Skip to content
LEGAL

Privacy Policy

Last updated: July 25, 2026

Our Role

This Privacy Policy is issued by Ruunly LLC(“Ruunly,” “we,” “us”), a Florida limited liability company located at 7901 4th St N #33392, St. Petersburg, FL 33702. It applies to ruunly.com, the Ruunly application, the Ruunly mobile app, and the websites Ruunly hosts for its business customers.

Ruunly processes two broad categories of information.

For information about Ruunly account owners, trial users, website visitors, prospects, and platform administrators, Ruunly acts as a business or controller.

For information about a Ruunly business customer's End Customers, Ruunly generally acts as a service provider or processor to the business customer. The business customer decides what End Customer information to collect, why it is collected, how long to keep it, and how to communicate with End Customers. End Customers should contact the business they purchased from to exercise privacy rights about that business's records. If Ruunly receives an End Customer request directly, we may forward it to the relevant business customer unless the law requires us to respond directly.

Categories of Personal Information

Depending on how the Service is used, Ruunly may collect or process these categories of personal information:

Identifiers

Examples
Name, email, phone number, account ID, IP address, business name
Sources
You, business customers, End Customers, service providers
Purposes
Account creation, authentication, support, fraud prevention, communications

Customer records

Examples
Billing contact details, service address, invoice history, membership status
Sources
Business customers, End Customers, Stripe
Purposes
Billing, customer management, subscription management, dispute handling

Commercial information

Examples
Plan selected, invoices, payments, refunds, chargebacks, subscription status
Sources
You, Stripe, business customers
Purposes
Payment processing, accounting, tax, support, analytics

Internet and device information

Examples
Log data, browser type, pages viewed, dashboard events, error reports
Sources
Your browser or device
Purposes
Security, debugging, product improvement, abuse prevention

Geolocation

Examples
Approximate location from IP address; service addresses entered by users
Sources
Your device, user-entered information
Purposes
Security, tenant routing, scheduling, service delivery

Professional or business information

Examples
Company name, role, service category, team members, business address
Sources
You, business customers
Purposes
Account administration, onboarding, support

Communications

Examples
Support emails, chat or form submissions, message metadata, delivery events
Sources
You, End Customers, Resend, Twilio
Purposes
Support, message delivery, compliance, suppression management

Sensitive personal information

Examples
Account login credentials, payment-related identifiers, contents of messages where users include sensitive information
Sources
You, End Customers, Stripe, Supabase
Purposes
Authentication, payment processing, security, service delivery

Ruunly does not intentionally collect government IDs, biometric identifiers, children's data, protected health information subject to HIPAA, or precise geolocation unless a user or business customer enters that information into the Service. The Service is not designed for HIPAA-covered use.

How we use your data

We use your data to:

  • Operate and improve the Ruunly platform
  • Process payments and manage billing
  • Send transactional emails (receipts, alerts, account notifications)
  • Provide customer support
  • Detect and prevent fraud and abuse
  • Comply with legal obligations

We do not sell your personal data or your clients' data to third parties.

Data we receive from the Google APIs (your Google Calendar connection) and the Microsoft APIs (your Outlook connection) is excluded from the general purposes described in this section and throughout this policy. We use that data only to provide the calendar-sync features described in “Connecting Your Google Calendar” and “Connecting Your Outlook Calendar” — never for analytics, advertising, marketing, profiling, product research, or improving any other product or service. Ruunly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How We Disclose Personal Information

We disclose personal information to service providers and subprocessors that help us provide the Service, including hosting, database, authentication, payment processing, email delivery, SMS delivery, file storage, analytics, logging, support, and security providers.

We may disclose information to Stripe and financial institutions for payment processing, fraud prevention, disputes, refunds, tax reporting, and legal compliance. We may disclose information between a Ruunly business customer and its authorized users or End Customers as needed to provide the Service.

We may disclose information to comply with law, enforce our terms, protect rights and safety, investigate abuse or fraud, complete a business transaction such as a merger or acquisition, or with your direction or consent.

We do not sell personal information for money. Ruunly may share limited information — for example, that a visit to our marketing site led to a signup — with advertising partners (Google Ads and/or Meta), solely to measure whether our ads are working (“conversion tracking”). This runs only if you click “OK” on the cookie banner (see Cookies below); if you decline analytics, or the integration isn't configured, no conversion data is sent. See State Privacy Rights below for how to opt out.

Google user data and Microsoft user data are never part of any such disclosure: we never share data received from the Google or Microsoft APIs with advertising partners, analytics providers, data brokers, or any other third party. The only systems that touch it are the infrastructure strictly necessary to run the calendar-sync feature itself (our own encrypted database and hosting), as described in the Google Calendar and Outlook sections. We never sell it and never share it for cross-context behavioral advertising.

