Who this applies to
This policy applies to (a) businesses/clinics using getbookedin.app to manage bookings and (b) consumers booking appointments through getbookedin.app booking pages.
Data we collect
- Account & business info: name, email address, business/clinic details, and settings you provide.
- Booking info: customer name, email, phone number, selected service, date/time, notes (if provided), and booking history.
- Communications: messages sent through the platform such as appointment emails and SMS reminders (when enabled).
- Google user data (optional): if you connect Google Calendar, we access and store OAuth access and refresh tokens, calendar identifiers, and calendar event details needed to sync BookMeIn bookings to your Google Calendar and to read external events for availability blocking. We only request Google Calendar scopes required for this sync feature.
- Technical data: basic logs and diagnostic information needed to operate and secure the service.
How we use data
- Provide and operate bookings, scheduling, and dashboard features.
- Send transactional emails and SMS reminders you configure.
- Sync bookings to Google Calendar and import external calendar events for availability when you enable calendar sync. Google user data is used only to provide these user-facing calendar sync features.
- Prevent abuse, secure the platform, and troubleshoot issues.
We do not sell Google user data, use it for advertising, or transfer it to third parties except as needed to operate the service as described in this policy.
Who we share data with
We share data only as needed to provide the service, for example:
- Google (Google Calendar API) for calendar sync when you connect your account.
- Resend to send transactional emails (if enabled).
- Twilio to send SMS messages (if enabled).
Data protection and security
We use encryption and security procedures to protect the confidentiality of your information, including Google user data obtained through Google APIs.
- Encryption in transit: all traffic between your browser/app and our servers is protected using HTTPS/TLS.
- Encryption at rest for sensitive tokens: Google OAuth access and refresh tokens are encrypted before storage using AES-256-GCM (authenticated encryption) with application-managed encryption keys.
- Access controls: access to production systems and stored data is limited to authorized personnel who need it to operate, maintain, or secure the service.
- Account authentication: passwords are stored using one-way hashing (not reversible plaintext).
- Token lifecycle: if you disconnect Google Calendar, we revoke the Google authorization where possible and delete the stored OAuth tokens from our systems.
Retention
We retain personal data for as long as necessary to provide the service and comply with legal obligations.
- Account & booking data: for the duration of your relationship with us and a reasonable period after account closure.
- Fiscal receipts & tax invoices: at least 6 years from the end of the calendar year (Malta VAT Act). Accounting records may be kept up to 9–10 years under Malta income tax and company law.
- Marketing data: until you withdraw consent or request deletion.
If you request deletion, we will remove personal data from active systems where possible. Data we must keep for tax or accounting law (for example issued receipts and invoices) is retained as originally issued and explained in our response to your request.
Data export
Business account owners can export their data from the dashboard under Settings → Data & privacy. The export includes bookings, customers, invoices, receipts, and related files in a ZIP archive.
Your choices and rights
You may request access, correction, or deletion of your personal data by contacting us at hello@getbookedin.app.
Contact
If you have questions about this policy, email hello@getbookedin.app.