Back
Legal

Privacy Policy

Effective date: 11th of August 2026

1. Introduction

Welcome to Bloomin ("Bloomin," "we," "our," or "us")

This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit or use our website and platform at https://www.trybloomin.ai/ (the "Platform").

Bloomin provides tools for educators, tutors, coaches, and similar service providers ("Service Providers") to manage students, sessions, scheduling, payments, and related business workflows.

This Privacy Policy applies to:

  • Visitors to our website
  • Users who create an account on the Platform
  • Service Providers who use Bloomin to manage their work
  • Individuals whose personal information may be entered into Bloomin by a Service Provider (such as students, clients, or parents)

Data controller: Saman EdTech OÜ, a company registered in Estonia (registry code: 17369778), with its registered address at Harju maakond, Tallinn, Kesklinna linnaosa, J. Poska tn 14a-5 10126

For questions or requests relating to this Privacy Policy or your personal data, you can contact us at info@trybloomin.ai.

By using Bloomin, you acknowledge that your personal information will be processed as described in this Privacy Policy.

2. Information We Collect

We collect personal information from several sources: directly from you, automatically through your use of the Platform, and from Service Providers who use Bloomin to manage their work.

2.1 Information you provide to us

When you create an account or use the Platform, you may provide:

  • Name
  • Email address
  • Phone number
  • Account login credentials
  • Profile information (such as bio, photo, or professional details)
  • Business or teaching-related information
  • Availability and scheduling preferences
  • Messages or support requests
  • Information submitted through forms on the Platform

2.2 Information provided by Service Providers about their students or clients

Service Providers using Bloomin may enter information about their students, clients, or service recipients. This may include:

  • Student or client names
  • Contact details (email, phone number)
  • Session times and attendance information
  • Notes related to scheduling, tutoring, coaching, or service delivery
  • Payment or invoice-related information

Service Providers are responsible for ensuring they have the appropriate consent, contractual basis, or other lawful ground to enter personal information about their students or clients into Saman. Where a Service Provider enters information about a child, the Service Provider is responsible for ensuring that appropriate parental or guardian consent has been obtained where required by law.

2.3 Information received through Google Sign-In and Calendar Integration

If you choose to sign in to Bloomin using Google Sign-In (Google SSO), we receive limited profile information from your Google Account, which may include:

  • Your name
  • Your email address
  • Your profile picture (if available)
  • A unique account identifier

We use this information solely to create and authenticate your Bloomin account.

Google Calendar Data:

If you choose to connect your Google Calendar to Bloomin, we request access limited to the events Bloomin itself creates on your primary Google Calendar. This allows us to:

  • Automatically create a Google Calendar event on your primary calendar when a Bloomin lesson is created
  • Update that event if you reschedule the lesson in Bloomin
  • Delete that event if you cancel the lesson in Bloomin, while the integration remains connected

We do not access your Gmail messages, Google Drive files, contacts, or any other Google Workspace data. We do not list, import, or read pre-existing or unrelated events already on your calendar, and we do not use your Google Calendar to calculate availability or detect scheduling conflicts. Calendar operations are limited to the primary calendar of the Google account you connect, and only to the events Bloomin itself created.

Bloomin's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2.4 Payment-related information

If payments are available through the Platform, payment transactions are processed by third-party payment providers. We do not collect or store full payment card details.

Payment-related information we may receive or store includes:

  • Billing name and address
  • Transaction status and reference numbers
  • Payment amount and date
  • Limited card information (such as last four digits and card type), provided by the payment processor for record-keeping

2.5 Information collected automatically

When you visit or use the Platform, we may automatically collect technical and usage information, such as:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages visited and features used
  • Date, time, and duration of access
  • Referring website or link
  • Cookies and similar tracking identifiers

Calendar Synchronization Data:

If you have connected your Google Calendar, the only lesson information Bloomin sends to Google is what is required to create, update, or delete the corresponding Google Calendar event:

  • The lesson's date, start time, end time, and time zone
  • A title identifying the lesson and the connected student
  • A brief description (a fixed label, or your session's meeting link if one is set)
  • The student's email address, if available, so they can be added as an event attendee

Bloomin stores the Google Calendar event identifier for each lesson so that a later reschedule or cancellation can update or delete the correct event, and securely stores the OAuth authorization tokens required to make these Calendar API calls on your behalf.

3. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process personal information only when we have a valid legal basis to do so. The legal bases we rely on include:

Performance of a contract (Article 6(1)(b) GDPR)

We process personal information where it is necessary to provide you with the Platform and its features — for example, creating your account, managing sessions, processing bookings, or facilitating payments. If you are a Service Provider, this includes the processing necessary to deliver the services described in our Terms of Service.

Legitimate interests (Article 6(1)(f) GDPR)

We process personal information where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights. Our legitimate interests include operating, securing, and improving the Platform; understanding how users interact with Saman; preventing fraud and abuse; and maintaining business records. Where we rely on legitimate interests, we carry out a balancing assessment to ensure our processing is proportionate.

Consent (Article 6(1)(a) GDPR)

Where required, we process personal information based on your consent — for example, for certain marketing communications or non-essential cookies. You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Legal obligation (Article 6(1)(c) GDPR)

We process personal information where it is necessary to comply with a legal obligation — for example, tax and accounting requirements, or responding to lawful requests from authorities.

Where a Service Provider enters personal information about their students or clients into Saman, the Service Provider is the data controller for that information and is responsible for establishing the appropriate legal basis. Saman processes that information on behalf of the Service Provider as a data processor. Our processing is governed by the terms of our agreement with the Service Provider, including any applicable Data Processing Agreement.

4. How We Use Information

We use personal information for the following purposes:

  • Creating and managing user accounts
  • Authenticating users, including through Google Sign-In
  • Providing access to the Platform and its features
  • Allowing Service Providers to manage students, sessions, schedules, and payments
  • Creating profiles, availability pages, and shareable booking links
  • Processing bookings, session requests, or payments
  • Communicating with users about their account, bookings, or use of the Platform
  • Providing customer support
  • Sending service-related notifications (such as booking confirmations or payment receipts)
  • Improving the Platform's performance, reliability, and user experience
  • Understanding how users interact with the Platform through analytics
  • Detecting, preventing, and responding to fraud, abuse, security incidents, or technical issues
  • Maintaining business, tax, accounting, and operational records
  • Complying with applicable legal or regulatory obligations

Google Calendar Integration Specific Uses:

When you connect your Google Calendar to Bloomin, we use the information described above solely to:

  • Create a Google Calendar event on your primary calendar when a Bloomin lesson is created
  • Update that event when you reschedule the lesson in Bloomin
  • Delete that event when you cancel the lesson in Bloomin, while the integration remains connected

We do not use personal information for purposes unrelated to the Platform unless we have a valid legal basis or your consent. Google Calendar data is used exclusively to keep the Bloomin-generated event on your primary calendar in sync with the corresponding Bloomin lesson — Bloomin does not read your existing calendar or use it to determine availability.

5. Cookies and Tracking Technologies

Saman uses cookies and similar technologies to operate the Platform, maintain security, and understand usage patterns.

Strictly necessary cookies

are required for the Platform to function properly — for example, keeping you signed in and remembering your preferences. These cookies do not require consent.

Analytics cookies

help us understand how visitors use the Platform, measure performance, and identify areas for improvement. These cookies are used only with your consent where required by applicable law. We use PostHog, hosted in the European Union, for this purpose. We do not store your IP address: approximate location (country/city) is derived at ingestion and the IP itself is discarded. If you decline analytics cookies, we collect only anonymous, cookie-free usage statistics that cannot be linked to you.

Marketing cookies

if used, help us understand the effectiveness of our communications and may support relevant messaging. These cookies are used only with your consent.

When you first visit our website, you may be presented with a cookie banner that allows you to accept or reject non-essential cookies. You can also manage cookies through your browser settings at any time.

Blocking some cookies may affect how the Platform works.

6. Sharing Information with Third Parties

We do not sell personal information.

We may share personal information with third parties where necessary to operate, support, secure, or improve the Platform. These third parties act as data processors on our behalf (where applicable under GDPR) and are bound by contractual obligations to protect the personal information they process.

