Privacy Policy

Last updated: 28 July 2026

1 — Introduction

DayRounds is built to be privacy-quiet: we collect only what is strictly needed to plan your round, and nothing more. This policy explains which personal data we process, for what purposes, on what legal bases, with whom it is shared, how long it is kept and what your rights are. It applies to the DayRounds service and the associated public website.

2 — Data controller

The controller is OJR CONSULTING (EURL), 78 avenue des Champs-Élysées, 75008 Paris, France, publisher of DayRounds. For any data question, write to hello@dayrounds.com. OJR CONSULTING has not appointed a Data Protection Officer, as its size and processing do not require one; the address above is your point of contact.

3 — Our two roles: controller and processor

For data about you as a customer (account, workshop address, billing, usage), DayRounds is the controller. For the personal data of third parties you entrust to us through your calendar — appointment titles and addresses, which may identify your own customers — you are the controller and DayRounds acts as processor, only on your instructions, to build your round. This processing is detailed in the Data Processing Addendum (DPA) attached to the Terms.

4 — Data, purposes, legal bases and retention

We process the following categories of data.

Account and authentication: the email you sign in with (magic-link sign-in). Purpose: create and secure your access. Basis: performance of the contract. Retention: for the life of your account.

Workshop settings: workshop label and address geocoded to latitude/longitude, timezone, language, notification email and sending preferences. Purpose: compute and send your round. Basis: contract. Retention: life of the account.

Calendar connection: an iCal link or Google Calendar tokens, in both cases encrypted at rest. Purpose: read your appointments. Basis: contract. Retention: until disconnection or account deletion.

Calendar events and appointment addresses: times, titles and locations of your appointments, plus an address geocoding cache; may relate to third parties (your customers). Purpose: compute the optimal daily order. Basis: contract (and, for third-party data, processing carried out as a processor on your instructions). Retention: the computed daily round is purged automatically after 7 days; the address cache is kept as long as useful.

Billing: your Stripe customer and subscription identifiers, plan and status, trial and period dates; we never see or store your full card number. Purpose: manage your subscription and meet accounting obligations. Basis: contract and legal obligation. Retention: accounting records and invoices kept 10 years (Article L123-22 of the French Commercial Code).

Product usage and activity: pages viewed in the app, your calendar connection, general account activity, billing events, and last activity. Purpose: run, secure and improve the service. Basis: legitimate interest. Retention: as needed to operate the service.

Lifecycle emails: onboarding and end-of-trial messages. Purpose: help you get started and inform you. Basis: legitimate interest, with opt-out at any time. Retention: a record of the send is kept as needed.

Technical logging and monitoring: minimal technical data for operation, error detection and availability. Purpose: security, stability and diagnostics. Basis: legitimate interest. Retention: short, specific to each monitoring tool.

5 — Google Calendar access (Limited Use)

If you connect Google Calendar, DayRounds requests read-only access (the calendar.readonly scope) and the email of the connected account. It reads only what it needs to build your round: the times, titles and locations of your events, and only for the days you look at. It never modifies, creates or deletes anything in your calendar. DayRounds' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: this data is used solely to show you your round, is never sold, never used for advertising, and never used to train an AI or language model.

6 — Recipients and processors

To provide the service, we rely on technical providers acting as processors, each for a specific purpose. We never sell your data and use no third-party advertising trackers.

Neon Inc. — database hosting; data stored in the EU (AWS eu-central-1, Frankfurt, Germany); also provides authentication (Neon Auth).

Vercel Inc. — application hosting and CDN; United States, with edge delivery in Europe.

Stripe — payment processing and subscription management; Ireland and United States; PCI-DSS certified.

Resend — transactional and lifecycle emails; United States.

Google (Google Ireland / Google LLC) — read-only Google Calendar access when connected; EU and United States.

MapTiler — address geocoding and base maps; European Union.

OpenRouteService — travel times and routing; European Union (Germany).

Sentry — monitoring and error detection; hosted in the EU (Germany).

BetterStack — uptime monitoring and heartbeats.

cron-job.org — external scheduled trigger that runs your morning round.

Umami — public-site analytics, cookieless and with no personal data.

7 — International transfers

Your data is primarily stored and processed in the EU (Neon database in Frankfurt, Sentry monitoring in Germany, MapTiler and OpenRouteService). Some providers are established in, or may process data in, the United States (notably Vercel, Stripe, Resend and Google). These transfers outside the EU are governed by appropriate safeguards under Articles 44 et seq. GDPR: the European Commission's Standard Contractual Clauses and, where applicable, the provider's participation in the EU-U.S. Data Privacy Framework. You can obtain a copy or details of these safeguards from the contact address.

8 — Security

Sensitive secrets are encrypted at rest with AES-256-GCM: an iCal link is encrypted at rest, and a Google Calendar connection is kept as an access token encrypted the same way; in both cases we read your appointments without ever exposing the identifier itself. Traffic is encrypted in transit (TLS). Payments are handled by Stripe and never expose your card number to DayRounds.

9 — Cookies and analytics

The DayRounds app carries no advertising and does not track you. It uses only a strictly necessary cookie for your session and authentication; this technical cookie is essential and requires no consent. The public website uses Umami, a privacy-friendly analytics tool, cookieless and with no personal data. We never use your calendar data, addresses or account information to train an AI or language model.

10 — Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent where processing relies on it. You can delete your own account at any time from the app settings: this erases all your DayRounds data, cancels your Stripe subscription and removes your sign-in identity. You can also exercise your rights, or request deletion, by writing to hello@dayrounds.com. We respond within the periods set by the regulation. If you believe your rights are not respected, you may lodge a complaint with the French supervisory authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.

11 — Changes

We may update this policy. For significant changes we will inform you by appropriate means. The last-updated date appears at the top.