Privacy Policy
Last updated September 26, 2026
This policy explains what personal information Tovira collects, how we use it, and the choices and rights you have, including under California law.
The short version
- We collect what's needed to run bookings: business account details, and clients' names, phone numbers, optional emails and appointment details.
- We never sell or share personal information for advertising, and we don't show ads.
- Clients' booking information belongs to the business they book with; we process it on the business's behalf.
- One essential sign-in cookie, no tracking cookies.
- You can ask to see, correct or delete your information by emailing info@mb3techs.com.
This summary helps you read the full text below; it doesn't replace it.
1. Who we are and our role
Tovira is an online booking service operated by mb3techs ("mb3techs", "we", "us"). We handle personal information in two different roles:
- For businesses and their team members who have a Tovira account, we decide how account information is used. This policy explains that use.
- For clients who book with a business, the business decides how their information is used and we process it on the business's behalf, as its service provider. The business's own privacy notice applies too, and it is the best place to send requests about your data (see section 8).
2. Information we collect
From businesses and team members:
- Account details: name, email address, optional phone number, and your password (stored only as a secure one-way hash, never in readable form).
- Business details you publish: business name, booking page address, address, city, phone, email, description, time zone, currency, opening hours and services.
- Team details you add: staff names, job titles and optional email addresses and phone numbers.
- Settings and content: email wording, notification choices and similar preferences.
From clients who book:
- Name and phone number, and optionally an email address and a note to the business.
- Appointment details: service, team member, date and time, price, and the history of changes and cancellations.
- Notes a business adds about a client or a booking.
Please don't include sensitive information, such as health details, in booking notes unless the business needs it for your appointment.
Collected automatically from everyone:
- IP address and basic request information (browser type, pages requested, time), used to run the service, keep it secure and stop abuse such as password guessing. For rate limiting we store only a one-way hash of the IP address or email, and delete it within a day.
- Records of emails we send (for example, whether a confirmation was delivered).
- Records of administrative actions, such as a business being suspended, kept for security.
3. How we use information
- To provide the service: show booking pages, take and manage bookings, and run business dashboards.
- To send appointment messages on a business's behalf: confirmations, reminders, and notices of changes or cancellations, with a calendar invite.
- To send account messages: password resets, security alerts and important service updates.
- To keep the service safe: prevent fraud, spam and unauthorized access, and investigate misuse.
- To support you when you contact us, and to fix and improve the service.
- To meet legal obligations and enforce our Terms.
4. We don't sell or share personal information
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined in California law. We don't show ads, and we don't use a business's client list to market to its clients.
We don't use personal information to train artificial intelligence models, and we don't make decisions with legal or similarly significant effects about anyone based solely on automated processing.
5. Who we disclose information to
- The business you book with. When you book, the business receives your details and booking.
- Service providers who help us run Tovira under contracts that limit their use of the data: Vercel (website hosting), Supabase (database hosting) and Resend (email delivery). We'll update this list if we add providers, for example for text messages or payments.
- Legal and safety reasons: if the law requires it, or to protect the rights, property or safety of our users, the public or mb3techs.
- A business transfer: if mb3techs or Tovira is involved in a merger, acquisition or sale of assets, information may transfer as part of it, still protected by this policy.
7. Retention and security
Retention. We keep account and business data while the account is open. Client and booking records are kept for the business while it uses Tovira, so it can see booking history. When an account is closed, we delete or anonymize its data within a reasonable time, unless we need to keep some of it for legal, security or dispute reasons. Password reset links expire after 30 minutes and security counters are deleted within a day.
Security. We use HTTPS encryption for all traffic, hash passwords with bcrypt, store only hashes of reset links and security counters, separate each business's data, limit repeated sign-in attempts, and sign users out on all devices when a password changes. No system is perfectly secure, but we work hard to protect your information and will notify you and the authorities of a breach as the law requires.
8. Your privacy rights
Depending on where you live, you may have the right to:
- know what personal information we have about you and how we use it, and get a copy of it;
- correct information that is wrong;
- delete your information;
- opt out of the sale or sharing of your information (we don't sell or share it);
- not be treated differently for using any of these rights.
How to make a request. Businesses and team members can update most details in the app; for anything else, email info@mb3techs.com from the email address on your account. Clients: please contact the business you booked with first, since it controls your booking information. If you contact us, we'll pass your request to the business and help it respond.
We'll confirm your request within 10 business days and respond within 45 days (we may extend this by another 45 days if needed and will tell you why). To protect you, we'll verify your identity, usually by confirming details that match our records. You can use an authorized agent; we'll ask for proof that they are allowed to act for you.
If we decline your request, you can appeal by replying to our decision. We'll respond to an appeal within the time the law requires, and if you're still not satisfied you can contact your state attorney general.
9. California residents
This section gives the information required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"). In the last 12 months we have collected the following categories of personal information, for the purposes in section 3:
- Identifiers: name, email address, phone number, IP address. Source: you, the business you book with, and your device.
- Customer records: contact details and booking notes. Source: you and the business.
- Commercial information: services booked, prices and appointment history. Source: you and the business.
- Internet activity: basic request and security logs. Source: your device.
- Professional information: a team member's job title. Source: the business.
- Sensitive personal information: account passwords (stored as hashes), used only to sign you in. We don't use sensitive information to infer characteristics about you.
We disclose these categories for business purposes only to the recipients in section 5. We have not sold or shared personal information, and we don't sell or share the information of anyone under 16. We keep each category for the periods in section 7.
Residents of other U.S. states with privacy laws, such as Colorado, Connecticut, Oregon, Texas, Utah and Virginia, have similar rights and can use the process in section 8.
10. Children
Tovira is not intended for children under 13, and businesses must be run by adults. We don't knowingly collect personal information from children under 13. If a parent or guardian books for a child, only the parent's contact details should be used. If you believe a child has given us information, email info@mb3techs.com and we'll delete it.
11. Where information is stored
Our service providers store and process information in data centers in several countries, currently including the United States and India. Wherever it is processed, we protect it as this policy describes. If you are in the UK or European Economic Area, we rely on performing our contract with you, our legitimate interests in running a secure service, and your consent where required, and you may also complain to your local data protection authority.
12. Changes to this policy
We'll update this policy when our practices change and change the date at the top. If a change is significant, we'll tell businesses by email or in the app before it takes effect.
13. Contact
Questions or requests about privacy? Email info@mb3techs.com. Tovira is a product of mb3techs. See also our Terms of Service.
See also our Terms of Service.