Privacy & Cookies Notice

Last updated: July 18, 2026

Introduction

This Privacy & Cookies Notice (the "Notice") describes how Dojo collects, uses, shares, and protects personal information when you interact with the Dojo platform — whether as a Tenant (an independent professional running their business on Dojo), a Buyer (an organization or individual booking a session through a Tenant's storefront), or an Attendee (someone participating in a booked session).

The Notice is designed around Quebec Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA) as the primary applicable frameworks. If you are in the European Economic Area, the GDPR addendum further below applies in addition. If we send you a commercial electronic message, Canada's Anti-Spam Legislation (CASL) governs that message.

1. Who we are

The entity responsible for the personal information described in this Notice is Dojo, a business based at 6226 rue de Saint-Vallier, Montréal, Quebec, Canada.

We have designated Julien Williams as the Person in charge of the protection of personal information (Privacy Officer) under Quebec Law 25 §3.1. You can reach the Privacy Officer at [email protected] for any question, request, or complaint about your personal information.

For general legal correspondence, including notices required by the Tenant Agreement or the Buyer Terms, write to [email protected].

2. What we collect

We collect only what we need to operate the Platform and deliver the Services. The categories below match the platform's actual data model as of the "Last updated" date.

2.1 Tenants

When you register as a Tenant and as you operate your account, we collect:

  • Identity and contact — your name, email address, phone number, the business address you use for your Tenant account, your tax identification number where required to operate as a business, and the URL slug for your public storefront.
  • Bank and payout — the bank-name and account information you enter for payouts (or, where you use Stripe Connect, the corresponding Stripe-managed details), plus your free-text payment-instructions block where applicable.
  • Stripe Connect identifiers — your Stripe-Connect account ID, your Stripe customer ID, your subscription ID, and subscription-status flags returned by Stripe.
  • OAuth tokens (encrypted at rest) — where you connect Google Calendar or QuickBooks Online, the access and refresh tokens issued by those providers, stored encrypted using AES-256-GCM.
  • Public profile — the tagline, biography, profile image, display location, website URL, and social URLs you choose to show on your storefront.
  • Usage timestamps — when you completed onboarding, when we sent your welcome email, when your record was created and last updated.
  • Marketing consent — when you actively select the optional marketing checkbox during sign-up, we record your email address, the consent source and disclosure version, and the time you consented. We also record when the consent was synchronized to our marketing provider.

2.2 Buyers

When you register as a Buyer and as you book through the Platform, we collect:

  • Identity and contact — your name, your billing email address, and (for organizational Buyers) your organization's tax identification number where you choose to enter it for invoicing.
  • Stripe Connect identifiers — a per-Tenant Stripe customer ID is created when you make a payment to a given Tenant, so future bookings with the same Tenant can reuse stored payment methods.
  • Booking history — the bookings, sessions, and seats you have purchased, your payment method (Stripe or invoice), your net-terms preference where invoicing is offered, and the status of each booking.
  • Organizational context — where you are an organizational Buyer, the name of the organization on whose behalf you are booking, plus the buyer-user account linking you to that organization.

2.3 Attendees

When you are enrolled as an Attendee — by yourself (B2C) or by an organizational Buyer (B2B) — we collect:

  • Identity and contact — your name and email address.
  • Participation — the bookings, sessions, and session assignments you are linked to, plus your attendance status (confirmed, attended, missed, or cancelled) recorded by the Tenant.

We do not require Attendees to provide a phone number, postal address, or any payment information.

3. How we use it

We use the personal information described above to:

  • operate the Platform — render storefronts, accept bookings, schedule sessions, send transactional emails (booking confirmations, payment receipts, reminders, cancellations);
  • process payments — through Stripe Connect, with the Tenant as the merchant of record;
  • generate invoices — through the Tenant's QuickBooks integration or as PDFs the Tenant uploads, for organizational Buyers using net-terms invoicing;
  • enable virtual sessions — through the Tenant's connected Google Calendar account, which creates a Google Meet link associated with each virtual session;
  • maintain accounts — authenticate sign-ins, recover passwords, send account-status notifications;
  • provide customer support — answer your questions, resolve disputes, and improve the Platform;
  • comply with legal obligations — keep records for tax, accounting, and audit purposes, respond to lawful requests from courts and regulators, and detect and prevent fraud or abuse;
  • measure use of the public landing site and pre-account onboarding flow using consent-aware Google Analytics; analytics cookies are used only after you consent (see Cookies further below).

4. Sub-processors

We engage the third parties listed below to process personal information on our behalf. Each is contractually bound to confidentiality and to process personal information only on our instructions. The list is current as of the "Last updated" date; we maintain it and will notify Tenants of additions or replacements as described in the DPA.

