Invite-only beta Luneday is open to invited hosts while we finish building. Ask for an invite

Privacy policy

Last updated 15 September 2026.

Who we are

Luneday is run by Willie Tech Ltd, company number 15837598, registered at 18 Gold Tops, Casnewydd (Newport), United Kingdom, NP20 5WJ. We are registered with the Information Commissioner's Office. Write to us about privacy at hello@luneday.com.

Our two roles

If you sign up to Luneday to run bookings, we are the controller of your account data. If you book through an organisation's Luneday page, that organisation is the controller of your booking data and we process it on their behalf. Their own privacy policy, linked from their page, is the first place to look. We help them answer any request you make.

Data we process

  • Host accounts: name, email address, time zone, sign-in credentials (passkeys and two-factor secrets), and session records.
  • Organisations: name, address on the web, custom domain, plan and billing status.
  • Bookings, on the organisation's behalf: the booker's name, email address, phone number, answers to the organisation's intake form, notes the organisation writes, attendance and payment status.
  • Connected calendars: an encrypted token for each Google or Microsoft calendar a host connects, the busy times we read from it, and the events we write to it.
  • Payments: subscription and transaction identifiers from Paddle for Luneday plans, and payment identifiers from Mollie for organisations' paid bookings. Card details never reach Luneday.
  • AI briefs: when an organisation turns the feature on, a booker's intake answers are sent to Mistral AI to draft a session brief or to suggest form questions.
  • Newsletter consent: a host's yes or no, synced to MailerLite.
  • Security logs: the network address a booking attempt came from and a one-way hash of the email address entered, magic-link sends, and the bodies of payment webhooks.

Why we process it and on what basis

  • To provide the service you or the organisation signed up for: contract performance.
  • To keep the service secure and to stop abuse (rate limits, sign-in protection, fraud checks on payments): our legitimate interests.
  • To send the newsletter, and to set analytics cookies on an organisation's page: your consent, which you can withdraw at any time.
  • To keep accounting records: our legal obligations.

Cookies

On app.luneday.com we set the cookies needed to keep you signed in and to remember your light or dark choice. They need no consent and there is no banner.

On luneday.com, this site, we set no cookies.

On an organisation's page (a luneday.com subdomain or their own domain) we set nothing until you answer the cookie question. Your answer is kept in luneday_consent for six months. If the organisation has connected Google Analytics or a Meta pixel and you accept, Google sets its _ga cookies (kept up to two years) and Meta sets _fbp (kept three months). If you decline, nothing is set. The "Cookie choices" line at the foot of the page lets you change your answer.

Processors and sub-processors

These companies process data for us, each for one purpose:

  • Hetzner Online GmbH: our server in Nuremberg and database backups in Helsinki.
  • Cloudflare: DNS for luneday.com, and the Turnstile bot check on booking forms when it is switched on.
  • Lettermint: the emails we send.
  • Paddle: merchant of record for Luneday subscriptions.
  • Mollie: paid bookings, under the organisation's own Mollie account. We hold payment identifiers only.
  • Google: sign-in for connected calendars, Google Calendar (times and busy status read, your bookings written), Google Meet links, and Google Analytics on an organisation's page when the organisation connects it.
  • Microsoft: Outlook calendar for hosts who connect one. The permission Microsoft grants can see event basics; Luneday reads only times and busy status, and writes the bookings you ask it to.
  • Zoom: meetings for bookings on events set to Zoom, scheduled under the organisation owner's Zoom account. Zoom receives the event name and the booking's time and length; the join link goes to the booker.
  • Mistral AI (France): AI session briefs and form-question suggestions, when an organisation turns the feature on.
  • MailerLite: newsletter consent for hosts.
  • Meta: the Meta pixel on an organisation's page when the organisation connects it.

Google, Microsoft, Meta and Zoom process some data in the United States under their own terms and the UK and EU transfer rules, and each is involved only when a host connects a calendar or Zoom, or an organisation connects analytics. Paddle is in the UK, with a separate US company for customers who pay from the United States. Hetzner, Lettermint, Mollie, Mistral AI and MailerLite are in the EU.

Retention

  • The network address a booking attempt came from and the one-way hash of the email address entered: one day.
  • Payment webhook bodies: their contents are redacted after 90 days.
  • Database backups: nightly copies kept 30 days and weekly copies kept 90 days, in Helsinki.
  • A booker's data: erased when the organisation asks, from their Clients page. Bookings are anonymised and nothing that could identify the booker is kept. A copy of a booking in the host's own calendar is the organisation's to remove.
  • Uploaded images and files: deleted when replaced, when the organisation is disbanded, and by a weekly sweep of any file no longer in use.
  • A host account: deleted when you ask, from Account settings. Organisations you own must be disbanded or handed over first, and other memberships left.
  • Everything else: for as long as the account or organisation exists.

Your rights

You can ask for a copy of your data, have it corrected or erased, take it with you, object to our processing, and withdraw any consent you gave. Booked through an organisation? Ask them first, and we will help them answer. You can complain to the Information Commissioner's Office in the UK, or to your own data protection authority in the EU.

Contact

hello@luneday.com