SMS/mobile information: No mobile information (including phone numbers collected for text messaging and SMS opt-in/consent) will be shared with, or sold to, third parties or affiliates for their marketing or promotional purposes. Mobile information is used only to deliver the messages you asked for from the business you interacted with, sent through Ruunly as its messaging provider. Text-message consent is never shared with third parties for their own marketing. You can opt out of text messages at any time by replying STOP.

Connecting Your Bank Account (Plaid)

If you choose to use Ruunly's financial-insight features, you can connect your own business bank account through Plaid Inc., a third-party service that securely links to your bank on your behalf. When you connect an account through Plaid Link, you authorize Plaid to access account information and share it with Ruunly.

What we receive: transaction history and account balances for the account you connect, together with basic account details (such as the institution, account name, type, and a masked account number). Plaid's access is read-only, and Ruunly cannot move money through Plaid. Ruunly does not receive or store your bank login credentials. Depending on your bank, you authenticate directly with your bank or provide credentials to Plaid; Plaid's handling of that information is governed by its own policy (linked below).

How we use it: to show you your own financial insights inside your Ruunly dashboard — cash-flow summaries and reconciling income against the invoices and subscriptions you run through Ruunly — and, as needed, to operate and secure the service (support, fraud prevention, debugging, and backups). We do not use this data for lending or credit decisions, we do not sell it, and we do not use it for any purpose incompatible with the ones described here.

Your control: you can disconnect your bank account at any time from your Ruunly settings; new data stops flowing on disconnect. You may request deletion of previously imported financial data by contacting [email protected]. You can also review and manage the connections Plaid holds for you, and delete data Plaid stores, through the Plaid Portal. Plaid's own handling of your data is governed by the Plaid End User Privacy Policy.

Connecting Your Google Calendar

If you choose to sync your schedule, you can connect your own Google account so the jobs you schedule in Ruunly also appear on your Google Calendar. Google will show you three permissions on the consent screen, and each one has a single purpose: view and edit events on your calendars, which is how your jobs get onto the calendar; see your primary Google Account email address; and sign in with Google. We ask for the last two only so we can show you which Google account is currently connected, on the same screen where you disconnect it. Ruunly does not use your email address to contact you or to create a Ruunly login.

What we receive: the email address of the Google account you connect, and a refresh token that we store in encrypted form. We do not download, read, index, or store your existing calendar events. The only calendar data Ruunly keeps is the identifier of each event it created for you, so that it can update or remove that same event later, plus which of your calendars you chose to write to.

How we use it: to write your own jobs to your calendar. When you create a job we add an event, when you edit a job we update that event, and when you cancel a job we remove it the same way — as long as your connection is still active and syncing is on at that moment. See If your calendar drifts out of sync below for when that can fall behind.

What ends up in the event: the event title contains your customer's name and the service, in whichever order you pick under Calendar settings; you can also set it to the customer's name on its own. The event also carries the scheduled time, your job notes, and the service address, unless you switch the address off in those same settings. This means your customers' names, and by default their addresses, are sent to Google as part of your calendar.

When syncing starts: connecting your calendar for the first time turns syncing on for you, so the next job you schedule is written to Google without any further step. You can turn syncing off at any time under Calendar settings. Jobs you add from the Calendar page also have their own Push to Google Calendar switch; jobs created elsewhere in Ruunly follow the account-wide setting.

Jobs already on your schedule: after you connect, Ruunly offers to add the upcoming jobs you already have to your calendar. That offer is a separate choice and you can decline it. Turning auto-sync on in Calendar settings — including turning it off and back on later — can trigger that same bulk write. Before sending anything, Ruunly checks that the number of jobs shown on screen still matches what it finds at that moment, and rejects the save entirely — nothing is sent, and the setting does not change — if the count has moved, rather than sending an outdated number's worth of jobs. Each job sent this way is written at once, up to a limit of 2,000, and is an event carrying a customer's name and, unless you have switched addresses off, their address.

If your calendar drifts out of sync: Ruunly only writes to your calendar — it never reads anything back — so the two can fall out of step. Known examples include: you edit or move an event directly in Google (Ruunly does not see that change, and the next time it updates that same job the edit is overwritten); your connection needs reconnecting and the job changes before you do; or syncing is paused while jobs keep changing inside Ruunly. When that happens, treat the schedule inside Ruunly as the source of truth — the calendar entry is a copy for your convenience, not the record.

If you connect more than one Google service: Ruunly uses a single Google application for Calendar and for Google Business Profile. If you connected Google Business Profile first, Google may carry that earlier permission forward when you then connect your calendar. Ruunly still uses the calendar permission only for the calendar sync described here, and the Business Profile permission only for Business Profile; the two connections are stored separately and neither is used against the other.

