Skip to content

Privacy policy

Last updated: 31 August 2026

1. Who we are

Bookify (bookify.one) provides appointment scheduling for service businesses. For data that businesses store about their own customers, the business is the data controller and Bookify acts as a processor. For your Bookify account itself, we are the controller. Contact: support@bookify.one.

2. Data we collect

  • Account data: name, email address, password (stored hashed), profile photo if you upload one.
  • Workspace data: business details, locations, services, staff, working hours and bookings.
  • Booking customers' data entered by businesses or by customers themselves: name, phone number, appointment details and notes.
  • Calendar data, only if a staff member connects a calendar: event times and identifiers needed to block availability and to create booking events. Event contents are not used for anything else.
  • Payment data: handled by our payment providers (Stripe, Creem). We never see or store full card numbers. We keep only transaction references, amounts and status.
  • Technical data: server logs (IP address, request time) kept for security and troubleshooting.
  • Usage data: pages visited, referrer, screen size and product events (such as "signup completed"), tied to a random visitor identifier — see the analytics section below.

3. Why we use it

To provide the service (contract): running your calendar and booking page, sending booking SMS, syncing calendars, processing payments. To keep the service safe (legitimate interest): abuse prevention, security logging. To meet legal obligations: invoicing and tax records. We do not sell personal data and we do not use it for advertising.

4. Who we share it with

Only processors needed to run Bookify, under data processing agreements: hosting infrastructure, SMSAPI (SMS delivery, which receives the recipient phone number and message text), Stripe and Creem (payments), Google or your CalDAV provider (calendar sync, only for connected staff), and Repora (analytics, which receives only the pseudonymous usage data described below). We disclose data to authorities only when legally required.

5. Analytics (Repora)

We measure how the site and app are used with Repora (repora.ro), a privacy-friendly analytics service. It records page views (URL, referrer, screen width), product events such as "signup completed", and purchase amounts, tied to a random visitor identifier stored in your browser and, for signed-in users, your numeric account id. It uses no advertising identifiers, does not follow you across other websites, and never receives names, email addresses, booking contents or customer data. Our legal basis is our legitimate interest in understanding and improving the product; the data is not used for advertising and not sold.

6. Retention

Account and workspace data is kept while your account is active and deleted or anonymised within a reasonable period after account deletion. SMS delivery logs and payment records are kept as long as needed for billing disputes and legal requirements. Backups roll off automatically.

7. Your rights

Under the GDPR you can request access, correction, deletion, restriction, portability, or object to processing. Write to support@bookify.one and we will respond within 30 days. You may also complain to your local supervisory authority. If you are a booking customer of a business using Bookify, contact that business first, since they control your data and we assist them.

8. Security

Data is encrypted in transit, passwords are hashed, calendar tokens are stored encrypted, and access to production systems is restricted. No system is perfectly secure, so tell us at support@bookify.one if you believe you have found a vulnerability.

9. Cookies

We use only cookies that are necessary to run the service. See the cookie policy for the full list and your choices.