Privacy Policy
Effective date: July 29, 2026 · Last updated: August 15, 2026
JustBook is booking software for businesses that run on appointments. We take a simple position on privacy: we sell software, not data. We run no advertising trackers and no data brokering — and your clients are yours, not ours. All measurement is built and hosted by us, never a third party: opt-in visit statistics a Business can enable on its own booking page, which never run without the visitor’s consent, and a cookieless visit count on JustBook’s own pages that stores nothing in your browser (see Section 10).
This policy explains what personal data we handle, why, and the rights you have. It uses the same defined terms as our Terms of Service: the “Business” is the business using JustBook — a salon, clinic, studio, gym, or anything else that books people in by appointment — the “Subscriber” is its account owner, “Staff” are its team members, and “Clients” are the Business’s customers.
1. The two hats we wear (controller vs. processor)
This distinction shapes everything below:
- For Business account data, JustBook is the data controller. When a Subscriber signs up, invites Staff, or contacts us, we decide how that data is handled, and this policy applies directly.
- For Client data, JustBook is a data processor and the Business is the controller. When a Client books with a Business through JustBook, their data belongs to that Business’s relationship with them. We store and process it only to run the Service on the Business’s behalf and on its instructions. We don’t use Client data for our own marketing, we don’t sell it, and we don’t combine it across Businesses.
If you’re a Client with a question about your data — a booking, your contact details, a message you received — the Business you booked with is the right first stop. The easiest way to reach them is the “Your data” link in the footer of their booking page: it records your request, passes it to that Business with the date they need to reply by, and emails you a copy. We’ll help them fulfill it, and if you contact us some other way we’ll route your request to them where the law requires it.
2. What we collect
From Subscribers and Staff (we act as controller)
- Account data: name, email address, phone number, password (stored only as a bcrypt hash — we never see or store your actual password), role and permissions, branch assignments.
- Business data: business name, address(es), contact details, website, logo and branding, service menu, working hours, tax and currency settings.
- Profile data: optional profile photo, title, bio; working hours and time-off entries (including any free-text reason your team enters).
- Billing data: your subscription plan and billing history. Card details go directly to Stripe on Stripe-hosted pages — JustBook never sees or stores card numbers.
- Files: documents attached to records in your account (for example staff or client attachments, invoice PDFs).
- Signup-in-progress data: if you start signing up but don’t finish, we keep the draft (business details, your name/email/phone, a hashed password) so you can resume; abandoned drafts are flagged after about 72 hours and the reserved web address is released.
- Security and audit data: login events (including failed attempts), IP address, browser user-agent, and an audit trail of significant account actions.
About Clients (we act as processor for the Business)
- Contact and booking data: name, email, phone number, appointments, special requests, notes the Business keeps, tags, marketing opt-in status, and communication preferences.
- Verification data: one-time codes (OTPs) sent to a Client’s phone or email to verify identity for the client portal; these expire after 10 minutes.
- Transaction records: deposits, payments, refunds, invoices, tips, loyalty points, and package purchases — including Stripe payment references. As with Subscribers, card details go only to Stripe, never through JustBook.
- Message history: a log of the booking-related messages sent to a Client (channel, recipient, delivery status), and the content of reminder/alert messages where the product stores it.
- Files: attachments a Business stores on a Client’s record (for example consent forms).
From website visitors
- Marketing site (justbookapp.com), our docs site, and our signup page: our contact form collects your name, email, and message; it’s emailed to us and not stored in a database. If you join a waiting list, we store the email address and any business name you give us, along with the campaign tag on the link you arrived through. We also count page visits using our own cookieless measurement — it stores nothing in your browser and never keeps your IP address, only a one-way hash of it under a secret that changes daily. No third-party analytics service is involved. See the Cookie Policy for exactly what is recorded.
- Public booking pages: browsing a Business’s booking page requires no account. Data is collected when you enter it to book — and, only if you accept the Business’s statistics banner, the Business’s opt-in visit statistics record the pages and booking steps you view, when, the referring site, and your device type, under a random ID. If you sign in or book, those visits may be linked to your client record with that Business. The Business is the controller of these statistics and JustBook the processor (Section 1); you can withdraw via the “Cookie preferences” link on the booking page at any time. Booking pages load fonts from Google Fonts (see Section 5).
- All properties: our infrastructure providers log IP addresses in the ordinary course of serving traffic and preventing abuse (rate limiting).
What we deliberately don’t collect
No advertising identifiers, no cross-site tracking, no biometric data, and no precise location. Visit statistics exist only on Businesses’ booking pages, only with your opt-in, and never follow you across Businesses or across sites. We don’t collect Client street addresses (a Business is visited in person; the address that matters is the Business’s).
