Bookixa

Privacy Policy

Last updated: [Insert Date]

This is a starting template with placeholders in [BRACKETS] — fill these in with your real details before relying on it, and consider a quick review from a solicitor or a service like Termly, since this isn't a substitute for legal advice.

1. Introduction

Welcome to Bookixa ("we", "us", or "our"). We operate a booking system that allows business owners to create accounts, manage appointments, and let their customers book services online.

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our website or services (collectively, the "Service"). By using Bookixa, you agree to the collection and use of information in accordance with this policy.

2. Who We Are (Data Controller)

Trading name: Bookixa

3. What Personal Data We Collect

Information provided directly:

  • Account details for business owners: email address and password (Firebase, our authentication provider, stores passwords only in securely hashed form — we never see or store plain-text passwords)
  • Business information: business name, services offered, prices, working hours
  • Booking information from customers: name, email address, phone number, and any notes entered when booking

Information collected automatically:

Our hosting provider (Vercel) automatically processes standard technical data needed to serve web pages, such as IP address and browser type, for security and reliability purposes. We do not currently use analytics or tracking tools on top of this.

We do not intentionally collect special category data (e.g. health, biometric, or religious data) unless voluntarily included in booking notes — please avoid including this where possible.

4. How and Why We Use Your Data

PurposeLegal Basis
Creating and managing a business accountPerformance of a contract
Processing and managing bookingsPerformance of a contract
Sending transactional emails (confirmations, reminders, password resets)Performance of a contract
Providing customer supportPerformance of a contract / Legitimate interests
Keeping the Service secure and working correctlyLegitimate interests
Complying with legal obligationsLegal obligation
Preventing fraud and abuseLegitimate interests

We do not currently send marketing communications or use analytics tools. If that changes, this section will be updated.

5. Payment Information

[Update this section to match your actual payment setup.] Currently, payment is collected in cash at the appointment — no card or payment details are collected or stored by this website. If online card payment (e.g. via Stripe, Square, or PayPal) is added in future, this section will be updated to explain that card details are entered directly with that payment provider and never seen or stored by us.

6. How We Share Your Data

We do not sell your personal data.

We share data only with the following service providers, who process it on our behalf under their own security and privacy terms:

  • Google Firebase — account login and database storage
  • Resend — sending confirmation and reminder emails
  • Vercel — website hosting

We may also share data if required by law, court order, or to protect our rights, users, or the public, or in the event of a business transfer such as a merger or sale (you would be notified where required).

7. International Data Transfers

Where data is processed outside your country of residence, our service providers use appropriate safeguards such as Standard Contractual Clauses.

8. Data Retention

We retain personal data only for as long as necessary to provide the Service and for legitimate business or legal purposes. Account data is kept for as long as the account remains active, plus a reasonable period after deletion. When data is no longer needed, we delete it.

9. Your Rights

Depending on your location, you may have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Lodge a complaint with your local data protection authority (e.g. the ICO in the UK)

To exercise any of these rights, contact us using the details on our Contact page. We will respond within the timeframe required by applicable law (usually 30 days under GDPR).

10. Cookies and Local Storage

This site does not currently use tracking, marketing, or analytics cookies. Our login system (Firebase Authentication) stores a small piece of data in your browser to keep you securely logged in — this is necessary for the Service to function and isn't used for tracking. [Update this section if analytics or marketing tools are added later.]

11. Data Security

We use reasonable technical measures to protect personal data, including:

  • Hashing of passwords (we never store them in plain text)
  • Encryption of data in transit (HTTPS/TLS)
  • Database-level access rules so business owners can only ever see their own customers' data

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. Children's Privacy

Bookixa is not intended for children under the age of 16 (or the applicable age of digital consent in your country). We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.

14. Contact Us

Questions about this policy or your data can be sent to us via our website.
[Add a real contact email or address here before relying on this policy — it's a required part of a valid privacy policy.]