This policy explains how BookingOS ("we", "us", "our") collects and uses personal data when you use bookingos.co.uk and the BookingOS booking platform (the "Service"). It covers both shop owners who subscribe and members of the public who book an appointment.
1.Who we are
BookingOS is operated by a UK sole trader trading as "BookingOS". A trading address is available on request by emailing bookingos.legal@gmail.com.
For the information described in Section 3(a) below, we are the data controller — we decide how it is used. For the information described in Section 3(b), we are a data processor, acting on behalf of the barbershop ("Shop") a Client books with. That Shop is the controller for its own Clients' data.
2.Who this policy covers
- Account Holders — shop owners and staff who sign up for a BookingOS subscription to manage their business.
- Clients — people who book an appointment with a Shop through a BookingOS booking page, without holding a BookingOS account themselves.
- Visitors — anyone who simply browses the website.
3.What we collect
(a) About Account Holders — we are the data controller:
- Name and email address, and whether that email has been verified
- Your login credential, stored only as a secure one-way hash — we never store or see it in readable form
- Business name, address, opening hours, services, prices and the photographs you upload
- Staff usernames created by the shop owner
- Billing information — we do not see or store full card details; card payments are handled directly by Stripe
- If you switch on online payments, the identifier of the Stripe account you connect and its status. We do not receive the identity documents you give Stripe.
- Any support requests or other messages you send us
(b) About Clients booking an appointment — the Shop is the data controller and we process this on their behalf:
- Name and contact details (phone and/or email) given at booking
- The barber, service and appointment time selected
- Any notes added when booking
- A one-off secure link so the Client can cancel or move their own appointment
- Where the Shop takes payment online, whether a deposit or payment was made, and its Stripe reference. Card numbers go straight to Stripe and never reach us.
(c) Technical information — we are the data controller:
- Your IP address and basic request details, held briefly so we can apply rate limits, block abuse and diagnose faults
- Server error logs, which may incidentally contain some of the above
We do not use analytics or advertising trackers, and we do not build profiles of visitors.
4.How we use this information
- To create and run your account and provide the booking Service
- To verify your email address at sign-up
- To process subscription payments and send billing emails
- To send booking confirmations, reminders, cancellation links and password-reset emails
- To enable online deposits and payments where a Shop has switched them on
- To review photographs uploaded to public booking pages
- To keep the Service secure, apply rate limits and prevent misuse
- To enforce subscription status — for example, pausing access if a subscription lapses
- To respond to support requests
We do not use your data, or your Clients' data, to send marketing without your consent, and we never sell it.
5.Our legal bases (UK GDPR)
- Contract — to provide the account or subscription you have signed up for, and to process a Client's booking on the Shop's behalf
- Legitimate interests — keeping the Service secure, preventing fraud and abuse, moderating public content, and improving the platform
- Legal obligation — where we need to keep records for tax or accounting purposes
- Consent — for anything optional, such as non-essential cookies, if we ever introduce them
6.Payments
All card handling is done by Stripe. We never receive full card numbers.
Subscriptions. When a Shop pays us for BookingOS, Stripe processes the card on our behalf and we see only the outcome, the last four digits and the expiry.
Client payments. Where a Shop has switched on online deposits or payments, the money goes directly to that Shop's own Stripe account — it never passes through us. For that payment, Stripe and the Shop are the ones handling the card data; we simply record that a payment happened. Stripe's own privacy policy applies to how it uses that information.
8.International transfers
Some of our service providers (including Stripe, Resend, Render and Google) may process data outside the UK or EEA, including in the United States. Where that happens it is done under appropriate safeguards, such as the UK International Data Transfer Addendum or Standard Contractual Clauses. You can ask us for more detail using the contact address below.
10.How long we keep data
- Incomplete sign-ups — if you start creating an account but never finish, the part-made record is deleted within a few days.
- Account Holder data — kept while the account is active. After it closes we keep it for up to 30 days so it can be restored or exported, then delete it, apart from records we must keep for tax and accounting (normally six years).
- Client booking data — kept for as long as the Shop keeps it in its booking history, or until the Shop or the Client asks for it to be deleted. It is deleted when the Shop's account is deleted.
- Cancellation and reset links — expire automatically after a short period.
- Technical logs — kept only briefly, for security and fault-finding.
11.Your rights
Under UK GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict or object to how it is used, and to receive it in a portable format. You can also withdraw consent where we have relied on it.
To exercise these rights, contact us at bookingos.legal@gmail.com. We will respond within one month. If your request relates to a booking made with a specific Shop, we may need to direct you to that Shop, as they are the controller for that information.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
12.Automated decisions
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not carry out profiling.
13.Children
BookingOS is not intended for use by children under 16, and we do not knowingly collect their data. Where a parent or guardian books an appointment for a child, the Shop is responsible for handling that information appropriately.
14.Security
We take reasonable technical and organisational measures to protect personal data. These include encrypted connections (HTTPS), one-way hashing of login credentials, rate limiting on sensitive routes, access controls that keep each Shop's data separate, and restricting administrative access.
No system is completely secure and we cannot guarantee absolute security. If a breach happens that is likely to put your rights at risk, we will tell you and the Information Commissioner's Office as the law requires.
15.Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above, and flag anything significant on the site or by email.
16.Contact us
bookingos.legal@gmail.com
Trading address available on request.