PandaCue (the “Service,” “Platform,” “we,” “us,” or “our”) is operated by CodeSol Technologies (“CodeSol,” “Company”). This Privacy Policy explains how we collect, use, disclose, store, and protect information when you use PandaCue.
Our services are available at pandacue.com, related API hosts, embeds, widgets, and any successor domains we operate for PandaCue.
For privacy requests, contact [email protected].
1. Scope and roles
1.1 What this Policy covers
This Privacy Policy applies when you:
- create or use a PandaCue / CodeSol account (platform staff or business staff);
- use business features such as CRM, booking, messaging, social publishing, finance, forms, automations, and related tools;
- visit public surfaces we host for a business (online booking, invoices, estimates, payment links, forms, chat widgets, gift cards, packages, memberships, and embeds);
- connect third-party integrations (Google, Meta, LinkedIn, TikTok, Pinterest, X, Stripe, Twilio-related messaging, email providers, storage, and similar services);
- communicate with us about support, billing, or trial signup.
1.2 Controller vs. processor
PandaCue is a multi-tenant business operations platform. Each customer business (“Customer,” “Business,” or “Tenant”) uses the Service to manage its own clients, patients, leads, and visitors.
| Data type | Typical role |
|---|---|
| Staff account data, authentication, platform billing, product analytics about account use, infrastructure logs, and our marketing or support communications | CodeSol / PandaCue acts as an independent controller. |
| Contacts, leads, appointments, messages, form submissions, invoices issued to your end customers, social posts you publish, files you upload for your business, chatbot transcripts of your website visitors, and similar business content | The Customer Business is the controller. We process that content as a processor / service provider on the Business’s instructions. |
If you are an end customer of a Business (for example, you booked an appointment, filled a form, paid an invoice, or chatted on a Business website), that Business’s own privacy notice governs how they use your information. This Policy explains how we process that information on their behalf.
1.3 What this Policy does not fully cover
- Third-party websites, apps, or services linked from the Service (such as Google, Meta, TikTok, or Stripe Customer Portal) have their own policies.
- Content published by a Business to social networks is also subject to those networks’ terms and privacy rules.
2. Information we collect
2.1 Account and authentication information
When you register, are invited, or log in, we may collect:
- name, email address, and phone number;
- password (stored as a one-way hash; we do not store plaintext passwords);
- email verification status and related tokens;
- password reset tokens (hashed) and related security metadata;
- business membership role (
OWNER,ADMIN,MEMBER) and status; - platform roles for CodeSol staff (
SUPER_ADMIN,PLATFORM_ADMIN,SUPPORT) where applicable; - staff profile details used for operations (for example, service-provider flags, work schedules, calendars, and time-clock PIN stored hashed);
- staff permissions and notification preferences;
- invite tokens and acceptance metadata;
- last login and session-related security data;
- authentication context (platform vs. business) when you switch workspaces.
Trial signup: We may collect a phone number for OTP verification via SMS, then email, password, and business profile details to complete trial signup.
2.2 Business profile and settings
For each Business we may store:
- business name, industry branding, website, timezone, address, and contact fields;
- lifecycle status and plan entitlements;
- financial and invoice settings (for example, legal business name and tax identifiers where provided);
- online booking, calendar, notification, automation, and integration settings;
- branding and product display name overrides.
2.3 CRM and relationship data (Customer Content)
Businesses may enter or import:
- Contacts / clients: names, company, email, phone, address, timezone, avatar, notes, tags, source, metadata, and block or suppression flags;
- Leads: pipeline stage, value, assignment, and notes;
- notes and related CRM records;
- services, industries, pipelines, and similar configuration.
Staff permissions may limit which contact fields other staff can see.
2.4 Scheduling, booking, and operations
We process:
- appointments (times, staff, status, source, and related services or resources);
- calendars, availability, work schedules, waitlists, and tasks;
- time cards / time clock data;
- resources and related operational records;
- cancellation and booking policy acceptances, which may include IP address and user agent at the time of acceptance;
- express booking and public booking submissions (name, contact details, requested time, notes, and related fields configured by the Business).
2.5 Finance and payments
Depending on features enabled, we may process:
- estimates, invoices, payments, products, inventory, gift cards, packages, memberships, and offers;
- contact wallets and saved payment method references;
- Stripe customer IDs and Connect account identifiers;
- platform subscription, plan, add-on, and billing event records;
- amounts, currencies, statuses, and related metadata.
Card numbers are handled by Stripe. We do not store full payment card numbers on our servers.
2.6 Communications content
We may process:
- conversations and messages across channels such as Email, SMS, WhatsApp, Facebook, Instagram, LinkedIn, and web chat, including message bodies, attachment metadata, external message IDs, and participant identifiers;
- email templates and outbound or inbound email content;
- SMS content and delivery metadata, including opt-out / suppression records;
- WhatsApp template and messaging content where Meta WhatsApp products are connected;
- notification preferences for appointment reminders and similar alerts;
- automation runs that may send messages or update records based on Business configuration.
