At BookingPam, your privacy matters. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data. We are committed to being transparent about our data practices.
1. Who We Are
BookingPam is an appointment booking and business management platform for service businesses. We operate at bookingpam.com and related subdomains. For privacy inquiries, contact us at info@bookingpam.com.
BookingPam acts as a data controller for information about our Vendors and their accounts, and as a data processor for client data that Vendors collect through their booking pages.
2. Information We Collect
2.1 Information You Provide
When you create a BookingPam account or use our Services, we collect:
- Account Information: Name, email address, phone number, business name, industry, and password.
- Business Information: Business address, website, logo, brand colors, service descriptions, pricing, and staff details.
- Payment Information: Billing details processed securely through Stripe. We do not store your full card number — Stripe handles all payment data.
- Communications: Emails or messages you send to our support team.
- Reviews: Reviews you submit about BookingPam or about Vendor businesses.
2.2 Information Collected Automatically
When you use BookingPam, we automatically collect:
- Usage Data: Pages visited, features used, time spent on the platform, and actions taken.
- Device Information: IP address, browser type, operating system, and device type.
- Log Data: Server logs including request timestamps, error logs, and access records.
- Cookies: As described in our Cookie Policy.
2.3 Client Data (Collected by Vendors)
When clients book appointments through a Vendor's booking page, the following data is collected on behalf of the Vendor:
- Client name, email address, and phone number.
- Booking history, appointment details, and service preferences.
- Intake form responses (if the Vendor uses intake forms).
- Payment records for services booked.
- Reviews and ratings submitted by clients.
This data belongs to the Vendor. BookingPam processes it as a data processor on the Vendor's behalf and does not use it for our own marketing purposes.
2.4 Affiliate Data
If you participate in our affiliate program, we collect your name, email address, payment details for commission payouts, referral codes, and conversion data.
3. How We Use Your Information
We use the information we collect to:
- Provide the Services: Create and manage your account, process bookings, send notifications, and enable payments.
- Send Communications: Booking confirmations, reminders, subscription notifications, and support responses.
- Process Payments: Handle subscription billing and coordinate payment processing through Stripe.
- Improve the Platform: Analyze usage patterns to fix bugs, optimize performance, and develop new features.
- Security & Fraud Prevention: Monitor for suspicious activity, enforce rate limits, and protect against unauthorized access.
- Legal Compliance: Meet our legal obligations and respond to lawful requests from authorities.
- Affiliate Tracking: Attribute referrals and calculate commissions for our affiliate program.
- Marketing: With your consent, send promotional emails about new features, tips, and offers. You can unsubscribe at any time.
4. How We Share Your Information
We do not sell your personal data. We share information only in the following circumstances:
4.1 Service Providers
- Stripe — Payment processing and subscription management.
- Resend — Email delivery for notifications, reminders, and system emails.
- Cloudflare — CDN, DDoS protection, and DNS management.
- Google — Calendar sync (when you connect Google Calendar) and font delivery.
- Mailchimp — Email marketing integration (when you connect your Mailchimp account).
4.2 Vendors and Clients
When a client books through a Vendor's booking page, the Vendor receives the client's booking details. Vendors agree to our Terms of Service which restrict how they may use client data.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of BookingPam, our users, or others.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Services. Specifically:
- Active accounts: Data is retained for the lifetime of your account.
- Cancelled accounts: Data is retained for 90 days after cancellation, then permanently deleted.
- Booking records: Retained for 3 years for legal and accounting purposes.
- Payment records: Retained for 7 years as required by financial regulations.
- Audit logs: Retained for 2 years.
- Support communications: Retained for 2 years.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: All data transmitted between your browser and our servers is encrypted via HTTPS/TLS.
- Password Security: Passwords are hashed using bcrypt with a minimum of 10 rounds — we never store plain text passwords.
- Authentication: Two-factor authentication (2FA) is required for all vendor and affiliate logins.
- Rate Limiting: Login endpoints are protected against brute force attacks.
- Security Headers: HTTP security headers including X-Frame-Options, X-Content-Type-Options, and HSTS are enforced.
- Access Control: Staff accounts have role-based access — staff members only see what they need.
- Audit Logs: All sensitive actions are logged for Business plan accounts.
While we take these precautions, no security system is 100% secure. We cannot guarantee absolute security of your data. You are responsible for keeping your account credentials confidential.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data ("right to be forgotten").
- Portability: Request your data in a machine-readable format.
- Objection: Object to our processing of your data for marketing purposes.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at info@bookingpam.com. We will respond within 30 days.
8. Children's Privacy
BookingPam is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately and we will delete it.
9. International Data Transfers
BookingPam is based in the United States. If you are accessing our Services from outside the United States, your data may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using BookingPam, you consent to this transfer.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect, use, disclose, and sell.
- The right to delete personal information we have collected from you.
- The right to opt out of the sale of personal information. BookingPam does not sell personal information.
- The right to non-discrimination for exercising your CCPA rights.
11. GDPR (European Users)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:
- Contract Performance: Processing necessary to provide the Services you have subscribed to.
- Legitimate Interests: Security, fraud prevention, and platform improvement.
- Legal Obligation: Compliance with applicable laws.
- Consent: Marketing communications and optional analytics cookies.
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your data protection rights.
12. Cookies
We use cookies to operate the platform, remember your preferences, and understand how you use BookingPam. For full details, including how to manage your cookie preferences, please see our Cookie Policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on our website. The "Last Updated" date at the top of this page reflects when changes were most recently made. We encourage you to review this policy periodically.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: info@bookingpam.com
- Website: bookingpam.com
© 2026 BookingPam. All rights reserved. · Terms of Service · Cookie Policy · Affiliate Terms