What we never do: we never read events that Ruunly did not create, we never sell or share calendar data, and we never use it for advertising, profiling, or training artificial-intelligence models. Ruunly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect it: the refresh token is encrypted with AES-256-GCM before it is written to our database, using a key that lives in the application environment and is never stored next to the data it protects. That database runs on an encrypted volume (LUKS2, AES-256) on hardware Ruunly operates, and it is not reachable from the public internet. Traffic between Ruunly and Google travels over HTTPS. The token is only ever decrypted on our servers, in two places: the job that writes your events, and the disconnect step that tells Google to retire the token. It is never sent to your browser and never appears anywhere in the Ruunly interface. Access to the production database is restricted to Ruunly's own operators and is used only to run and support the service.

How long we keep it: the encrypted token is deleted the moment you disconnect, and it is also deleted automatically if Google tells us it is no longer valid. The identifier of each event Ruunly created is stored on the job that event belongs to, and it goes away when that job record does. Closing your own Ruunly login is a narrower thing than it sounds, so we would rather be precise about it: it removes your personal records, and it deliberately leaves the business's records alone, because those belong to the business rather than to you. The calendar connection is one of the business's records. Disconnecting is what removes the token, and a data deletion request sent to [email protected] is what removes the rest. The email address of the Google account you connected outlives a disconnect on purpose — it is the record of which account was used — and we delete it whenever you ask, at the same address. We do not keep copies of your calendar events, because we never download them.

Your control: you can disconnect at any time from your Ruunly calendar settings. Ruunly revokes its token with Google and deletes the stored token. We keep a record of which Google account was connected until you ask us to remove it. Events already written stay on your calendar unless you remove them. You can also revoke access directly from your Google Account permissions page.

Connecting Your Outlook Calendar

Ruunly also lets you connect a Microsoft (Outlook / Microsoft 365) account instead of, or alongside, Google. It is a separate connection with Microsoft. The event your job becomes, and the drift/source-of-truth caveat described above, work the same way for Outlook, and connecting turns syncing on automatically the same way too. What is different — including who can actually see or change any settings for an Outlook-only connection — is covered below under Your control; do not assume every Google control above is available here.

What we ask Microsoft for: permission to read and write your calendar events, so your jobs can get onto your calendar; permission to read your Microsoft account profile, so we can identify and store which account you connected — Ruunly's calendar page does not yet display that email address back to you the way it does for Google, but the same information is captured and held under the same rules; and permission to keep syncing while you are not actively signed in, which is what lets Ruunly push a job to your calendar without you having to reopen Microsoft every time.

What we receive and how we use it: the email address of the Microsoft account you connect, and a refresh token we store encrypted the same way as Google's. As with Google, Ruunly does not download, read, index, or store your existing Outlook events, does not use your email to contact you or create a Ruunly login, and never uses this data for advertising, profiling, or training artificial-intelligence models. The event-title format and whether addresses are included are one shared setting for your whole account, not per provider, so whatever you currently have them set to also applies to Outlook events — see Your control below for who can actually change that setting. The same offer to add the upcoming jobs you already have — described above under Jobs already on your schedule — applies here too, regardless of which provider you connected.

Your control: unlike Google, Ruunly currently has no in-app control at all for a connection that is Outlook only. The Auto-sync switch, the event-title-format and address settings, and the Disconnect button all live in the same Calendar settings dialog, and that dialog only shows those controls once Google is connected — connecting Outlook by itself does not unlock them, even though the gear icon that opens the dialog is still visible. If Outlook is the only calendar you have connected, syncing stays on with Ruunly's current default settings until you either also connect Google or ask us to remove the connection. You can still revoke access at any time from the Microsoft account you connected — removing Ruunly from the apps and services it has been given access to stops our access immediately on Microsoft's side, the same as disconnecting Google does — and Ruunly will delete the stored connection, including the saved account email, from our own records if you ask us to.

If you connect both Google and Outlook: Ruunly currently sends your jobs to Google only — Outlook stays connected but does not receive anything while Google is also connected. If you disconnect Google from Ruunly's Settings, Outlook takes over from that point on; disconnecting one does not disconnect the other.

Third-party services

Ruunly uses the following third-party services. A complete list is on our Subprocessors page.