2.7 Forms, chatbots, and widgets
Public and embedded surfaces may collect:
- form field answers stored as structured submissions configured by the Business;
- chatbot and webchat sessions, including visitor identifiers, name, email, or phone if provided, page URL, referrer, user agent, and hashed or truncated IP where implemented;
- consent acknowledgements shown in chatbot interfaces;
- gift card, package, membership, and offer interactions on public catalog pages.
2.8 Social Planner and connected social accounts
When a Business connects social providers and publishes content, we may process:
- OAuth tokens and account identifiers (encrypted at rest);
- selected pages, channels, boards, or creator accounts;
- post captions, media files, scheduled times, and destination settings (for example, TikTok privacy level, YouTube privacy status, Made for Kids designation, and categories);
- publish status, platform-returned IDs, engagement metrics, and comments or replies where the product syncs them;
- creator information needed for publishing rules.
Connected providers may include, as enabled: Google (including YouTube, Google Calendar, and Google Business Profile where configured), Meta (Facebook, Instagram, WhatsApp), LinkedIn, TikTok, Pinterest, X (Twitter), and Stripe Connect.
2.9 Files and media
Uploaded files may include file name, MIME type, size, category, storage object key, visibility, uploader, and file content, stored in object storage we operate or contract (for example, Cloudflare R2 or S3-compatible storage).
2.10 Audit, security, and diagnostics
We maintain:
- audit logs of significant actions (actor, business, action, entity type or ID, and metadata);
- application and access logs (IP, timestamps, request paths, status codes, and approximate location derived from IP where available);
- job, queue, and webhook event records;
- optional error-monitoring tools if enabled in a given environment.
2.11 Cookies, local storage, and similar technologies
We use:
Strictly necessary / authentication
- HTTP-only cookies for access and refresh tokens;
- a readable cookie for authentication context (platform vs. business workspace);
- server-side session routes that attach credentials to API calls.
Preferences
- UI state such as sidebar open or closed.
Local / session storage
- form drafts;
- chatbot visitor or session IDs for embedded widgets;
- OAuth popup result keys;
- other user-experience caches.
Realtime
- Server-Sent Events and/or WebSockets (when enabled) for near-real-time business events, authenticated for logged-in users.
We do not currently use third-party advertising pixels or consumer marketing analytics SDKs in the core application. In-product analytics generally means business reports and social engagement metrics for the Customer’s own use.
2.12 Information from third parties
We receive data from:
- OAuth providers (profile or page identifiers, tokens, and granted scopes);
- Stripe (payment and subscription events via webhooks);
- Meta, Twilio, Resend, and similar providers (delivery, inbound messages, and webhook payloads);
- Google Calendar sync and other connected APIs;
- hosting, DNS, CDN, and email infrastructure providers.
3. How we use information
We use information to:
- Provide and operate the Service — accounts, multi-tenant isolation, CRM, booking, messaging, social publishing, finance, forms, automations, notifications, and admin tools.
- Authenticate and secure — login, refresh tokens, invite and verify flows, PIN time clock, rate limiting, fraud and abuse prevention, and audit trails.
- Process payments — platform subscriptions and Customer payment collection via Stripe / Stripe Connect.
- Send transactional communications — security emails, invitations, booking confirmations and reminders, and system notices.
- Enable integrations you connect — exchanging the minimum data needed with each provider under your authorization.
- Improve reliability — debugging, queues, retention cleanup, and capacity planning.
- Support and compliance — respond to requests, enforce our Terms, comply with law, and protect rights and safety.
- Product development — aggregated or de-identified insights about feature usage where permitted.
We do not sell personal information for monetary exchange of consumer lists. We do not use Customer Content to train public foundation models unless we expressly disclose a separate AI feature and obtain the required rights.
4. Legal bases (EEA/UK and similar)
Where GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Service to account holders;
- Legitimate interests — security, product improvement, multi-tenant integrity, and support, balanced against your rights;
- Consent — where required (for example, certain cookies, marketing communications if offered, optional chatbot notices, or certain OAuth scopes);
- Legal obligation — tax, accounting, and lawful requests;
- Processor instructions — for Customer Content, we process under the Business’s documented instructions and our Terms or Data Processing Addendum, if executed.
5. How we share information
5.1 Service providers and subprocessors
We share information with providers used for:
| Category | Examples |
|---|---|
| Database | PostgreSQL hosting |
| Cache / queues / realtime | Redis, BullMQ workers |
| Object storage | Cloudflare R2 or S3-compatible storage |
| Email delivery and inbound | Resend and related notification domains |
| SMS | Twilio (platform and/or Business numbers; trial OTP) |
| Payments | Stripe (platform billing and Connect) |
| Error monitoring | Tools such as Sentry if enabled |
| Hosting / CDN / networking | Cloud hosting providers for app and API |
5.2 Integration providers you connect
When a Business connects an integration, relevant data is shared with that provider as needed to perform the requested action. Tokens are stored encrypted. Disconnecting an integration stops new sharing; residual copies may remain with the third party under their policies.
