StudioInSync

Privacy Policy - StudioInSync

Last updated: October 20, 2025

StudioInSync Inc. (“StudioInSync,” “we,” “us,” or “our”) is committed to protecting your personal information in accordance with this Privacy Policy. Please read it carefully to understand how we collect, use, and protect your data when you visit our website (https://studioinsync.com/) or use our AI Reviews services for studios powered by Mindbody or other studio management apps..

This Policy complies with Québec’s Law 25 and Canada’s PIPEDA, and we also apply applicable data-protection principles for other jurisdictions where we operate.

Definitions

Consent – A clear, freely given, specific, and informed indication of your wishes allowing the processing of your personal information.

Personal information – Any information that can identify an individual, directly or indirectly.

Processing – Any operation performed on personal information (collection, use, retention, disclosure, deletion, etc.).

Privacy incident – Unauthorized access, use, disclosure, loss, or compromise of protected personal information.

Controller – The studio client who determines the purposes and means of processing personal data.

Processor – StudioInSync, which processes personal data on behalf of the studio according to its documented instructions.

Scope and roles

Website visitors: StudioInSync acts as the controller for information collected through our site, contact forms, and newsletters.

Studio clients and their customers: The studio is the controller, and StudioInSync acts as a processor, handling data only to provide the AI Reviews service under a Data Processing Addendum (DPA) available on request.

Information we collect

We collect or receive personal information when you provide it voluntarily or when it’s shared through integrations necessary to perform the service, such as Mindbody or Google Business Profile.

Information you provide

  • Name, email, phone number, role, and business information.

  • Communication preferences and consent records.

  • Messages sent through our contact forms or support channels.

Information we receive via integrations

  • Mindbody or other studio management app data (limited to operational details): class booking events, attendance status, or cancellations triggering AI Review. We do not process health or payment data.

  • Google Business Profile data: review links sent, review status, ratings, and timestamps.

  • Technical data: IP address, browser type, device information, pages visited, cookies and analytics logs.

Cookies and automatic collection

We use cookies and similar technologies to:

  • Ensure the proper functioning and security of our website;

  • Remember preferences and improve user experience;

  • Analyze traffic and performance metrics.

You may manage or disable cookies through your browser or our consent banner. Some cookies are essential for the service to function properly.

Purpose of processing

We process personal information to:

  • Provide and operate the AI Reviews service (e.g., sending automated review requests after classes, tracking responses, and generating reports).

  • Personalize and improve user experience.

  • Communicate with you (transactional and marketing messages, with opt-out options).

  • Perform analytics, fraud prevention, and security monitoring.

  • Comply with legal and contractual obligations.

We do not sell data or build independent profiles from studio clients’ customers.

Legal basis and consent

  • For website visitors/prospects: Consent (forms and opt-ins), legitimate interest (security, fraud prevention), and legal obligations.

  • For studio client data: Processing is based on contract performance and on the studio’s responsibility to obtain valid customer consent for email or SMS communications.

Consent can be withdrawn at any time (subject to legal or contractual requirements).

Disclosure to third-parties

We may share personal information with:

  • Service providers (e.g., hosting, email/SMS delivery, analytics, support) acting under confidentiality agreements.

  • Integration partners (e.g., Mindbody, Google Business Profile) as needed to provide services.

  • Legal authorities if required by law or court order.

  • Corporate transactions (fusion or sale) under adequate data-protection commitments.

We never sell your personal information.

Data transfers outside Quebec or Canada

Some sub-processors (Mindbody, Google) may process data outside Canada (e.g., in the United States).
We take reasonable technical measures to protect your information. Please note that foreign laws may permit local authorities to access data for lawful purposes.

Data retention

We retain personal information only as long as necessary to:

  • Deliver our services and support your account;

  • Fulfill legal, security, and audit obligations.

Some technical logs or aggregated data may be kept longer for security and compliance purposes as per Law 25.

Security measures

We retain personal information only as long as necessary to:

  • Deliver our services and support your account;

  • Fulfill legal, security, and audit obligations.

Some technical logs or aggregated data may be kept longer for security and compliance purposes as per Law 25.

Your rights

Under Law 25 and PIPEDA, you may request:

  • Access to your personal information;

  • Correction of inaccurate data;

  • Deletion where legally permitted;

  • Portability of your data when applicable;

  • Withdrawal of consent or objection to certain uses.

  • If you are a studio client’s customer: Please contact the studio directly (the controller). We will cooperate with the studio to fulfill your request.

  • If you are a StudioInSync visitor or client: Contact us using the information below.

Marketing and SMS/Email consent

  • Transactional communications (e.g., review link confirmation) are essential to the service.

  • Marketing communications are sent only with your consent and include an unsubscribe option.

  • Studios are responsible for obtaining valid consent for SMS outreach and for honoring “STOP” requests as required by law. StudioInSync provides the technical means to enforce these preferences.

Third-party links and services

Our website or dashboard may include links to third-party services (e.g., Mindbody, Google, analytics tools). Their own privacy policies apply; we do not control their practices.

Children’s privacy

Our services are not intended for children. We do not knowingly collect personal information from minors without parental consent as required by law.

Changes to this policy

We may update this Privacy Policy from time to time to reflect legal or operational changes.
We will post the updated version with its effective date and, when necessary, notify you by email or banner on our site.
Continued use after changes constitutes acceptance.

Governing law

If any part of this Policy conflicts with Law 25 or other applicable regulations, the legal provisions take precedence.

Contact information

For questions about this Policy or to exercise your rights, please contact: info@studioinsync.com.

Copyright © 2025 StudioInSync™. All rights reserved.