SCT Session Booking Privacy Notice
This notice covers SCT Session Booking on scryptotrader.com. Contact [email protected] for questions or requests to access, correct, or delete booking information.
Booking information
The service processes your email, session duration, payment and order identifiers, payment amount and status, and appointment time. Records support payment verification, booking, duplicate prevention, and customer enquiries.
Your IP address is processed to limit repeated checkout, booking, availability and recovery requests. The booking database stores time-limited keyed hashes rather than the raw IP address. Hosting providers may separately process network and operational information.
A private booking token is stored in your browser tab's session storage; the server stores its hash. This connects payment to booking without a customer login. Keep checkout in the same browser tab and do not share private access information.
For paid-order recovery, we send a one-time link to the payment email through the host’s existing Gmail send permission. Recovery links expire after 15 minutes; the server stores only their hashes. Recovered access is stored in your browser tab and does not cancel access in an existing tab. Expired recovery and rate-limit records are cleaned up during subsequent requests.
Google Calendar and Meet
The host connects their Google account. Customers do not grant the service access to their own Calendar. The host's identity is checked during authorization. Calendar free/busy information is used to calculate availability. The service creates a private appointment and Meet link and reads that appointment to confirm or recover a booking. Your email and appointment details are sent to Google so Calendar can issue an invitation.
Unrelated event titles and descriptions are not used to calculate availability. Google credentials are stored in encrypted server-side Cloudflare secrets and are not sent to customer browsers or intentionally written to application logs.
Google account and Calendar information is used for booking availability and Calendar/Meet sessions, not advertising or sale. The host can revoke access through their Google Account third-party connections settings. Revocation stops further Calendar access and session creation.
Providers
The host also grants Gmail send permission so the service can email booking confirmations to the host inbox. These messages contain the customer email, appointment time, duration, order reference and Meet link. The service does not request permission to read Gmail messages. A delivery-attempt record helps prevent duplicate notifications.
Cloudflare hosts the application and database. Suby processes crypto checkout and payment notifications and receives the checkout email, product selection, and order reference. Google provides Calendar invitations and Meet sessions. Providers also process information under their own applicable privacy notices. Crypto payments may create public blockchain records that this service cannot delete.
Storage and deletion
The current application retains order, payment receipt, and booking records until manually removed. Expiration of a private access token does not automatically delete records. Calendar appointments remain until removed from the host's Calendar. Contact the address above to request review, correction, or deletion. Deletion here does not automatically remove records independently held by providers.
Scope
This notice covers the booking integration. Other website forms and services are outside its scope. Updates will be published on this page.