Last updated:
TimeNest is a platform for managing appointments, bookings, and WhatsApp reminders.
This Privacy Policy describes how TimeNest collects, uses, stores, shares, and protects the personal information of people who use the platform, including features that rely on WhatsApp Business.
TimeNest, a service operated by Eder Jahziel Calderilla Rodríguez, is the party responsible for processing the data described in this Privacy Policy. The service is operated from Mexico and available at timenest.app. For any question about this policy or about your personal data, write to us at contacto@timenest.app.
1. Who this policy applies to
TimeNest lets service businesses — barbershops, salons, studios, clinics, and similar — publish a booking page, manage their calendar, and communicate with their customers over WhatsApp.
This policy distinguishes between two groups:
- Business users: the business owner and their team, who create an account and sign in to TimeNest. For that data, TimeNest acts as the data controller.
- People who book: anyone who schedules an appointment on a business's public page or receives its WhatsApp messages. For that data, the business is the controller; TimeNest processes it solely on that business's behalf and under its instructions, as a data processor.
If you booked an appointment and want to exercise your rights over that information, contact the business you booked with first. You can also write to us at contacto@timenest.app and we will help route your request.
2. Information we collect
We collect only what is necessary to operate the platform. Depending on how it is used, this may include:
Business account
- Name and email address.
- Profile photo, if you upload one or sign in with Google.
- Sign-in method used: email and password, or a Google account.
- Role within the business (owner, manager, or staff) and preferred language.
Business profile
- Business name, business type, and description.
- Logo, cover image, and gallery images.
- Address, city, postal code, and country; public contact phone and email.
- Website and social media profiles.
- Branches, business hours, absences, and calendar exceptions.
- Services, durations, and prices, along with the team of professionals.
People who book
- Name and mobile phone number.
- Email address and notes for the business, both optional.
- The name of the person attending, when the appointment is booked for someone else.
- The language used to make the booking.
Appointments
- Date, time, time zone, service, professional, and branch.
- Appointment status and attendance confirmation status.
- The reference price of the booked service. TimeNest does not charge that amount.
WhatsApp messaging
- Phone numbers of the sending business and of the recipient.
- The WhatsApp profile name of whoever writes to us.
- The content of the messages we send and of the replies we receive.
- Message identifiers assigned by Meta and delivery status: sent, delivered, read, or failed.
- Error codes and descriptions when a message cannot be delivered.
Technical information
- Service access logs: IP address, request date and time, and basic browser or device data.
- These are generated automatically and used for security and troubleshooting, not for profiling.
Storage in your browser
- The private link used to view or cancel your appointment, so you do not have to look it up again.
- Usage preferences: language, visual theme, and the branch selected in the dashboard.
- This is functional storage only. We do not use advertising cookies, tracking pixels, or third-party analytics tools.
What we do not collect. We neither request nor store bank card details, and we do not process payments: services are paid for directly with the business. We do not store passwords either, since authentication is handled by Google Firebase Authentication. We do not collect precise location, contacts, or sensitive personal data.
3. How we use the information
We use the information we collect to:
- Create and manage sign-in accounts for the business and its team.
- Publish the business's booking page and let its customers schedule online.
- Record, display, and manage appointments, availability, and schedules.
- Send booking confirmations, reminders, attendance confirmation requests, and cancellation notices over WhatsApp.
- Process replies to those messages in order to update the appointment status.
- Record the delivery status of each message to diagnose delivery failures.
- Let whoever booked view or cancel their appointment through a private link.
- Invite team members to the business account and manage their permissions.
- Provide technical support and respond to requests.
- Keep the platform secure and prevent fraud, abuse, or unauthorized access.
- Comply with applicable legal obligations.
We do not use personal information for purposes other than those described without informing you first and, where the law requires it, obtaining your consent. We do not use it for advertising or to build commercial profiles.
4. WhatsApp and Meta
TimeNest uses the WhatsApp Business Platform (Cloud API) from Meta Platforms, Inc. to send and receive appointment-related messages.
- Automated messages are sent using templates previously approved by Meta: booking confirmation, appointment reminder, attendance confirmation request, cancellation notice, and post-appointment thank-you.
- To send them we share with Meta the recipient's phone number and the data the template requires: name, business, service, professional, date and time, and — where applicable — the link to manage the appointment.
- Meta returns a message identifier and its status — sent, delivered, read, or failed — which we store to know whether the notification arrived and to troubleshoot errors.
- When you reply to a message or tap one of its buttons, we receive and store that reply along with your number, your WhatsApp profile name, and the message date, in order to update your appointment status.
You receive these messages because you booked an appointment with a business that uses TimeNest. Any processing Meta and WhatsApp carry out on their own account is governed by their own terms and policies: WhatsApp Privacy Policy and Meta Privacy Policy.