5.3 Within a Business
Owners and admins control staff access through roles and permissions. Platform support staff may access tenant data only as needed for support, security, or legal compliance, subject to internal controls.
5.4 Business transfers and legal disclosures
We may disclose information in connection with a merger, acquisition, financing, or sale of assets, or when required by law, legal process, or to protect the rights, safety, and integrity of the Service or users.
5.5 Public content
Information you or a Business choose to publish (public booking pages, public social posts, catalogs, and similar) may be visible to others.
6. International transfers
We may process and store information in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms, such as Standard Contractual Clauses, in customer contracts or Data Processing Addenda.
7. Retention
| Category | Typical retention |
|---|---|
| Account and Business data | For the life of the account or Business relationship, then deletion or anonymization within a reasonable period after closure, subject to legal holds. |
| Customer Content | Retained until the Business deletes it or closes the account; many records use soft delete and may remain recoverable for a period. |
| Audit logs | Retained for security and compliance. Contact us for enterprise retention needs. |
| Webhook event records | Typically cleaned up after about 30 days. |
| Async job records | Typically cleaned up after about 90 days. |
| Trial signup sessions | Expired sessions cleaned by scheduled jobs. |
| Orphan pending uploads | Cleaned after a short pending window. |
| SMS suppressions | Kept to honor opt-outs. |
| Backups | May persist for a limited backup cycle after deletion. |
Exact periods may vary by plan, legal requirement, or written agreement.
8. Security
We implement technical and organizational measures appropriate to the Service, including:
- TLS in transit for standard web and API access;
- password hashing and hashed refresh tokens;
- encryption of integration credentials at rest;
- role- and permission-based access control and business scoping;
- soft-delete and confirm-delete patterns for destructive actions;
- rate limiting on sensitive authentication and OTP endpoints;
- separation of API, worker, and scheduler processes where deployed.
No method of transmission or storage is completely secure. You are responsible for protecting staff credentials, PINs, device access, and OAuth connections under your control.
9. Your choices and rights
9.1 Account users
You may:
- access and update profile and many Business settings in-product;
- manage notification preferences;
- disconnect integrations;
- request a password reset;
- request account or Business deletion by contacting support (subject to Owner authority and legal retention).
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent. Email [email protected]. We may verify identity and, for Customer Content, may redirect end-user requests to the relevant Business.
9.2 End customers of a Business
To exercise rights regarding appointments, invoices, messages, or form data held for a Business, contact that Business first. We will assist the Business as required by law and contract.
9.3 SMS and email communications
- SMS: follow STOP, START, or equivalent instructions in messages; suppressions are recorded.
- Email: use unsubscribe links where provided for non-essential mail; transactional mail may still be sent as needed to provide the Service.
9.4 Cookies
Browser controls can block cookies; blocking authentication cookies will prevent login. Local storage used by widgets and forms can be cleared in browser settings.
10. Children’s privacy
The Service is designed for businesses and their adult staff, not for children under 13 (or the higher age required in your region) as primary users.
- We do not knowingly collect personal information from children for platform accounts.
- Businesses that use YouTube publishing must correctly set Made for Kids and related YouTube/COPPA obligations; that designation is the Business’s responsibility.
- Businesses must not use PandaCue to target or collect children’s data unlawfully.
If you believe a child has provided us account data, contact [email protected] so we can delete it.
11. Artificial intelligence
If a Business enables AI features that send content to a model provider, that content may be processed by the provider under its terms. Enabled AI features will be described in-product. Do not submit sensitive data to AI features unless your policies allow it.
12. Public pages, embeds, and branding
Public booking, payment, form, chat, and catalog pages may display Business branding and/or “Powered by CodeSol / PandaCue.” Visitor data submitted on those pages is Customer Content processed for that Business.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Continued use after the effective date constitutes acceptance where permitted by law.
14. Contact
Privacy and data requests: [email protected]
Company: CodeSol Technologies
Appendix A — Data categories
- Identifiers and account credentials
- Commercial and financial information (invoices, subscriptions, Stripe IDs)
- Internet and device data (IP, user agent, cookies, realtime connection metadata)
- Professional and employment-related staff data within a Business
- Customer Content: CRM, communications, booking details, forms, files, and social content
- Inferences limited to product reports configured by the Business
- Approximate geolocation (timezone, address fields, IP-derived location where applicable)
Appendix B — Key subprocessors and partners
PostgreSQL host; Redis; Cloudflare R2 or S3-compatible storage; Resend; Twilio; Stripe; Meta Platforms; Google; LinkedIn; TikTok; Pinterest; X Corp.; hosting providers for web, API, and workers; optional OpenAI or similar if AI features are enabled; optional error monitoring vendor if enabled.
A current subprocessor list may be provided on request or via a customer Data Processing Addendum.

