1. Two different roles
Booklino handles personal data in two distinct capacities, and which one applies changes your rights and who you should contact.
- As a controller, for the businesses that subscribe to Booklino and for visitors to our own marketing site. We decide why and how that data is used, and this policy governs it.
- As a processor, for the customers who book appointments with those businesses. The business decides why and how that data is used; we act on its instructions. If you booked an appointment and want your data removed, contact the business you booked with, though you can also contact us and we will help you reach them. The terms of that arrangement are in the Data Processing Agreement.
The controller for the first category is [Company legal name B.V.], [Registered address, Netherlands], KvK 91548640.
2. What we collect
If you run a business on Booklino
| Data | Why | Lawful basis |
|---|---|---|
| Name and email address | To create and secure your account, and to send service email you need (confirmations, billing, security notices) | Performance of a contract |
| Business details, opening hours, services, prices, photos | To build and publish your booking page | Performance of a contract |
| Billing identifiers from Stripe | To manage your subscription. We store a Stripe customer reference, never your card number | Performance of a contract |
| Login and audit records (IP address, timestamps, actions taken) | To secure the account, investigate abuse, and give you an audit trail of changes | Legitimate interest in a secure service; legal obligation for financial records |
If you booked an appointment with a business
We hold your name, phone number and email address on behalf of that business, together with the appointments you made and whether you turned up. That is what a booking needs, and it is what we keep. We do not build a profile of you across different businesses for our own purposes and we never sell your details.
Your browser may also store your name, phone number and email locally on your own device so a second booking is pre-filled. That never reaches our servers and the “not you?” control on the booking form clears it.
If you just visit booklino.net
One analytics measurement that counts visits, and only if you accept it when asked. Decline and nothing is loaded. See the Cookie Policy.
3. What we deliberately do not do
- We do not sell, rent or share personal data with advertisers or data brokers.
- We do not email a business’s customers for our own marketing. The only email we send them is the booking email that business asked us to send.
- We do not use third-party advertising or tracking cookies, and there are no social-media pixels on our site.
- We do not store card numbers. Payment details go to Stripe and never touch our servers.
- We do not put booking-management tokens in analytics, logs, or web addresses that could leak them.
4. Where your data is stored
Data is stored in the European Union, in Google Cloud’s European region, using Firebase (authentication, database and file storage). Backups stay in the same region.
Two of our providers may process limited data outside the EU. Where that happens it is covered by the European Commission’s Standard Contractual Clauses:
| Provider | What it handles | Where |
|---|---|---|
| Google Cloud / Firebase | Database, authentication, file storage | EU (europe-west) |
| Stripe | Subscription billing and, via Connect, your customers' payments | EU and US, under SCCs |
| Resend | Delivery of transactional email | EU and US, under SCCs |
We keep the current list of sub-processors here and will give notice before adding a new one that processes personal data.
5. How long we keep it
- Business accounts: for as long as the account is open, and 30 days after closure so an accidental closure can be reversed.
- Booking records: kept while the business needs them, and deleted or anonymised when the business deletes them or closes its account.
- Invoices and financial records: seven years, as Dutch tax law requires.
- Security and audit logs: up to 12 months.
When we anonymise rather than delete a record, we strip the personal details irreversibly and keep only counts, so a business does not lose its historical totals.
6. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. You can also ask for it in a portable format.
These requests are handled by our support team; the dashboard does not currently include self-service export or deletion controls. If you run a business, or if you booked an appointment and cannot reach the business, email [email protected]. We respond within one month.
If you are unhappy with how we have handled your data you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
7. Security
Data is encrypted in transit and at rest. Access to production data is limited to the people who need it and is logged. Booking-management links use tokens of at least 128 bits of randomness, stored only as hashes, so a leak of our database does not hand anyone a working link. Every mutating action a business owner or an administrator takes is written to an audit log.
If a breach occurs that is likely to result in a risk to people’s rights, we notify the Autoriteit Persoonsgegevens within 72 hours and tell affected users without undue delay. Read more on our trust and security page.
8. Children
Booklino is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 in their own right. A parent may of course book an appointment for a child, in which case the details submitted are the parent’s responsibility and the business’s.
9. Changes
If we change this policy in a way that materially affects you, we will email account holders at least 30 days beforehand. The date at the top of this page always reflects the current version.
10. Contact
[Company legal name B.V.], [Registered address, Netherlands]. KvK 91548640, VAT NL004899454B23. Privacy questions: [email protected].