Privacy Policy
Last updated: July 4, 2026
1. Overview
BookLocally is a scheduling platform used by two kinds of people: local service businesses (“Businesses”) that create an account and publish a booking page, and their customers (“Customers”) who book appointments through those pages. This policy explains what we collect from each, how it’s used, and the choices you have.
The short version: we collect only what’s needed to run bookings, we send only transactional email (confirmations, reminders, and the like), we use no advertising or third-party analytics trackers, and we never sell personal information.
2. Information we collect
From Businesses: your email address (used to sign in via magic link or Google), your name, business name, phone, business description, services, prices, availability, and — if you subscribe to Pro — billing details handled by Stripe (we never see or store full card numbers).
From Customers making a booking:the details you enter in the booking form — your name, email, phone, the service and time you chose, and, where the Business has enabled them, your service address, zip code, access notes (such as gate codes or pet instructions), and answers to the Business’s booking questions. If you join a waitlist or ask to be notified when your area is served, we store the email you provide for that purpose.
Automatically:standard technical data such as IP addresses (used for rate limiting and abuse prevention) and, when you submit site feedback, your browser’s user-agent string. We do not run third-party analytics, advertising pixels, or cross-site trackers.
3. Cookies and local storage
- Session cookie — keeps Businesses signed in to their dashboard. Essential; set only when you sign in.
- Referral cookie (“bl_ref”)— if you arrive via a partner’s invite link, a cookie remembers that code for 30 days so the referral can be credited if you sign up. It contains only the invite code.
- Local storage — booking pages remember the contact details you typed in your own browser so repeat bookings are faster. This never leaves your device except when you submit a booking; you can clear it in your browser at any time.
4. How we use information
- to operate bookings: showing availability, creating appointments, and letting Customers manage them via secure links;
- to send transactional email through our email provider: booking confirmations, reminders, reschedule and cancellation notices, waitlist openings, and — for Businesses — new-booking alerts and optional daily/weekly summaries;
- to bill Pro subscriptions through Stripe;
- to prevent abuse (rate limiting) and to fix problems;
- to credit partner referrals.
We do not sell personal information, and we don’t use Customer contact details for marketing.
5. Who can see your information
The Business you book withsees everything you submit in its booking form — that’s the point of the form. Each Business is responsible for how it handles its own customers’ information; our Terms of Service require Businesses to use it only for delivering the booked services.
Service providers we rely on to run BookLocally: Resend (sends our email), Stripe (payment processing for Pro subscriptions), Google (only if you choose to sign in with Google), and Cloudflare (DNS and traffic protection). Each receives only what it needs for its function.
Referral partnerswho refer a Business can see that Business’s name, signup date, and plan — never Customer data or booking details.
We may also disclose information if required by law or to protect the safety and rights of our users.
6. Data retention
Business account data and appointment history are kept while the account is active. Anonymous out-of-area interest data (zip codes with no contact info) is deleted after 180 days. Waitlist entries expire after their requested date passes. We keep short-lived encrypted backups of our database for disaster recovery.
7. Your choices and rights
Customers:to correct or delete information you submitted with a booking, the fastest route is the Business you booked with, or the manage link in your confirmation email. You can also contact us directly and we’ll help.
Businesses: you can edit your information in your dashboard, or contact us to delete your account and its data.
For any access, correction, or deletion request, email [email protected]. We respond to all requests, including those made under applicable privacy laws.
8. Security
All traffic is encrypted in transit (HTTPS). Customer-facing manage links use unguessable tokens. Access to production data is limited to the operator of the service. No system is perfectly secure, but we keep the amount of data we hold small and use it narrowly.
9. Children
BookLocally is not directed at children under 13, and we don’t knowingly collect their information. If you believe a child has submitted personal information, contact us and we’ll delete it.
10. Changes to this policy
If we make material changes we’ll update the date above and, for significant changes affecting Businesses, notify account holders by email.
11. Contact
Privacy questions or requests: [email protected].