Skip to main content

Legal

Privacy Policy

Last updated: September 2026

1. Who We Are

This privacy policy applies to GETBOOKD LTD ("we", "us", "our", "the Company", "Bookd").

Data Controller: GETBOOKD LTD

Registered Address: 49 Maes y Crofft, Morganstown, Cardiff CF15 8FE, United Kingdom

Email: info@getbookd.io

Website: getbookd.io

ICO Registration Number: C1896648

We are a UK-based SaaS platform that provides booking management and client record software for appointment-based service businesses across the United Kingdom. We are the data controller when you use our platform to manage your business.

2. What Data We Collect and Why

We collect personal data when you register for an account, use our services, or interact with us. Below is a summary of the data we collect and the lawful basis for processing it:

Account Registration Data

Data collected: Name, email address, phone number, business name, address

Lawful basis: Contract (Article 6(1)(b) UK GDPR) — necessary to provide you with access to our platform and services.

Client Records

Data collected: Client names, contact details (email, phone), appointment dates, service history, service preferences, and any additional notes you store

Lawful basis: Contract (Article 6(1)(b) UK GDPR) — to facilitate booking management and service delivery through our platform.

Important note: When you input client data into our platform, you are acting as the data controller and we are acting as your data processor. You are responsible for obtaining appropriate consent from your clients to share their data with us. See Section 9 for our data processing agreement responsibilities.

Payment Information

Data collected: Subscription tier, billing address, transaction history (but NOT payment card details)

Lawful basis: Contract (Article 6(1)(b) UK GDPR) — to process subscriptions and manage billing. Card details are handled directly by Stripe (see Section 4).

Usage Data and Analytics

Data collected: IP address, browser type, pages visited, time spent on pages, interactions with features, device type

Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR) — to improve our service, understand how the platform is used, identify technical issues, and enhance user experience.

Communication Data

Data collected: Email content, support tickets, feedback, complaint records

Lawful basis: Contract (Article 6(1)(b) UK GDPR) — to respond to your inquiries and provide customer support. Legitimate interests — to maintain records and resolve disputes.

Marketing Data

Data collected: Email address, preferences, engagement with marketing communications

Lawful basis: Consent (Article 6(1)(a) UK GDPR) — for direct marketing via email under PECR. You may withdraw consent at any time by clicking "unsubscribe" in any email or contacting us.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Providing and administering your account and access to our platform
  • Processing subscription payments and managing billing
  • Sending service-related notifications (appointment reminders, account updates)
  • Sending transactional emails (payment confirmations, password resets)
  • Improving our platform, features, and user experience
  • Analysing platform usage and performance
  • Providing technical and customer support
  • Detecting and preventing fraud, abuse, or security incidents
  • Complying with legal obligations and enforcing our Terms of Service
  • Sending marketing communications (with your consent under PECR)

4. Third-Party Data Processors

We use the following third-party service providers who process personal data on our behalf. All processors are contractually bound to comply with UK GDPR and adopt appropriate security measures:

Supabase (Database, Storage & Infrastructure)

Purpose: Hosting user accounts, storing business and client data, and hosting before/after photos uploaded by groomers

Location: European Union servers (GDPR compliant)

Privacy: supabase.com/privacy

Stripe (Payment Processing)

Purpose: Processing subscription payments, booking deposits, and billing

Data: Payment card details (not stored by us), billing address, transaction history

Compliance: PCI-DSS Level 1 certified

Privacy: stripe.com/privacy

Vercel (Web Hosting)

Purpose: Hosting and serving the website

Location: Global CDN with European data residency options

Privacy: vercel.com/privacy

Brevo (Email & Marketing Notifications)

Purpose: Sending email notifications and marketing campaigns

Data: Email address, engagement data, marketing preferences

Compliance: GDPR compliant, EU data centres

Privacy: brevo.com/privacy

Twilio (SMS Notifications)

Purpose: Sending SMS appointment reminders and notifications

Data: Phone number, message content

Privacy: twilio.com/privacy

PostHog (Product Analytics)

Purpose: Understanding platform usage, feature adoption, and improving user experience

Data: Page interactions, feature usage, session activity

Location: European Union (EU Cloud)

Privacy: posthog.com/privacy

Sentry (Error Monitoring)

Purpose: Detecting and fixing software errors to improve platform reliability

Data: Browser type, device information, error logs and, only when an error occurs in the app, a replay of the minute before it, with all text, form entries and images masked before it leaves your browser

Location: European Union

Privacy: sentry.io/privacy

We have data processing agreements in place with all third parties that require them. These agreements ensure that your data is processed lawfully and securely. We do not share your data with any third parties for their own marketing purposes without your explicit consent.

5. Data Retention

We retain your personal data for as long as necessary to provide our services and comply with legal obligations:

  • Account data: Retained for the duration of your subscription plus 12 months after cancellation (for historical/financial records)
  • Client records: Retained as long as needed for your business operations. You can request deletion at any time
  • Pet photos: Stored as legitimate interest for grooming record-keeping. Image metadata (EXIF including any location data) is stripped client-side before upload. Photos are compressed to 500KB / 1280px on upload before they ever leave your device. Photos are retained until the groomer manually deletes them or the associated pet or customer record is deleted (cascade). Customers may ask their groomer to delete photos at any time. Photo hosting currently runs on the Supabase Free tier (1GB shared cap with daily backups but no point-in-time recovery); we monitor usage and will move to a paid tier with PITR before approaching the cap
  • Payment data: Retained as required by UK tax law (6 years for business records)
  • Marketing communications: Retained until you unsubscribe or request deletion
  • Support tickets: Retained for 2 years for dispute resolution and service improvement
  • Usage analytics: Up to 24 months (in aggregated, non-personal form)

If you delete your account, we will securely delete your personal data within 30 days, unless we are required by law to retain it. You may also request erasure of your data at any time (see Section 7).

