Privacy Policy
Last updated: January 15, 2025
Data Protection
Industry-standard encryption and security measures
GDPR Compliant
Full compliance with data protection regulations
Transparency
Clear communication about data usage
1. Information We Collect
Account Information
When you create a BookTime account, we collect:
- Name and email address (via Google OAuth)
- Profile picture (optional)
- Business information (company name, industry, timezone)
- Payment information (processed securely via Stripe)
Client Data
Information about your clients that you enter into the system:
- Contact details (name, email, phone)
- Appointment history and preferences
- Custom notes and tags
- Form submissions and responses
Usage Data
- Log data (IP address, browser type, pages visited)
- Device information (operating system, device type)
- Feature usage analytics (to improve the platform)
2. How We Use Your Information
We use collected information to:
- Provide Services: Enable appointment scheduling, client management, and form submissions
- Communication: Send booking confirmations, reminders, and important updates
- Billing: Process payments and manage subscriptions
- Improvement: Analyze usage patterns to enhance features and user experience
- Security: Detect and prevent fraud, abuse, and security incidents
- Legal Compliance: Meet legal and regulatory requirements
3. Data Sharing and Disclosure
We DO NOT sell your data
Your data is never sold to third parties. We only share information in these limited circumstances:
- Service Providers: Trusted partners who help us operate (e.g., AWS for hosting, Stripe for payments)
- Legal Requirements: When required by law or to protect rights and safety
- Business Transfers: In the event of a merger or acquisition (with prior notice)
- Your Consent: When you explicitly authorize sharing
4. Data Security
Security Measures
- • End-to-end encryption for data in transit (TLS 1.3)
- • AES-256 encryption for data at rest
- • Row-Level Security (RLS) for database isolation
- • Regular security audits and penetration testing
- • JWT-based authentication with HTTP-only cookies
- • Multi-factor authentication (MFA) available
5. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to data processing for certain purposes
- Withdraw Consent: Revoke consent for data processing at any time
To exercise these rights, contact us at [email protected]
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. When you delete your account:
- Account data is permanently deleted within 30 days
- Backups are purged within 90 days
- Some data may be retained for legal compliance (e.g., tax records for 7 years)
7. Cookies and Tracking
We use cookies for:
- Essential Cookies: Authentication and session management (required)
- Analytics Cookies: Usage statistics to improve the platform (optional)
- Preference Cookies: Remember your settings and preferences (optional)
You can control cookie preferences in your browser settings.
8. International Data Transfers
BookTime operates globally. Your data may be transferred to and processed in countries outside your residence. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the EU Commission
- Data Processing Agreements (DPAs) with all processors
- Compliance with local data protection laws
9. Children's Privacy
BookTime is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such data, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via:
- Email notification (to your registered email address)
- In-app notification
- Prominent notice on our website
Continued use after changes constitutes acceptance of the updated policy.
11. Contact Us
For questions about this Privacy Policy or your data:
Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of the jurisdiction where BookTime is registered. For EU/EEA users, GDPR provisions take precedence.