BookByOnline
PrivacyTermsPartnersCookiesDPAAcceptable useAI

Privacy Policy

Last updated 11 July 2026

This Privacy Policy explains how BookByOnline collects, uses, shares and protects personal information, the legal bases we rely on, and the choices and rights you have under the EU/UK GDPR, the California CCPA/CPRA and comparable laws. It applies to our websites, booking pages, merchant dashboard, APIs and AI features.

Introduction

BookByOnline is an appointment-booking and business-management platform. We take a plain-language approach to privacy: we collect what we need to run the service, we tell you why, and we give you meaningful control. If anything here is unclear, contact privacy@bookbyonline.com.

Definitions

“Platform” means the BookByOnline websites, apps, booking pages and APIs. “Merchant” means a business using the Platform. “Customer” means an end-user booking with a Merchant. “Personal information/data” means information relating to an identified or identifiable person. “Controller” and “Processor” have the meanings given under applicable data-protection law.

Who this policy applies to

This policy covers website visitors, Customers booking appointments, Merchant businesses and their team members, marketplace/directory users, and users of AI Receptionist features. For account and marketing data we act as a controller; for the booking and customer data a Merchant processes through the Platform, the Merchant is the controller and we act as their processor (see our Data Processing Addendum).

Account information we collect

When you create an account we collect your name, email address, phone number, password (stored only as a secure hash), profile details and business information you provide during signup and onboarding.

Business information we collect

For Merchants we process company details, addresses and locations, service listings and pricing, working hours, booking records, customer records you add or import, staff/team member records, and payment configuration such as deposit and payout settings.

Technical information we collect

We automatically collect device and browser information, IP address, cookie and similar identifiers, pages viewed and features used, approximate location derived from IP, and session information needed to keep you signed in and to secure the service.

Booking information we collect

We process appointment history, payment and deposit records, reviews and ratings, and communications sent through or about a booking (for example confirmations, reminders and cancellation notices).

AI services information

Where a Merchant enables AI Receptionist features, we may process call and chat metadata, chat history, appointment requests, and — only where recording/transcription is switched on and lawful notice has been given — call recordings and transcriptions. See our AI Terms for details and obligations.

Purposes of processing

We use personal information to provide and operate the service; authenticate users; deliver customer support; send service and (with consent) marketing communications; prevent fraud and abuse; monitor and improve security; develop and improve products; produce analytics and reporting; and comply with legal obligations.

Legal bases

We rely on: performance of a contract (to provide the service you or your Merchant requested); consent (for analytics/marketing cookies and non-essential messaging, withdrawable at any time); legitimate interests (to secure, maintain and improve the Platform, balanced against your rights); and legal obligations (tax, accounting and lawful requests).

International transfers

We and our subprocessors may process data outside your country. Where we transfer personal data internationally we use appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical and organisational measures.

Data retention

We keep account and business records for as long as an account is active and as needed to meet legal, tax and accounting obligations, after which we delete or anonymise them. Customer records deleted by a Merchant are anonymised rather than erased where retention is legally required. Specific retention periods are available on request.

Your rights

Subject to law you may access, correct, delete, export (portability), restrict or object to processing, and withdraw consent. To exercise a right that concerns data a Merchant controls, contact that Merchant; we will assist them as their processor. Email privacy@bookbyonline.com and we respond within 30 days. You may also complain to your supervisory authority (in the UK, the ICO).

Cookies and tracking

We use essential cookies to run the service and, only with your consent, analytics and marketing cookies. You can change or withdraw your choice at any time via “Your Privacy Choices”, and we honour the Global Privacy Control signal as an opt-out of sale/sharing. See our Cookie Policy.

Third-party providers

We share data only with the subprocessors that operate the service — including Stripe (payments), Supabase (database/auth), Vercel (hosting), Google and Microsoft (sign-in and maps), and email/SMS providers — under contract and only as needed. A current list is on our Subprocessors page. We do not sell personal information for money.

Data security

We encrypt data in transit and at rest, scope access by merchant with row-level security, enforce least-privilege access controls, keep audit logs, and support SSO and two-factor authentication on eligible plans. No system is perfectly secure, but we work to protect your data and to notify affected parties of incidents as required.

Children's privacy

The Platform is intended for businesses and adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy to reflect changes in our service or the law. Material changes will be notified in-product or by email, and the “last updated” date will change. Continued use after an update constitutes acceptance where permitted by law.

Contact & DPO

For privacy questions or to reach our Data Protection Officer, email privacy@bookbyonline.com. EU/UK customers may also contact us about appointing a representative where required.