Skip to main content

Yesss! You're one of the first to try Timing - perks included 😄😄

Timing
Timing

🔒 Privacy Policy

Last updated: August 1, 2026

1. Introduction

Welcome to the Timing Privacy Policy. We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you use our booking platform. By using Timing, you agree to the practices described in this policy. If you do not agree with this policy, please do not use our services.

2. Information We Collect

We collect various types of information to provide and improve our services: • Personal Information: Full name, email address, phone number, profile photo, date of birth, and gender. • Business Information: For service providers - business name, address, operating hours, services offered, and pricing. • Appointment Details: Appointment dates and times, selected services, preferred service provider, and appointment history. • Payment Information: Transaction details, payment history, and transaction identifiers (we do not store full credit card numbers). • Technical Information: Device type, operating system, app version, IP address, and unique device identifier. • Usage Data: In-app interactions, features used, screens viewed, and usage frequency. • Approximate Location: Coarse location derived from your IP address to set region, currency, and language (we do not collect precise or GPS device location).

3. How We Use Your Information

We use your information for the following purposes: • Providing appointment booking services and processing reservations. • Creating and managing your user account. • Sending appointment confirmations, reminders, and notifications. • Processing payments and issuing receipts. • Improving our services, user experience, and functionality. • Providing customer support and responding to your inquiries. • Sending updates, promotions, and marketing messages (only with your explicit prior consent, as required under anti-spam law including Israeli Amendment No. 40 to the Communications Law for commercial SMS; you can opt out at any time). • Analyzing usage patterns to improve the platform. • Preventing fraud, abuse, and ensuring platform security. • Complying with legal and regulatory requirements.

4. Information Sharing

We may share your information in the following circumstances: • With Service Providers: To enable appointment booking and service delivery. When you book an appointment, your contact details and appointment details are shared with the service provider. • With Third-Party Service Providers: We work with cloud services, payment processors, analytics, and messaging systems to operate the platform. • For Legal Requirements: When required by law, in response to legal proceedings, or to protect our rights. • With Your Consent: In any other case where we obtain your explicit consent. • In the Public Business Directory: business owners may choose (explicit opt-in, revocable at any time from the app) to display their business details: name, category, city and address, photos, description, service names, and rating, in a public business directory on our website. • With Search Engines: Each business's public booking page (app.timingapps.com/lp/...) is included by default in our sitemap for search engines, separately from and independently of the business directory. The owner can turn this off at any time using the "Show in search engines" switch in the app, after which we remove the page from our sitemap and ask search engines not to list it; the link itself keeps working. We have no control over third-party caches. When your details are shared with a business/service provider to fulfill a booking, that business acts as an independent controller of the information and processes it under its own privacy policy and practices; Timing is not responsible for how the business uses the information once shared. We do not sell your personal information to third parties.

5. Data Security

We implement industry-standard technical and organizational measures to protect your information: • Encryption of data in transit (TLS) and at rest. • Authentication managed by Firebase Authentication. • Role-based access controls and server-side database rules so businesses and staff can only reach data they are authorized to see. • Hosting on Google Cloud Platform / Firebase, which maintains its own recognized security certifications. While we strive to protect your information, no method of electronic transmission or storage is 100% secure and we cannot guarantee absolute security. We will notify you and, where required, the competent authority of a breach affecting your personal information as described in the Data Breach section.

6. Data Retention

We retain your personal information as long as your account is active or as needed to provide you with services. After account deletion, we retain certain information for the following periods: • Transaction records: 7 years (as required by tax laws). • Aggregated analytics data (anonymous): Indefinitely. • Backups: Up to 90 days. You may request deletion of your personal information at any time, subject to legal requirements for data retention.

