How we keep your data safe
Last updated: 2 August 2026
We encrypt your data, keep each business's data separate, take payments through Stripe and follow UK GDPR.
Payments handled by Stripe
Card details go straight to Stripe and never reach Bookr's servers. We receive only a token and a confirmation. Stripe is PCI-DSS Level 1, the highest standard in the payments industry.
Encryption everywhere
All traffic uses TLS 1.2 or higher, and HTTP redirects to HTTPS. Data at rest is encrypted with AES-256. Database access needs authenticated keys plus row-level security (RLS), so a business can only see its own bookings and customers, even if the app has a bug. We aim for high availability but don't offer a formal SLA. See live status.
UK GDPR
We comply with UK GDPR. Customers can ask for a copy of their data, or for it to be deleted, at any time. Business owners can export all their data in one click.
Your data is yours
We don't sell your data or share it with advertisers. You can export or delete your bookings, customer details and financial records, and take them with you if you leave.
What we collect
We collect what a booking needs: email, name, booking times and payment amount. We don't use third-party advertising or analytics trackers such as Google Analytics or Meta Pixel. The Privacy Policy lists what we collect and why.
Locked-down admin access
Only authorised team members can reach our database, hosting and email. Every login needs two-factor authentication (2FA) and is logged, and we review the logs for anything unusual.
If something goes wrong
If a personal-data breach puts your rights at risk, we notify the ICO within 72 hours of becoming aware of it and tell affected people without undue delay, as UK GDPR requires.
Found a security issue?
Email support@mybookr.app. We credit responsible disclosure in our security acknowledgements.