Privacy Policy

Last updated: 10/06/2026

1. Who we are

Bookd ("we", "us"), operating at get-bookd.co.uk, provides a booking platform connecting independent service businesses with their clients. We are the data controller for account information, and each business is the controller for the booking details you share with them. For privacy questions and data requests, contact us at support@get-bookd.co.uk.

2. What we collect

  • Account data — name, email, phone number, password (stored as a secure hash).
  • Business data — business name, description, logo, services, availability.
  • Booking data — appointment details, service address, comments you add.
  • Guest bookings — name, email and phone provided without an account.
  • Payment data — handled by Stripe; we never see or store full card details.
  • Technical data — login attempts (for account security) and essential cookies.

3. How we use your data (lawful bases)

We process data to provide the booking service (contract), to send booking confirmations and reminders (contract), to secure accounts and prevent abuse (legitimate interest), to take subscription payments via Stripe (contract), and to comply with legal obligations.

4. Cookies

We use strictly necessary cookies only: authentication session cookies (httpOnly, required to keep you signed in) and a cookie remembering your cookie-banner choice. We do not use advertising or tracking cookies.

5. Sharing

Booking details are shared between you and the business you book with. We use trusted processors: Supabase (database & authentication, EU/UK-compliant hosting), Stripe (payments) and Resend (transactional email). We never sell personal data.

6. Retention

Account data is kept while your account is active. Booking records are kept for 6 years to support business records, then deleted. Login attempt logs are kept for 90 days. You may request earlier deletion at any time.

7. Your rights (UK GDPR)

You have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and to withdraw consent. To exercise any right, email support@get-bookd.co.uk. You can also complain to the Information Commissioner's Office (ico.org.uk).

8. Security

Data is encrypted in transit (TLS) and at rest. Access is protected by row-level security so businesses and clients can only see their own records. Sessions use secure httpOnly cookies.

9. Changes

We'll post any changes to this policy here and update the date above. Material changes will be notified by email.