Privacy Policy

Draft. NOT legal advice. Have a lawyer review before publishing, especially the GDPR sections.

Last updated: July 3, 2026

The Desked team (“we”, “us”, “our”) operates the Desked desk booking service at https://desked.io (the “Service”). This policy explains what data we collect, why, and your rights over it.

Who we are

Desked is a desk booking service for hybrid offices. For any privacy question or request, contact privacy@desked.io.

What we collect

Account data. When you or your administrator create an account, we store your name, email address, and organization. If you sign in with Google, we receive your basic Google profile (name, email, profile identifier) through OAuth. We do not receive your Google password.

Booking data. Desks you book, dates, zones, and related booking activity you create in the Service.

Organization data. Floor plans, zones, seats, groups, and settings your administrator configures.

Billing data. We do not collect or store financial data. Payment processing is handled securely by Polar Software Inc. (“Polar”), acting as Merchant of Record. Polar collects and processes your payment information directly. We receive only your account email and subscription status from Polar to manage access. For details on how Polar handles your billing data, see the Polar Privacy Policy.

Technical data. Standard server logs (IP address, browser type, timestamps) used to operate and secure the Service.

How we use it

  • To provide the Service (create accounts, process bookings, show who is in).
  • To manage subscription access based on billing status received from Polar.
  • To send transactional email (booking confirmations, reminders, account notices) via our email provider, Brevo.
  • To secure, maintain, and improve the Service.

We do not sell your data. We do not share it for advertising. And we actually hate that practice.

Third-party data sharing

We share minimal user identifiers (such as your account email) with Polar to manage your account status, handle billing updates, and grant access to the Service. We share your email with Brevo solely to deliver transactional messages.

Where GDPR applies, we process account, booking, and organization data to perform our contract with your organization; billing-related identifiers shared with Polar under our legitimate interest in managing subscriptions; and technical data under our legitimate interest in operating a secure Service.

Sub-processors

We use these providers to run the Service:

  • Polar (polar.sh) — Merchant of Record, subscription billing, invoicing, tax collection, and payment processing
  • Brevo — transactional email
  • Google — optional sign-in (OAuth)
  • Hetzner — application hosting and database

Data retention

We keep account, booking, and organization data for as long as your organization has an active account, and delete or anonymize it within 30 days of account closure, except where law requires longer retention (e.g. billing records held by Polar).

Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Because your data usually belongs to your employer’s account, direct requests to your organization’s administrator, or contact us at privacy@desked.io and we will assist.

Data location and transfers

The Service is hosted in the United States (Hetzner, US-East). If data is transferred outside your region, we rely on appropriate safeguards.

Security

We use industry-standard measures to protect your data, including encryption in transit and access controls. No system is perfectly secure, but we work to protect your information and to notify you of a breach as required by law.

Changes

We may update this policy. Material changes will be posted here with a new “Last updated” date.

Contact

Email: privacy@desked.io