You can reach me at hello@gettingbooked.app for anything in this policy — a question, a data request, or a concern.
Legal · Privacy Policy
GettingBooked (gettingbooked.app) is built and operated by Dimitris Kalaitzidis, an individual based in Greece — not a registered company. This policy uses "we"/"us" to mean that operation.
You can reach me at hello@gettingbooked.app for anything in this policy — a question, a data request, or a concern.
Two kinds of people use GettingBooked, and each hands over different information.
Business owners — the studio, salon, or gym owners who run their schedule on GettingBooked — provide: their name and email address (used to sign in and receive notifications), their business name and public booking-page settings (timezone, cancellation policy, appearance choices), and — only if they choose to connect one — an API key for a third-party AI provider to power the AI Copilot.
Members — the people who book a class or appointment — provide: their name, and an email address and/or phone number, either when they book for themselves or when a business owner adds them manually. Their booking and attendance history is recorded automatically, and a business owner can add private notes about a member (visible only to that business, never to the member).
We also automatically see standard connection information any web request carries — IP address, browser type, pages requested — handled at the infrastructure level by Cloudflare (see Section 05), not separately logged or analyzed by us beyond what's needed to run and secure the service.
A member's email, phone number, and any notes an owner writes about them are encrypted at rest — not just access-controlled, actually unreadable without the encryption key.
We use industry-standard AES-256 encryption for those fields. To still let the app check "does this email already have a booking?" without ever decrypting data just to compare it, we keep a separate one-way cryptographic fingerprint of each email/phone alongside the encrypted value — it can confirm a match but can't be reversed back into the original.
A member's name is kept as plain text on purpose — business owners need to see, sort, and search it directly to run their day-to-day, the same way a paper sign-in sheet would work.
We do not sell member or business data, and we do not use it for advertising.
Google Analytics (GA4) only runs, and only sets its cookies, after you choose "Accept" on the cookie banner shown on your first visit. Choosing "Decline" — or just not choosing — means it never loads at all. You can change your mind any time by clearing your browser's site data for this domain, which brings the banner back.
Sentry can capture a masked video-like replay of the ~60 seconds before a crash to help fix it — by default it blurs all text and blocks all images/media, so it's built specifically to avoid capturing member details, but it's worth knowing it exists. It isn't gated by the cookie banner since it isn't a tracking/advertising cookie.
Signing in stores a session token in your browser's local storage (not a tracking cookie) so you don't have to re-enter a one-time code on every visit. It expires automatically after 24 hours.
If you're in the EU/EEA or UK, you have rights under GDPR (and equivalents elsewhere) to access, correct, delete, or export your information, and to object to how it's used.
For a member's own data, the business you booked with is usually the fastest route — they can see and edit it directly from their Members tab. For anything platform-level, or if you'd rather go straight to the source, write to hello@gettingbooked.app and we'll handle it directly.
GettingBooked isn't directed at, and doesn't knowingly collect information from, children under 16. If a business runs classes for minors (kids' swim lessons, junior gymnastics, and so on), that business — not GettingBooked — is responsible for getting whatever parental consent applies before entering a child's details, exactly as they would for a paper sign-up sheet.
Cloudflare, Resend, Google, Sentry, and (if a business owner connects it) Telegram all run global infrastructure, so information may be processed in countries other than where your business or its members are based. Each maintains its own security and privacy commitments, which is part of why they were chosen; you can read their respective privacy policies for details on their own practices.
No online service can honestly promise to be unbreakable — least of all one built and run for free by a single independent developer rather than a company with a dedicated security team. Real care has gone into the parts that matter most: encrypting member details at rest, expiring codes and sessions automatically, rate-limiting sign-in attempts, and using industry-standard encryption (TLS) everywhere data moves. That's a genuine effort, not an absolute guarantee, and it's better to say so plainly than to imply otherwise.
The date at the top always reflects the latest version. If a change is material — a new third party, a new use of member data — we'll flag it in the in-app "What's New" changelog the same way a new feature would be announced, not just quietly bump the date.
Questions, requests, or concerns about this policy: hello@gettingbooked.app.
Write to hello@gettingbooked.app — a real person (just the one) reads every message.
Also read the Terms of Service.