Tepidara Website Privacy Policy
The API Guys LLC Version: 1.0 Effective Date: 2026-10-07
1. What this policy covers, and what it does not
This policy describes what happens to personal information when you visit tepidara.com, send us a message, or book a call with us. For that information, The API Guys LLC is the controller — we decide what is collected and why, and this policy is the one that applies.
Tepidara is a brand of The API Guys LLC. It is not a separate company.
This policy does not apply to guest data we handle for a venue
Tepidara is also the name of the services we run for spa and thermal venues on top of their booking platform: phone check-in, staff tools, food and drink ordering, online shops, payment options, marketing syncs and reporting.
In that work we are a processor, not a controller. The venue decides what is collected about its guests and why; we act on its instructions under a written agreement with that venue. If you are a guest of a venue we work with, the venue’s privacy notice applies to your information, not this one. Their agreement with us governs how we may use it, and we may not use it for our own purposes.
So if you are a spa guest, this policy is almost certainly not about you. This website is for venue owners and managers evaluating our services. It does not take bookings, check-ins, orders or payments, and no guest data reaches it. For a question about your own booking, visit, order or payment, contact the venue — they hold that information, and we are not permitted to act on it for you.
Some payment options at a venue are provided by other companies under their own terms — for example Square for gift cards, Zaprite for bitcoin payments and TrueMed for HSA/FSA eligibility. If you pay with HSA or FSA funds, any health-related eligibility information is given to TrueMed on TrueMed’s own pages, and is governed by TrueMed’s privacy policy. It does not pass through this website. The systems we run for the venue receive only what is needed to complete the order: whether the payment went through, and whether TrueMed approved a letter of medical necessity and until when, so a returning guest is not asked again. We never receive the answers you give TrueMed.
(This is the same division a booking platform or payment provider draws: where we use a supplier to process information for us, their policy covers their own customers and ours covers you.)
2. Who is responsible
The API Guys LLC, a Massachusetts limited liability company with its principal office in Brookline, Massachusetts, United States, is the controller of the information described in this policy. It trades under the name Tepidara for these services.
Contact details are in §12.
3. What we collect, and when
There is no account to create. If you decline analytics, or ignore the banner, reading this website — including its help pages — collects nothing about you at all.
Two things collect information, and only when you choose to use them:
3.1 Booking a call
Book a call links to a scheduling page operated by HighLevel Inc. (the GoHighLevel / LeadConnector platform) on our behalf — see §4 for where it lives. If you book, you provide:
- your name
- your email address
- your phone number
- which booking platform your venue uses
- the appointment slot you choose
This information goes to HighLevel’s systems and into the customer-relationship account we maintain there. We use it to reply to you, to hold and prepare for the call, and to follow up afterwards about your enquiry.
Two optional tick-boxes about text messages. The booking form offers two separate consent boxes — one for messages about your appointment (confirmations, reminders, scheduling changes) and one for marketing messages (offers and product updates). Both are unticked by default and entirely optional: you can book without ticking either, and consent is never a condition of getting a call. If you tick one, you can withdraw at any time by replying STOP to any message, or by asking us — see §9. Reply HELP for assistance. Message frequency varies, and message and data rates may apply.
3.2 Emailing or calling us
If you email contact@tepidara.com or call the number on our contact page, we receive
whatever you choose to tell us — at minimum your email address or phone number, and the
contents of your message. Email reaches a shared address monitored by our team rather than
one individual.
3.3 What we do not collect
To be explicit, because the absence is deliberate:
- No advertising. No retargeting, no social pixels, no ad networks. Analytics, if you agree to it, is Google Analytics 4 and nothing else — see §4.
- No server access logs. Request logging on the content-delivery network serving this site is switched off, so we do not retain a record of who requested which page.
- No forms of our own. The contact page offers an email address rather than a form, so reaching us does not require handing us data first.
- No guest information. We neither ask for nor want information about any venue’s guests through this website. Please do not send any.
