days). Events we previously created in your Google Calendar remain in your Google Calendar — we do not delete entries from your calendar. You can also request deletion of your Google user data at any time by emailing hi@myyoga.guru.

Limited Use. Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

No AI/ML training. We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models.

Changes to our use of Google user data. If we materially change how we use Google user data, we will notify you and obtain your consent before the new use applies.

4. How we use information

We use your data to provide the MyYoga.Guru service: creating and managing your account, rendering your public-facing landing page, processing bookings and payments, sending transactional notifications (booking confirmations, reminders, receipts), and hosting your email inbox.

Where you have enabled AI features, your content (e.g. calendar data, customer queries, knowledge-base text) may be passed to third-party AI providers to generate responses. See the Third Parties section for details. Google user data is used only as described in Section 3.

We also use data for security and fraud prevention (detecting abuse, unauthorized access, and spam) and for aggregate, anonymized product analytics to understand how the platform is used and improve it. Google user data is excluded from analytics (see Section 3).

5. Third parties we share data with

We share data with the following service providers only to the extent necessary to operate MyYoga.Guru. Each is governed by their own privacy policy.

  • Amazon Web Services (AWS) — cloud hosting, database (DynamoDB), file storage (S3), email delivery (SES), and KMS encryption for social-platform tokens. Data is hosted in the AWS Sydney (ap-southeast-2) region.
  • Stripe — payment processing, subscription billing, and tenant Connect onboarding. Stripe is the processor of record for card transactions.
  • Google (Google Calendar) — when a tenant connects their Google Calendar, we sync event data with Google's Calendar API strictly as described in Section 3.
  • OpenAI — AI assistant features (chat, content suggestions, brief generation). Prompts may include tenant-supplied knowledge-base text and visitor queries. Google Calendar data is included only transiently and only when you actively use the AI assistant, as described in Section 3.
  • Meta (Facebook/Instagram) — when a tenant connects a Meta page or Instagram account, we interact with Meta's Graph API to publish content on the tenant's behalf. Access is limited to the scopes the tenant explicitly authorises.
  • Zoom — when a tenant connects their Zoom account, we call Zoom's API on their behalf solely to create meetings for their events and bookings. We do not read meeting content, recordings, or chat.
  • Microsoft (Outlook Calendar) — when a tenant connects their Microsoft Outlook Calendar, we call the Microsoft Graph API on their behalf (scopes Calendars.ReadWrite, User.Read, and offline_access) solely to sync their calendar events two ways and to show which account is connected. This is calendar-sync only — we do not access meetings, recordings, chat, or mail, and we never use Outlook data for advertising, analytics, or AI/ML training.
  • Twilio / Amazon SES — transactional email and SMS delivery for booking notifications, reminders, and verification messages.
  • Vercel — application hosting and edge networking for the MyYoga.Guru web application.

We do not sell personal data to third parties, and we do not share data with advertisers.

6. Data retention

Tenant account data and associated business data are retained while the account is active. When an account is closed or deleted, data is marked for deletion and purged within 30 days, except where we are required to retain it for legal or tax purposes.

Google OAuth tokens are kept only while the Google Calendar connection is active and are deleted immediately when you disconnect, as described in Section 3. Zoom OAuth tokens are likewise kept only while the Zoom connection is active and are deleted immediately when you disconnect — we also revoke our access with Zoom on disconnect. Outlook (Microsoft) OAuth tokens, including the refresh token, are kept only while the Outlook Calendar connection is active and are deleted immediately when you disconnect from Settings → Outlook in the app. Microsoft does not provide a token-revocation endpoint, so on disconnect we delete our stored copy of the tokens; you can also revoke MyYoga.Guru's access from your Microsoft account permissions. Social-platform access tokens are encrypted at rest using AWS KMS and deleted automatically when the tenant disconnects the integration from their settings. Revocation via the platform's own settings will also invalidate the token.

Application and server logs are retained for approximately 30 days for security and diagnostic purposes, after which they are automatically purged.

7. Your rights

Depending on your jurisdiction, you may have the following rights in respect of your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Deletion — ask us to delete your data (subject to legal retention obligations).
  • Portability — receive your data in a machine-readable format.
  • Objection / restriction — object to certain processing or ask us to restrict it while a dispute is resolved.

To exercise any of these rights, email us at hi@myyoga.guru. We will respond within 30 days. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

8. Children

MyYoga.Guru is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected data from a child, please contact us at hi@myyoga.guru and we will delete it promptly.

9. International data transfers

MyYoga.Guru's primary infrastructure is hosted in Australia (AWS Sydney region). If you are accessing MyYoga.Guru from outside Australia, your data may be transferred to and processed in Australia, which may have different data protection laws than your country.

When data is shared with third-party service providers (e.g. OpenAI, Stripe, Meta) those providers may process data in their own regions. We rely on each provider's standard contractual clauses or equivalent transfer mechanisms where applicable.

10. Security

We take reasonable technical and organisational measures to protect your data. All data in transit is encrypted using TLS. Social-platform and Google OAuth tokens are encrypted using AWS KMS (see Section 3). Access to production systems is restricted to authorised personnel.

No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly by emailing hi@myyoga.guru.

11. Contact us

If you have any questions or concerns about this policy or how we handle your data, please contact us at: hi@myyoga.guru.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the last-updated date at the top of this page. For material changes, we will notify tenants by email or via a notice in the MyYoga.Guru dashboard. If we materially change how we use Google user data, we will notify you and obtain your consent before the new use applies (see Section 3). Continued use of MyYoga.Guru after a change takes effect constitutes acceptance of the updated policy.

13. Effective date

This policy is effective as of 29 May 2026 and was last updated on 5 July 2026.