Privacy Statement
Last updated:
This statement explains what personal data Bookalio processes when you use the website or the scheduling software. It is written to be specific: for each type of data you can see why we need it and how long we keep it.
Who is responsible
Bookalio operates this website and the scheduling software behind it. If you have a question about your data, write to admin@bookalio.com.
One distinction is worth stating up front, because it determines who you need to talk to:
- For the data of business owners who create an account, we are the data controller.
- For the data of customers who book an appointment with a business, that business is the controller. We process it on their behalf, as a processor. If you want your customer record deleted, contact the business you booked with. If that goes nowhere, come to us and we will help.
What we process
We collect what is needed to make an appointment happen and to keep an account working. Nothing beyond that.
| Data | Why | Legal basis |
|---|---|---|
| Business account name, email address and password | Signing in, securing the account, contacting you about the service | Performance of a contract |
| Business name, contact details, services, prices, opening hours and staff names | Building your public booking page and calculating availability | Performance of a contract |
| Name, email address and phone number of the person booking | Recording and confirming the appointment and sending reminders | Performance of a contract |
| Date, time, chosen service, staff member and any notes on the appointment | Delivering the appointment and maintaining the calendar | Performance of a contract |
| Waitlist entries | Alerting you when a slot opens up after a cancellation | Performance of a contract |
| IP address, browser and timestamp in server logs | Diagnosing faults and blocking abuse | Legitimate interest (security) |
| Page-level usage statistics (Google Analytics) | Seeing which pages work and which do not | Consent |
We do not ask for a date of birth, a national ID number, a copy of an identity document or payment card details. As a business owner, please do not use the appointment notes field for medical or other special-category data unless you have your own lawful basis for holding it.
Cookies and measurement
By default the site sets only cookies it cannot work without: your signed-in session, a form security token, your language choice, and the cookie that records the cookie choice you made.
Google Analytics is loaded only after you click "Accept". If you click "Reject", or ignore the banner entirely, the script is never fetched at all. Where it does run, your IP address is anonymised. The cookie policy lists every cookie by name.
Who else sees your data
We sell nothing and we build no advertising profiles. Three categories of party necessarily see something:
- Our hosting provider. It runs the servers and delivers the confirmation and reminder emails. Without hosting there is no service.
- Google Ireland Limited, for Google Analytics — only if you consented to it.
- Google Fonts and a CDN that serves the site styling. Your browser fetches fonts and stylesheets from Google and from a content network, which makes your IP address technically visible to them. This happens on every page, including without consent, because the page would otherwise render incorrectly. We are moving these files onto our own server so those connections go away.
Beyond that, we hand over data only where the law obliges us to, for example on a valid order from a competent authority.
Transfers outside the EU
Google processes some data in the United States. That transfer relies on the EU-US Data Privacy Framework and the European Commission's standard contractual clauses. If you would rather avoid the transfer altogether, reject the analytics cookies — the rest of the site keeps working exactly as before.
How long we keep things
| Data | Retention |
|---|---|
| Business account data | For as long as the account exists. After you close it we delete the account within 30 days. |
| Appointments and customer records | Decided by the business you booked with. When their account is closed, the records go with it. |
| Waitlist entries | Until the slot is filled or the window you asked about has passed. |
| Server logs | Short-lived; only as long as needed for fault analysis and security. |
| Usage statistics | Held in Google Analytics under the retention period configured on the property. |
Security
All traffic runs over an encrypted connection (HTTPS). Passwords are never stored in readable form; they are hashed. Every request that reads or changes data checks that the account actually belongs to the business in question, so one business cannot reach another's calendar or customers.
No system is unbreakable. If you think something has gone wrong with your data, or you have found a vulnerability, email admin@bookalio.com. We will respond and fix it, and we would rather hear from you than not.
Your rights
Under the GDPR you can ask us to:
- Show you the data we hold about you.
- Correct anything that is wrong.
- Delete your data and your account.
- Restrict how we process it, or object to the processing.
- Export your data in a common file format.
- Withdraw your consent for statistics, which you can do at any time without giving a reason.
Send your request to admin@bookalio.com. We answer within a month. If you are unhappy with how we handle it, you can lodge a complaint with your national data protection authority — in the Netherlands that is the Autoriteit Persoonsgegevens.
Children
The service is built for business owners and their adult customers. We do not target anyone under 16 and we do not knowingly collect their data. If you believe a child has left data with us, tell us and we will remove it.
Changes
When the service changes, this statement changes with it. The date at the top shows when we last revised it substantively. For significant changes we will tell you by email or through a notice in your dashboard.
Something unclear on this page? admin@bookalio.com