7. Your Rights

You have the following rights regarding your personal information: • Right of Access: Request a copy of your personal information. • Right to Rectification: Correct inaccurate or incomplete information. • Right to Erasure: Request deletion of your personal information. • Right to Restriction: Restrict the processing of your information. • Right to Portability: Receive your information in a structured, common format. • Right to Object: Object to the processing of your information for certain purposes. • Right to Withdraw Consent: Withdraw previously given consent at any time. To exercise these rights, please contact us through the contact details below. We will respond to your request within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to improve your experience. Consent is asked for each purpose separately, not as a single bundle: • Essential Cookies: Required for basic platform functionality and to carry out something you asked for (such as making a booking). Always on and not subject to consent. • Analytics & session replay: Google Analytics and Microsoft Clarity, used to find faults and improve usability. Requires its own consent. • Advertising & remarketing: Meta Pixel. Requires its own consent; allowing analytics is not consent to advertising. On the marketing site, in the web app (app.timingapps.com), and on the booking pages (/lp), third-party tools: Meta Pixel and Microsoft Clarity session replay, are not loaded at all and make no request whatsoever to the third party until you actively accept the relevant purpose. Each surface offers only the purposes actually used there: the app and the booking pages run measurement alone, so consent given there covers measurement only and is never recorded as consent to advertising. Google Analytics loads for all visitors but in Consent Mode, all cookie storage and all advertising signals are disabled until you accept, so no Analytics cookie is written to your device beforehand. Refusing is available as easily as accepting, on the same screen and in the same number of taps. We retain a record of your choice: the purposes accepted, the consent version, and the time it was given. You can change or withdraw consent at any time: on the marketing site via 'Cookie settings' in the footer, on the booking page via 'Cookie settings' at the bottom of the page, and in the app via Profile → Cookie Settings. You can also manage cookies through your browser settings. Cookie-free audience measurement: we additionally count page views on our website using a first-party, cookie-free counter that stores nothing on your device and creates no profile. For each visit we derive a short-lived daily code from your IP address and browser type; it cannot be linked across days, the underlying data (IP and browser identity) is never stored, and the code is deleted within 72 hours. Only aggregate statistics are retained: pages, referral sources, country, and device type. Legal basis: our legitimate interest in measuring our own website. This data never leaves our systems and is never combined with account data. First-party marketing measurement: we store a random visitor identifier of our own on your device (the 'tv_id' cookie, lasting up to two years) together with the campaign details you arrived through, utm_source/medium/campaign and advertising click identifiers (Meta's fbclid, Google Ads' gclid/gbraid/wbraid). It serves one purpose: knowing which campaigns bring businesses that actually sign up. The identifier is random, contains no name, email or phone number, is never sold, and is never shared with any third party for advertising. If you open an account, the identifier and campaign are saved on your business profile so the signup can be traced to its source. Legal basis: our legitimate interest in measuring our own marketing. You can delete this at any time by clearing your browser cookies, or by contacting support@timingapps.com.

8b. Advertising Messages and Opt-Out

Advertising SMS is sent only to recipients who gave prior, explicit, recorded consent, as required by section 30A of the Communications Law (the Israeli "Anti-Spam Law", Amendment 40). An absent flag is not consent: a customer who never opted in is excluded from the send. Every advertising message carries the word "פרסומת" at its start, the sending business's name and a way to contact it, and a direct removal link. Following that link opens a page where a phone number can be entered and permanently removed from that business's mailing list. The removal is recorded and honoured even if the customer record is later recreated (for example by a file import). Operational messages about an appointment you made: confirmation, reminder, change, or cancellation: are not advertising, do not require marketing consent, and continue after a removal. To stop those, contact the business or us. A business owner using the platform to message its own clients is the advertiser for the purposes of the law and is responsible for holding the consent; Timing provides the technical controls: consent-based filtering, the mandatory message markings, and the removal link.

9. Third-Party Services

We use the following third-party services: • Google Firebase: For authentication, database, storage, and analytics. • Google Cloud Platform: For data storage and processing. • Grow (grow.business / Meshulam): For processing web subscription purchases, and - when the business owner enables it - for processing client payments for appointments through the business's own Grow account. Funds settle directly to the business's account; Timing does not hold funds and does not access card or bank details. • Apple App Store and Google Play Billing: For in-app purchases on iOS and Android. • Bit: For processing appointment payments (when enabled). • WhatsApp Business API (Meta): For sending appointment confirmations and reminders to phone numbers you or your customers provide, only where messaging is enabled and consented. • Email Services: For sending notifications and reminders. • Google Analytics: For usage analysis and service improvement. • Firebase Crashlytics: For crash reporting on iOS and Android apps. • Sentry: For error monitoring and human-readable stack traces from the web app. Your Firebase User ID is attached to error events to aid diagnosis. • Microsoft Clarity: For anonymous session replays and UI heatmaps on the website and web app, to identify usability issues. • IP Geolocation (ipapi.co, ip-api.com): to detect your country from your IP address and set region, currency, and language on our website. Each third-party service has its own privacy policy, and we recommend reviewing them. We only select providers that meet strict security and privacy standards.

