SECURITY & COMPLIANCE

Your customer data never leaves your server.

Schedularity is self-hosted by design. No third-party SaaS holding your bookings, no per-booking analytics fingerprinting your customers — just a WordPress plugin running on infrastructure you already control.

By design

Security built into the platform, not bolted on.

Six structural guarantees. Not features you have to turn on — defaults you can't turn off.

Self-hosted
Every booking and customer record lives in your WordPress DB — never in a third-party SaaS.
Append-only audit log
Immutable record of every change. Even site owners can't rewrite history — only append to it.
RBAC
Per-module permissions. Front-desk staff see calendars, not payouts or audit logs.
Signed webhooks
HMAC signatures on every webhook delivery. Forged payloads can't impersonate the platform.
Rate-limited APIs
Public endpoints are rate-limited by default — no need to add a WAF rule yourself.
Data portability
Export everything — bookings, customers, transactions — as CSV, JSON, or iCal at any time.
PLACEHOLDER · GDPR EXPORT UI
GDPR & data subject rights

GDPR-friendly out of the box, by construction.

Self-hosting solves most of GDPR's hardest questions — there is no third party to enter into a DPA with. We give you the controls for the rest.

1
Right to access
One-click data export per customer in machine-readable formats (CSV, JSON, iCal).
2
Right to erasure
Hard delete or anonymize a customer record with full audit trail of who issued the request.
3
Consent & waivers
E-signed consent and liability waivers stored with the booking — not in a separate tool.
4
Cookie & PII granularity
Only the analytics & pixel integrations you explicitly enable run on the booking widget.
Regulated industries

Designed for clinics, law firms & data-residency requirements.

Self-hosting means you choose the region, the cloud, the hosting provider — and you stay compliant with sector-specific rules.

Healthcare & clinics

Patient PII stays on your servers. Intake forms, consents, and audit logs satisfy most data-residency rules.

HIPAA-ready posture
§

Law firms & legal

Privileged matter intake, signed engagement letters, and full activity audit — without a third-party SaaS in the chain.

Privilege-aware

EU data residency

Host in the EU. No cross-border transfers. No vendor SCCs to negotiate.

GDPR-aligned
$

PCI-scope minimization

Card data is tokenized by Stripe, Razorpay & friends — never touches your DB.

SAQ-A territory
Responsible disclosure

Found something? Tell us first.

Schedularity runs a coordinated disclosure program. If you believe you've found a security issue affecting the plugin, the admin UI, or any of our public infrastructure, email security@schedularity.com with a proof-of-concept and impact analysis.

We acknowledge within 48 hours, triage within 5 working days, and publish a CVE for any issue affecting a stable release. Researchers are credited in the changelog.

Self-hosted booking, built right.

Get the depth of Mindbody and the UX of Calendly — on the WordPress install you already own and control.