4. Cookies
This website sets no cookies unless you agree to analytics.
When you first visit, a banner asks whether we may use analytics cookies. Until you say yes, nothing is stored on your device by us — and Google Analytics does not run at all. It is not merely restricted: the tag does not load, no measurement is sent, and no cookie is written. If you decline, or ignore the banner entirely, it stays that way.
If you do agree, Google Analytics 4 sets two cookies (_ga and one beginning _ga_) so
we can tell which pages help people find us. It does not tell us who you are, and we never
send Google your name or email address.
We use no advertising cookies, no retargeting, and no social media pixels — agreeing to analytics does not switch advertising on, because we do not do it.
Google Tag Manager itself loads on every page, since it is the switch that turns analytics on when you agree. That means your browser contacts Google, but it carries no measurement and sets no cookie of its own.
Full detail, including how to change your mind, is in our Cookie Policy.
Booking a call is different, because it hands you to someone else — under our name.
The “book a call” button is an ordinary link. Following it takes you to a scheduling page
at links.tepidara.com. That address is ours, but the page is not: it is operated
by HighLevel Inc. on our behalf, and we point our own subdomain at their systems so the
link looks like the rest of our site.
We are telling you this because you could not otherwise tell. The address bar will
still say tepidara.com.
That page sets a security cookie. It is called __cf_bm, it comes from Cloudflare,
and its job is to tell real visitors from automated traffic so the booking page keeps
working. It lasts about half an hour and cannot be read by any script. Because the web
address is ours, it is stored against our domain name — but it is HighLevel’s cookie, set
for that purpose as our service provider.
Whatever that page sets is governed by HighLevel’s own privacy and cookie policies, which are linked from it. We do not run it and we do not control what it loads.
Nothing about any of that happens unless you click.
5. Who else sees your information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either.
Your mobile number, specifically. If you give us a phone number, it stays with us and the providers who deliver messages for us.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted.
Those subcontractors — the messaging platform that actually sends a text, for example — may use it only to deliver the service to us, and for nothing of their own.
One provider we name, because it is the one that matters. Booking a call sends your details to HighLevel Inc. (the GoHighLevel / LeadConnector platform), which runs our forms, our scheduling and our record of your enquiry. It is named here rather than left to a category because it receives everything anyone submits through this site.
Otherwise we use service providers in the ordinary categories — website hosting and content delivery (Amazon Web Services), analytics if you agree to it (Google), business email, and IT and security tooling. They handle information only as needed to provide those services to us, under contracts that limit what they may do with it and require them to protect it.
Partners who introduced you. Tepidara works with venues that use booking platforms such as Trybe, and those partners sometimes introduce venues to us. If a partner introduced you, we may tell that partner how the introduction is progressing — for example, that we have spoken. We do not share your enquiry with a partner who did not introduce you, and we never give partners your details for their own marketing.
We may also disclose information where the law requires it, or where we need to establish, exercise or defend a legal claim.
6. Where your information is processed
We are based in the United States, and the providers named above process information in the United States. If you contact us from outside the United States — including from the United Kingdom, the European Economic Area or Canada — your information will be transferred to and processed in the United States, where data protection law may differ from your own.
Where the law that applies to you requires a safeguard for that transfer, we rely on the contractual safeguards our providers offer for it.
7. Links to other websites
Some links on this site take you somewhere we do not run — the booking calendar operated by HighLevel, and pages of the booking platforms and payment providers we work with.
Once you follow a link, you are on someone else’s website and their privacy policy applies, not ours. They may set their own cookies and collect their own information, and we do not control that.
8. How long we keep it
If you enquire and do not become a client, we delete your record 24 months after your last contact with us. If you do become a client, your information is kept for the life of that relationship and then under the retention terms of our services agreement.
That period is not set here. It comes from our Data Retention & Destruction Policy, which is the single place every retention period at The API Guys LLC is maintained — this document restates one row of it for you. If the two ever disagree, the Data Retention & Destruction Policy is correct and the restatement here is a bug.
