Privacy Policy
Last updated: 27 July 2026
Bookatu("we", "us", "our") operates the booking platform at bookatu.com. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and what rights you have. Please read it carefully.
1. Who We Are
Bookatuprovides booking and business management software to service businesses ("Businesses"). When a Business uses our platform, their clients ("Clients") book appointments through a branded page hosted by us.
For the purposes of data protection law, Bookatu acts as a data controller for the personal information of Business account holders (the people who sign up and administer a Bookatu account). For personal information that a Business uploads or collects about its own Clients, Bookatu acts as a data processor on behalf of that Business, which is itself the data controller.
Because we wear two hats, this Policy is split by role. Sections about Business account holders describe data we control and are directly responsible for. Sections about Clients(the people who book with a Business) describe data we only process on a Business’s instructions under a written Data Processing Agreement (DPA) — for that data the Business is the controller, decides why it is used, and is responsible for having a lawful basis. Where this Policy describes a purpose for Client data (for example marketing), we act only on the relevant Business’s instructions and not on our own initiative. Businesses can request our standard DPA at hello@bookatu.com.
You can contact us at any time: hello@bookatu.com
2. Information We Collect
2a. Business Account Information
When a Business registers for Bookatu, we collect name, email address, business name, phone number, business address, payment details (handled by Stripe) and any other information provided during signup or later through the admin settings.
2b. Client and Booking Data
When Clients book through a Business page, or when a Business imports its existing client list, we collect and store on behalf of the Business: client name, email address, phone number, booking history, service preferences, loyalty points and any notes the Business records. This data belongs to the Business and is processed under their instructions.
2c. Payment Information
Payments, including booking deposits, are processed by Stripe. We do not store card numbers or payment credentials on our servers. We receive limited payment confirmation data (such as whether a payment succeeded and the last four digits of a card) from Stripe.
2d. Usage Data and Cookies
We collect information about how our platform is used, including IP addresses, browser type, pages visited, referral sources and session duration. We use cookies that are strictly necessary to keep you logged in and run the site, which do not require consent. Where we use optional analytics cookies, we load them only after you acknowledge our cookie notice and we honour consent signals (including Global Privacy Control). You can also control cookies through your browser settings, though disabling strictly-necessary ones may affect platform functionality.
3. How We Use Your Information
We use personal information to:
- Create and manage Business accounts and provide the Bookatu platform.
- Enable Clients to make, amend and cancel bookings and send confirmation, reminder and post-visit emails on behalf of the Business.
- Send marketing emails (such as win-back offers and birthday promotions) at a Business’s instruction and only to Clients that Business tells us have consented. We do not decide who receives Business marketing.
- Process and reconcile payments and deposits via Stripe.
- Follow up on incomplete attempts: when someone starts a booking, package or gift-card purchase, or (for signups) a Bookatuaccount but does not finish, we store the contact details they entered (such as name, email, phone and what they were arranging) so the Business — or, for signups, Bookatu— can reach out to help them complete it.
- Detect and prevent fraud, security incidents and technical issues.
- Improve platform features and monitor performance through aggregated and pseudonymised analytics.
- Communicate with Business account holders about their subscription, billing and product updates.
- Comply with legal and regulatory obligations.
The purposes above describe our use of personal information generally. Our use of data obtained through Google APIs is further restricted and is governed solely by the "Google User Data" section below; nothing here authorises any use of Google user data beyond what that section permits.
4. Legal Bases for Processing (GDPR)
Where the General Data Protection Regulation (GDPR) applies, we rely on the following legal bases:
- Contract: processing necessary to provide the services you or the Business has signed up for.
- Consent: sending marketing emails to Clients who have opted in. Consent can be withdrawn at any time via the unsubscribe link in any marketing email.
- Legitimate interests: security monitoring, fraud prevention, product improvement and certain communications with Business account holders, where these interests are not overridden by your rights.
- Legitimate interests (incomplete attempts): following up on a booking, purchase or signup that you began but did not finish, using the contact details you entered, so a Business or Bookatu can help you complete it. We balance this against your interests — the data is kept only briefly (see “Data Retention”), and you can object or ask us to delete it at any time.
- Legal obligation: record-keeping required by applicable law.
5. Sharing Your Information
We do not sell or share personal information for advertising. We share it only as described below. For Client data, the providers below act as our sub-processors under our DPA with the Business:
- Stripe: to process payments and deposits. Stripe operates under its own privacy policy at stripe.com/privacy.
- Resend: to deliver transactional and marketing emails on behalf of Businesses. Resend processes recipient email addresses and message content.
