Privacy Notice
Last updated: 5 September 2026
Who we are
Book Time With is operated by Ryan Johnson trading as Book Time With, based in the United Kingdom. We are the data controller for personal data collected through booktimewith.com (the owner application) and booktimewith.link (the public booking pages).
Contact: [email protected]
What data we collect
Owner account data
When you sign up as an owner, we collect and process:
- Email address (used for passwordless sign-in, billing, and notifications)
- Display name and booking handle (public on your booking page)
- Service name, duration, and location settings
- Weekly availability and time-off periods
- Timezone preference
- Notification preferences
- Billing currency preference
Client booking data
When someone books through your page, we collect:
- Client name and email address
- Preferred timezone
- Address (for in-person appointments, if required by the service)
- Booking date, time, and service selected
- Booking status and history (confirmed, moved, cancelled)
Calendar connection data
If you connect Google Calendar or Microsoft Outlook:
- OAuth access and refresh tokens (encrypted at rest with a dedicated key)
- Calendar free/busy information (used to block unavailable slots)
- Calendar event IDs (to sync booking events)
Billing data
For paid subscriptions, we store references to your Stripe account:
- Stripe customer ID
- Stripe subscription ID and status
Payment card details are held directly by Stripe; we do not store card numbers.
Technical and security data
- IP address and request metadata (for rate limiting and abuse prevention)
- Cloudflare Turnstile challenge tokens (to prevent automated abuse on booking forms)
- Email delivery status and logs (stored temporarily)
- Session tokens (signed, stateless cookies for owner authentication)
- Email verification tokens (single-use links to confirm owner email addresses)
How we use your data
We process personal data for these purposes:
To provide the booking service (contract)
- Creating and managing owner accounts
- Verifying owner email addresses — we send a verification link when you publish your booking page and when you change your email address; your public booking page does not accept client bookings until your email is verified (you can resend the verification link from Settings)
- Publishing booking pages and handling appointments
- Sending confirmation emails, reminders, and schedule change notifications
- Syncing with connected calendars
- Processing subscription payments through Stripe
To protect against abuse (legitimate interests)
- Rate limiting booking and sign-in requests
- Detecting and preventing fraudulent bookings
- Maintaining security logs
To communicate essential service information (legitimate interests)
- Trial expiry notices and billing reminders
- Service updates affecting your account
We do not send marketing emails. The only scheduled messages are booking notifications, morning summaries (opt-in), and billing notices.
Lawful basis
We rely on the following lawful bases under UK GDPR:
- Contract: Processing necessary to provide the booking service you signed up for.
- Legitimate interests: Abuse prevention, security logging, and essential service communications. We have assessed that these interests do not override your rights.
Data retention
Owner account data
Your account data is retained while your subscription is active. If you cancel, your account settings and booking history are retained for 90 days after your paid access ends, allowing you to reactivate if you change your mind. After this period, your account is permanently deleted.
Client booking data
Client personal data (name, email, address, timezone, and manage tokens) is retained for 730 days (two years) after each appointment ends. After this period, client-identifying information is automatically removed while anonymous booking history (service, date, time, status) is retained for the owner's business records.
Technical logs
Rate-limit counters expire within days. Email delivery logs are retained only as long as needed for troubleshooting and are removed with the related booking data.
Backups
Database backups follow the same retention schedule. Deleted data may persist in backups for up to 30 days beyond the stated retention periods.
Who we share data with
We use the following service providers (sub-processors) to operate Book Time With:
Stripe
Processes subscription payments. Receives owner email and payment information. Stripe is a US company with EU/UK standard contractual clauses in place. Stripe Privacy Policy
Cloudflare
Provides CDN, email sending infrastructure, and Turnstile bot protection. Receives request metadata and email content for delivery. Cloudflare Privacy Policy
Google (when calendar connected)
Syncs booking events to Google Calendar and reads free/busy information. Receives appointment details for connected owners only. Google Privacy Policy
Microsoft (when calendar connected)
Syncs booking events to Outlook Calendar and reads free/busy information. Receives appointment details for connected owners only. Microsoft Privacy Statement
Hosting provider
The application and database are hosted on infrastructure in the EU/UK. The hosting provider has access to server logs and database backups as part of infrastructure management.
We do not sell personal data or share it with advertisers.
International transfers
Some of our sub-processors (Stripe, Google, Microsoft, Cloudflare) are US-based companies. For transfers of personal data outside the UK, we rely on:
- UK adequacy decisions where applicable
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office
Cookies and local storage
Book Time With uses only essential cookies required for the service to function:
- Session cookie (booktimewith.com only): A signed token that keeps you signed in as an owner. Contains no personal data beyond a session identifier.
- Turnstile cookies (booktimewith.link): Cloudflare Turnstile may set cookies when presenting a challenge to verify a booking request is not automated.
We do not use analytics cookies, advertising trackers, or third-party marketing cookies.
Your rights
Under UK data protection law, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Ask us to delete your data where there is no compelling reason to keep it.
- Restriction: Ask us to restrict processing in certain circumstances.
- Portability: Request your data in a structured, machine-readable format. Owners can export bookings as CSV from the app.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, email [email protected].
Data controller and processor roles
For owner accounts: Book Time With is the data controller.
For client booking data: The owner (service provider) is typically the data controller for their clients' booking information, determining why and how client data is used for their business. Book Time With acts as a data processor, processing client data on the owner's behalf to deliver the booking service.
Owners requiring a formal Data Processing Agreement should contact [email protected].
Children
Book Time With is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us to have it removed.
Complaints
If you are unhappy with how we handle your data, please contact us first at [email protected].
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
ico.org.uk/make-a-complaint
Helpline: 0303 123 1113
Changes to this notice
We may update this Privacy Notice from time to time. Material changes will be communicated to account holders by email. The "last updated" date at the top indicates when this notice was last revised.
