Privacy & Data Protection Policy

Last updated: 8 August 2026

This policy explains how personal information is collected, used, and protected when customers use VCMP Solo booking pages operated by businesses using the VCMP platform.

1. Platform operator

VCMP Solo is operated by StartMadeSimple Ltd. Businesses using the platform manage their own customer bookings and are generally responsible for how they use customer information.

2. Information collected

Booking pages may collect customer names, email addresses, phone numbers, selected services, preferred staff, appointment dates, appointment times, booking notes, and related booking information.

3. How information is used

Information is used for booking management, appointment confirmation, appointment changes, customer communication, operational administration, security, fraud prevention, and legal compliance.

4. Data controller and processor roles

The business receiving the booking request is generally the data controller for customer booking information. StartMadeSimple Ltd generally acts as a processor or service provider by operating the technical platform.

5. Consent and booking communication

By submitting a booking request, customers consent to their details being used for booking management, appointment confirmation, appointment changes, and related booking communication. Marketing messages should only be sent where a lawful basis exists.

6. International privacy rights

Depending on location, customers may have rights under UK GDPR, EU GDPR, United States state privacy laws, Canadian privacy laws, Australian privacy law, New Zealand privacy law, and other applicable legislation. These rights may include access, correction, deletion, restriction, objection, portability, and complaint rights.

7. Security

VCMP Solo uses reasonable technical and organisational measures to protect data, including secure connections, account authentication, tenant separation, access controls, validation, and operational monitoring. No online system can be guaranteed completely secure.

8. Retention

Booking information is retained only as long as reasonably necessary for booking operations, legal obligations, dispute handling, security, fraud prevention, and platform continuity.

9. Google Calendar and Google user data

Google Calendar access is optional. VCMP Solo accesses Google Calendar data only after a user explicitly chooses to connect their Google Calendar and grants the requested permission.

VCMP accesses and uses Google Calendar event data solely to provide the Google Calendar integration and booking functionality requested by the user. This data is used only to:

  • read event times needed to identify unavailable periods;
  • prevent conflicting customer bookings;
  • create Google Calendar events for bookings made through VCMP Solo;
  • update Google Calendar events when the corresponding VCMP booking changes;
  • delete Google Calendar events when the corresponding VCMP booking is cancelled or removed; and
  • maintain the calendar synchronisation explicitly authorised by the user.

VCMP does not use Google Calendar or other Google Workspace API data for any unrelated VCMP feature or purpose. Google user data is not used for advertising, marketing, profiling, credit decisions, lending, or data brokerage.

VCMP does not sell Google user data. VCMP does not transfer or disclose Google Calendar or other Google Workspace API data to advertisers, data brokers, information resellers, or other unrelated third parties.

VCMP uses OpenAI for separate AI-powered features within the VCMP platform. Google Calendar and other Google Workspace API data is not transferred to OpenAI or to any other artificial intelligence or machine-learning provider. Google Workspace API data is not included in AI prompts and is not processed by VCMP's AI functionality.

VCMP does not use raw, derived, aggregated, anonymised, or de-identified Google Workspace API data to develop, train, or improve general-purpose or non-personalised artificial intelligence or machine-learning models. Google Workspace API data is not transferred to third-party AI or machine-learning services for inference, training, model development, or model improvement.

Google OAuth access and refresh credentials are stored only while the Google Calendar connection is active and only so VCMP can provide the authorised Google Calendar synchronisation functionality. When the user disconnects Google Calendar from VCMP Solo, VCMP clears its stored Google OAuth access token, refresh token, and token expiry information and deactivates the connection. Future access requires the user to reconnect and authorise Google Calendar again.

Disconnecting Google Calendar stops future VCMP access to the connected Google Calendar. VCMP booking records created and maintained independently within VCMP may remain subject to the normal retention requirements described in this policy. Users may request deletion of eligible personal data by contacting privacy@startsimple.cc.

Google user data is protected using technical and organisational safeguards including secure connections, authenticated access, tenant separation, access controls, validation, and operational monitoring.

VCMP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10. SMS communications

Customers who provide a phone number when making a booking may receive transactional SMS notifications relating to their appointment, including confirmations, reminders, cancellations, rescheduling notices, booking updates, and deposit notifications.

Message frequency varies based on booking activity. Message and data rates may apply. Customers may reply STOP to opt out of SMS messages and HELP for assistance where supported.

SMS consent is not shared with third parties or affiliates for marketing purposes.

11. Contact

Privacy enquiries may be sent to privacy@startsimple.cc.