Privacy Policy for Cita

(Last updated: 31st July 2026)

This policy explains what personal data Cita, Cita Wallet, and Cita Stays collect, why we collect it, and the choices you have. It applies to all Cita products operated by Insharp Technologies.

Protecting your privacy matters to us. This Privacy Policy describes the personal data we collect across Cita, Cita Wallet, and Cita Stays, and how it’s used, stored, and shared — including where that data touches our payment partners, OnePay & Directpay. By using any Cita service, you agree to the practices described here.

Consent

By using our website, you hereby consent to our Privacy Policy and agree to its terms.

 

1. Overview

This policy applies to all products operated by Insharp Technologies under the Cita brand: the Cita scheduling app, Cita Wallet, and Cita Stays. Each product may collect slightly different information depending on the feature you’re using, but all of it is handled under the same principles set out below. 

Booking and Service Categories

Cita provides an online platform that enables users to discover, book, reserve, schedule and pay for a variety of services. These services currently include:

  • Accommodation bookings, including hotels, villas and hostels;
  • Food and beverage reservations, including restaurants, cafés and buffets;
  • Meeting-space reservations, including meeting rooms, event spaces, co-working spaces and hot desks;
  • Paid appointments, consultations and professional services;
  • Event registrations and bookings, including conferences, concerts, workshops and similar events; and
  • Electric vehicle (EV) charging-station reservations and charging payments.
This Privacy Policy applies to all bookings, reservations, appointments and payments made through Cita’s service categories, including any additional categories or services introduced in the future. It covers our online services and applies to Visitors, Users and Invitees, as defined in Section 2, but does not apply to information collected offline or through channels other than our services.

2. Definitions

A few terms are used throughout this policy:

  • Services — all text, data, information, software, graphics, and other content made available by Cita and its affiliates, including our websites, apps, extensions, and plugins
  • Users — individuals who have created a Cita account
  • Invitees — individuals who schedule or attend a meeting through Cita with a User, including candidates in relevant contexts
  • Visitors — individuals who visit our services without necessarily being a User or Invitee
  • Personal Data — any data relating to an identified or identifiable natural person that we process, as described in this policy

3. What we collect

Depending on which Cita product you use, we may collect:

  • Contact information — your name, email address, and phone number when you register, or when you contact us directly (including the contents of any messages or attachments you send us)
  • Scheduling, reservation and booking information — booking date and time, selected service, venue or location, number of guests or attendees, reservation status, booking preferences, special requests, accommodation stay details, meeting or consultation details, event registrations, EV charging-session details, and other information necessary to provide the selected service.
  • Usage data — how you interact with our apps, including pages visited, features used, and usage patterns or preferences
  • Meeting data — if you enable the meeting transcript widget and request a transcript for a specific meeting, we collect an audio recording for that meeting solely to generate the transcript; recording only starts after we’ve obtained your consent
  • Calendar data — if you connect Google Calendar, Outlook, or similar, to display and sync availability
  • Wallet & transaction data — top-ups, withdrawals, transaction history, and linked bank account details (see Section 4)
  • Device & log data — IP address, browser type, Internet Service Provider, date/time stamps, referring and exit pages, and similar technical information collected automatically
  • Payment information — payment amount, currency, transaction reference, payment status and other transaction information required to process and manage payments.

We only ask for the personal data needed for the feature you’re using — for example, scheduling a meeting typically only requires names, email addresses, and the date and time. We recommend sharing only the details essential to using our services; declining to share certain data may limit our ability to provide some features.

4. Payment data

When you make a payment through Cita, payments may be processed by authorized third-party payment service providers. Cita does not store complete payment-card numbers or card security codes (CVV). We retain transaction records, including payment amount, date, status and transaction reference, as required for customer support, dispute resolution, financial reporting and legal obligations.

5. How your information is used

We use the information we collect to provide, operate, maintain, improve, personalize and expand our services; understand and analyze how our services are used; and develop new products, features and functionality.

We also use your information to create, process, confirm, modify and cancel bookings, reservations and appointments; facilitate, verify, process and reconcile payments; issue booking confirmations, receipts, reminders and other service-related notifications; connect you with the relevant accommodation provider, restaurant, venue operator, consultant, event organizer, EV charging-station operator or other service provider to fulfil your booking or requested service; provide customer support and resolve booking, reservation and payment-related issues; detect, investigate and prevent fraud, unauthorized transactions, abuse and other security incidents; communicate with you about your account, transactions, updates and, where permitted by law, marketing or promotional offers; and comply with applicable legal, regulatory, financial and accounting obligations.

We do not sell your personal data to third parties.

6. Sharing & third parties

We share your information only where reasonably necessary to provide, operate, and improve our services.