3. Why we use it (and our lawful bases)
| Purpose | Examples | Lawful basis (GDPR) |
|---|---|---|
| Running the Service | accounts, bookings, calendars, reminders, invoices, the client portal | Contract (Subscribers); processing on the Business’s instructions (Clients) |
| Payments & billing | subscription charges, connecting Stripe accounts, payment records | Contract; legal obligation (financial records) |
| Communications you asked for | booking confirmations, reminders, OTP codes, password resets, trial notices | Contract / legitimate interests |
| Business marketing to its Clients | win-back campaigns, promotional messages | Consent, gathered and owned by the Business (opt-in with easy opt-out) |
| Booking-page visit statistics | pageview and booking-step counts, “looked but didn’t book” | Consent, gathered per Business on its booking page (opt-in, withdrawable at any time) |
| Security & abuse prevention | login throttling, rate limiting, audit logs, fraud prevention | Legitimate interests |
| Support & troubleshooting | answering your requests, error monitoring | Legitimate interests |
| Legal compliance | tax, accounting, responding to lawful requests | Legal obligation |
We do not use personal data for advertising, we do not sell or “share” (as the CCPA defines it) personal data, and we do not use it to train AI models.
4. Sub-processors and service providers
These are the third parties that actually touch data in running JustBook, and what each handles:
| Provider | What it does | Data it touches |
|---|---|---|
| Stripe | Subscription billing; payment processing for Businesses (Stripe Connect) | Billing details, card data (entered on Stripe’s own pages), Client email for payment receipts, transaction amounts and references |
| Render | Application hosting and our PostgreSQL database (US — Oregon) | All Service data |
| Cloudflare | Hosting for our websites and app frontend (Cloudflare Workers); network edge in front of our application hosting; DNS | IP addresses, request metadata in transit |
| Amazon Web Services (S3 + CloudFront) | File storage and delivery (images, invoice PDFs, attachments); encrypted database backups | Uploaded files (public images via CDN; private documents served only through authenticated requests); backup copies of the database |
| Twilio | SMS and WhatsApp delivery | Recipient phone numbers and message content (confirmations, reminders, OTP codes) |
| Zoho ZeptoMail | Transactional email delivery | Recipient email addresses and message content (confirmations, receipts, invoices, sign-in codes) |
| Sentry | Error monitoring so we can fix crashes | Technical error context (request path, tenant/user identifiers); configured not to collect message bodies or personal profiles |
| GitHub | Code hosting; runs our automated daily database backup job | Backup job transiently handles database contents in an encrypted pipeline |
| Google Fonts | Font delivery on Businesses’ booking pages | Visitor IP address and browser metadata (a standard web font request; Google sets no cookies for this) |
Businesses on eligible plans can also plug in their own email or SMS providers (“bring your own sender”). Those providers are chosen by and contracted to the Business, not JustBook — the Business is responsible for them. We store the credentials the Business provides, encrypted.
We’ll keep this list current as providers change.
5. International data transfers
JustBook is operated from the United States, and data is stored on servers in the United States (Oregon). If you use JustBook from outside the US — including Businesses in the UAE and visitors from the EU/UK — your data is transferred to and processed in the US.
By using the Service, you understand that your data is stored and processed in the United States. Our infrastructure and messaging providers operate their own safeguards for the data they handle on our behalf.
If you’re an EU or UK business and need formal transfer safeguards — a data processing agreement with Standard Contractual Clauses — contact us at privacy@justbookapp.com before signing up, and we’ll tell you where we stand.
6. Security
Security measures actually in place — not aspirations:
- Encryption in transit: all traffic is served over TLS (HTTPS), with HTTP Strict Transport Security enforced.
- Passwords are hashed with bcrypt. Third-party credentials Businesses store with us (e.g., their own SMTP or messaging credentials) are encrypted at rest.
- Authentication: short-lived signed session tokens (24-hour expiry) with server-side revocation; verification codes expire in 10 minutes; strict rate limits on login, verification, and booking endpoints; two-factor authentication available for a Business’s admins (a Business can make it mandatory for its team) and mandatory for JustBook’s own platform administrators.
- Tenant isolation: every Business’s data is scoped to that Business at the query layer, with automated tests that audit every API route for access guards on every build.
- Least-visibility support access: when our support staff access a Business’s account to help, the session is time-limited (1 hour), flagged in-product, and every action is written to that Business’s own audit log.
