You can reach me at [email protected] for anything in this policy — a question, a data request, or a concern.
Legal · Privacy Policy
GettingBooked (gettingbooked.app) is built and operated by Dimitris Kalaitzidis, an individual based in Greece — not a registered company. This policy uses "we"/"us" to mean that operation.
You can reach me at [email protected] for anything in this policy — a question, a data request, or a concern.
Two kinds of people use GettingBooked, and each hands over different information.
Business owners — the studio, salon, or gym owners who run their schedule on GettingBooked — provide: their name and email address (used to sign in and receive notifications), their business name and public booking-page settings (timezone, cancellation policy, appearance choices), and — only if they choose to connect one — an API key for a third-party AI provider to power the AI Copilot.
Members — the people who book a class or appointment — provide: their name, and an email address and/or phone number, either when they book for themselves or when a business owner adds them manually. Their booking and attendance history is recorded automatically, and a business owner can add private notes about a member (visible only to that business, never to the member).
We also automatically see standard connection information any web request carries — IP address, browser type, pages requested — handled at the infrastructure level by Cloudflare (see Section 05), not separately logged or analyzed by us beyond what's needed to run and secure the service.
A member's email, phone number, and any notes an owner writes about them are encrypted at rest — not just access-controlled, actually unreadable without the encryption key.
We use industry-standard AES-256 encryption for those fields. To still let the app check "does this email already have a booking?" without ever decrypting data just to compare it, we keep a separate one-way cryptographic fingerprint of each email/phone alongside the encrypted value — it can confirm a match but can't be reversed back into the original.
A member's name is kept as plain text on purpose — business owners need to see, sort, and search it directly to run their day-to-day, the same way a paper sign-in sheet would work.
We do not sell member or business data, and we do not use it for advertising.
Google Analytics (GA4) runs across the site to understand traffic — it sets its own cookies in your browser to do this. You can block it with any standard ad-/tracker-blocker, or by browsing in a private window.
Sentry can capture a masked video-like replay of the ~60 seconds before a crash to help fix it — by default it blurs all text and blocks all images/media, so it's built specifically to avoid capturing member details, but it's worth knowing it exists.
Signing in stores a session token in your browser's local storage (not a tracking cookie) so you don't have to re-enter a one-time code on every visit. It expires automatically after 24 hours.
If you're in the EU/EEA or UK, you have rights under GDPR (and equivalents elsewhere) to access, correct, delete, or export your information, and to object to how it's used.
For a member's own data, the business you booked with is usually the fastest route — they can see and edit it directly from their Members tab. For anything platform-level, or if you'd rather go straight to the source, write to [email protected] and we'll handle it directly.
GettingBooked isn't directed at, and doesn't knowingly collect information from, children under 16. If a business runs classes for minors (kids' swim lessons, junior gymnastics, and so on), that business — not GettingBooked — is responsible for getting whatever parental consent applies before entering a child's details, exactly as they would for a paper sign-up sheet.
Cloudflare, Resend, Google, and Sentry all run global infrastructure, so information may be processed in countries other than where your business or its members are based. Each maintains its own security and privacy commitments, which is part of why they were chosen; you can read their respective privacy policies for details on their own practices.
No online service can honestly promise to be unbreakable — least of all one built and run for free by a single independent developer rather than a company with a dedicated security team. Real care has gone into the parts that matter most: encrypting member details at rest, expiring codes and sessions automatically, rate-limiting sign-in attempts, and using industry-standard encryption (TLS) everywhere data moves. That's a genuine effort, not an absolute guarantee, and it's better to say so plainly than to imply otherwise.
The date at the top always reflects the latest version. If a change is material — a new third party, a new use of member data — we'll flag it in the in-app "What's New" changelog the same way a new feature would be announced, not just quietly bump the date.
Questions, requests, or concerns about this policy: [email protected].
Write to [email protected] — a real person (just the one) reads every message.
Also read the Terms of Service.