Privacy Policy

Effective 26 August 2026. Written to be read, not to be survived.

1. Who is responsible

BookNow is operated by Yiftach, a sole trader in Israel. For privacy questions, or to exercise any right below, email freemansseo@gmail.com. This policy is written with Israel’s Protection of Privacy Law in mind, and follows GDPR practice where it applies.

2. Two kinds of people, two different roles

Business owners and staff who sign up: we decide how their account data is handled, so we are the controller.

Clients of those businesses, whose details are entered when they book: the business decides what to collect and why. We only process it on their instructions, as a processor. If you are a client and want your record changed or removed, ask the business you booked with first — and if you cannot reach them, contact us and we will help.

3. What is collected

From business owners and staff: name, email address, business details, working hours, and — if a payment for a booking is recorded — the amounts involved. Note that we never receive card details; see clause 5.

From clients of a business: the record a booking creates can contain:

  • Name, email address and phone number
  • Appointment history, including services booked, times and prices
  • Date of birth, where a client provides one
  • Notes a business records about a client, which may include allergies or health information
  • Notification preferences and marketing opt-out status

Notes recorded by a business may include health information such as allergies. That is sensitive data. A business using this feature must have its client’s consent, and is responsible for obtaining it.

4. Why, and on what basis

  • To run the service — showing availability, taking bookings, sending confirmations and reminders. This is necessary to perform the contract.
  • To keep it working and secure — error monitoring, rate limiting and abuse prevention, on the basis of our legitimate interest in a service that stays up.
  • Marketing messages from a business to its clients — sent only where the business has a lawful basis, and always with a working unsubscribe link. Opting out is honoured immediately and permanently.

5. Payment data: none

No payment provider is connected to BookNow. We do not collect, transmit or store card numbers, and there is no card data in our systems to lose. Prices shown are a record of what a business and its client agreed; money changes hands between them.

6. Who else sees it

We do not sell personal data and we do not share it for advertising. It reaches these service providers only so the service can function:

ProviderWhyWhat
ClerkAccount sign-in for business owners and staffEmail address, name, profile image
UploadThingStorage for images a business uploads to its pageUploaded image files
Google CalendarOptional two-way calendar sync, only if a business connects itAppointment times, service name, client name
Green API (WhatsApp)WhatsApp appointment notifications, where enabledPhone number, appointment details
SentryError monitoring, so faults get fixedTechnical error reports; may incidentally include an account identifier
Hetzner Online GmbHServer hostingAll service data, stored in Germany

Email is sent from our own mail server, not a third-party marketing platform. We may also disclose data where the law requires it.

7. Where it is stored

On servers in Germany (Hetzner Online GmbH). If you are outside that country, your data is transferred there in order to provide the service.

8. How long it is kept

Account and booking records are kept while the account is open, because a business needs its own history. When an account is deleted we remove its data within 30 days, except anything we must keep longer by law. A business can delete an individual client record at any time from its dashboard.

9. Security

Traffic is encrypted in transit (HTTPS). Access to a business’s data requires an authenticated session, and every request is scoped to that business. Third-party credentials we store on your behalf — such as a connected Google Calendar — are encrypted at rest. Public booking pages are rate limited to prevent abuse.

No system is perfectly secure. If a breach affects you, we will notify you and the relevant authority as the law requires.

10. Cookies

We use only what the service needs to work: a session cookie so you stay signed in, and a short-lived cookie protecting the Google Calendar connection flow against cross-site request forgery. There are no advertising or cross-site tracking cookies, which is why you are not being shown a consent banner.

11. Your rights

You can ask to access, correct, export or delete your personal data, to object to processing based on legitimate interest, and to withdraw consent where consent was the basis. Email freemansseo@gmail.com and we will respond within 30 days. You may also complain to your local data protection authority.

12. Children

The service is not intended for children under 16 to sign up for directly. A business may book an appointment for a child at the request of a parent or guardian, who is responsible for that consent.

13. Changes

If this policy changes materially we will update the effective date above and notify account holders by email.