Sub-processorPurposePersonal information processed
SupabaseDatabase and authentication; primary store for the Platform's data.All personal information described above, plus Supabase Auth session cookies.
Stripe and Stripe ConnectPayment processing for all booking transactions; Tenant onboarding (KYC, AML).Tenant business details; Buyer name and email; charge amounts; card or bank-account fingerprints stored by Stripe.
Resend (or equivalent SMTP provider)Transactional email delivery.Recipient name; recipient email; message body.
Google Calendar and Google MeetCalendar event creation and video conferencing for virtual sessions, where the Tenant has connected Google.Tenant Google OAuth tokens; session title and time; the resulting Google Meet link and calendar event identifier. Attendee email addresses are not sent to Google — see Google user data below.
QuickBooks Online (Intuit)Invoicing for organizational Buyers, where the Tenant has connected QuickBooks.Tenant QuickBooks identity; Buyer organization name and billing email; invoice line items.
BrevoMarketing contact and list management for Tenants who actively opt in during sign-up.Opted-in Tenant email address and associated marketing-list membership.
CloudflareEdge networking and IP-based currency detection for landing prices.Visitor IP address (used only to derive the country header passed to our request proxy); HTTP request metadata.
Google Analytics (Google LLC)Consent-aware aggregate measurement of the public landing site and pre-account onboarding flow.Page views; structural click and onboarding events; cookie identifiers (_ga, _ga_*) when analytics storage is accepted; Google-defined cookieless request and device information when storage is denied. No account, Tenant, or entered onboarding values are sent as event properties.
RailwayApplication hosting (compute).All personal information described above transits Railway-hosted infrastructure.

Where you do not connect Google or QuickBooks, the corresponding Sub-processor is not engaged with respect to your data. Brevo receives your email address only when you actively opt in to marketing during sign-up.

4.1 Google user data

Where a Tenant connects Google Calendar, Dojo requests the https://www.googleapis.com/auth/calendar.events scope from Google. This scope lets us create, update, and delete a single Google Calendar event — with an attached Google Meet video-conferencing link — for each virtual session the Tenant publishes. We do not request, and cannot access, the Tenant's existing calendar events, contacts, Gmail, Drive, or any other Google data outside this scope.

The Google user data we hold is limited to: the OAuth access and refresh tokens Google issues to authorize the above (encrypted at rest with AES-256-GCM — see "OAuth tokens" under What we collect), and the event details we ourselves create through the API — the session title, start and end time, and the resulting Google Meet link and event identifier.

With whom we share, transfer, or disclose Google user data:

  • Google, as necessary to make the API calls described above — this is inherent to using the Calendar API and is not a separate disclosure to a third party;
  • Supabase, our database sub-processor (see the Sub-processors table above), which stores the encrypted OAuth tokens and the resulting event and Meet identifiers as part of the Platform's data;
  • Railway, our hosting sub-processor, through whose infrastructure all Platform data — including Google user data — transits;
  • Attendees enrolled in the corresponding session, who receive the Google Meet link (never the underlying OAuth tokens) in their booking confirmation and reminder emails so they can join;
  • law enforcement, courts, or regulators, only where required by valid legal process.

We do not sell Google user data. We do not use Google user data for advertising, including retargeting or interest-based advertising. We do not use Google user data to train generalized artificial-intelligence or machine-learning models. We do not permit any human to read Google user data except: with your affirmative consent; to investigate a security incident; to comply with applicable law; or in narrowly scoped internal debugging necessary to maintain the Platform, limited to what the specific issue requires.

Dojo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke Dojo's access to your Google account at any time from your Google Account's Security settings ("Third-party apps with account access"), or by disconnecting Google Calendar from your Tenant settings — either action immediately revokes the stored refresh token with Google and deletes it from our database.

5. International transfer

The Platform's primary hosting infrastructure may be located in Canada, the United States, or the European Economic Area, depending on the region of each Sub-processor. Where personal information is transferred outside Canada, we rely on contractual safeguards with each Sub-processor. Where the transfer involves personal data of individuals located in the European Economic Area, we use the Standard Contractual Clauses approved by the European Commission as the transfer mechanism.

You can request additional information about the safeguards in place by writing to [email protected].

6. Retention and deletion

We keep personal information only for as long as we need it to provide the Platform, to comply with our legal obligations (including for tax and accounting purposes), to resolve disputes, and to enforce our agreements. There is no fixed automated retention schedule beyond the operational lifecycle of the data.

You can ask us to delete your personal information at any time by writing to [email protected]. We handle such requests manually, and we will respond within 30 days of receipt. Where we are required by law to retain certain information (for example, tax records), we will tell you and explain the basis. Server-backup copies are overwritten in the ordinary backup-rotation cycle.

We do not currently operate an automated purge schedule or a self-service deletion endpoint inside the Platform. If and when we do, this Notice will be updated.

7. Your rights

Under Quebec Law 25, PIPEDA, and — for users in the EEA — the GDPR, you have rights with respect to the personal information we hold about you, including the right to:

  • access the personal information we hold about you and obtain a copy in a structured, commonly used, machine-readable format where the law requires it;
  • rectify inaccurate or incomplete personal information;
  • request erasure ("right to be forgotten") of personal information that is no longer necessary for the purposes for which it was collected, that you originally consented to be processed and have now withdrawn consent for, or that we have processed unlawfully — subject to our legal obligations to retain;
  • request portability of your personal information to another service in a machine-readable format;
  • withdraw consent at any time for any processing we carry out on the basis of consent (this does not affect the lawfulness of processing carried out before the withdrawal);
  • object to certain processing on the basis of your particular situation, where the law allows;
  • complain to a supervisory authority — see Complaints below.

