Legal · Privacy Policy

Your data, plainly explained.

What GettingBooked collects about business owners and their members, why, and how it's protected — written by the person who built it, not a law firm.

Effective September 4, 2026 Last updated September 4, 2026
Plain-English disclaimer: GettingBooked is built and run by one person, not a law firm, so this policy is written to be genuinely readable rather than exhaustively lawyered. It's accurate about what the product actually does — but it isn't a substitute for your own legal advice if you need it, particularly for your own obligations to your members.

What's covered

01 Who runs GettingBooked 02 What we collect 03 How member details are protected 04 How we use what we collect 05 Who we share it with 06 Cookies, analytics & local storage 07 How long we keep it, and deleting it 08 Your rights 09 Children 10 Where your data is processed 11 Security, honestly 12 Changes to this policy 13 Contact
01

Who runs GettingBooked

GettingBooked (gettingbooked.app) is built and operated by Dimitris Kalaitzidis, an individual based in Greece — not a registered company. This policy uses "we"/"us" to mean that operation.

You can reach me at [email protected] for anything in this policy — a question, a data request, or a concern.

02

What we collect

Two kinds of people use GettingBooked, and each hands over different information.

Business owners — the studio, salon, or gym owners who run their schedule on GettingBooked — provide: their name and email address (used to sign in and receive notifications), their business name and public booking-page settings (timezone, cancellation policy, appearance choices), and — only if they choose to connect one — an API key for a third-party AI provider to power the AI Copilot.

Members — the people who book a class or appointment — provide: their name, and an email address and/or phone number, either when they book for themselves or when a business owner adds them manually. Their booking and attendance history is recorded automatically, and a business owner can add private notes about a member (visible only to that business, never to the member).

We also automatically see standard connection information any web request carries — IP address, browser type, pages requested — handled at the infrastructure level by Cloudflare (see Section 05), not separately logged or analyzed by us beyond what's needed to run and secure the service.

03

How member details are protected

A member's email, phone number, and any notes an owner writes about them are encrypted at rest — not just access-controlled, actually unreadable without the encryption key.

We use industry-standard AES-256 encryption for those fields. To still let the app check "does this email already have a booking?" without ever decrypting data just to compare it, we keep a separate one-way cryptographic fingerprint of each email/phone alongside the encrypted value — it can confirm a match but can't be reversed back into the original.

A member's name is kept as plain text on purpose — business owners need to see, sort, and search it directly to run their day-to-day, the same way a paper sign-in sheet would work.

What this means in practice: if our database were ever exposed, an attacker would see names and booking patterns, but not usable email addresses, phone numbers, or notes.
04

How we use what we collect

  • Running the service: letting a business manage its schedule and members, and letting a member book, cancel, or join a waitlist.
  • Signing you in: passwordless sign-in works by emailing a one-time 6-digit code — that's the entire purpose of collecting an email address at sign-in.
  • Notifications: booking confirmations, cancellation notices, waitlist offers, and — for business owners — automatic 30/90/365-day "how's it going" stats reports.
  • Keeping things running: diagnosing bugs and errors (Section 05) and understanding traffic patterns so pages load well on the phones most visitors actually use.

We do not sell member or business data, and we do not use it for advertising.

05

Who we share it with

GettingBooked runs on a small set of specialist providers rather than our own servers. Here's exactly who sees what, and why.

ProviderWhat it doesWhat it can see
CloudflareHosting, database, image storage, and bot-protection for sign-up/sign-in forms (Turnstile)Everything the app stores or processes — it's the infrastructure GettingBooked runs on
ResendSends every email GettingBooked sends — OTP codes, confirmations, cancellations, waitlist offers, milestone reportsThe recipient's email address and the message content, at the moment of sending
Google AnalyticsAggregate traffic analytics — which pages get visited, from what kind of deviceStandard web-analytics data (see Section 06); not member booking details
SentryCatches and helps diagnose bugs and crashesTechnical error data, and occasionally a masked ~60-second session replay (Section 06)
Your own AI provider (only if connected)Powers the AI Copilot, an alpha featureWhatever your query touches — see the callout below
The AI Copilot only talks to a third-party AI provider if you connect one. Nothing is ever sent to Anthropic, OpenAI, or Ollama by default. If a business owner deliberately connects their own API key, a Copilot query sends along whatever it needs to answer you — e.g. asking "how many no-shows last month?" sends attendance figures; asking it to add a member sends that member's name and contact details. That exchange happens under the account and terms the owner has directly with their chosen provider, not with us.
06

Cookies, analytics & local storage

Google Analytics (GA4) runs across the site to understand traffic — it sets its own cookies in your browser to do this. You can block it with any standard ad-/tracker-blocker, or by browsing in a private window.

Sentry can capture a masked video-like replay of the ~60 seconds before a crash to help fix it — by default it blurs all text and blocks all images/media, so it's built specifically to avoid capturing member details, but it's worth knowing it exists.

Signing in stores a session token in your browser's local storage (not a tracking cookie) so you don't have to re-enter a one-time code on every visit. It expires automatically after 24 hours.

Honest gap: there is currently no cookie-consent banner in front of Google Analytics. For a free, single-operator project this is a known limitation rather than an oversight we're unaware of — it's on the list to fix, and in the meantime any standard browser privacy setting or tracker-blocker will stop it working.
07

How long we keep it, and deleting it

  • One-time codes are single-use and expire after 15 minutes, whether or not they're used.
  • Session tokens expire automatically after 24 hours.
  • A business owner can permanently delete their entire business at any time, from Settings → Danger zone — every member, booking, and setting goes with it, and it can't be undone.
  • Businesses that go quiet (no owner sign-in and no scheduled sessions for a while) are flagged internally and, after a warning period, may be removed to keep the platform tidy.
  • A member who wants their information removed can ask the business they booked with — an owner can remove any member from their roster at any time — or write to us directly at [email protected].
08

Your rights

If you're in the EU/EEA or UK, you have rights under GDPR (and equivalents elsewhere) to access, correct, delete, or export your information, and to object to how it's used.

For a member's own data, the business you booked with is usually the fastest route — they can see and edit it directly from their Members tab. For anything platform-level, or if you'd rather go straight to the source, write to [email protected] and we'll handle it directly.

09

Children

GettingBooked isn't directed at, and doesn't knowingly collect information from, children under 16. If a business runs classes for minors (kids' swim lessons, junior gymnastics, and so on), that business — not GettingBooked — is responsible for getting whatever parental consent applies before entering a child's details, exactly as they would for a paper sign-up sheet.

10

Where your data is processed

Cloudflare, Resend, Google, and Sentry all run global infrastructure, so information may be processed in countries other than where your business or its members are based. Each maintains its own security and privacy commitments, which is part of why they were chosen; you can read their respective privacy policies for details on their own practices.

11

Security, honestly

No online service can honestly promise to be unbreakable — least of all one built and run for free by a single independent developer rather than a company with a dedicated security team. Real care has gone into the parts that matter most: encrypting member details at rest, expiring codes and sessions automatically, rate-limiting sign-in attempts, and using industry-standard encryption (TLS) everywhere data moves. That's a genuine effort, not an absolute guarantee, and it's better to say so plainly than to imply otherwise.

12

Changes to this policy

The date at the top always reflects the latest version. If a change is material — a new third party, a new use of member data — we'll flag it in the in-app "What's New" changelog the same way a new feature would be announced, not just quietly bump the date.

13

Contact

Questions, requests, or concerns about this policy: [email protected].

Have a question we didn't answer?

Write to [email protected] — a real person (just the one) reads every message.

Email us →