Legal · Privacy Policy

Your data, plainly explained.

What GettingBooked collects about business owners and their members, why, and how it's protected — written by the person who built it, not a law firm.

Effective September 4, 2026 Last updated September 23, 2026
Plain-English disclaimer: GettingBooked is built and run by one person, not a law firm, so this policy is written to be genuinely readable rather than exhaustively lawyered. It's accurate about what the product actually does — but it isn't a substitute for your own legal advice if you need it, particularly for your own obligations to your members.

What's covered

01 Who runs GettingBooked 02 What we collect 03 How member details are protected 04 How we use what we collect 05 Who we share it with 06 Cookies, analytics & local storage 07 How long we keep it, and deleting it 08 Your rights 09 Children 10 Where your data is processed 11 Security, honestly 12 Changes to this policy 13 Contact
01

Who runs GettingBooked

GettingBooked (gettingbooked.app) is built and operated by Dimitris Kalaitzidis, an individual based in Greece — not a registered company. This policy uses "we"/"us" to mean that operation.

You can reach me at hello@gettingbooked.app for anything in this policy — a question, a data request, or a concern.

02

What we collect

Two kinds of people use GettingBooked, and each hands over different information.

Business owners — the studio, salon, or gym owners who run their schedule on GettingBooked — provide: their name and email address (used to sign in and receive notifications), their business name and public booking-page settings (timezone, cancellation policy, appearance choices), and — only if they choose to connect one — an API key for a third-party AI provider to power the AI Copilot.

Members — the people who book a class or appointment — provide: their name, and an email address and/or phone number, either when they book for themselves or when a business owner adds them manually. Their booking and attendance history is recorded automatically, and a business owner can add private notes about a member (visible only to that business, never to the member).

We also automatically see standard connection information any web request carries — IP address, browser type, pages requested — handled at the infrastructure level by Cloudflare (see Section 05), not separately logged or analyzed by us beyond what's needed to run and secure the service.

03

How member details are protected

A member's email, phone number, and any notes an owner writes about them are encrypted at rest — not just access-controlled, actually unreadable without the encryption key.

We use industry-standard AES-256 encryption for those fields. To still let the app check "does this email already have a booking?" without ever decrypting data just to compare it, we keep a separate one-way cryptographic fingerprint of each email/phone alongside the encrypted value — it can confirm a match but can't be reversed back into the original.

A member's name is kept as plain text on purpose — business owners need to see, sort, and search it directly to run their day-to-day, the same way a paper sign-in sheet would work.

What this means in practice: if our database were ever exposed, an attacker would see names and booking patterns, but not usable email addresses, phone numbers, or notes.
04

How we use what we collect

  • Running the service: letting a business manage its schedule and members, and letting a member book, cancel, or join a waitlist.
  • Signing you in: passwordless sign-in works by emailing a one-time 6-digit code — that's the entire purpose of collecting an email address at sign-in.
  • Notifications: booking confirmations, cancellation notices, waitlist offers, and — for business owners — automatic 30/90/365-day "how's it going" stats reports.
  • Keeping things running: diagnosing bugs and errors (Section 05) and understanding traffic patterns so pages load well on the phones most visitors actually use.

We do not sell member or business data, and we do not use it for advertising.

05

Who we share it with

GettingBooked runs on a small set of specialist providers rather than our own servers. Here's exactly who sees what, and why.

ProviderWhat it doesWhat it can see
CloudflareHosting, database, image storage, and bot-protection for sign-up/sign-in forms (Turnstile)Everything the app stores or processes — it's the infrastructure GettingBooked runs on
ResendSends every email GettingBooked sends — OTP codes, confirmations, cancellations, waitlist offers, milestone reportsThe recipient's email address and the message content, at the moment of sending
Google AnalyticsAggregate traffic analytics — which pages get visited, from what kind of deviceStandard web-analytics data (see Section 06); not member booking details
SentryCatches and helps diagnose bugs and crashesTechnical error data, and occasionally a masked ~60-second session replay (Section 06)
Your own AI provider (only if connected)Powers the AI Copilot, an alpha featureWhatever your query touches — see the callout below
Telegram (only if connected)Optional booking and cancellation alerts to a business owner's own Telegram account, plus schedule replies to the bot's /today and /tomorrow commandsThe member's name, the session and its time, and booking or cancellation details in each alert (e.g. a first booking, a seat taken from the waitlist, or how many late cancellations that member made in the last 30 days), stored in the owner's Telegram chat under Telegram's terms
The AI Copilot only talks to a third-party AI provider if you connect one. Nothing is ever sent to Anthropic, OpenAI, or Ollama by default. If a business owner deliberately connects their own API key, a Copilot query sends along whatever it needs to answer you — e.g. asking "how many no-shows last month?" sends attendance figures; asking it to add a member sends that member's name and contact details. That exchange happens under the account and terms the owner has directly with their chosen provider, not with us.
Telegram alerts are off by default. They only start if a business owner connects their own Telegram account from Settings, and they only go to that owner's own chat. Disconnecting (from Settings, or by sending /stop to the bot) stops new alerts immediately. Messages already delivered stay in the owner's Telegram chat, outside GettingBooked's retention and encryption controls; deleting them is up to the owner.
06

