Privacy Policy
Last updated: 31 July 2026
This page is a draft for review — it is not legal advice and may not yet reflect final business decisions.
1. Who we are
ReserveMe (operated by [operator name and address]) provides the appointment booking Service described in the Terms of Service. This Privacy Policy explains what personal data we collect, why, and the rights you have over it.
For privacy questions, contact us at [email protected].
2. Data we collect
We collect: account data (name, email, hashed password, sign-in sessions, and Google account identifier if you sign in with Google); business profile data (business name, branches, services, and availability); booking data (guest name, email, phone, chosen service, and date/time); payment identifiers from Stripe for paid bookings; and push subscription data when you enable notifications.
3. How we use data
We use personal data to provide and operate the Service, send booking confirmations and reminders, process payments, deliver notifications you opt into, prevent abuse, and comply with legal obligations. We do not sell personal data and we do not use it for advertising.
4. Legal bases for processing (GDPR)
Where you are in the EEA or the UK, our legal bases are: performance of a contract (to provide the Service and manage billing); legitimate interests (security, abuse prevention, reliability); consent (push notifications); and legal obligation (records retention).
5. Third parties we share data with
We use service providers to run the Service, including Stripe for payments and Resend for transactional email, Google for optional sign-in, and cloud hosting and database providers that store data on our behalf. We share only the data each provider needs and require them to protect it.
6. Cookies and local storage
We do not use advertising or analytics cookies. The Service uses session cookies required for signed-in accounts and local storage on the guest's device for a device identifier and recent booking history.
7. Data retention
We keep personal data only as long as needed for the purposes above: account data while your account is active, booking data as needed to provide the Service and handle disputes, and payment records as required by Stripe and applicable financial record-keeping law.
8. Your rights
Where applicable, you may request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, and you may withdraw consent at any time. To exercise these rights, email [email protected].
9. International transfers
Your data is stored on hosting infrastructure that may be located outside your country. Where we transfer personal data from the EEA or the UK, we rely on appropriate safeguards, including the European Commission's standard contractual clauses where required.
10. Security
We protect data with encryption in transit (HTTPS), hashed passwords, per-organisation data isolation, and restricted access to production data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the "last updated" date and, where practicable, notified by email or through the Service.
13. Contact
For privacy questions or to exercise your rights, email [email protected].