Privacy information
A plain-language overview of information handled when organizations use Ordovola to coordinate appointments, pickups, returns and delays.
- Last updated
- 29 Aug 2026
About this privacy information
Ordovola is scheduling software used by organizations to coordinate appointments and rentals with their customers. This page explains, in practical terms, what information the current service handles and how it is used.
Information handled by Ordovola
- Account information: name, email address, Firebase user identifier, sign-in provider information and authentication state.
- Organization information: organization name, member role and business presentation settings such as timezone, currency, language and date preferences.
- Reservation information: catalogue item, customer name and optional contact details, scheduled times, notes, optional price and cancellation state entered by an authorized business user.
- Public confirmation responses: an on-time or delay response for an appointment, pickup or return, authorized by a phase-specific confirmation link.
- Technical information: Firebase Hosting, Auth, Firestore and Cloud Functions may process operational request, security and error logs. Provider logs may include details such as timestamps, IP addresses, user agents and request metadata.
Why information is used
Information is used to:
- authenticate users and protect organization workspaces;
- create and operate schedules, reservations and catalogue items;
- show delays, conflicts, pickups and returns;
- record customer timing responses requested by a business;
- maintain service reliability, investigate errors and prevent abuse;
- respond to support, correction, access or deletion requests.
The applicable legal basis depends on the relationship between Ordovola, the organization using the service and the individual concerned, as well as applicable law. An organization using Ordovola remains responsible for the privacy information and legal basis applicable to the customer data it enters.
Who can receive information
Authorized members of the relevant organization can access its workspace information. Customers using a public confirmation link see only privacy-minimized schedule information for that link. Google Firebase provides authentication, database, hosting and serverless infrastructure. With analytics consent, Google Analytics for Firebase receives limited product-usage events. When an entitled organization enables automated confirmations, Resend processes the customer email address and transactional email, while Twilio processes a valid international phone number and approved transactional WhatsApp template needed to deliver the existing confirmation link. Provider processing locations and safeguards are governed by the configured services and applicable provider agreements.
Optional product analytics
Ordovola uses Firebase / Google Analytics only after you allow analytics. It measures limited product actions and navigation so the service can be understood and improved. Core Ordovola features work without analytics. Reservation contact details, notes, confirmation messages, public confirmation tokens and billing identifiers are not intentionally sent as analytics events. Advertising, remarketing and ad-personalization features are not introduced. You can change this choice on the Cookies and browser storage page; disabling it stops future collection but does not retroactively delete data already collected by Google Analytics.
Retention and deletion
Ordovola keeps account, organization and reservation records while they are needed to provide the service or until they are changed or removed through an authorized process. Reservations use soft cancellation and remain available as operational history. Some records may be retained longer where needed for security, dispute resolution or legal obligations. Firebase operational logs follow provider and project retention settings.
Your privacy requests
Depending on applicable law and the roles of the organization using Ordovola, individuals may have rights to request access, correction, deletion, restriction, objection or data portability. Identity and authority may need to be verified before a request is fulfilled.
Send a privacy request to support@ordovola.com. Describe the request and the organization it concerns. Ordovola may ask for information needed to verify identity, authority and the relevant workspace before acting on it.
Security and public links
Ordovola uses Firebase Authentication, organization-scoped Firestore rules and token-validated Cloud Functions. Public confirmation URLs are reusable bearer links: anyone who receives a valid link can use its limited confirmation flow. Businesses and customers should treat those links as sensitive. No technical measure eliminates every risk.
Changes to this information
Ordovola will update this information when its services, providers, retention practices or legal obligations materially change. The latest revision date appears at the top of this page.