10. Google User Data

Timing accesses Google user data only when you choose to use Google-powered features. For Google Sign-In, we receive and use your Google account identifier, email address, display name, profile photo, and authentication tokens through Firebase Authentication so we can create or sign you in to your Timing account, link staff/business access by email, prevent duplicate accounts, secure your session, and provide support. For Google Calendar, after your explicit authorization, we request calendar.readonly to list calendars you can select and calendar.events to create, update, delete, and read events needed for two-way appointment sync and optional import of external calendar events as availability blocks. Calendar data we may access includes calendar IDs/names, event IDs, titles, descriptions, locations, start/end times, time zone, busy/free status, all-day status, and app-specific private extended properties used to identify Timing-created events and business/staff scope. We use Google Calendar data only to provide calendar sync, restore sync state, show calendar choices, keep Timing appointments aligned with the selected Google calendar, and optionally import selected external calendar events as private availability blocks. Imported external events are stored in Timing/Firebase with the event ID, selected calendar ID, title, description/notes, start/end time, all-day status, busy/free blocking status, and sync metadata so your availability can be calculated and updated. Timing-created appointments may be written to your selected Google calendar with appointment title, description, location, start/end time, business/staff identifiers in private extended properties, and the Google event ID stored in Timing. We do not use Google Calendar data for advertising, sell it, or use it to train AI models. Google user data is stored in Firebase/Google Cloud and, for the selected calendar preference and short-lived web Calendar API access token, in secure local storage on your device/browser. The cached access token is used only to restore Calendar API access after a web page reload, expires after about 50 minutes, and is cleared when you disconnect or sign out. Google OAuth credentials are otherwise handled by Google Sign-In/Firebase SDKs. We do not share Google user data except with service providers that operate Timing infrastructure, with the business/staff/customer participants necessary to display or manage bookings, when required by law, or with your explicit consent. You can disconnect Google Calendar in the app, revoke access from your Google Account permissions page, sign out, or request account/data deletion by contacting support@timingapps.com. Timing's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

11. Children's Privacy

Timing is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you discover that a child under 16 has provided us with personal information, please contact us immediately and we will delete such information from our systems. If we discover that we have collected information from a child under 16 without parental consent, we will take steps to delete the information as soon as possible.

12. Changes to Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by: • Posting the updated policy in the app. • Sending an email or in-app notification. • Updating the 'Last Updated' date at the top of the policy. Your continued use of Timing after such changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us:

📧 Email: support@timingapps.com

📍 Address: Timing, Tel Aviv, Israel

📞 Phone: +972-52-331-6433

🏢 Legal entity: Omer Rahmany

14. GDPR Compliance

Timing is committed to compliance with the European Union's General Data Protection Regulation (GDPR). As part of this commitment: • We process personal information only on a legal basis (consent, contract performance, legitimate interest, or legal obligation). • We implement the data minimization principle - collecting only information necessary for our purposes. • We ensure full transparency regarding information collection and use. • We enable you to exercise all your rights under GDPR. • In Israel we comply with the Privacy Protection Law, 1981, including Amendment No. 13 (in effect since August 2025). • Where a business uploads personal data about its own clients, that business is the controller and Timing acts as its processor under the Data Processing section of our Terms of Use. • For any privacy request, contact support@timingapps.com; EU/EEA/UK users may also lodge a complaint with their local supervisory authority.

15. Data Breach

In the event of a personal-data breach: • Where legally required, we will notify the competent supervisory authority without undue delay - and within 72 hours where GDPR applies, to the extent feasible. • We will notify affected users without undue delay where the breach is likely to affect their rights. • We will take immediate steps to minimize damage and prevent further breaches. • We will document the incident and conduct a thorough investigation. We maintain reasonable measures to detect, investigate, and respond to security incidents.

16. International Data Transfer

Your information may be transferred and processed in countries outside your country of residence, including countries that may not provide the same level of data protection. When we transfer information internationally, we ensure: • Our infrastructure providers (Google Cloud / Firebase) process data under data processing agreements that incorporate the European Commission's Standard Contractual Clauses (SCCs) for international transfers where applicable. • Implementation of appropriate technical and organizational safeguards. Your information is primarily stored on Google Cloud / Firebase servers, including in the EU and other regions.

17. Automated Decision-Making

Timing may use automated processing for: • Personalized recommendations for services and service providers. • Fraud detection and prevention. • Optimization of appointment times and schedules. We do not make automated decisions with legal or significant impact on you without human involvement. You have the right to request human intervention, express your point of view, and contest automated decisions.