Privacy Policy
Last updated: 1 August 2025
1. Who we are
Bookingly Ltd (“we”, “us”, “our”) operates the Bookingly online booking platform at bookingly.co.uk. We are the data controller for personal data collected through our platform. We are registered with the Information Commissioner's Office (ICO) under UK GDPR.
Contact: privacy@bookingly.co.uk
2. Data we collect
2.1 Business owners and staff
- Name, email address, and account credentials (via Clerk)
- Business name, phone number, and address
- Stripe Connect account details for payment processing
- Usage data (page views, feature usage, login times)
2.2 End customers (booking through a Bookingly-powered page)
- Name, email address, and phone number
- Appointment history and notes
- GDPR consent timestamp
- Payment information (processed by Stripe — we do not store card numbers)
3. Legal basis for processing
We process personal data under the following lawful bases:
- Contract performance — to provide the Bookingly service you have signed up for.
- Consent — for end customers who consent to their data being stored by a business using Bookingly.
- Legitimate interests — for fraud prevention, security, and service improvement.
- Legal obligation — to comply with UK law including tax and financial record-keeping.
4. How we use your data
- Providing and improving the Bookingly platform
- Processing and managing bookings
- Sending booking confirmations and reminders
- Processing payments via Stripe
- Communicating service updates and support
- Complying with legal obligations
5. Data sharing
We share data with:
- Stripe — payment processing (Stripe Privacy Policy applies)
- Clerk — authentication (Clerk Privacy Policy applies)
- Neon / Vercel — database and hosting (EU/UK data centres)
- Resend — transactional email delivery
- Businesses using Bookingly — their customers' booking data is shared with them as the relevant data controller
We do not sell personal data to third parties.
6. Data retention
- Business account data: retained for the duration of the subscription plus 6 years for legal/tax purposes.
- End customer booking data: retained for 2 years from the last appointment unless you request earlier deletion.
- Anonymised analytics data: retained indefinitely.
7. Your rights under UK GDPR
You have the right to:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restriction — ask us to stop processing your data temporarily
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — withdraw any consent at any time
To exercise these rights, email privacy@bookingly.co.uk. We will respond within one calendar month.
If you are unhappy with how we handle your data, you may complain to the ICO at ico.org.uk.
8. Cookies
We use strictly necessary cookies for authentication sessions. We do not use advertising or tracking cookies. Analytics cookies (if used) are anonymised and require no consent under UK GDPR guidance.
9. International transfers
Our primary data storage is within the UK/EEA. Where data is transferred outside the UK (e.g. to US-based sub-processors), we ensure adequate safeguards via Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA).
10. Changes to this policy
We may update this policy. We will notify business customers of material changes by email at least 30 days before they take effect.
11. Contact
Bookingly Ltd
Email: privacy@bookingly.co.uk
Website: bookingly.co.uk