Legal

Privacy Policy

Last updated: 19 May 2026

Who we are. Bookr (mybookr.app) is a UK-based booking marketplace, currently operating as a pre-incorporation startup. Our registered company details will be published here once incorporation is complete. Throughout this document, "Bookr", "we", "us" and "our" refer to the operator of mybookr.app and the associated mobile applications. For any privacy question, email support@mybookr.app. We are the "data controller" for the personal data described in this policy under the UK GDPR.
Contents
  1. What data we collect
  2. Special category data
  3. Why we collect it (legal bases)
  4. Marketing & communications
  5. Who we share it with
  6. International data transfers
  7. How long we keep it
  8. Your rights
  9. Profiling & automated decisions
  10. Cookies
  11. Children
  12. Security
  13. Changes to this policy
  14. Contact & complaints
  15. Businesses as data controllers

1. What data we collect

The personal data we hold about you depends on whether you're a customer making bookings, a business owner accepting them, or simply visiting the site. We collect only what we need to run the service.

If you're a customer — guest checkout

Bookr allows you to make a booking without creating an account. When you book as a guest, we collect:

If you're a customer — with an account

If you choose to create a Bookr account (which allows you to see all your past and upcoming bookings in one place), we additionally hold:

If you're a customer — mobile app users

If you're a business owner

Everyone — technical and usage data

1b. Special category data

Some services available on Bookr involve health-related information. For example, dental clinics, physiotherapists, or personal trainers may ask you to add health notes to a booking (such as existing injuries, medical conditions, or treatment history). This type of information is classified as "special category data" under UK GDPR and receives the highest level of protection.

If you choose to add health notes to a booking:

2. Why we collect it — and our legal basis

What we doWhyLegal basis (UK GDPR)
Process bookings and paymentsTo deliver the service you asked forPerformance of a contract
Send confirmations & remindersSo you don't miss your appointmentPerformance of a contract
Send OTP verification codesTo verify you control the email address before taking paymentPerformance of a contract
Send the post-appointment review requestHelps businesses grow; helps other customers chooseLegitimate interest
Detect and prevent fraudProtect customers and businessesLegitimate interest
Comply with tax & accounting lawsRequired by HMRCLegal obligation
Improve the productMake Bookr better over timeLegitimate interest
Send transactional SMS (opt-in)Booking alerts and reminders via textConsent
App crash reportingMaintain service stability and fix bugs promptlyLegitimate interest
Push notifications (opt-in)Real-time booking and platform alertsConsent
Health/special category data in booking notesEnable businesses to deliver health-related services safelyExplicit consent
Business onboarding email sequences via Loops.soHelp new business owners set up and get value from the platformLegitimate interest (business contacts)

2b. Marketing & communications

We do not currently send marketing emails to customers. If we introduce marketing communications in the future, we will only do so to people who have explicitly opted in via a double opt-in process (you will receive a confirmation email and must click to confirm your subscription). You will always be able to unsubscribe from every marketing email with a single click.

For business owners, we send a welcome and onboarding email sequence via Loops.so when you first sign up. These emails help you configure your booking page, understand your plan features, and get your first bookings. They are sent on the basis of our legitimate interest in helping you succeed on the platform — but you can opt out at any time using the unsubscribe link or via your account settings.

SMS messages are sent only with your explicit consent, and you can opt out at any time by replying STOP or by updating your preferences in account settings.

Push notifications require opt-in at app install. You can withdraw permission at any time through your device OS notification settings or from within the app settings. Withdrawing push notification permission does not affect your ability to use the app.

Transactional messages (booking confirmations, reminders, refund notifications, security alerts) are not marketing and cannot be opted out of while you have an active account, as they are necessary for the operation of the service.

3. Who we share your data with

We share the minimum needed to run the service. Specifically:

We never sell your personal data. Ever. We do not share your data with data brokers, advertising networks, or any commercial third party for marketing purposes.

4. International data transfers

Some of our processors (Stripe, Resend, Vercel, Loops.so) are based in the United States, which means your data may be transferred outside the UK and the EU. When data moves outside the UK, we rely on the UK International Data Transfer Addendum to Standard Contractual Clauses (UK IDTA) or the European Commission's Standard Contractual Clauses (SCCs), both signed with each processor as part of their data processing terms. Supabase stores data within the EU (Ireland), which does not require a transfer mechanism under UK GDPR.

If you would like to receive a copy of the transfer safeguards we have in place with any specific processor, please email support@mybookr.app.

5. How long we keep your data

DataRetention period
Booking records (completed, cancelled, refunded)7 years after the booking date (UK tax law requires this for financial records)
Customer account dataUntil you request deletion (then within 30 days from live systems; backup copies purge within 35 days)
Reviews you have writtenUntil you delete the review or close your account; after account closure, reviews remain attributed to your booking but your name is anonymised within 30 days
Cancellation recordsRetained as part of the booking record for 7 years (financial record); the reason for cancellation is retained for 2 years for dispute resolution purposes
Support emails and communications3 years after the last interaction in the thread
Server and request logs (IP address, user-agent)30 days, then automatically purged
OTP verification codesDeleted immediately on successful verification, or after 10 minutes if unused — whichever comes first. Never retained after expiry.
Booking access tokensActive until the booking is completed or cancelled, then retained for reference within the booking record for 7 years (as part of the financial record) but no longer usable as an authentication token after the booking closes
Marketing preferences and opt-out recordsRetained indefinitely so we can honour your opt-out even after data deletion requests (an opt-out record does not constitute marketing use)
Push notification tokensDeleted within 7 days of account deletion or notification permission withdrawal
Health and special category booking notesDeleted from live systems 90 days after the appointment date (or immediately on request); backup copies purge within 35 days of deletion
Business profile data (after account closure)The public-facing booking page is taken offline immediately on account closure. The underlying business profile data (name, address, service descriptions, photos) is retained for 90 days to allow for account recovery, then deleted. Financial records associated with the account are retained for 7 years.
Crash reportsAggregated and anonymised after 30 days; no personal data is retained after that point
App session analyticsAggregated only — not retained at individual user level; no personal data linked

6. Your rights

Under UK GDPR you have the following rights over your personal data. You can exercise any of them by contacting us at support@mybookr.app.