  • Supabase — Authentication and session management (login, magic links, password reset). Supabase does not host the Ruunly application database — your business and customer records are stored in a PostgreSQL database Ruunly operates on its own hosting. Supabase is SOC 2 Type II certified (their certification, not Ruunly's). Supabase Privacy Policy
  • Stripe — Payment processing. Stripe is PCI DSS Level 1 certified. Card data never touches Ruunly servers — we use Stripe-hosted Checkout. Stripe Privacy Policy
  • Plaid — Bank-account connectivity for optional financial-insight features. Read-only access to transaction history and balances for accounts you connect; does not store your bank login credentials. Plaid Privacy Policy
  • Resend — Transactional and marketing email delivery.
  • Twilio — SMS and voice delivery for text messaging features, including appointment reminders and billing notifications (where enabled).
  • Cloudflare — CDN, DDoS protection, file storage (R2), and Turnstile (bot and spam prevention on public forms). Data stored in US regions.
  • PostHog — Product analytics, proxied through our own domain. Runs by default on the Ruunly marketing site; the cookie banner shown on your first visit lets you decline immediately, and a stored decline is always honored. See our Cookie Policy for how to change your choice later.
  • Google Analytics — Web analytics. Runs by default on the Ruunly marketing site, subject to the same decline control as PostHog above. Google Privacy Policy
  • Sentry — Error monitoring and crash reporting. Receives anonymized error context (stack traces, browser metadata) to help us diagnose application issues.
  • Inngest — Background job orchestration for billing, messaging, and workflow automation. Processes event payloads on Ruunly's behalf.

State Privacy Rights

Depending on your state of residence and how you interact with Ruunly, you may have rights to request access, correction, deletion, portability, restriction, limitation of sensitive personal information, and opt-out of sale, sharing, targeted advertising, or certain profiling. California residents also have the right not to be discriminated against for exercising CCPA rights.

To make a request, email [email protected]. If your request concerns a Ruunly business customer's records about you, we may direct you to that business or forward your request to that business. We may verify your identity before fulfilling a request. You may use an authorized agent where permitted by law, but we may require proof of authorization and identity verification.

We respond to verifiable consumer requests within 45 days where CCPA applies, unless we notify you that more time is needed. If your state provides an appeal right and we deny your request, you may appeal by replying to our decision email with “Privacy Appeal” in the subject line.

Ruunly does not sell personal information for money. Ruunly may use an advertising/conversion pixel (Google Ads and/or the Meta advertising pixel) to measure ad performance, where that integration is configured and you have consented (see Cookies below) — if that or any future practice is treated as a “sale” or “share” under state law, declining analytics in the cookie banner (or emailing [email protected]) opts you out of it. Ruunly will also honor legally required opt-out preference signals, including Global Privacy Control, where recognition is required.

Retention

We keep personal information only as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law.

Data typeTypical retention
Account and tenant profile dataWhile the account is active, then for a limited recovery period after cancellation
Trial account dataThrough the trial and post-trial recovery period described in the product, then deletion or deactivation
End Customer operational recordsAs configured by the business customer, subject to legal, financial, backup, and abuse-prevention needs
Invoices, payment, refund, dispute, and tax recordsGenerally up to 7 years or longer if required for tax, accounting, dispute, or legal obligations
Consent records, unsubscribe records, and suppression listsAs long as needed to prove consent or honor opt-out obligations
Security logs and audit logsAs long as needed for security, fraud prevention, compliance, and investigation
BackupsDeleted on a rolling schedule, unless retained for security, legal, or disaster recovery needs

Children

Ruunly is not directed to children under 13 and does not knowingly collect personal information from children under 13. Business customers may not use Ruunly to knowingly collect children's personal information without legally required parental consent and Ruunly's written approval.

AI Features

Ruunly may use automated tools to generate or suggest website copy, service descriptions, marketing text, and related content. We may process the business information and prompts you provide to deliver those features. Do not enter sensitive personal information, protected health information, government IDs, payment credentials, or confidential third-party information into AI prompts unless Ruunly expressly approves that use in writing.

Cookies

We use essential cookies for authentication (session tokens) and security (CSRF protection), and — by default, on the Ruunly marketing site — analytics cookies (first-party product analytics, proxied through our own domain, and web analytics) for product analytics and error diagnostics. The cookie banner shown on your first visit lets you decline analytics cookies using the “Decline analytics” control; a stored decline is always honored. Essential cookies cannot be rejected without breaking core functionality.

Ruunly may also use an advertising/conversion pixel to measure whether our marketing and ads led to a signup. Unlike analytics, any such pixel is off by default and loads only when both (a) you click “OK” on the cookie banner — the same choice that keeps analytics on — and (b) Ruunly has that integration configured. Declining analytics keeps every advertising pixel off. If a pixel is enabled, the current one is named on our Cookie Policy. For a full list of third-party services we use, including how to change your choice later, see our Cookie Policy and Subprocessors.

Changes to This Policy

Ruunly may update this Policy to reflect changes in our practices, the Service, or applicable law. When we do, we revise the “Last updated” date at the top of this page. If a change is material, we will provide additional notice — for example by email to account owners or an in-product notice — before it takes effect, where required by law. Continuing to use the Service after an update takes effect means you accept the updated Policy. Prior versions are retained in our document version records; to request the version in effect on a specific date, email [email protected].

Contact

Privacy questions: [email protected]

Ruunly LLC
7901 4th St N #33392
St. Petersburg, FL 33702