6. Cookies and Tracking

Our website uses cookies and similar tracking technologies to:

  • Keep you logged into your account
  • Remember your preferences
  • Analyse how you use our platform (using analytics tools)
  • Improve our website performance

Types of Cookies

  • Essential cookies: Required for the website to function (e.g., authentication tokens)
  • Analytics cookies: Help us understand how you use the site, only when you choose to allow analytics cookies
  • Marketing cookies: Used to personalise marketing content and track conversions (lawful basis: consent)

Your Choices

You can control cookies through your browser settings. However, disabling essential cookies may prevent the website from functioning properly. We will request your explicit consent for non-essential cookies when you first visit.

PECR Compliance

We request permission before placing non-essential cookies. Visiting the site does not by itself give consent. You can accept analytics and marketing separately, reject both, or change your choice through Cookie Preferences.

Campaign measurement and outreach

When you create an account, we record the campaign labels in the link you signed up from (for example, that it came from a Facebook advert) and your answer to “How did you hear about Bookd?”. We use them to understand which marketing brings us customers. They come from the sign-up itself, so nothing is stored on or read from your device for this and it does not depend on your cookie choice. Our lawful basis is legitimate interests, and we keep these labels with your account until the account is deleted. If you also allow analytics or marketing measurement, we keep campaign labels in your browser for up to 30 days so that a later sign-up can still be matched to the campaign. Our account records separately track verified registration, completed setup, confirmed bookings and successful subscription payment so we can operate and assess the service.

When you allow marketing cookies and our Bookd advertising integration is enabled, Meta receives website and completed-registration events through its pixel. We do not include your email address, phone number, booking details or client records in those events. Meta also receives information from the browser connection, including your IP address. See Meta's privacy policy. Changing your choice stops future optional tracking; it cannot recall events already received by a provider.

For eligible business outreach, we use HubSpot to manage business contact and permission evidence, and Google Workspace to send email and process replies. Every outreach message provides an opt-out. We retain the minimum suppression record needed to honour an objection even if other prospect or CRM records change. Booking and account-service messages are separate from outreach. You can contact us using the details below to ask about your information or object to direct marketing.

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you. We will provide this within 30 calendar days of receiving your request.

Right to Rectification

You can request that we correct inaccurate or incomplete personal data about you.

Right to Erasure ("Right to be Forgotten")

In certain circumstances, you can request that we delete your personal data. This right is not absolute and may not apply if we have a legal obligation to retain the data.

Right to Restrict Processing

You can request that we limit how we use your data in certain situations (e.g., if you believe the data is inaccurate).

Right to Data Portability

You can request your data in a structured, commonly used format so you can transfer it to another service provider.

Right to Object

You can object to us processing your data for direct marketing purposes or on the basis of legitimate interests. You can unsubscribe from marketing emails at any time by clicking "unsubscribe" in any email.

Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing if it produces a legal or similarly significant effect. We do not use automated decision-making for critical decisions about you.

How to Exercise Your Rights

To exercise any of these rights, please contact us at info@getbookd.io with details of your request. We will respond within 30 calendar days. You may need to provide proof of identity to confirm your request.

8. International Data Transfers

Some of our third-party processors (such as Stripe and Vercel) may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place:

  • Data Processing Agreements with Standard Contractual Clauses (SCCs)
  • Assessment of adequacy decisions by the UK government
  • Adequacy decisions by the European Commission

We primarily process data within the UK and European Union. Where services involve international transfers, we ensure these safeguards are in place.

9. Data Security

We implement comprehensive technical and organisational measures to protect your personal data:

  • End-to-end encryption for data in transit (TLS/SSL)
  • Encrypted data storage at rest
  • Regular security audits and penetration testing
  • Access controls and role-based permissions
  • Staff training on data protection and security
  • Incident response procedures for data breaches
  • Backup and disaster recovery systems

However, no method of transmission over the internet is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.

Data Breach Notification

In the unlikely event of a personal data breach, we will notify affected individuals within 72 hours (unless the breach is unlikely to result in risk to your rights and freedoms). We will also report breaches to the Information Commissioner's Office (ICO) where required.

10. Children's Data

Our platform is not intended for children under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a child has provided data to us, we will take steps to delete it promptly.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.

11. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by posting the updated policy on our website with a new "Last updated" date.

Your continued use of our services following such changes constitutes your acceptance of the updated privacy policy.

12. Contacting Us About Privacy

If you have questions about this privacy policy, your rights, or how we handle your data, please contact us:

Email: info@getbookd.io

Postal Address: GETBOOKD LTD, 49 Maes y Crofft, Morganstown, Cardiff CF15 8FE, United Kingdom

Complaint to the ICO

If you believe we have not handled your data properly or violated your rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Phone: 0303 123 1113

Email: casework@ico.org.uk

Website: www.ico.org.uk

You can also use the ICO's online complaint form at ico.org.uk/make-a-complaint.

Data Protection Officer Note: This privacy policy reflects our current practices as of September 2026. As we grow and evolve our platform, we will update this policy to remain compliant with all applicable UK and EU data protection laws. For the most up-to-date information, please visit our website regularly.