Legal
Privacy Policy
Last updated: March 2026
1. Who We Are
This privacy policy applies to GETBOOKD LTD ("we", "us", "our", "the Company", "Bookd").
Data Controller: GETBOOKD LTD
Registered Address: 49 Maes y Crofft, Morganstown, Cardiff CF15 8FE, United Kingdom
Email: info@getbookd.io
Website: getbookd.io
ICO Registration Number: C1896648
We are a UK-based SaaS platform that provides booking management and client record software for appointment-based service businesses across the United Kingdom. We are the data controller when you use our platform to manage your business.
2. What Data We Collect and Why
We collect personal data when you register for an account, use our services, or interact with us. Below is a summary of the data we collect and the lawful basis for processing it:
Account Registration Data
Data collected: Name, email address, phone number, business name, address
Lawful basis: Contract (Article 6(1)(b) UK GDPR) — necessary to provide you with access to our platform and services.
Client Records
Data collected: Client names, contact details (email, phone), appointment dates, service history, service preferences, and any additional notes you store
Lawful basis: Contract (Article 6(1)(b) UK GDPR) — to facilitate booking management and service delivery through our platform.
Important note: When you input client data into our platform, you are acting as the data controller and we are acting as your data processor. You are responsible for obtaining appropriate consent from your clients to share their data with us. See Section 9 for our data processing agreement responsibilities.
Payment Information
Data collected: Subscription tier, billing address, transaction history (but NOT payment card details)
Lawful basis: Contract (Article 6(1)(b) UK GDPR) — to process subscriptions and manage billing. Card details are handled directly by Stripe (see Section 4).
Usage Data and Analytics
Data collected: IP address, browser type, pages visited, time spent on pages, interactions with features, device type
Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR) — to improve our service, understand how the platform is used, identify technical issues, and enhance user experience.
Communication Data
Data collected: Email content, support tickets, feedback, complaint records
Lawful basis: Contract (Article 6(1)(b) UK GDPR) — to respond to your inquiries and provide customer support. Legitimate interests — to maintain records and resolve disputes.
Marketing Data
Data collected: Email address, preferences, engagement with marketing communications
Lawful basis: Consent (Article 6(1)(a) UK GDPR) — for direct marketing via email under PECR. You may withdraw consent at any time by clicking "unsubscribe" in any email or contacting us.
3. How We Use Your Data
We use your personal data for the following purposes:
- Providing and administering your account and access to our platform
- Processing subscription payments and managing billing
- Sending service-related notifications (appointment reminders, account updates)
- Sending transactional emails (payment confirmations, password resets)
- Improving our platform, features, and user experience
- Analysing platform usage and performance
- Providing technical and customer support
- Detecting and preventing fraud, abuse, or security incidents
- Complying with legal obligations and enforcing our Terms of Service
- Sending marketing communications (with your consent under PECR)
4. Third-Party Data Processors
We use the following third-party service providers who process personal data on our behalf. All processors are contractually bound to comply with UK GDPR and adopt appropriate security measures:
Supabase (Database, Storage & Infrastructure)
Purpose: Hosting user accounts, storing business and client data, and hosting before/after photos uploaded by groomers
Location: European Union servers (GDPR compliant)
Privacy: supabase.com/privacy
Stripe (Payment Processing)
Purpose: Processing subscription payments, booking deposits, and billing
Data: Payment card details (not stored by us), billing address, transaction history
Compliance: PCI-DSS Level 1 certified
Privacy: stripe.com/privacy
Vercel (Web Hosting)
Purpose: Hosting and serving the website
Location: Global CDN with European data residency options
Privacy: vercel.com/privacy
Brevo (Email & Marketing Notifications)
Purpose: Sending email notifications and marketing campaigns
Data: Email address, engagement data, marketing preferences
Compliance: GDPR compliant, EU data centres
Privacy: brevo.com/privacy
Twilio (SMS Notifications)
Purpose: Sending SMS appointment reminders and notifications
Data: Phone number, message content
Privacy: twilio.com/privacy
PostHog (Product Analytics)
Purpose: Understanding platform usage, feature adoption, and improving user experience
Data: Page interactions, feature usage, session activity
Location: European Union (EU Cloud)
Privacy: posthog.com/privacy
Sentry (Error Monitoring)
Purpose: Detecting and fixing software errors to improve platform reliability
Data: Browser type, device information, error logs
Location: European Union
Privacy: sentry.io/privacy
We have data processing agreements in place with all third parties that require them. These agreements ensure that your data is processed lawfully and securely. We do not share your data with any third parties for their own marketing purposes without your explicit consent.