- Google:if a Business or staff member connects a Google account, we access their Google Calendar and basic Google profile to power calendar sync and Google Meet links. We do not sell, rent or transfer Google user data to any third party for advertising, credit assessment or data brokerage, and we share it onward only as described in the "Google User Data" section below.
- AI features (Google Gemini):some features send information to an AI model to produce a result — for example organising the notes a Business keeps on a Client, drafting copy, or answering a Business owner’s question about their own diary. What is sent is limited to what the feature needs: a Client is identified by initials rather than by name, and we do not send email addresses, phone numbers or payment details. The model returns a result; it is not given the ability to act on your data. A Business may instead connect its own Google API key, in which case the same information goes to that Business’s own Google account under its own terms with Google. AI features can be switched off per Business.
- Cloud hosting and infrastructure (Supabase and Vercel): our platform runs on cloud infrastructure. Your data is stored in a database operated by Supabase and processed by our hosting provider, Vercel.
- Business transfers: if Bookatu is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction; we will require the recipient to honour this Policy.
- Legal requirements: we may disclose personal information if required by law, court order or to protect the safety and rights of our users and of Bookatu.
We keep an up-to-date list of sub-processors and will give Businesses advance notice of changes.
6. Google User Data
Bookatuoffers an optional integration with Google. A Business, or an individual staff member, can connect a Google account to sync appointments to Google Calendar and to add Google Meet video links to bookings. Separately, you can use "Continue with Google" to sign in — either to your Bookatuaccount (as a Business owner or staff member) or to a Business’s booking page (as a Client). These features are optional and only run after you explicitly grant access through Google’s consent screen. This section governs all Google user data and overrides any more general statement elsewhere in this Policy.
What Google data we access, and why
- Basic profile (openid, email, profile): when you sign in or connect with Google we read your Google account identifier, email address, verified-email status, name and profile picture. We use these to identify your account and confirm your email.
- Calendar availability (calendar.readonly):for a connected calendar we read your busy/free times only — the start and end of existing events, never their titles or details — so we do not book a Client over a time you are already busy (only when you turn this on). Requested only for staff and organisation calendar connections.
- Calendar events (calendar.events): we create, update and delete the calendar events for bookings made through Bookatu. We request this events scope rather than full Calendar access, and only manage the events we create. Each event we write contains only the service name, a booking reference, any appointment notes the Business records, and the start and end time. When video meetings are enabled for a service we also add a Google Meet link to the event and read that link back so it can be shared with the Client. We do not add Clients as attendees on your Google Calendar. Requested only for staff and organisation calendar connections.
The calendar scopes (calendar.events and calendar.readonly) are requested onlywhen a staff member or a Business connects a calendar for syncing. Signing in with Google — whether to your Bookatuaccount or through "Continue with Google" on a booking page — requests the basic-profile scopes only and never the calendar scopes.
How we store it
- Staff and organisation calendar connections:when a staff member or a Business connects a calendar, we store the resulting Google sign-in tokens (including a refresh token), your basic profile (account identifier, email, name and profile-picture URL), the scope granted, and — for each booking — the Google Calendar event identifier and any Google Meet link. We store the tokens so the calendar connection keeps working without asking you to sign in for every booking. This data is transmitted over encrypted (TLS) connections and held in our access-controlled database (operated by Supabase, which encrypts data at rest at the infrastructure level) and processed by our hosting provider (Vercel). Access is restricted on a need-to-know basis to the systems and authorised personnel required to operate the integration.
- Signing in to your Bookatu account with Google: if you are a Business owner or staff member and use Google to sign in, we store only your Google account identifier (to match you to your account) together with your name and email on your user record. This sign-in is online-only: we do not request or store any Google access or refresh token.
- "Continue with Google" on a booking page (Clients): when a Client signs in this way, we store noGoogle tokens and no Google profile data. We use the Google sign-in once, in the moment, to read your name and email so the Business can identify your booking, and we save only that name and email to the Business’s customer record — the same as if you had typed them in.
How long we keep it and how to remove it
We keep stored Google tokens and profile data only for as long as the relevant Google account stays connected to Bookatu. You can disconnect Google at any time from the Bookatudashboard — a staff connection on the Team page, or an organisation connection in Settings (both restricted to owners and admins). Disconnecting deletes the stored Google tokens and profile for that connection; when you disconnect, or when yourBookatuaccount is closed, this data is deleted from our active systems within 30 days, and any short-lived backup copy is purged on our normal backup-rotation cycle. Calendar events and Meet links we already created in your Google Calendar are not removed automatically — you can delete those in Google Calendar. For Clients who used "Continue with Google" there is no stored Google data to disconnect (we keep only the name and email on the Business’s customer record, which the Business controls). To fully revoke Bookatu’s access on Google’s side, remove it at myaccount.google.com/permissions. For any deletion request you can also email hello@bookatu.com.
Who we share it with
The only Google-derived data shared onward is the Google Meet link, which we include in the booking-confirmation email (delivered through our email provider, Resend) so the Client can join the meeting. Your connected Google account tokens, identifier and profile are not sent to Resend, Stripe or any other third party beyond the hosting and database providers named in this Policy.
Limited Use
Bookatu’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Bookatu does not:
- sell Google user data to third parties;
- use or transfer Google user data for serving advertisements, including personalised or targeted advertising;
- transfer or sell Google user data to data brokers, information resellers, or any party for credit-worthiness or lending-eligibility (credit assessment) purposes;
- use Google user data to train, develop or improve generalised or non-personalised artificial-intelligence or machine-learning models; or
- allow humans to read Google user data, except (a) with your affirmative agreement to view specific data; (b) where necessary for security purposes (for example, investigating abuse); or (c) where necessary to comply with applicable law.
Bookatuonly uses Google user data to provide and improve the user-facing features described in this Policy — calendar availability, booking calendar events, Google Meet links and Google sign-in — and does not use it for any other purpose.
7. International Transfers
We and some of our service providers are based outside your country, including in the United States. Whenever we move personal information out of the EEA, the UK or another region with transfer restrictions, we put a lawful transfer mechanism in place before the data moves:
- the European Commission’s Standard Contractual Clauses (SCCs) for transfers from the EEA;
- the UK’s International Data Transfer Agreement (IDTA), or the UK Addendum to the SCCs, for transfers from the United Kingdom;
- the EU-U.S. Data Privacy Framework and its UK Extension, where the receiving provider participates in it; and
- additional safeguards such as encryption in transit and access controls where appropriate.
You can ask us for a copy of the relevant safeguards for a specific transfer by emailing hello@bookatu.com.
8. Data Retention
We keep personal information only as long as we need it, then delete or de-identify it. The criteria and typical periods we apply are:
- Business account data: for as long as the account is open, then a limited period after closure (typically up to 90 days) to allow for reactivation and wind-down.
- Client booking data: for as long as the Business’s account is open and under that Business’s instructions. When a Business closes its account we delete or de-identify the Client data on the Business’s instruction and in line with our DPA.
- Incomplete booking, purchase and signup details: contact details from attempts that were started but not finished are kept for up to 90 days to allow follow-up, then deleted; if dismissed sooner they are kept for up to 30 days.
- Payment and invoice records: for the period tax and accounting law requires us to keep them (commonly several years).
- Email, notification, security and fraud logs: for a limited period for deliverability, audit, dispute resolution and security, then deleted.
Where the law requires us to keep certain records for longer (for example to defend a legal claim), we keep them for that period and then delete them. The exact periods can vary by country; we can confirm the period for a specific record on request.
9. Security
We implement technical and organisational measures designed to protect your personal information, including encrypted connections (TLS) in transit, encryption of stored data at rest at the infrastructure level provided by our hosting providers, salted and hashed passwords (scrypt), role-based access controls, the principle of least privilege, logging and monitoring, and periodic reviews of our security practices. We restrict access to personal information to staff and contractors who need it to do their job and who are bound by confidentiality obligations. No system is completely secure; if you have concerns about the security of your account, please contact us immediately.
10. Data Breaches
We have procedures to detect, investigate and respond to personal-data breaches. If a breach affects data we control (Business account data) and is likely to put your rights at risk, we will notify the relevant supervisory authority without undue delay — within 72 hours where the GDPR or UK GDPR requires it — and we will tell affected people directly when the law requires it or when it is the right thing to do.
For Client data we process on behalf of a Business, we will notify that Business without undue delay after we become aware of a breach, so they can meet their own obligations to their Clients and regulators.
11. Your Rights
Depending on your location, you may have the following rights in relation to your personal information:
- Access: request a copy of the personal information we hold about you.
- Rectification: ask us to correct inaccurate information.
- Erasure: ask us to delete your personal information, subject to our legal obligations.
- Portability: receive a structured, machine-readable copy of the personal information you provided to us.
- Restriction: ask us to pause processing of your information in certain cases (for example while we check a correction you’ve asked for).
- Object: object to processing carried out on the basis of legitimate interests.
- Withdraw consent: if we rely on your consent (for example, for marketing emails), you can withdraw it at any time by clicking the unsubscribe link in any email or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
How the right of access works on our platform
Access is self-service and immediate. A Business can generate a complete, machine-readable copy of the data held about a Client directly from its dashboard, without waiting on us, and a Business account holder can download a copy of their organisation’s own data (profile, settings, services, products, team, client records, appointments, campaigns, posts and forms) at any time. Security credentials — encrypted keys, connected-account tokens and payment credentials — are never included in any export.
How the right to erasure works on our platform
Where an erasure request is made through our built-in tools, the process is designed to verify identity and prevent mistakes. First, we send a confirmation email to the address on record; the request proceeds only once it is confirmed from that email (if it is not confirmed within 48 hours, it lapses and nothing is deleted). Once confirmed, a 48-hour cooling-off period applies, during which the request can be cancelled at any time. After the cooling-off period the deletion is carried out and a confirmation is sent. Where the account has open matters — an upcoming appointment, an outstanding balance or an active card-on-file agreement — the request is referred to the Business to review and complete rather than executed automatically.
We only erase records we can provably link to you. Records are matched by direct account linkage or by the email address on your record; we do not guess. Where a record cannot be reliably attributed to you (for example, a payment record bearing only a name shared with another person), we leave it untouched rather than risk altering or disclosing someone else’s data.
Erasure is subject to the retention obligations described in “Data Retention”. In particular, payment and invoice records that tax and accounting law require to be kept are not deleted; instead they are anonymised — your name and contact details are removed while the transaction amounts and dates are retained for the legally required period.
To exercise any of these rights, please email hello@bookatu.com. We will respond as soon as we can, and in any case within one month of receiving a verifiable request (or 45 days where the CCPA/CPRA applies). If your request is complex or you have made several, we may extend this by up to two further months and will tell you why within the first month.
You also have the right to complain to a data protection regulator. In the UK that is the Information Commissioner’s Office (ICO). In the EEA you can complain to the supervisory authority in your country of residence or work (a list is at edpb.europa.eu). We’d appreciate the chance to resolve your concern first, so please contact us before you do.
Note for Clients of Businesses: if you are a Client of a salon, spa or other business that uses Bookatu, you should contact that business directly to exercise your rights regarding the data they hold about you. We will assist the Business in responding to your request.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights over the personal information we hold as a business(broadly, our Business account holders’ data). For Client data we act as a service provider to the Business and handle your request with them.
We do not sell or share your personal information
We do not “sell” your personal information for money, and we do not “share” it for cross-context behavioural advertising, as those terms are defined under the CPRA. Because we do not sell or share, we do not need a “Do Not Sell or Share My Personal Information” link — but if that ever changes, we will add one and honour opt-out signals, including the Global Privacy Control (GPC).
Sensitive personal information
We only use sensitive personal information (such as account log-in credentials) to provide the service you asked for and for the limited purposes the CPRA permits. We do not use it to infer characteristics about you.
Your California rights
- Know / Access: the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclose to.
- Delete: ask us to delete personal information we collected from you, subject to legal exceptions.
- Correct: ask us to fix inaccurate personal information.
- Opt out: of any sale or sharing (we do neither — see above).
- Non-discrimination: we will never deny you service, charge a different price, or give you a lower quality of service for exercising any of these rights.
Categories we collect (last 12 months)
- Identifiers (name, email, phone, account ID, IP address).
- Customer records (business and billing details; payment confirmation data from Stripe — we do not store card numbers).
- Commercial information (bookings, service history, loyalty points).
- Internet/network activity (pages visited, device and usage data).
- Account credentials (treated as sensitive personal information).
We disclose these categories only to the service providers named in this Policy, and only for the business purposes described here. To make a request, email hello@bookatu.com. You may use an authorised agent (with proof of authorisation), and we will verify your identity before we act.
13. Marketing Emails
Marketing emails (such as promotional offers and birthday messages) are only sent to Clients who have given explicit consent. Every marketing email includes an unsubscribe link. Clicking it will immediately remove you from future marketing emails from that Business. Booking confirmations and appointment reminders are transactional and will continue regardless of your marketing preference.
14. Children's Privacy
Bookatuis built for businesses and is not directed at children. We do not knowingly collect personal information directly from children to run our own platform. A Business may book appointments for a minor (for example a child’s haircut) — in that case the Business is the controller of that information and is responsible for having the right consent from a parent or guardian. If you believe a child has given us personal information directly, contact us at hello@bookatu.com and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify Business account holders of material changes by email or through the platform. Where a change affects how we access, use, store or share data obtained through Google APIs, we will notify affected users and, where required, obtain renewed consent before the change takes effect. The updated policy will be effective from the "Last updated" date at the top of this page.
16. Contact Us
For any privacy-related questions, requests or concerns, please contact:
BookatuEmail: hello@bookatu.com
Website: bookatu.com
© 2026 Bookatu. All rights reserved. Terms of Service