Subject Access Requests — what we include

When you submit a Subject Access Request (SAR), we will compile a response that covers all personal data we hold about you, including:

We will not include data belonging to third parties that may appear in your records (for example, a business owner's name in a booking confirmation).

How to submit a Subject Access Request

Email support@mybookr.app with the subject line "Data Access Request". Include enough information to verify your identity — typically the email address associated with your account, or for guest bookings, the booking reference from your confirmation email. We will respond within one calendar month of receiving your request. For complex or numerous requests, we may extend this by a further two months — if so, we will notify you within the first month and explain why. There is no fee for a SAR unless the request is manifestly unfounded or excessive.

Requesting deletion

Email support@mybookr.app with the subject line "Deletion Request". We will confirm receipt and begin processing within 5 working days. Booking records that form part of our financial records must be retained for 7 years under HMRC rules — we will delete all data we are not legally required to keep and will provide you with a written summary of what has been retained and the legal basis for each category.

7. Profiling & automated decisions

We use aggregate booking data to improve the platform — for example, to surface relevant services, improve search results, and detect unusual patterns that may indicate fraud (such as repeated chargebacks, account takeovers, or coordinated fake reviews).

We do not use individual profiling to affect your pricing or eligibility to use Bookr. Every customer and every business is charged the same rates for equivalent services.

Fraud-risk flags — such as an account being associated with repeated chargeback abuse — are generated algorithmically but are always reviewed by a human member of the Bookr team before any account suspension or restriction is applied. You will be notified if your account is restricted and will be given an opportunity to respond before any permanent action is taken.

8. Cookies

We use a small number of cookies strictly necessary to keep the service running. We do not use advertising cookies, retargeting pixels, or third-party analytics trackers. The full list of cookies we set is below.

Cookie nameTypePurposeDurationFirst / third party
sb-access-token Strictly necessary Supabase authentication JWT. Stores your session token so you remain logged in between page loads. Contains an encrypted reference to your user ID; it does not contain your name, email, or booking data in readable form. 1 hour (refreshed automatically while you are active) First party (set by mybookr.app)
sb-refresh-token Strictly necessary Supabase refresh token. Used to obtain a new access token when the current one expires, without requiring you to log in again. Session (expires when you log out or after 7 days of inactivity) First party (set by mybookr.app)
__csrf (or equivalent) Strictly necessary Cross-site request forgery (CSRF) protection token. Validates that form submissions originate from the Bookr site and not from a third-party page. Required for security compliance; contains no personal data. Session First party (set by mybookr.app)
Stripe cookies (e.g. __stripe_mid, __stripe_sid) Strictly necessary (functional) Set by Stripe on checkout pages for fraud detection, device fingerprinting, and payment flow continuity. Bookr does not control these cookies; they are governed by Stripe's privacy policy. Up to 1 year (__stripe_mid); session (__stripe_sid) Third party (set by stripe.com)

We do not currently use any analytics or performance cookies (no Google Analytics, Hotjar, Mixpanel, or equivalent). If this changes in the future, we will update this policy and, where required by law, ask for your consent before setting non-essential cookies.

You can configure your browser to refuse or delete cookies at any time. Refusing strictly-necessary cookies will prevent you from logging in or completing a booking. Refusing Stripe's cookies may interfere with payment processing.

Full details are also available in our separate Cookie Policy.

9. Children

Bookr is not for under-16s. We don't knowingly collect data from anyone under that age. If you believe we have, email us and we'll delete it.

10. Security

We take the security of your personal data seriously and have implemented a range of technical and organisational measures proportionate to the risks involved.

If you discover a security vulnerability in Bookr, please report it responsibly to hello@mybookr.app. We will acknowledge receipt within 2 working days and will not take legal action against researchers acting in good faith.

11. Changes to this policy

We'll update this page when our practices change. The "Last updated" date at the top will move. For material changes (anything that meaningfully affects your rights or how we use your data) we'll email account holders at least 30 days before the change takes effect. Non-material changes (typos, clarifications that don't change substance) may take effect immediately on publication.

12. Contact & complaints

For any privacy matter, email support@mybookr.app. We aim to acknowledge privacy queries within 2 working days and to resolve them within 14 days. For complex matters we may need longer; we will keep you informed of progress.

If you're not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ICO). The ICO is the UK's independent supervisory authority for data protection. You can contact them at ico.org.uk or by telephone on 0303 123 1113. We would always prefer to hear from you first so we can try to put things right, but your right to go to the ICO is unconditional.

14b. Businesses as data controllers

When a customer makes a booking with you through Bookr, we share limited customer data with you — specifically, the customer's name, email address, phone number, and the booking details — so that you can prepare for and deliver the appointment. At this point, you become an independent data controller for that personal data under UK GDPR, separate from Bookr.

As a data controller in your own right, you have legal obligations that are entirely your responsibility. In particular:

If you have questions about your data protection obligations as a business using Bookr, the ICO's website at ico.org.uk has extensive free guidance. For complex situations, independent legal advice is recommended.