Legal

Privacy Policy

Last updated: July 4, 2026

TimeKey is committed to protecting your privacy. This policy explains how we collect, use and protect your personal data in accordance with GDPR and applicable data protection laws.

01Who we are

TimeKey is a booking platform for tour & rental operators, provided by MageCodes FZ-LLC, headquartered in Dubai, United Arab Emirates.

CompanyMageCodes FZ-LLC
Emailprivacy@timekey.ai
Websitetimekey.ai

02Data we collect

Data you provide directly

  • Account: name, email, phone, password
  • Business: name, address, hours, services
  • Bookings: reservations, guest history, notes
  • Financial: billing info (no credit cards stored)

Automatically collected data

  • Device: type, OS, browser
  • Usage: pages visited, time on site
  • IP address: for security
  • Cookies: see the Cookie Policy

03Legal basis for processing

Contract performance

Providing booking and scheduling services

Legitimate interest

Service improvement and fraud prevention

Consent

Marketing messages (withdrawable)

Legal obligation

Financial data retention

04How we use your data

Platform servicesSMS remindersCommunicationService improvementFraud preventionMarketing (with consent)Analytics

05Who we share data with

SendGrid

Email delivery

NTH / BulkGate

SMS delivery

Payment gateways (e.g. Stripe)

Card processing — card data never touches our servers

Railway

Hosting

Google Analytics

Analytics (anonymized)

We never sell your personal data to third parties.

06Your guests’ data

When an operator uses TimeKey to manage bookings, we process their guests’ data as a data processor on the operator’s behalf. The operator is the data controller for that data.

  • If you booked a tour or rental with a business that uses TimeKey, contact that business first to exercise your rights — we support them in responding
  • We use guests’ data only to provide the Services to the operator — never for our own marketing
  • A data processing agreement (DPA) is available to operators on request

07International transfers

Our providers may process data outside your country. Where data of EU/EEA or UK residents is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses with those providers.

08Data retention

Data typeRetention period
Account dataWhile active + 30 days
Booking data3 years
Financial data10 years (legal)
Log data90 days

09Your rights

Access

Request a copy of your data

Rectification

Correct inaccurate data

Erasure

Right to be forgotten

Portability

Download in JSON/CSV

Restriction

Restrict processing

Object

Object to processing

10Security

  • TLS/SSL encryption
  • AES-256 for data
  • 2FA authentication
  • Regular audits
  • Limited access

If a breach affects your personal data, we will notify you and the competent authority as required by law. TimeKey accounts are for adults (18+); guest details of minors may only be entered by the responsible adult making the booking.

11Contact

For privacy questions or to exercise your rights:

We will respond within 30 days. You have the right to lodge a complaint with your local data protection authority.