- Payment isolation: card data never touches our servers — payments happen on Stripe’s hosted, PCI-compliant pages, and webhook messages from our providers are cryptographically verified.
- Backups: the database is backed up daily to separate, access-restricted encrypted storage, where copies expire automatically after 30 days. Our hosting provider additionally keeps a rolling 3-day point-in-time recovery window. Restores are tested.
No system is perfectly secure, but if we learn of a breach affecting your personal data, we’ll notify affected parties and authorities as the law requires. Security reports: security@justbookapp.com.
7. Retention
- Active accounts: we keep Business and Client data for as long as the Business’s account exists — appointment history is a core feature of the product.
- After cancellation: nothing is deleted when you cancel. Your booking page goes offline, but your records are kept so you can reactivate or export them, and 60 days later the account is closed (you lose access; the data is still there).
- After closure: we keep a closed account’s data for 6 months, then delete it permanently. We email the account owner 30 days before that happens, so there is always time to reactivate or ask us for a copy. Reactivating at any point cancels the deletion entirely. This applies to every closed account on the same terms, whether or not it was ever a paying subscription.
- Deletion on request: a Subscriber can ask us to permanently delete the Business’s account at any time. We complete verified deletion requests within 30 days, removing the Business’s records, Clients, files, and history from live systems. Encrypted backup copies age out within a further 30 days.
- Specific shorter windows: verification codes expire after 10 minutes; sign-in sessions after 24 hours; abandoned signup drafts are flagged after ~72 hours of inactivity; security/audit logs are kept for 180 days; error reports are retained per our monitoring provider’s rolling window.
- Business-level tools: a Business can delete individual Client records (where no appointment history exists, records are removed entirely, including files) and can export its data at any time.
8. Your rights
Everyone
You can ask us what we hold about you, ask for corrections, ask for deletion, and object to processing — subject to legal limits. The quickest way is our contact form — choose “Privacy / my data”. It gives you a reference straight away and starts the clock on our side. If you’d rather email, or the form isn’t working for you, write to privacy@justbookapp.com — a request sent that way counts exactly the same. We’ll verify your identity before acting, respond within the timeframe the law requires, and never discriminate against you for exercising your rights.
If you’re a Client, remember Section 1: for data a Business controls, the Business is legally responsible for honoring your request, and we give Businesses the tools to do it (record correction, deletion, and per-client data export). The fastest route is the “Your data” link in the footer of that Business’s booking page — it reaches them directly, with the date they need to reply by. We’ll forward misdirected requests to the right Business.
California (CCPA/CPRA)
California residents have the rights to know, access, correct, delete, and port their personal information, and to opt out of “sale” or “sharing.” JustBook does not sell or share personal information as those terms are defined by the CCPA, and we do not use sensitive personal information beyond what’s necessary to provide the Service. We honor requests as described above; you may also use an authorized agent.
EEA / UK (GDPR)
You additionally have the rights to restriction of processing and data portability, the right to withdraw consent where processing is based on consent, and the right to lodge a complaint with your supervisory authority. Where we act as processor, we support the Business (the controller) in honoring these rights.
UAE and elsewhere
We extend the same core rights — access, correction, deletion — to everyone, wherever you are.
9. Children
JustBook is a business tool, and Subscriber/Staff accounts require users to be 18+. Businesses may serve Clients of different ages under their own policies and local law; we don’t knowingly collect data directly from children under 13, and we’ll delete it if we learn we have.
10. Cookies and tracking
Short version: no advertising trackers, no third-party analytics, no cross-site tracking — ever. Sign-in state lives in your browser’s local storage, first-party only. Two kinds of measurement exist, both ours and neither shared with anyone: a Business’s opt-in visit statistics on its own booking page, which run only after you accept that Business’s consent banner, are processed by JustBook on that Business’s behalf, and can be withdrawn in one tap; and, on JustBook’s own pages, a cookieless visit count that stores nothing in your browser and keeps no IP address — which is why it needs no banner. The full detail, including exactly what’s stored in your browser, is in our Cookie Policy.
11. Changes to this policy
We’ll update this policy as the product and law evolve. Material changes get advance notice to Subscribers (email or in-app). The current version always lives at justbookapp.com/privacy.
12. Contact
Privacy questions and data requests: use the contact form and choose “Privacy / my data” — you get a reference immediately. Or email privacy@justbookapp.com. Security reports: security@justbookapp.com — please email these rather than using the form, so you can attach details and keep the thread. Everything else: use the contact form, or email support@justbookapp.com.
JustBookApp LLC, a Georgia limited liability company