How to stop receiving messages. You can ask the business you booked with directly, block the number in WhatsApp, or write to us at contacto@timenest.app with your number and the name of the business. Opting out of notifications does not cancel your appointments: use the management link or contact the business for that.
5. Who we share information with
We share information only where necessary to operate the service, with:
- The business you booked with: receives your name, phone number, email if you provided one, and your appointment details, because it needs them to serve you.
- Meta Platforms, Inc. / WhatsApp: to send and receive the messages described above. See their policy.
- Google LLC (Firebase Authentication): manages sign-in for business accounts; it receives the email address and, if you choose that method, the details of the Google account you sign in with. See their policy.
- Amazon Web Services, Inc.: provides the infrastructure that runs the application and stores the database and files — logos, business images, and profile photos. See their policy.
- Competent authorities: where a legal obligation or a duly founded request exists, or where necessary to defend legal rights.
These providers receive only the information needed to deliver their service and are bound by their own legal and contractual obligations. We do not sell, rent, or trade personal information, and we do not share it with advertisers.
6. Where information is stored
The platform runs on Amazon Web Services infrastructure located in the United States. The Meta and Google services we use also operate from the United States and other countries where those companies have a presence.
This involves an international transfer of personal data. By using TimeNest you accept that transfer, which takes place under each provider's contractual commitments and security measures, and solely for the purposes described in this policy.
7. Data retention
We keep information only for as long as necessary to provide the service, keep the platform secure, resolve disputes, and comply with legal obligations:
- Business account and profile: for as long as the account remains active.
- Customers and appointments: for as long as the business account remains active, since they make up its operating history.
- WhatsApp messaging records (content, delivery statuses, and errors): up to 24 months from the date sent or received.
- Technical access logs: up to 12 months.
Once information is no longer necessary, we delete it or anonymize it so that it can no longer be linked to an identifiable person.
8. Data deletion
You can request deletion of your personal data at any time by writing to contacto@timenest.app with the subject “Data deletion”.
If you have a TimeNest business account
- Write to us from the email address you used to create the account and include the business name.
- We will delete your sign-in account, the business profile and branches, its services and team, its customer information, the appointment history, and the associated messaging records.
If you booked an appointment with a business
- You can request it directly from the business you booked with, which is the controller of that data.
- You can also write to us at contacto@timenest.app with the phone number you booked with and the business name, so we can locate your information and coordinate deletion with them.
Timelines
- We acknowledge the request within 5 business days.
- We complete deletion within a maximum of 30 calendar days once your identity has been verified.
- Backup copies are overwritten within a further period of up to 90 days.
We may temporarily retain certain information where a legal obligation exists, where it is necessary to prevent fraud or abuse, or to defend legal claims. Note also that messages already delivered remain on the recipient's device and in WhatsApp's systems under Meta's policies, outside our control.
9. Your rights
Under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties, you may exercise your ARCO rights at any time:
- Access: find out what personal data we hold about you and what we use it for.
- Rectification: correct inaccurate or incomplete data.
- Cancellation: ask us to delete your data when you consider it is not required.
- Objection: object to the use of your data for specific purposes.
- You may also withdraw your consent and limit the use or disclosure of your information.
To exercise them, write to contacto@timenest.app including your full name and a way to reach you, a clear description of your request, and a document proving your identity or your legal authority to act.
We respond within a maximum of 20 business days and, where the request is well founded, act on it within the following 15 business days. If your request concerns an appointment booked with a business, we will route it to that business as the controller of the data. If you believe your request was not handled properly, you may file a complaint with the competent data protection authority in Mexico.
10. Security
We apply reasonable administrative and technical measures to protect information against unauthorized access, alteration, disclosure, loss, or use. Among others:
- All communication with the platform is encrypted using HTTPS/TLS.
- We do not store passwords: authentication is handled by Google Firebase Authentication.
- The link you use to view or cancel your appointment is stored as a SHA-256 hash; we never keep the token in plain text.
- Access to information is segmented by business and by role: each account can only see data belonging to its own business.
- Profile photos are kept in private storage and served only through temporary signed links.
No method of electronic transmission or storage can guarantee absolute security. If we detect an incident that significantly affects your personal data, we will inform you and notify the authorities where applicable.
11. Minors
TimeNest is intended for people aged 18 or over, and we do not create accounts for minors.
When an appointment is booked for a minor, the person booking must be their parent or legal guardian and should provide only the name needed to identify the appointment. If we detect that we have received a minor's data without that basis, we will delete it.
12. Changes to this policy
We may update this Privacy Policy when our services, the applicable legal requirements, or our data handling practices change.
The current version will always be available on this page, showing the date it was last modified. If a change is substantial, we will notify active accounts before it takes effect.
13. Contact
For any question about this Privacy Policy or about how we handle your personal information, write to us at contacto@timenest.app.