Legal
Privacy Notice
How BOOKSAFE LTD collects, uses, shares, and protects personal information across our public site, booking services, business app, and integrations.
Version 2026-06-28 · Last updated: 28 June 2026
1. Who we are
BOOKSAFE LTD (company number 17098929) is registered in England and Wales. Our registered office is 167-169 Great Portland Street, London, England, W1W 5PF. You can contact us about privacy or exercise your rights at hello@booksafe.co.uk.
BOOKSAFE is a controller for business accounts, platform billing, support, security, and our own service improvement. A business using BOOKSAFE is normally the controller for its customer, staff, booking, and service data; BOOKSAFE processes that data on the business's instructions. Our Data Processing Agreement explains that relationship.
2. Information we collect
- Account and identity details, including name, email address, role, authentication identifiers, and verification status.
- Business profile, services, staff, availability, branding, subscription, and billing information.
- Customer and booking details, including contact details, appointment information, notes, addresses where required, and booking preferences.
- Payment status and Stripe identifiers. BOOKSAFE does not store complete card numbers or card security codes.
- Messages, support requests, reviews, uploaded files, and communications sent through the service.
- Calendar connection details, encrypted OAuth tokens, calendar identifiers, and event information needed to synchronise availability and bookings.
- Approximate or precise location and postcode information when you choose location-based search.
- Device, push-notification, cookie preference, IP address, browser, session, login-attempt, diagnostic, and usage information.
- Legal acceptance evidence, including policy versions, acceptance time, source, IP address, and user agent.
3. Why we use information and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Create accounts, provide bookings, subscriptions, support, payments, and requested integrations | Performance of a contract or steps requested before entering one |
| Protect accounts, prevent abuse and fraud, troubleshoot, maintain audit records, and improve reliability | Our legitimate interests in operating a secure and effective service |
| Accounting, tax, regulatory, legal claims, law-enforcement requests, and compliance | Legal obligation and, where applicable, legitimate interests |
| Optional non-essential cookies and communications that require permission | Consent, which you may withdraw |
| Relevant product updates and business communications where permitted | Legitimate interests or consent where required by law |
Businesses are responsible for selecting and documenting an appropriate lawful basis for the customer data they enter into BOOKSAFE.
4. Where information comes from
We receive information directly from you, from a business you book with or work for, from your device, and from integrations you choose such as Clerk, Stripe, Google, postcode, and mapping services. Public directory information may also be supplied by a business or obtained from public business sources.
5. Who we share information with
We share information only where needed with the business involved in a booking, authorised staff, payment and identity providers, infrastructure and email providers, optional integration providers, professional advisers, and authorities where legally required. We do not sell personal information. Our current service providers are listed on the Subprocessors page.
Stripe may act as an independent controller for payment, fraud-prevention, verification, and regulatory activities under its own privacy notice. A business may also use its own processors outside BOOKSAFE.
6. International transfers
Some providers may process information outside the UK. Where a restricted transfer occurs, we use an applicable UK adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, together with appropriate risk and security assessments where required. Contact us if you would like more information about safeguards relevant to your data.
7. How long we keep information
- Active account and booking data is kept while needed to provide the service and according to the business's instructions.
- When account deletion is requested, operational data is normally scheduled for deletion after 30 days, subject to active subscriptions, disputes, security holds, and legal obligations.
- Page-view and login-attempt telemetry is normally kept for 180 days, directory telemetry for 365 days, and ended session records for 90 days.
- Contract, billing, legal acceptance, and transaction evidence may be kept for up to six years after the relevant relationship or transaction.
- Backups are deleted through their normal secure rotation. Some information may be retained longer where law or an active legal claim requires it.
8. Google services
Google Sign-In uses basic identity scopes such as openid, userinfo.email, and userinfo.profile. If you separately connect Google Calendar, BOOKSAFE may requestcalendar.events and calendar.readonly to create, update, delete, and check calendar events for booking synchronisation and conflict detection.
Calendar access and refresh tokens are encrypted at rest. We do not use Google user data for advertising, credit decisions, sale, or training general-purpose AI models. You can disconnect the integration in BOOKSAFE or revoke access through your Google Account permissions.
9. Your rights
Depending on the circumstances, you may have rights to be informed, access your information, correct it, erase it, restrict its use, object to processing, receive portable data, and withdraw consent. You may also have rights relating to automated decisions. Email us to make a request. We may need to verify your identity and, for business-controlled booking data, may refer the request to the relevant business.
10. Security and data breaches
We use access controls, encrypted transport, protected credentials, tenant separation, audit logging, backups, monitoring, and supplier controls appropriate to the service. No system is completely risk-free. We investigate suspected breaches and notify affected controllers, individuals, or the ICO where the law requires it.
11. Complaints and changes
Please contact us first so we can investigate. You can also complain to the Information Commissioner's Office at ico.org.ukor by calling 0303 123 1113. We may update this notice as the service or law changes; the version and date above identify the current notice.