Skip to content

Trust & security

Built for the EU from day one

You are handing us your calendar and your customers’ contact details. This page says where they go, who can reach them, and what we will never do with them, in enough detail that you could check.

The four promises

What we will not do

Your customers are yours

We never email them for our own reasons, never market to them, and never sell or share their details. The only mail they get from us is the booking mail you asked us to send.

The smallest amount of data

A name, a phone number, an email address. That is what a booking needs, so that is what we ask for and what we keep.

Hosted in the EU

Google Cloud’s European region, with a documented processing agreement. Access, export and deletion requests go to [email protected].

Payments handled by Stripe

Card details never touch Booklino. Your payouts come from your own Stripe account, not from us.

How it is built

The decisions happen on our servers

Most booking bugs that cost money come from trusting the browser. We do not: the browser sends choices, and the server decides what they mean.

Prices are never client-side

Your customer’s browser sends a service id, not a price. The amount charged is worked out on the server from your settings, so it cannot be edited on the way through.

No double bookings

A slot is locked inside a database transaction while it is being taken. Two people tapping the same time at the same moment cannot both succeed. One gets the slot and the other is told to pick another.

Checked on every request

Identity, then business membership, then role, then plan, then ownership of the exact record. One business can never read another’s data, even with a valid login.

The link in your customer’s email

A manage link is a key, so we treat it like one

Guests do not have accounts, so the link that lets them change an appointment is the only credential involved. That makes it worth protecting properly.

  • At least 128 bits of randomness, so they cannot be guessed by trying.
  • Stored only as a hash, so a copy of our database does not yield working links.
  • Never written to logs, analytics, or a web address that could be shared.
  • The page carries no-referrer, no-store and noindex headers, so it cannot leak to the next site or to a search engine.

Availability answers are deliberately uninformative too: a taken slot is simply unavailable. Your page never reveals who booked it, or that you are at the dentist.

Who else touches it

The complete list of sub-processors

Sub-processors used by Booklino
ProviderPurposeLocation
Google Cloud / FirebaseDatabase, authentication, file storage, hostingEU (europe-west)
StripeSubscription billing and, via Connect, your customers' paymentsEU / US under SCCs
ResendDelivery of transactional emailEU / US under SCCs

That is the whole list. We give 30 days’ notice before adding another, and you can object. The contractual detail is in the Data Processing Agreement.

If something goes wrong

What we do, and how fast

We would rather tell you about a problem than be asked about it. If a breach is likely to put anyone’s rights at risk, we notify the Dutch data protection authority within 72 hours and affected users without undue delay. Businesses hear from us within 48 hours of us becoming aware, so you can meet your own obligations.

Reporting a vulnerability

Email [email protected] before disclosing it anywhere else. Good-faith research within your own test account will not be pursued.

Honest status

Booklino is a young product in beta. We have not yet completed an independent security audit or a SOC 2 report, and we would rather say so than imply otherwise.

Start with a calendar you can trust

14 days free · no charge today · your page is live the same afternoon

Trust & security · Booklino