Cookies, analytics & local storage

Google Analytics (GA4) only runs, and only sets its cookies, after you choose "Accept" on the cookie banner shown on your first visit. Choosing "Decline" — or just not choosing — means it never loads at all. You can change your mind any time by clearing your browser's site data for this domain, which brings the banner back.

Sentry can capture a masked video-like replay of the ~60 seconds before a crash to help fix it — by default it blurs all text and blocks all images/media, so it's built specifically to avoid capturing member details, but it's worth knowing it exists. It isn't gated by the cookie banner since it isn't a tracking/advertising cookie.

Signing in stores a session token in your browser's local storage (not a tracking cookie) so you don't have to re-enter a one-time code on every visit. It expires automatically after 24 hours.

07

How long we keep it, and deleting it

  • One-time codes are single-use and expire after 15 minutes, whether or not they're used.
  • Session tokens expire automatically after 24 hours.
  • A business owner can permanently delete their entire business at any time, from Settings → Danger zone — every member, booking, and setting goes with it, and it can't be undone.
  • Businesses that go quiet (no owner sign-in and no scheduled sessions for a while) are flagged internally and, after a warning period, may be removed to keep the platform tidy.
  • A member who wants their information removed can ask the business they booked with — an owner can remove any member from their roster at any time — or write to us directly at hello@gettingbooked.app.
  • Telegram alerts, if a business owner has connected Telegram, are kept by Telegram in the owner's chat. Deleting a member or a business in GettingBooked doesn't remove alerts already delivered; the owner can delete them in Telegram.
08

Your rights

If you're in the EU/EEA or UK, you have rights under GDPR (and equivalents elsewhere) to access, correct, delete, or export your information, and to object to how it's used.

For a member's own data, the business you booked with is usually the fastest route — they can see and edit it directly from their Members tab. For anything platform-level, or if you'd rather go straight to the source, write to hello@gettingbooked.app and we'll handle it directly.

09

Children

GettingBooked isn't directed at, and doesn't knowingly collect information from, children under 16. If a business runs classes for minors (kids' swim lessons, junior gymnastics, and so on), that business — not GettingBooked — is responsible for getting whatever parental consent applies before entering a child's details, exactly as they would for a paper sign-up sheet.

10

Where your data is processed

Cloudflare, Resend, Google, Sentry, and (if a business owner connects it) Telegram all run global infrastructure, so information may be processed in countries other than where your business or its members are based. Each maintains its own security and privacy commitments, which is part of why they were chosen; you can read their respective privacy policies for details on their own practices.

11

Security, honestly

No online service can honestly promise to be unbreakable — least of all one built and run for free by a single independent developer rather than a company with a dedicated security team. Real care has gone into the parts that matter most: encrypting member details at rest, expiring codes and sessions automatically, rate-limiting sign-in attempts, and using industry-standard encryption (TLS) everywhere data moves. That's a genuine effort, not an absolute guarantee, and it's better to say so plainly than to imply otherwise.

12

Changes to this policy

The date at the top always reflects the latest version. If a change is material — a new third party, a new use of member data — we'll flag it in the in-app "What's New" changelog the same way a new feature would be announced, not just quietly bump the date.

13

Contact

Questions, requests, or concerns about this policy: hello@gettingbooked.app.

Have a question we didn't answer?

Write to hello@gettingbooked.app — a real person (just the one) reads every message.

Email us →