If you would like your record deleted sooner, ask — see §9.
9. Your rights
We extend these rights to everyone, wherever you live. Some of them are required of us in some places and not others; rather than making you work out which apply to you, we apply them all. Where a specific law gives you something additional, that law still wins.
You can ask us to:
- Know and access — what we hold, where we got it, and who we shared it with.
- Correct — have inaccurate information fixed.
- Delete — have your information erased, subject to records we are required to keep.
- Portability — receive your information in a portable form.
- Object — to our following up with you about our services; we will stop.
- Opt out of sale or sharing — we do not sell or share personal information for behavioural advertising, so there is nothing to opt out of; the right stands regardless.
- Non-discrimination — we will not treat you differently for exercising any right.
Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect anything done before you withdrew it.
How to exercise a right
Use our request form: compliance.theapiguys.com/dsar-form
It is the same form we use for every privacy request across our business, and it is the fastest route because it opens a tracked record the moment you submit it. You can also email us (§12) if you would rather — we log those the same way.
What happens then:
| Acknowledgement | Within 3 business days |
| Identity check | We confirm you control the email address in our records, so we do not hand your information to someone else |
| Answer | Within 30 days. If a request is genuinely complex we may extend, and we will tell you why before the 30 days are up |
| Cost | Free. If a request is repetitive or excessive we may charge or decline, and we will explain which and why |
| Agents | Someone may act for you if you authorise them |
We run one process for everyone rather than a different clock per jurisdiction. Some laws allow longer than 30 days; we do not take it as a matter of course.
If you think we have got it wrong, you can complain to a regulator. In the United Kingdom that is the Information Commissioner’s Office. In Canada it is the Office of the Privacy Commissioner of Canada, or your provincial commissioner. In the EEA it is your national supervisory authority. In California it is the California Privacy Protection Agency or the Attorney General. We would rather you raised it with us first so we can put it right, but that is your choice and not a precondition.
10. Why we are allowed to do this
We only handle your information for a reason we can point to:
| Purpose | Why we may |
|---|---|
| Replying to a message you sent | You contacted us and expect an answer |
| Arranging and holding a call you booked | You asked us to — these are steps taken at your request before any contract |
| Following up about our services after an enquiry you started | Our legitimate interest in pursuing an enquiry you initiated — and you can tell us to stop at any time |
| Analytics, if you agree to it | Your consent, which you can withdraw through the banner |
| Keeping the forms working and free of automated abuse | Our legitimate interest in a service that functions |
| Meeting legal, tax and regulatory obligations | Required of us by law |
(In UK and EU GDPR terms these are pre-contractual steps, legitimate interests, consent and legal obligation. Under Canadian law they rest on your implied or express consent, which you may withdraw. We have written the table in plain terms because the label matters less than the reason.)
11. Children
This website is directed at businesses. It is not intended for anyone under 16, and we do not knowingly collect information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
12. How to reach us
| General enquiries | contact@tepidara.com |
| Privacy matters | privacy@tepidara.com — subject line “Privacy Rights Request” or “Privacy Inquiry” |
| Privacy requests | compliance.theapiguys.com/dsar-form — fastest, opens a tracked record |
| Phone | +1 888-457-9944 |
| Post | Privacy Officer, The API Guys LLC, 1789 Beacon St Unit 1, Brookline, MA 02445, United States |
We identify our Privacy Officer by role rather than by name so that this policy stays accurate when the role changes hands. The addresses above are Tepidara’s own. They are answered by the same privacy desk that handles requests for every part of The API Guys LLC — a branded address, not a separate team. The request form is shared for the same reason: it opens a tracked record whichever brand you came from.
13. Changes to this policy
If we change this policy we will update the version and effective date above. Where a change materially affects how we handle information you have already given us, we will take reasonable steps to tell you directly rather than relying on you to re-read this page.
The version you are reading is published from our compliance repository, which is the single source of truth for it. Superseded versions are retained there.