← Back to PreventNoShows
Privacy Policy
Effective September 26, 2026. Version 1.1.
This Privacy Policy explains how X3 E-Commerce LLC d/b/a FrontDesk Global (“FrontDesk Global”, “we”, “us”) collects, uses, and shares personal information in connection with PreventNoShows (the “Service”).
We have built PreventNoShows with three commitments: we do not sell personal information, we do not train AI models on customer data, and we treat all users — wherever they live — to the same baseline privacy rights.
1. Who is the Controller / Processor
When we provide the Service to you (our customer), you act as the “controller” of your customers' or tenants' personal information, and we act as a “processor” or “service provider” on your behalf, in the sense those terms are used in the GDPR, CCPA/CPRA, and similar laws.
When we collect personal information directly from you to manage our relationship with you (account, billing, support), we act as a controller. This Policy covers both relationships.
2. Information We Collect
2.1 Information you give us
- Business details (name, reminder settings)
- Appointment details: customer name, phone or e-mail, time, service
- Calendar feed links or Square connection tokens, if you connect them
- Waitlist entries: name, phone or e-mail, preferred times, text consent
- Confirm, cancel, claim and STOP replies
2.2 Account and billing information
- Name, email address, phone number, business name and address.
- Payment-method information processed by our payment provider, Stripe (we never see or store full card numbers).
- Authentication credentials (passwords are stored hashed; we use OAuth where supported).
2.3 Information collected automatically
- Device, browser, and connection metadata (IP address, user agent, language).
- Usage logs (pages visited, actions taken, errors encountered).
- Cookies and similar technologies — see Section 9.
3. How We Use Information
We use information to:
- Provide and operate the Service, including the AI features described in our AI Disclosure.
- Process payments and manage your subscription.
- Communicate with you about your account, security, billing, and product updates.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our Terms.
- Improve the Service through aggregated, anonymized analytics. We do not use the content of customer data to train AI models.
4. AI Processing
When we use AI to generate output, we send the relevant input to our AI provider (currently Anthropic, with select third-party speech and translation providers identified in our AI Disclosure). These providers process information solely to return output to us; they do not retain inputs to train their models on your data.
5. How We Share Information
We share information only as needed to operate the Service:
- Sub-processors. We use trusted vendors for hosting, payments, email, SMS, AI inference, and analytics. A current list is available on request and is also linked from our website.
- Your authorized integrations. We exchange data with services you connect (Google, Microsoft, your CRM, etc.).
- Legal compliance. We may disclose information when required by law, valid legal process, or to protect rights, safety, and property.
- Business transfers. If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you and any successor will be bound by this Policy.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
5A. Appointment and Messaging Data
To provide PreventNoShows, we process the following data only for the purposes stated:
- Appointment details (customer name, mobile number, e-mail, appointment time, service name, and location) that you enter or that we read from the calendar feed or Square account you connect. Used only to send reminders and show confirmation status.
- Calendar feed links and Square tokens are stored only to sync your appointments. You can disconnect them at any time, and we stop reading your calendar immediately.
- Replies (confirm and cancel taps and text replies) are used to update the appointment status you see.
- No clinical information needed. The Service only needs appointment times and service names. Please do not put diagnoses or treatment details in appointment names or notes.
- Waitlist entries (name, mobile number or e-mail, preferred days and times, notes, and whether the person agreed to be texted). Used only to offer open appointment slots. Slot offers go by text only to people who agreed to texts; everyone else is offered the slot by e-mail.
- Opt-outs. Anyone who replies STOP is never messaged again through the Service.
What we do not do with this data:
- We do not sell it, and we do not share it with anyone other than the sub-processors listed below that are strictly necessary to run the Service.
- We do not use it to train or improve AI models — ours or our vendors’.
- We do not use it for advertising or to contact anyone on behalf of any business other than you.
Current sub-processors (vendors that process this data for us):
- Cloudflare, Inc. — hosting, database, content delivery, security
- Telnyx LLC — text-message (SMS) delivery
- Resend, Inc. — transactional e-mail delivery
- Stripe, Inc. — subscription billing and payment processing (we never see full card numbers)
5B. Text Messaging (SMS) Privacy
- Mobile phone numbers are used only to send the messages the business set up in PreventNoShows and to process replies (such as CONFIRM, STOP, or HELP).
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent will not be shared with any third parties, except our SMS delivery provider (Telnyx) for the sole purpose of delivering messages.
- We keep a record of each opt-out (STOP) so the number is never messaged again through PreventNoShows.
- Message and data rates may apply. Reply HELP for help or e-mail [email protected].
6. Retention
We retain Your Content for as long as your account is active. After termination, we retain it for at least 30 days to support export, then delete it within 90 days unless we are required to retain it longer for legal or accounting purposes. Account and billing records are retained for the period required by tax and accounting law (typically seven years).
7. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete information, subject to legal retention requirements.
- Object to or restrict certain processing.
- Receive a copy of your information in a portable format.
- Withdraw consent for processing based on consent.
- Opt out of any sale or sharing of personal information (we do not sell or share, but the right is preserved).
- Lodge a complaint with a data-protection authority.
To exercise these rights, email [email protected]. We will verify your identity and respond within the time required by your jurisdiction (typically 30 to 45 days).
8. International Transfers
We are based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our service providers operate. For transfers from the European Economic Area, the United Kingdom, and Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
9. Cookies and Similar Technologies
We use a small number of cookies to keep you signed in, remember your preferences, and measure aggregate usage. We do not use third-party advertising cookies. You can manage cookie preferences in your browser; blocking certain cookies may break parts of the Service.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect information from them. If you believe a child has provided us information, contact [email protected] and we will delete it.
11. Security
We protect information using industry-standard administrative, technical, and physical safeguards, including encryption in transit (TLS 1.2+) and at rest, role-based access controls, and continuous security monitoring. No system is perfectly secure; if you suspect unauthorized access to your account, contact [email protected] immediately.
12. Changes to This Policy
We may update this Policy. We will notify you of material changes by email or in-app notice at least 30 days before the changes take effect.
13. Contact
Privacy questions: [email protected]. Mailing: X3 E-Commerce LLC d/b/a FrontDesk Global, Michigan, United States.
X3 E-Commerce LLC d/b/a FrontDesk Global • Michigan, United States