Privacy Policy

Last updated: 1 May 2025

1. Who we are

BookMe (“we”, “us”, “our”) is a booking platform for independent beauty and body art professionals. When you use BookMe — whether as a business owner or as a customer booking an appointment — this policy explains how we handle your personal data.

2. Information we collect

Business owners

  • Name, email address, and phone number (collected during sign-up via Clerk)
  • Business name, service type, and location display
  • Working hours, buffer settings, and service details
  • Bank details you enter for deposit collection (stored encrypted at rest)
  • Portfolio photos and media you upload
  • Web push notification subscription tokens (for in-app alerts)

Customers

  • Name, phone number, and email address provided when booking
  • Appointment details (service, date, time)
  • Notes you add to a booking

3. How we use your information

  • To provide the service — processing bookings, sending confirmation and reminder emails, managing availability.
  • To communicate with you — transactional emails sent via Resend (booking confirmations, 24-hour reminders, cancellation notices).
  • To improve BookMe — aggregate, anonymised analytics to understand how the product is used. We do not sell personal data.
  • To prevent abuse — detecting spam bookings and no-show patterns.

4. Legal basis for processing (UK/EU users)

We process personal data on the following legal bases under UK GDPR and the EU General Data Protection Regulation:

  • Contract performance — processing necessary to deliver the booking service you requested.
  • Legitimate interests — improving the product, preventing fraud, sending transactional communications.
  • Consent — web push notifications (you can revoke at any time in your browser settings).

5. Data sharing

We share data only with trusted sub-processors required to operate the service:

ProviderPurposeLocation
ConvexDatabase, file storage, scheduled jobsUSA (SOC 2)
ClerkAuthenticationUSA (SOC 2)
ResendTransactional emailUSA
VercelHosting / CDNGlobal

We do not sell, rent, or share personal data with advertisers or third-party marketing platforms.

6. Data retention

  • Booking records are retained for 3 years to support business records requirements.
  • Owner account data is retained while your account is active. After deletion, we remove personal data within 30 days.
  • Email logs are retained for 90 days.

7. Your rights

Under UK/EU data protection law you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Object to or restrict certain processing
  • Data portability

To exercise any of these rights, email us at privacy@bookme.app. We will respond within 30 days.

8. Cookies

BookMe uses only essential cookies required for authentication (set by Clerk) and session management. We do not use advertising or tracking cookies.

9. Security

All data is transmitted over HTTPS. Sensitive fields (bank details) are encrypted at rest. We use industry-standard access controls and our sub-processors are SOC 2 certified where applicable. If you discover a security issue, please contact security@bookme.app.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified via email to registered business owners at least 14 days before taking effect. The “Last updated” date at the top of this page will always reflect the current version.

11. Contact

Questions about this policy? Reach us at privacy@bookme.app.