5. Data Retention
We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
- Account data: Retained for the duration of your subscription plus 12 months after cancellation (for historical/financial records)
- Client records: Retained as long as needed for your business operations. You can request deletion at any time
- Pet photos: Stored as legitimate interest for grooming record-keeping. Image metadata (EXIF including any location data) is stripped client-side before upload. Photos are compressed to 500KB / 1280px on upload before they ever leave your device. Photos are retained until the groomer manually deletes them or the associated pet or customer record is deleted (cascade). Customers may ask their groomer to delete photos at any time. Photo hosting currently runs on the Supabase Free tier (1GB shared cap with daily backups but no point-in-time recovery); we monitor usage and will move to a paid tier with PITR before approaching the cap
- Payment data: Retained as required by UK tax law (6 years for business records)
- Marketing communications: Retained until you unsubscribe or request deletion
- Support tickets: Retained for 2 years for dispute resolution and service improvement
- Usage analytics: Up to 24 months (in aggregated, non-personal form)
If you delete your account, we will securely delete your personal data within 30 days, unless we are required by law to retain it. You may also request erasure of your data at any time (see Section 7).
6. Cookies and Tracking
Our website uses cookies and similar tracking technologies to:
- Keep you logged into your account
- Remember your preferences
- Analyse how you use our platform (using analytics tools)
- Improve our website performance
Types of Cookies
- Essential cookies: Required for the website to function (e.g., authentication tokens)
- Analytics cookies: Help us understand how you use the site (lawful basis: legitimate interests)
- Marketing cookies: Used to personalise marketing content and track conversions (lawful basis: consent)
Your Choices
You can control cookies through your browser settings. However, disabling essential cookies may prevent the website from functioning properly. We will request your explicit consent for non-essential cookies when you first visit.
PECR Compliance
Under the Privacy and Electronic Communications Regulations (PECR), we only place cookies on your device with your prior consent (except for strictly necessary cookies). By using our site, you consent to our cookie policy.
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this within 30 calendar days of receiving your request.
Right to Rectification
You can request that we correct inaccurate or incomplete personal data about you.
Right to Erasure ("Right to be Forgotten")
In certain circumstances, you can request that we delete your personal data. This right is not absolute and may not apply if we have a legal obligation to retain the data.
Right to Restrict Processing
You can request that we limit how we use your data in certain situations (e.g., if you believe the data is inaccurate).
Right to Data Portability
You can request your data in a structured, commonly used format so you can transfer it to another service provider.
Right to Object
You can object to us processing your data for direct marketing purposes or on the basis of legitimate interests. You can unsubscribe from marketing emails at any time by clicking "unsubscribe" in any email.
Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing if it produces a legal or similarly significant effect. We do not use automated decision-making for critical decisions about you.
How to Exercise Your Rights
To exercise any of these rights, please contact us at info@getbookd.io with details of your request. We will respond within 30 calendar days. You may need to provide proof of identity to confirm your request.
8. International Data Transfers
Some of our third-party processors (such as Stripe and Vercel) may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place:
- Data Processing Agreements with Standard Contractual Clauses (SCCs)
- Assessment of adequacy decisions by the UK government
- Adequacy decisions by the European Commission
We primarily process data within the UK and European Union. Where services involve international transfers, we ensure these safeguards are in place.
9. Data Security
We implement comprehensive technical and organisational measures to protect your personal data:
- End-to-end encryption for data in transit (TLS/SSL)
- Encrypted data storage at rest
- Regular security audits and penetration testing
- Access controls and role-based permissions
- Staff training on data protection and security
- Incident response procedures for data breaches
- Backup and disaster recovery systems
However, no method of transmission over the internet is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.
Data Breach Notification
In the unlikely event of a personal data breach, we will notify affected individuals within 72 hours (unless the breach is unlikely to result in risk to your rights and freedoms). We will also report breaches to the Information Commissioner's Office (ICO) where required.
10. Children's Data
Our platform is not intended for children under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a child has provided data to us, we will take steps to delete it promptly.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
11. Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by posting the updated policy on our website with a new "Last updated" date.
Your continued use of our services following such changes constitutes your acceptance of the updated privacy policy.
12. Contacting Us About Privacy
If you have questions about this privacy policy, your rights, or how we handle your data, please contact us:
Email: info@getbookd.io
Postal Address: GETBOOKD LTD, 49 Maes y Crofft, Morganstown, Cardiff CF15 8FE, United Kingdom
Complaint to the ICO
If you believe we have not handled your data properly or violated your rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Phone: 0303 123 1113
Email: casework@ico.org.uk
Website: www.ico.org.uk
You can also use the ICO's online complaint form at ico.org.uk/make-a-complaint.
Data Protection Officer Note: This privacy policy reflects our current practices as of March 2026. As we grow and evolve our platform, we will update this policy to remain compliant with all applicable UK and EU data protection laws. For the most up-to-date information, please visit our website regularly.