Categories of third-party recipients may include:

  • Cloud hosting and infrastructure providers
  • Database and storage providers
  • Payment processors (such as Stripe)
  • Email and communication service providers
  • Analytics providers (PostHog, hosted in the EU)
  • Customer support tools
  • Scheduling and calendar integration services (Google Calendar API)
  • Authentication providers (such as Google, for Sign-In)
  • Security and fraud-prevention services
  • Professional advisers (such as lawyers, accountants, or auditors)

Google Calendar API Data Sharing:

When you connect your Google Calendar to Bloomin, the lesson information listed in Section 2.3 is shared with Google's Calendar API to create, update, or delete the corresponding event on your primary calendar. Specifically:

  • We send the lesson's date, time, time zone, a title and brief description, and (if available) the student's email to Google's servers to create, update, or delete that one event
  • Google stores that event, like the rest of your calendar, on its own secure servers (not on Bloomin's servers)
  • All Calendar API operations are limited to the primary calendar of the Google account you connect — Bloomin does not read, list, or enumerate any other calendar
  • Your Google authorization tokens are used only to perform these Calendar API operations and are never shared with other parties

If you disconnect or revoke Bloomin's access to your Google Calendar — whether through Bloomin's settings or your Google Account settings — Bloomin can no longer create, update, or delete Calendar events. Any event already created by Bloomin will remain on your calendar unless Bloomin was able to delete it (for example, on lesson cancellation) before access was revoked.

We may also disclose personal information where required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, property, or safety of Saman, our users, or the public.

7. International Data Transfers

Saman EdTech OÜ is established in Estonia, within the European Economic Area (EEA). However, some of the third-party service providers we use may be located outside the EEA, including in the United States and other countries.

Where personal information is transferred outside the EEA to a country that has not been deemed to provide an adequate level of data protection by the European Commission, we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • An adequacy decision by the European Commission for the recipient country
  • Other legally recognised transfer mechanisms under GDPR

You can request more information about the specific safeguards applied to international transfers by contacting us at info@trybloomin.ai.

8. Data Retention

We retain personal information only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

General retention guidelines:

  • Account data: Retained for the duration of your account and for up to 12 months after account deletion, unless a longer period is required for legal, tax, or accounting purposes.
  • Transaction and payment records: Retained for the period required by applicable tax and accounting legislation (typically 7 years in Estonia).
  • Usage and analytics data: Retained in identifiable form for up to 24 months, after which it is aggregated or anonymised.
  • Support correspondence: Retained for up to 24 months after the most recent interaction.
  • Data processed on behalf of Service Providers: Retained in accordance with our agreement with the Service Provider and deleted or returned upon termination of the agreement, subject to legal obligations.

Google Calendar Data Retention:

  • Google Calendar event identifiers: Retained for as long as the corresponding Bloomin lesson exists, so that a reschedule or cancellation can update or delete the correct Google Calendar event. Deleted when the lesson is deleted from Bloomin.
  • Events created by Bloomin on your Google Calendar: Remain in your Google Calendar indefinitely (stored by Google, not by Bloomin), unless Bloomin deletes the event on cancellation while still connected, or you delete it yourself.
  • Calendar connection tokens: Retained only while your account is active and the calendar integration is connected. Deleted when you disconnect or close your account.

When personal information is no longer needed, we securely delete or anonymise it. Note that events created by Bloomin remain in your Google Calendar account and are not automatically deleted by Bloomin unless the corresponding lesson is cancelled while the integration is still connected.

9. Data Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.

These measures include access controls, encryption of data in transit and at rest where appropriate, monitoring, and internal policies for handling personal information.

Google Calendar Data Security:

Calendar data security is managed by both Bloomin and Google:

  • Encryption in transit: All calendar data is transmitted to Google's servers using HTTPS encryption.
  • Google's storage security: Calendar events are stored securely on Google's servers and protected by Google's enterprise-grade security infrastructure.
  • Least-privilege API access: Bloomin's access is limited to the single OAuth scope described in Section 17, which permits creating, changing, and deleting only events on calendars you own — Bloomin never requests read access to your existing calendar.
  • Token security: Your Google authorization tokens are stored securely and never logged or shared with unauthorized parties.
  • Revocation capability: You can revoke Bloomin's access to your calendar at any time, and Bloomin will immediately lose the ability to create, update, or delete events on your calendar.

However, no website, platform, internet transmission, or electronic storage system is completely secure. Users should take care when sharing information online, keep their account login credentials confidential, and regularly review their connected apps in their Google Account settings.

10. Your Rights Under GDPR

If you are located in the EEA, the United Kingdom, or another jurisdiction that grants similar rights, you have the following rights regarding your personal information:

Right of access

Request a copy of the personal information we hold about you.

Right to rectification

Ask us to correct inaccurate or incomplete information.

Right to erasure ("right to be forgotten")

Ask us to delete your personal information, subject to certain legal exceptions.

