Legal
Privacy Policy
Effective September 10, 2026
MainLodge is made by SkyTechSport Inc. ("SkyTechSport", "we", "us"). This policy explains what personal information we collect through the MainLodge website (the "Site") and the MainLodge software service (the "Service"), how we use and share it, and the choices and rights you have. We write it in plain language on purpose; the short version is that we collect what we need to run a booking and business-management product for studios, we do not sell personal information, and we never see your payment card number.
1. Who this covers
Different people interact with MainLodge in different ways, and our role differs for each:
- Visitors and prospects — people who browse the Site, request a demo, or send us a feature request. We decide how this information is used; we are the "controller" (or "business").
- Studio staff — owners, managers, front-desk staff and instructors who sign in to the Service. We are the controller for account and usage information about staff.
- Studio clients — the members and customers of a studio that uses MainLodge. Their information (bookings, memberships, waivers, messages, purchase history) belongs to the studio, which decides how it is used. The studio is the controller; we process it only on the studio's instructions as its "processor" or "service provider". If you are a client of a studio, the studio's own privacy policy governs, and requests about your information should go to the studio first. We help studios respond to such requests.
2. Information we collect
Information you give us.
- When you request a demo or a feature: your name, email address, phone number, studio name, and the message you write.
- When a studio creates an account: the business's name, address, time zone and billing details, and each staff member's name, email address, role and password (stored only as a one-way hash) or sign-in provider identity.
- When a studio enters or its clients submit information through the Service: client contact details, dates of birth where a studio collects them, appointment and attendance history, membership and credit balances, purchases, gift cards, notes, signed waivers (which may include emergency-contact and health declarations a studio chooses to ask for), and messages exchanged with the studio.
- When you contact support: the content of your request and any attachments.
Information collected automatically. Server logs record IP address, browser type, device information, pages visited, referring page, and timestamps. Within the Service we record actions taken by staff (who booked, changed, refunded or exported what, and when) — this audit trail is a core feature that protects studios and their clients. Online booking pages record the referring link so a studio can attribute a booking to a campaign; this uses a first-party identifier, not advertising tracking.
Information from other sources. If a studio connects a third-party service — for example a payment processor or a calendar — we receive the information needed to make that connection work, such as a payment status or a busy/free time block. If you sign in with Google, we receive your name, email address and profile picture from Google.
We do not intentionally collect precise geolocation, biometric identifiers or government ID numbers, and we ask studios not to enter them.
3. How we use information
- To provide, operate, secure and support the Service: schedule appointments and classes, manage memberships and credits, process sales through our payment partner, send the confirmations and reminders a studio configures, and keep the audit trail.
- To respond to demo and feature requests and to communicate with prospects and customers about the Service, including service announcements and billing.
- To detect, prevent and investigate fraud, abuse, security incidents and violations of our Terms.
- To improve MainLodge — understanding which features are used and where errors occur — using aggregated or de-identified data wherever possible.
- To comply with law, enforce our agreements, and protect the rights, property and safety of SkyTechSport, our customers and others.
We do not use Customer Data to train machine-learning models for other customers, and we do not use it for advertising.
4. Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service to a studio and its staff); legitimate interests (securing the Service, improving it, responding to inquiries, and marketing to business prospects in a way they would reasonably expect); consent where we ask for it, for example for optional marketing email, which you can withdraw at any time; and legal obligation (tax, accounting and responding to lawful requests). For studio clients' information, the studio determines the legal basis and we act on its instructions.
5. How we share information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We share it only:
- With service providers that process it on our behalf under contracts that restrict its use, listed below.
- With the studio whose client you are — all information you provide through a studio's booking page, portal or waiver is visible to that studio's authorized staff.
- With third parties a studio chooses to connect, such as its payment processor or calendar, to the extent needed to provide that integration.
- For legal reasons — to comply with law or a valid legal process, to enforce our agreements, or to protect rights, safety and property. Where permitted we will notify the affected studio before disclosing its data.
- In a business transfer — if SkyTechSport is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction under this policy's protections.
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure | Hosting, storage, backups and networking for the ServiceUnited States / European Union | United States / European Union |
| Stripe | Payment processing, card storage and payouts for studios that connect a Stripe accountUnited States | United States |
| Optional "Sign in with Google" for staff and optional Google Calendar synchronizationUnited States | United States | |
| SMS delivery provider | Appointment reminders and messages a studio sends to its clients by textUnited States | United States |
| Email delivery provider | Transactional and studio-authored email to staff and clientsUnited States / European Union | United States / European Union |
| Cloudflare | Bot protection (Turnstile) on public forms and edge securityUnited States | United States |
Studios may request the current named list of sub-processors, and we will give notice of additions so a studio can object.
