Privacy Notice

Last updated 22 September 2026

1. Who we are

BookAppt is the data controller for personal data processed through the BookAppt service. You can reach us through the feedback form available on every page of the app.

2. Data we collect and why

  • Account data (name, email address, login credentials, timezone, booking handle) — to create and secure your account and provide the Service. Legal basis: performance of a contract.
  • Availability and appointment data (hours, blocked dates, appointment times, notes, address, phone number, email of the person booking) — to schedule and display appointments. Legal basis: performance of a contract.
  • Messages exchanged between a host and a client on an appointment — to provide in-app messaging. Legal basis: performance of a contract.
  • Support and feedback messages you send us — to answer you and improve the product. Legal basis: legitimate interests.
  • Technical and usage data (IP address, device and browser information, log and error data) — for security, fraud prevention, and reliability. Legal basis: legitimate interests.
  • Subscription status (plan, trial and renewal dates) — to manage access to paid features. Legal basis: performance of a contract and legal obligation. Card and billing details are collected and handled by Paddle, not by us.

3. Who we share data with

  • Service providers / subprocessors — our hosting, database, email delivery and error-monitoring providers, who process data only on our instructions.
  • Paddle.com, our Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing.
  • Professional advisers (legal, accounting) and authorities where we are required to disclose by law.

We do not sell personal data.

4. International transfers

Our providers are located primarily in the United States. Where data is transferred from the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision.

5. Retention

We keep account, appointment and message data for as long as your account is active, and for up to 12 months after closure so you can reactivate or request an export. Records we must keep for tax or accounting reasons are retained for the period required by law. After that, data is deleted or anonymised.

6. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent at any time. You may also complain to your local data protection supervisory authority. Contact us through the in-app feedback form and we will respond within one month.

7. Security

We use appropriate technical and organisational measures, including encryption in transit, encryption of stored calendar credentials, row-level access controls in our database, and restricted administrative access.

8. Cookies and similar technologies

We use essential cookies and browser storage to keep you signed in and to keep the Service secure; these are required for the app to work. Our checkout provider, Paddle, may set cookies necessary to complete a purchase. We do not use advertising cookies. You can clear or block cookies in your browser settings, though signing in will then not work.