Right to restriction of processing

Ask us to restrict certain processing activities while a concern is resolved.

Right to data portability

Request that we provide your personal information in a structured, commonly used, machine-readable format.

Right to object

Object to processing based on legitimate interests, including profiling. We will stop processing unless we can demonstrate compelling legitimate grounds.

Right to withdraw consent

Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. In Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You may also contact the supervisory authority in your country of residence.

To exercise any of these rights, please contact us at info@trybloomin.ai. We will respond within one month of receiving your request, unless the request is complex, in which case we may extend this period by up to two additional months with notice.

If your personal information was entered into Bloomin by a Service Provider, we may direct your request to that Service Provider where they are the data controller responsible for the information.

11. Automated Decision-Making

Saman does not currently use fully automated decision-making or profiling that produces legal effects or similarly significant effects on users.

If this changes in the future, we will update this Privacy Policy and, where required by GDPR Article 22, provide you with meaningful information about the logic involved, the significance of the processing, and its envisaged consequences.

Saman may use automated tools to assist with features such as scheduling suggestions, matching, or recommendations. These tools support human decision-making and do not produce decisions with legal or similarly significant effects.

12. Marketing Communications

We may send marketing emails, product updates, newsletters, or promotional messages if you have opted in to receive them, or where otherwise permitted by applicable law (such as soft opt-in for existing customers in the EEA).

You can unsubscribe from marketing emails at any time by clicking the "unsubscribe" link included in each email.

Even after unsubscribing from marketing communications, we may still send you service-related messages, such as account notifications, security alerts, booking confirmations, payment receipts, or platform updates.

13. Children's Privacy

Saman is primarily intended for Service Providers (educators, tutors, coaches, and similar professionals).

Saman is not designed for children to use directly unless access is clearly authorised by a parent, guardian, school, or other responsible adult.

Because Service Providers may use Saman to manage students who are children (under the age of 16, or the applicable age in the relevant jurisdiction), those Service Providers are responsible for ensuring they have the appropriate parental or guardian consent, or other lawful basis, before entering a child's personal information into the Platform.

We do not knowingly collect personal information directly from children without appropriate consent. If you believe that a child's personal information has been provided to us without appropriate permission, please contact us at info@trybloomin.ai

We will review the matter and take appropriate action, which may include deleting the information.

14. Third-Party Links and Services

The Platform may contain links to third-party websites, services, or integrations. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party service before providing your personal information.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, the Platform, technology, legal obligations, or business operations.

When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email or through the Platform.

We encourage you to review this Privacy Policy periodically.

16. Contact Information

If you have questions, concerns, or requests about this Privacy Policy or how Saman handles personal information, please contact us:

Data controller: Saman EdTech OÜ

Registry code: 17369778

Address: Harju maakond, Tallinn, Kesklinna linnaosa, J. Poska tn 14a-5 10126

Email: info@trybloomin.ai

Website: https://www.trybloomin.ai/

17. Google API Services Disclosure

Bloomin uses Google Sign-In to allow users to authenticate using their Google Account. Through this integration, Bloomin accesses only your basic profile information (name, email address, and profile picture) for the purpose of account creation and authentication.

Google Calendar Integration:

Bloomin also integrates with the Google Calendar API so that a Bloomin lesson has a corresponding event on your own Google Calendar. Bloomin creates that event when the lesson is created, updates it if the lesson is rescheduled, and deletes it if the lesson is cancelled while the integration remains connected. Bloomin does not list, read, or import your existing calendar events, and does not use Google Calendar to determine availability or detect scheduling conflicts. When you authorize calendar access, we request exactly one scope:

  • https://www.googleapis.com/auth/calendar.events.owned: create, change, and delete events on Google calendars you own — limited in practice to the single event Bloomin creates for each lesson on your primary calendar.

Bloomin's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We limit our use of Google Calendar data to creating, updating, and deleting the single event that corresponds to each Bloomin lesson on the Platform.
  • We do not transfer Google Calendar data to third parties except as necessary to provide or improve Platform features (such as to payment processors for booking confirmation), to comply with applicable law, or as part of a merger or acquisition with adequate data protection provisions.
  • We do not use Google Calendar data for serving advertisements or marketing purposes.
  • We do not allow humans to read Google Calendar data except with your affirmative consent (e.g., for customer support), where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.
  • You retain full control over your calendar and can revoke Bloomin's access at any time through your Google Account settings. Events Bloomin creates remain your property and are never shared with other users.