On Your Time
Privacy Policy
Last updated 13 August 2026.
On Your Time is operated by Certago LLC. This explains what we hold, why, who else touches it, and how to get it removed.
Almost everything here belongs to a practice rather than to us. A practice signs up; their clients do not. If you are a client who has been sent a booking link, the firm that sent it is who holds your relationship — this describes what happens to your details inside the software they use.
What we store
- Practice configuration. The practice’s name, address, logo, colours, meeting types, advisers and their calendar addresses, compliance text, and the settings that make its pages look like its own.
- Connection credentials. The API credentials a practice supplies for Wealthbox, Microsoft 365 and MyRepChat. These are encrypted at rest, are never shown again after they are saved — only the last four characters — and are never sent back to a browser.
- The people who can sign in. For everybody an owner invites: their email address, their name if they give one, their role, and whether their account is active. If they set up an authenticator, its secret is stored encrypted; their recovery codes are stored only as digests.
- Scheduling requests and bookings. Who a meeting is for, what kind, which advisers, when it was booked, and the link code.
- Client details supplied for scheduling. A client’s name, and their email address and mobile number where the practice provides them so the link and confirmation can be sent. These come from the practice’s own CRM.
- A change log. What was changed in a practice’s configuration, when, and which person did it, so a question months later has an answer. Credential changes record only which service changed and the last four characters, never the value.
What we do not store
- Card numbers. Payments are handled by Stripe on Stripe’s own pages. Card details are typed into Stripe, never into On Your Time. There is no field in our system that holds a card number, and we could not show you one if you asked.
- The contents of your calendars or your CRM. We read free/busy times and look up a contact when a request is being made; we do not copy your calendar or your client list into our database.
- Advertising or behavioural profiles. We do not build them and we do not sell anything to anybody.
Who else touches it
We use seven processors, each doing one job. This is all of them:
- Vercel — runs the application and serves the pages.
- Neon — hosts the database.
- Stripe — processes subscription payments and holds the card details we never see.
- Vercel Blob — stores logo files a practice uploads.
- Resend — sends the emails the product sends: sign-in links, invitations to colleagues, the welcome note. Every one of them goes to somebody who works at a practice; none is ever addressed to a client.
- Axiom — receives our application logs, so that a failure can be found and fixed. Those lines carry the page and the practice and nothing that identifies a person — no name, no email address, no telephone number.
- Better Stack — checks from outside that the site is still answering. It sees the answer to that one check and nothing else.
Separately, a practice’s own connected services — Wealthbox, Microsoft 365 and MyRepChat — receive data because that is the point: the meeting has to reach the calendar and the confirmation has to reach the phone. Those are the practice’s own accounts, under the practice’s own agreements with them, and we act on the practice’s instructions when we write to them.
Cookies
On Your Time sets one kind of cookie: a session cookie, when somebody signs in to a staff or administrator screen, so they stay signed in between pages. It expires, and it holds nothing but an identifier and a signed timestamp — no name, no email address and nothing about what they did.
There are no advertising cookies, no analytics cookies and no third-party trackers on any page we serve — which is why you have not been asked to dismiss a cookie banner.
How long we keep it
Practice configuration is kept while the practice has an account. Scheduling requests are kept so a practice can see its own history; an unbooked link stops working after 30 days. The change log is kept so that questions about past changes can be answered.
When a practice closes its account, we give a reasonable opportunity to export the data and then delete it.
Getting your data, or getting it deleted
Write to hello@onyourti.me and a person will answer. A practice can ask for a copy of its data or for it to be deleted. If you are a client of a practice and want your details removed, the quickest route is to ask that firm, since it is their record — but you can write to us and we will help.
Security
Connection credentials and authenticator secrets are encrypted at rest, and neither is ever sent back to a browser — a saved credential is shown only as its last four characters, so nobody, including us, can read one back to you. Sign-in links are single-use and short-lived: following one spends it, whether or not the sign-in finishes. Session cookies are signed, and are tied to the person and the practice they were issued for, so one cannot be used anywhere else. Traffic is served over HTTPS. No system is perfectly secure, and we will tell affected practices promptly if something goes wrong.
Changes to this policy
If we change it in a way that matters, we will tell the email address on the practice’s account before the change takes effect.
Contact
Certago LLC — hello@onyourti.me