6. Cookies and similar technologies
The Site and the Service use only cookies and browser storage that are necessary to work:
- a session cookie that keeps staff signed in to the Service;
- a security token from Cloudflare Turnstile that tells our public forms a request came from a person, not a script;
- local preferences such as the last calendar view you opened, stored in your own browser.
The Site uses Google Analytics 4 to understand which pages are read and where visitors come from, configured without advertising features or ad personalization and with IP anonymization. It sets first-party _ga cookies for up to two years. We do not set advertising or cross-site tracking cookies. You can opt out with the Google Analytics opt-out add-on or by clearing cookies in your browser; the Service will sign you out.
7. Payment information
Payment cards are handled by our payment partner, Stripe, which is certified to PCI DSS Level 1. Card numbers are entered directly into Stripe's secure fields or terminals and are never transmitted to or stored on MainLodge servers. We store only a payment token, the card's last four digits, brand and expiry so a studio can recognize a saved card. Stripe's privacy policy applies to its processing of payment information.
8. Email and text messages
Studios use the Service to send appointment confirmations, reminders and other messages to their clients. The studio decides who receives what; we are the delivery mechanism. Text messages are sent only to numbers whose owners have agreed to receive them from the studio, and every marketing message includes a way to stop future messages (reply STOP to texts; use the unsubscribe link in email). Message and data rates from your carrier may apply. Transactional messages about a booking you made may still be sent after you opt out of marketing.
We send our own email to prospects and customers about demos, billing, security and product changes. You can unsubscribe from non-essential email at any time.
9. How long we keep information
- Demo and feature requests: up to 24 months after our last contact, unless you become a customer or ask us to delete them sooner.
- Studio and staff account information: for the life of the account and 30 days after termination, so the studio can export its data; then deleted except from routine backups, which expire on their normal schedule (currently within 35 days).
- Studio clients' information: for as long as the studio keeps it in the Service. Studios can delete client records at any time and are responsible for their own retention rules. Signed waivers are kept for as long as the studio instructs, since they may be legal evidence.
- Financial records and audit logs: as required by tax, accounting and legal obligations, typically seven years.
- Server logs: up to 90 days, longer if needed for a security investigation.
10. Security
We protect information with measures appropriate to its sensitivity: encryption in transit (TLS) and at rest, tenant isolation so one studio can never see another's data, role-based permissions inside each studio, hashed passwords, optional single sign-on, regular encrypted backups, access logging, and an append-only audit trail of changes to bookings, credits, payments and permissions. Sensitive fields such as waiver health declarations are restricted to roles that need them and are excluded from the anonymized copies we use for testing. No system is perfectly secure; if we learn of a breach affecting your information we will notify you and any regulator as required by law.
11. Your privacy rights
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; delete it; receive a copy in a portable format; object to or restrict certain processing; withdraw consent where processing is based on consent; and complain to a supervisory authority. To exercise these rights, email us at the address in section 16. We will verify your identity — usually by confirming control of the email address on file — and respond within the time required by law (45 days in California, one month under the GDPR, extendable where permitted). You may use an authorized agent; we will ask for proof of authorization. We will not discriminate against you for exercising your rights.
If you are a studio client, please contact the studio first; it controls your information and has tools in the Service to fulfil your request. If you contact us directly, we will forward your request to the studio and help it respond.
12. California residents
Under the California Consumer Privacy Act as amended by the CPRA, the categories of personal information we have collected in the preceding 12 months are: identifiers (name, email, phone, IP address); commercial information (purchases, memberships); internet activity (pages visited, actions in the Service); professional information (studio and role); and, only where a studio's waiver requests it, sensitive personal information (health declarations). We collect it from you, from your studio, and automatically, for the purposes in section 3, and disclose it to service providers for business purposes as described in section 5. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes other than providing the Service. You have the rights to know, delete, correct and to limit use of sensitive personal information, exercisable as described in section 11.
13. International transfers
SkyTechSport is based in the United States, and information is processed in the United States and, for some infrastructure, in the European Union. Where we transfer personal information of people in the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful mechanism, and we require the same of our sub-processors.
14. Children
The Site and staff accounts are not directed to anyone under 16, and we do not knowingly collect their information. Studios may serve minors; in that case the studio is responsible for obtaining a parent's or guardian's consent, the Service flags client records with a date of birth under 18 as minors, and waivers for minors are signed by a guardian. If you believe we have collected a child's information without appropriate consent, contact us and we will delete it.
15. Changes to this policy
We will update this policy when our practices change. The effective date at the top tells you when it was last revised. For material changes we will notify studio account owners by email or in the Service before the change takes effect, and we keep prior versions available on request.
16. Contact us
Privacy inquiries and rights requests:
SkyTechSport Inc.
8954 Ellis Ave., Los Angeles, CA 90034, United States
team@mainlodge.io