Skip to content

Legal

Privacy Policy

What personal data Booklino handles, why, where it lives, and how to get a copy of it or have it deleted. Written to match how the product actually behaves, not what is convenient to claim.

Last updated

Draft pending legal review. These documents describe how Booklino actually works and are written to be accurate, but they have not yet been reviewed by a qualified lawyer and are not legal advice. The company legal name and registered address are still placeholders. Both are gated before public launch.

1. Two different roles

Booklino handles personal data in two distinct capacities, and which one applies changes your rights and who you should contact.

  • As a controller, for the businesses that subscribe to Booklino and for visitors to our own marketing site. We decide why and how that data is used, and this policy governs it.
  • As a processor, for the customers who book appointments with those businesses. The business decides why and how that data is used; we act on its instructions. If you booked an appointment and want your data removed, contact the business you booked with, though you can also contact us and we will help you reach them. The terms of that arrangement are in the Data Processing Agreement.

The controller for the first category is [Company legal name B.V.], [Registered address, Netherlands], KvK 91548640.

2. What we collect

If you run a business on Booklino

Personal data collected from subscribing businesses
DataWhyLawful basis
Name and email addressTo create and secure your account, and to send service email you need (confirmations, billing, security notices)Performance of a contract
Business details, opening hours, services, prices, photosTo build and publish your booking pagePerformance of a contract
Billing identifiers from StripeTo manage your subscription. We store a Stripe customer reference, never your card numberPerformance of a contract
Login and audit records (IP address, timestamps, actions taken)To secure the account, investigate abuse, and give you an audit trail of changesLegitimate interest in a secure service; legal obligation for financial records

If you booked an appointment with a business

We hold your name, phone number and email address on behalf of that business, together with the appointments you made and whether you turned up. That is what a booking needs, and it is what we keep. We do not build a profile of you across different businesses for our own purposes and we never sell your details.

Your browser may also store your name, phone number and email locally on your own device so a second booking is pre-filled. That never reaches our servers and the “not you?” control on the booking form clears it.

If you just visit booklino.net

One analytics measurement that counts visits, and only if you accept it when asked. Decline and nothing is loaded. See the Cookie Policy.

3. What we deliberately do not do

  • We do not sell, rent or share personal data with advertisers or data brokers.
  • We do not email a business’s customers for our own marketing. The only email we send them is the booking email that business asked us to send.
  • We do not use third-party advertising or tracking cookies, and there are no social-media pixels on our site.
  • We do not store card numbers. Payment details go to Stripe and never touch our servers.
  • We do not put booking-management tokens in analytics, logs, or web addresses that could leak them.

4. Where your data is stored

Data is stored in the European Union, in Google Cloud’s European region, using Firebase (authentication, database and file storage). Backups stay in the same region.

Two of our providers may process limited data outside the EU. Where that happens it is covered by the European Commission’s Standard Contractual Clauses:

Sub-processors
ProviderWhat it handlesWhere
Google Cloud / FirebaseDatabase, authentication, file storageEU (europe-west)
StripeSubscription billing and, via Connect, your customers' paymentsEU and US, under SCCs
ResendDelivery of transactional emailEU and US, under SCCs

We keep the current list of sub-processors here and will give notice before adding a new one that processes personal data.

5. How long we keep it

  • Business accounts: for as long as the account is open, and 30 days after closure so an accidental closure can be reversed.
  • Booking records: kept while the business needs them, and deleted or anonymised when the business deletes them or closes its account.
  • Invoices and financial records: seven years, as Dutch tax law requires.
  • Security and audit logs: up to 12 months.

When we anonymise rather than delete a record, we strip the personal details irreversibly and keep only counts, so a business does not lose its historical totals.

6. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our using it. You can also ask for it in a portable format.

These requests are handled by our support team; the dashboard does not currently include self-service export or deletion controls. If you run a business, or if you booked an appointment and cannot reach the business, email [email protected]. We respond within one month.

If you are unhappy with how we have handled your data you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

7. Security

Data is encrypted in transit and at rest. Access to production data is limited to the people who need it and is logged. Booking-management links use tokens of at least 128 bits of randomness, stored only as hashes, so a leak of our database does not hand anyone a working link. Every mutating action a business owner or an administrator takes is written to an audit log.

If a breach occurs that is likely to result in a risk to people’s rights, we notify the Autoriteit Persoonsgegevens within 72 hours and tell affected users without undue delay. Read more on our trust and security page.

8. Children

Booklino is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 in their own right. A parent may of course book an appointment for a child, in which case the details submitted are the parent’s responsibility and the business’s.

9. Changes

If we change this policy in a way that materially affects you, we will email account holders at least 30 days beforehand. The date at the top of this page always reflects the current version.

10. Contact

[Company legal name B.V.], [Registered address, Netherlands]. KvK 91548640, VAT NL004899454B23. Privacy questions: [email protected].