Privacy Policy

Last updated: January 15, 2025

Data Protection

Industry-standard encryption and security measures

GDPR Compliant

Full compliance with data protection regulations

Transparency

Clear communication about data usage

1. Information We Collect

Account Information

When you create a BookTime account, we collect:

  • Name and email address (via Google OAuth)
  • Profile picture (optional)
  • Business information (company name, industry, timezone)
  • Payment information (processed securely via Stripe)

Client Data

Information about your clients that you enter into the system:

  • Contact details (name, email, phone)
  • Appointment history and preferences
  • Custom notes and tags
  • Form submissions and responses

Usage Data

  • Log data (IP address, browser type, pages visited)
  • Device information (operating system, device type)
  • Feature usage analytics (to improve the platform)

2. How We Use Your Information

We use collected information to:

  • Provide Services: Enable appointment scheduling, client management, and form submissions
  • Communication: Send booking confirmations, reminders, and important updates
  • Billing: Process payments and manage subscriptions
  • Improvement: Analyze usage patterns to enhance features and user experience
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: Meet legal and regulatory requirements

3. Data Sharing and Disclosure

We DO NOT sell your data

Your data is never sold to third parties. We only share information in these limited circumstances:

  • Service Providers: Trusted partners who help us operate (e.g., AWS for hosting, Stripe for payments)
  • Legal Requirements: When required by law or to protect rights and safety
  • Business Transfers: In the event of a merger or acquisition (with prior notice)
  • Your Consent: When you explicitly authorize sharing

4. Data Security

Security Measures

  • • End-to-end encryption for data in transit (TLS 1.3)
  • • AES-256 encryption for data at rest
  • • Row-Level Security (RLS) for database isolation
  • • Regular security audits and penetration testing
  • • JWT-based authentication with HTTP-only cookies
  • • Multi-factor authentication (MFA) available

5. Your Rights (GDPR)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Export your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to data processing for certain purposes
  • Withdraw Consent: Revoke consent for data processing at any time

To exercise these rights, contact us at [email protected]

6. Data Retention

We retain your data for as long as your account is active or as needed to provide services. When you delete your account:

  • Account data is permanently deleted within 30 days
  • Backups are purged within 90 days
  • Some data may be retained for legal compliance (e.g., tax records for 7 years)

7. Cookies and Tracking

We use cookies for:

  • Essential Cookies: Authentication and session management (required)
  • Analytics Cookies: Usage statistics to improve the platform (optional)
  • Preference Cookies: Remember your settings and preferences (optional)

You can control cookie preferences in your browser settings.

8. International Data Transfers

BookTime operates globally. Your data may be transferred to and processed in countries outside your residence. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the EU Commission
  • Data Processing Agreements (DPAs) with all processors
  • Compliance with local data protection laws

9. Children's Privacy

BookTime is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such data, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via:

  • Email notification (to your registered email address)
  • In-app notification
  • Prominent notice on our website

Continued use after changes constitutes acceptance of the updated policy.

11. Contact Us

For questions about this Privacy Policy or your data:

Email: [email protected]

Data Protection Officer: [email protected]

Response Time: Within 30 days

Jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of the jurisdiction where BookTime is registered. For EU/EEA users, GDPR provisions take precedence.