BookFlow AI
Features Pricing Blog Contact Sign In Get Started
Privacy Policy

Privacy Policy

Last updated: June 6, 2026

1. Data We Collect

BookFlow collects information you provide directly, including:

  • Account information: name, email address, phone number, business name, industry, and timezone
  • Booking data: client name, email, phone number, service booked, date and time of appointment, and any notes provided
  • Payment information: billing name, address, and Stripe transaction references — BookFlow does not store raw credit card numbers
  • Usage data: IP address, browser type, and interaction logs for service improvement purposes

2. How We Use Your Data

We use collected data to:

  • Provide, maintain, and improve the BookFlow platform
  • Process bookings and send confirmation and reminder emails to clients
  • Notify business owners of new bookings
  • Bill subscription fees and manage Stripe subscriptions
  • Respond to support requests and enforce our Terms of Service

3. Data Sharing

BookFlow does not sell, rent, or trade your personal data to third parties. We share data only in these limited circumstances:

  • Stripe: for payment processing — Stripe's Privacy Policy applies to all payment data
  • Email delivery: our email service provider (Polsia) processes client email addresses to send booking confirmations and reminders only
  • Legal compliance: when required by law, court order, or to protect the rights, safety, or property of BookFlow

4. Cookies

BookFlow uses session cookies for authentication in the owner dashboard. These cookies are essential to keeping your account secure and are not used for advertising or cross-site tracking. You may disable cookies in your browser settings, but some features of the dashboard may not function correctly without them.

5. Data Retention

We retain account data for as long as your account is active. Booking records are retained for a minimum of 3 years for legal and accounting purposes. If you cancel your subscription, we retain your data for 90 days after cancellation for record-keeping, after which it is deleted or anonymized.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate or outdated data
  • Request deletion of your account and associated personal data (subject to legal retention requirements)
  • Opt out of promotional emails at any time via the unsubscribe link in each email

To exercise any of these rights, contact us at support@bookflow.ai. We will respond within 30 days.

7. CCPA / GDPR Notice

California (CCPA): California residents have the right to request disclosure of personal information collected, shared, or sold. BookFlow does not sell personal information. To submit a rights request, email support@bookflow.ai.

European Union (GDPR): Users in the EU have the right to access, rectify, restrict processing, port, and delete their personal data. Our legal basis for processing is contract fulfillment and legitimate interest. Data is processed in the United States; by using BookFlow, you consent to cross-border data transfer.

8. Security

BookFlow uses industry-standard encryption (TLS/SSL) for all data in transit. Passwords are hashed using bcrypt. Stripe handles all payment card data in compliance with PCI-DSS Level 1. Access to internal systems is restricted to authorized personnel only. No security measure is 100% impenetrable, and we cannot guarantee absolute security, but we are committed to maintaining appropriate technical and organizational safeguards.

9. Contact

For questions about this Privacy Policy or to submit a data rights request, contact us at support@bookflow.ai.

BookFlow AI
  • Features
  • Pricing
  • Blog
  • Contact
  • Sign In
  • Terms
  • Privacy
© 2026 BookFlow AI