To exercise any of these rights, write to [email protected]. We may need to verify your identity before acting on a request.

8. Complaints

If you believe we have not handled your personal information in accordance with applicable law, you can complain:

  • to us, by writing to the Privacy Officer at [email protected]. We will respond within 30 days;
  • to the Commission d'accès à l'information du Québec (CAI), which oversees Quebec Law 25 for individuals located in Quebec;
  • to the Office of the Privacy Commissioner of Canada (OPC), which oversees PIPEDA;
  • if you are in the EEA, to the data-protection supervisory authority of the EU Member State in which you live, work, or where the alleged infringement took place.

9. Legal bases for processing

We process personal information on the following legal bases:

  • performance of a contract — to provide the Platform and the Services you have signed up for;
  • legitimate interests — to operate, secure, and improve the Platform, where those interests are not overridden by your fundamental rights and freedoms;
  • consent — where consent is required (for example, for non-essential cookies on the landing page, and where applicable for commercial electronic messages);
  • legal obligation — to keep records and respond to lawful requests from courts and regulators;
  • vital interests, in the rare circumstances where processing is necessary to protect someone's life or physical integrity.

10. Users in the European Economic Area

If you access the Platform from the European Economic Area (EEA), the General Data Protection Regulation (GDPR) applies to our processing of your personal information in addition to Canadian law.

For purposes of the GDPR:

  • the data controller of your personal information when you book through a Tenant's storefront is the Tenant. Dojo acts as a processor on the Tenant's behalf under the DPA included in the Tenant Agreement;
  • the lawful bases on which we process your personal information are those listed above, mapped to GDPR Article 6;
  • the transfer mechanism for personal data leaving the EEA is the Standard Contractual Clauses approved by the European Commission, supplemented by additional safeguards where appropriate;
  • you have the rights described above, and you can lodge a complaint with the supervisory authority of the EU Member State where you live, work, or where the alleged infringement took place;
  • we have not appointed an EU representative under GDPR Article 27. If you need one, contact [email protected] and we will assess whether one is required for your case and, if so, take reasonable steps to address it.

11. Commercial electronic messages (CASL)

If we send you a commercial electronic message — for example, a marketing email about new Platform features — we comply with Canada's Anti-Spam Legislation (CASL):

  • we send you commercial messages only where we have your express consent (for example, you actively selected the optional marketing checkbox during sign-up) or, in narrow cases, implied consent under CASL §10(9);
  • every commercial message identifies Dojo as the sender and includes our contact information and a working unsubscribe mechanism that takes effect within 10 business days;
  • transactional messages — booking confirmations, payment receipts, reminders, password-reset emails, and other operational messages sent in connection with the Services you have signed up for — are sent on the basis of the underlying transaction or contract, not on the basis of CASL consent.

12. Cookies and similar technologies

We use a small number of cookies and browser-storage entries. The full inventory is below. The Google tag loads in advanced Consent Mode with analytics and advertising storage denied by default. While storage is denied, Google Analytics does not read or write _ga cookies, but Google may receive cookieless consent or measurement requests containing Google-defined request and device information.

NameCategoryPurposeConsent-gated?Retention
dojo_ccyFunctional (HTTP cookie).Remembers the currency to display on the landing page, derived from Cloudflare's IP-country header.No (functional and necessary for the service).1 year.
dojo_cookie_consentFunctional (HTTP cookie and landing browser localStorage).Remembers and shares your accepted, rejected, or pending cookie choice with the public pre-account onboarding flow.No (it stores your consent decision itself).Up to 1 year, or until you clear browser storage or change the choice through "Manage cookies".
Supabase Auth session cookies (sb-*)Essential (HTTP cookies).Keep you signed in across pages.No (strictly necessary for authentication).Session, with rolling renewal.
_ga, _ga_*Analytics (HTTP cookies).Aggregate measurement of landing-site and public onboarding usage.Yes — Google Analytics reads or writes these cookies only after you click "Accept all" in the cookie choices dialog.Up to 2 years.

We do not sell personal information. We do not run advertising trackers, retargeting pixels, third-party fingerprinting, or any cookie used for cross-site personalized advertising. We do not embed Facebook, X, LinkedIn, or other social-media tracking on the public landing or onboarding surfaces.

You can change your consent at any time by clicking "Manage cookies" in the landing footer or the public platform onboarding and authentication shell. This returns you to the landing consent dialog without deleting your non-sensitive onboarding draft.

13. Children

The Platform is not directed at children under 14 years old. We do not knowingly collect personal information from children under 14. If you believe that a child under 14 has provided personal information to us, write to [email protected] and we will delete it.

14. Changes to this Notice

We may revise this Notice from time to time. We will post the revised version on the Platform with an updated "Last updated" date at the top. Where the revision materially affects your rights or the way we use your personal information, we will provide notice in advance — typically by email to the address on your account and, where appropriate, by an in-Platform banner.

15. Contact

For any question, request, or complaint relating to this Notice or your personal information: