Privacy Policy
Last updated: 7 July 2026
This policy explains how BookAppointment ("we", "us", "our") collects, uses and protects personal data when you visit our website (www.bookappointment.co.uk), create an account, subscribe to a plan, or make a booking on a shop that uses our platform. It is written to comply with UK GDPR and the Data Protection Act 2018.
1. Who we are
BookAppointment is a UK-built booking platform for salons, spas, clinics and other appointment-led businesses. We act as a data controller for our own website and account holders, and as a data processor when we host booking data on behalf of a shop (the "tenant") that uses our platform. In that case the tenant is the controller of their customer data.
2. What we collect
- Account data — name, email, hashed password, business details, billing address.
- Booking data — appointments, services booked, staff assigned, notes.
- Customer data (on behalf of tenants) — name, email, phone, appointment history.
- Payment data — handled by Stripe; we store the last 4 digits, card brand and Stripe customer IDs only.
- Usage data — pages viewed, features used, log data, IP address (kept short-term for abuse prevention).
- Cookies — see our Cookie Policy.
3. Why we use it (legal bases)
- Contract — to run your account, process bookings and payments.
- Legitimate interests — to keep the service secure, prevent fraud, and improve features.
- Legal obligation — accounting, tax and regulatory records.
- Consent — for optional marketing emails and non-essential cookies. You can withdraw consent at any time.
4. Who we share it with
We only share data with providers strictly necessary to run the service:
- Stripe — payment processing (UK/EU/US).
- Cloudflare — hosting, DNS and DDoS protection (UK/EU).
- Supabase — database and authentication (EU region).
- Resend — transactional email delivery.
- Twilio / MessageBird — SMS delivery (only if you enable SMS features).
We never sell your data. We only transfer data outside the UK/EEA under Standard Contractual Clauses or equivalent safeguards.
5. How long we keep it
- Account data — while your account is active, plus 30 days after cancellation.
- Booking and financial records — 6 years (UK accounting requirements).
- Support tickets — 24 months.
- Marketing preferences — until you unsubscribe.
6. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data.
- Correct inaccurate data.
- Erase data (where we're not required to keep it).
- Restrict or object to processing.
- Data portability.
- Withdraw consent where processing is based on consent.
- Complain to the Information Commissioner's Office (ICO).
To exercise any of these rights, email privacy@bookappointment.co.uk.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is role-based and audited. We follow least-privilege principles for staff access. Read more on our Security & GDPR page.
8. Data on behalf of shops (tenants)
When a shop uses BookAppointment to run its bookings, that shop controls its own customer data. If you're a customer of a shop, contact the shop directly for access, correction or deletion requests. We'll assist as processor and route the request if you're not sure who to contact.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or a banner in the app. The "last updated" date at the top always reflects the latest revision.
10. Contact
Data Protection contact: privacy@bookappointment.co.uk
General support: bookappointment.co.uk/support