← Back to Dashboard

OpenBook legal

Privacy notice

How OpenBook handles booking, customer, payment, communications, calendar, and operational data.

Last updated 4 August 2026

PrivacyCookiesTerms

OpenBook is a booking platform for salons, barbers, beauty, fitness, wellness, tattoo, hospitality, and mixed-service businesses. This notice explains how personal data is handled when someone books, manages an appointment, session, or reservation, joins a waitlist, contacts a business, or uses the owner and staff dashboard.

The business you book with is normally the controller for its customer, booking, policy, and service records. OpenBook acts as its processor for hosted booking, reminders, payments, calendar sync, dashboard tools, and support operations. OpenBook is controller for its own account, platform administration, security, and product operations data.

Data we process

Booking and customer records can include names, email addresses, phone numbers, appointment, session, or reservation details, staff and service choices, location, notes, custom-field answers, package usage, waitlist preferences, cancellation or reschedule requests, no-show risk settings, and private manage-link tokens.

Payment records include Stripe account ids, payment intent or checkout ids, payment status, amounts, refunds, failure reason summaries, and webhook event ids. OpenBook does not store full card numbers.

Email and reminder records can include sender and recipient email addresses, message content, attachment metadata, templates, thread and provider message identifiers, delivery status, suppressions, bounces, failures, and timestamps. OpenBook does not retain raw inbound email payloads or temporary attachment download URLs in the communications inbox.

If a business connects a supported professional messaging channel, communications records can include WhatsApp Business numbers or scoped sender identifiers, Facebook Page or Instagram Professional identifiers, message text, attachment metadata, provider thread and message identifiers, delivery or read state, and timestamps. The selected professional asset access token is stored encrypted server-side and is not included in inbox views or data exports. Personal Facebook, Instagram, or WhatsApp inboxes are not supported.

Optional customer sign-in can include a Supabase Auth user identifier, confirmed email address, authentication provider identity, customer-account link, and security timestamps. A customer Facebook sign-in does not give a business access to that customer’s Facebook messages or profile inbox.

Calendar integration records can include Google or Microsoft provider account identifiers, encrypted OAuth tokens, external event ids, free/busy metadata, and disconnect state.

Why we process it

OpenBook uses this information to show live availability, create and manage bookings, send confirmations and reminders, take deposits or balances, prevent conflicting appointments, sessions, or reservations, support owner/staff access, protect against abuse, deliver webhooks, and help businesses answer customer requests.

Private booking tokens and manage links are bearer-style links. Anyone with a current link can view or manage the related booking, so they should be treated like private customer emails and not posted publicly. Links expire, and a business can revoke or replace one if it may have been shared.

Who receives data

The business you book with can access the booking and customer records needed to provide the service.

Stripe processes payment and connected-account information for checkout, deposits, refunds, balance links, disputes, and account onboarding.

Resend or SendGrid may process email addresses, message content, attachment metadata, and delivery events when live email delivery or inbound email is enabled.

Meta processes Facebook sign-in when a customer chooses it. Meta also processes messages and professional business-asset identifiers only when a business separately connects WhatsApp Business, a Facebook Page, or an Instagram Professional account. These are separate permissions and connections.

Google or Microsoft process calendar data only if the business connects a calendar account. Calendar OAuth tokens are stored encrypted server-side and can be disconnected.

Supabase provides database, authentication, and storage services for the production deployment.

Deletion, access, and retention

Customers can ask the business they booked with to access, correct, delete, or restrict customer records. The customer portal includes a profile deletion request flow where enabled.

Businesses can update, anonymise, export, or delete supported customer records according to their own legal obligations, dispute handling, accounting requirements, and retention policy. Connected communications, account links, and provider-side copies must also be considered when answering an access, export, or deletion request.

Operational records such as reminder jobs, webhook deliveries, payment events, failed-job logs, and security rate-limit counters should be kept only for support, audit, abuse prevention, or legal reasons, then deleted or anonymised under the deployment retention schedule.

Backups and provider logs may take longer to expire. Stripe, email providers, Supabase, Meta, Google, and Microsoft each maintain their own retention controls and legal obligations. Removing one business profile does not by itself delete a separate Supabase Auth account or provider account.

Your rights and contact

UK customers may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and complaint depending on the context and lawful basis.

For a booking, contact the business you booked with first because it controls the customer relationship and booking or reservation record. For OpenBook platform privacy questions, contact jaydenbis2013@gmail.com.

If you are in the UK and cannot resolve a concern, you can complain to the Information Commissioner's Office.