To fulfil your booking or reservation requests, we may share the information reasonably necessary with the relevant service providers, including hotels, villas, hostels, restaurants, buffet providers, meeting-space operators, consultants, event organizers, EV charging-station operators, and other partners involved in delivering the requested service.

We may also share payment and transaction information with authorized payment gateways, banks, and financial institutions where necessary to process, verify, refund, reconcile, or manage payments. This includes payment processors such as OnePay and DirectPay.

If you choose to connect third-party services, we may share information with those providers as required to enable the integration, including calendar and meeting service providers such as Google, Outlook, and Zoom.

We may also share information with hosting, infrastructure, analytics, security, and other service providers that help us operate, maintain, and improve Cita. These providers are required to handle your information securely and maintain appropriate confidentiality obligations.

We may share information with advertising partners as described in Section 8, and with government authorities or other parties where required by applicable law, legal processes, or to protect the rights, security, and safety of Cita, our users, or others.

We only share information that is reasonably necessary to provide the requested service, comply with legal obligations, prevent fraud, or protect the security of Cita and its users.

Third parties we work with have their own privacy policies governing how they handle any information shared with them. This Privacy Policy does not apply to their practices, and we encourage you to review their privacy policies directly.

7. Calendar & meeting integrations

If you connect a third-party calendar or meeting tool, we access and use the following information solely to power that integration:

  • Google Calendar — used to display your availability, schedule appointments around your existing commitments, and keep events synced between Cita and Google Calendar. Our use and transfer of information received via Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
  • Outlook Calendar — used the same way as Google Calendar, for displaying availability and syncing appointments. We use this information only for scheduling and display within Cita and do not share it with any other third-party applications.
  • Zoom — when you authorize the Zoom integration, we collect your Zoom name, email address, and meeting history, along with meeting information such as topic, participants, and recordings (if applicable), and usage data about how you use the integration. This is used to facilitate scheduling, joining, and hosting meetings, to improve the integration, and to send you related updates. We share this information with Zoom to enable the integration and with service providers who help us operate it. You can manage these permissions in your Zoom account settings or disconnect the integration at any time.
  • Google Meet — when enabled, we collect limited Google account information needed for scheduling, joining, and hosting meetings, such as your name, email address, and calendar events, along with meeting details (topic, participants, recordings) and usage data. This is shared with Google to enable the integration and with trusted service providers who assist our operations.

8. Cookies & advertising

Cita uses cookies and similar technologies (including web beacons) to remember your preferences, keep you signed in, and understand how our services are used, so we can improve and customize them. You can disable cookies through your browser settings, though some features may not work correctly without them.

Some of our advertising partners may also use cookies, JavaScript, or web beacons in the ads and links that appear on our services to measure ad performance or personalize the content you see; these technologies can automatically receive your IP address when they’re triggered. We have no access to or control over the cookies used by third-party advertisers, and this policy doesn’t apply to their practices — consult their own privacy policies for details, including how to opt out.

9. Security & retention

We use industry-standard measures to protect your data, including encrypted storage, HTTPS for data in transit, and secure password hashing using the Bcrypt algorithm — we never store passwords in plain text. We encourage you to choose a strong, unique password (a mix of uppercase and lowercase letters, numbers, and special characters) and to avoid easily guessable information like your name or birthdate. We retain your data only as long as your account is active or as required to meet legal and regulatory obligations, after which it is securely deleted or anonymised.

10. Your rights

Depending on where you live, you may have rights over your personal data. Sri Lankan users are protected under the Personal Data Protection Act; users elsewhere may have equivalent rights under their local law, such as the GDPR or CCPA.

Under the GDPR, you have the right to: access copies of your personal data (we may charge a small fee for this); request correction of inaccurate or incomplete data; request erasure of your data under certain conditions; request that we restrict processing of your data; object to our processing of your data; and request that we transfer your data to another organization or to you directly (data portability).

Under the CCPA, California consumers have the right to: request disclosure of the categories and specific pieces of personal data we’ve collected; request deletion of personal data we’ve collected; and request that we not sell their personal data (Cita does not sell personal data).

If you make a request under either framework, we aim to respond within one month. To exercise any of these rights, contact us using the details in Section 13.

11. Children’s privacy

Our services are not directed at children under 13, and we do not knowingly collect personal data from them. We encourage parents and guardians to observe, participate in, and monitor their children’s online activity. If you believe a child has provided us with personal information, please contact us and we will take steps to remove it.

12. Changes to this policy

We may update this Privacy Policy periodically, including to reflect new payment partners or regulatory requirements. We’ll update the “Last updated” date above whenever we make a change, and encourage you to review this page from time to time.

13. Contact us

Questions about this Privacy Policy or your data can be directed to:

Phone: 011 2 839 594
Address: Bristol Building, 133 2/1, High Level Rd, Maharagama 10280, Sri Lanka
 

Scroll to Top

Book Your Free Seat - New

Book Your Free Seat