Skip to content
20% off with code

Privacy policy

Last updated: 1 September 2026

1. Who we are

Bookify (bookify.one) provides appointment scheduling for service businesses. For data that businesses store about their own customers, the business is the data controller and Bookify acts as a processor. For your Bookify account itself, we are the controller. Contact: support@bookify.one.

2. Data we collect

  • Account data: name, email address, password (stored hashed), profile photo if you upload one.
  • Workspace data: business details, locations, services, staff, working hours and bookings.
  • Booking customers' data entered by businesses or by customers themselves: name, phone number, appointment details and notes.
  • Calendar data, only if a staff member connects a calendar: see the Google user data section below.
  • Payment data: handled by our payment providers (Stripe, Creem). We never see or store full card numbers. We keep only transaction references, amounts and status.
  • Technical data: server logs (IP address, request time) kept for security and troubleshooting.
  • Usage data: pages visited, referrer, screen size and product events (such as "signup completed"), tied to a random visitor identifier — see the analytics section below.

3. Why we use it

To provide the service (contract): running your calendar and booking page, sending booking SMS, syncing calendars, processing payments. To keep the service safe (legitimate interest): abuse prevention, security logging. To meet legal obligations: invoicing and tax records. We do not sell personal data and we do not use it for advertising.

4. Who we share it with

Only processors needed to run Bookify, under data processing agreements: hosting infrastructure, SMSAPI (SMS delivery, which receives the recipient phone number and message text), Stripe and Creem (payments), Google or your CalDAV provider (calendar sync, only for connected staff), Repora (analytics), Google Analytics (audience measurement), and FeedFast (in-app feedback, which receives your name and email address only when you send us feedback from inside the app, so we can reply). We disclose data to authorities only when legally required.

5. Google user data

Bookify uses Google APIs for two optional features. Neither is required to use the product, and each is granted separately by you.

What we access

  • Signing in with Google (openid, profile and email scopes): your name, email address, profile picture and your Google account identifier. We store the identifier so we can recognise you at the next sign-in, along with your name and email address as your Bookify account details.
  • Google Calendar (the https://www.googleapis.com/auth/calendar scope), only for a staff member who connects their calendar: the names and identifiers of their calendars, and for events in those calendars the event identifier, title, start and end time, all-day flag and busy/free status. We do not read attendees, guest lists, attachments, conferencing links or event descriptions.

How we use it

  • The account data signs you in and identifies your Bookify account. Nothing else.
  • The calendar data blocks the times a staff member is already busy so customers cannot double-book them, and writes their Bookify appointments into the connected calendar so both stay in step. The stored event title is shown only to that staff member and their managers inside your own workspace, so a blocked slot is recognisable.

Who we share it with

Nobody. Google user data is never sold, never transferred for advertising, never used to build advertising profiles or train generalised artificial intelligence or machine learning models, and never disclosed to third parties except to the hosting provider that runs Bookify on our behalf under a data processing agreement, or where the law compels us. No human at Bookify reads your calendar data, except where you explicitly ask us to for support, where it is necessary for security or to comply with the law.

Bookify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect it

OAuth access and refresh tokens are encrypted at rest with authenticated encryption, are never exposed through our own API or interface, and travel only over TLS. Access to the production systems that hold them is restricted to the people who operate the service and protected by individual accounts.

How long we keep it, and how to remove it

  • Disconnecting a calendar in Bookify (Staff → the staff member → Calendar) immediately deletes the stored tokens and the busy periods imported from it.
  • Imported busy periods are refreshed on every sync and are only kept for the window we need to check availability; they are not archived.
  • Deleting your Bookify account deletes the Google account identifier and any remaining calendar data within 30 days, except where the law requires us to keep a record.
  • You can also revoke Bookify's access at any time from your Google account permissions, which stops all further access immediately.

6. Analytics

We measure how the site and app are used with Repora (repora.ro), a privacy-friendly analytics service. It records page views (URL, referrer, screen width), product events such as "signup completed", and purchase amounts, tied to a random visitor identifier stored in your browser and, for signed-in users, your numeric account id. It uses no advertising identifiers, does not follow you across other websites, and never receives names, email addresses, booking contents or customer data.

We also use Google Analytics, which sets its own cookies, assigns a Google analytics identifier and processes data on Google's infrastructure, including outside the EU under the appropriate safeguards. It is used for audience measurement only, and we do not use it to build advertising audiences.

Our legal basis for analytics is your consent where consent is required, and otherwise our legitimate interest in understanding and improving the product; the data is not sold. You can withdraw consent at any time in the cookie settings.

7. Retention

Account and workspace data is kept while your account is active and deleted or anonymised within a reasonable period after account deletion. SMS delivery logs and payment records are kept as long as needed for billing disputes and legal requirements. Backups roll off automatically.

8. Your rights

Under the GDPR you can request access, correction, deletion, restriction, portability, or object to processing. Write to support@bookify.one and we will respond within 30 days. You may also complain to your local supervisory authority. If you are a booking customer of a business using Bookify, contact that business first, since they control your data and we assist them.

9. Security

Data is encrypted in transit, passwords are hashed, calendar tokens are stored encrypted, and access to production systems is restricted. No system is perfectly secure, so tell us at support@bookify.one if you believe you have found a vulnerability.

10. Changes to this policy

We update this policy when what we do with personal data changes. The date at the top always reflects the current version. If a change materially affects how we handle your data — including any change to how we use Google user data — we announce it in the app and email account owners before it takes effect.

11. Cookies

We use only cookies that are necessary to run the service. See the cookie policy for the full list and your choices.