Bookmefy

Privacy Policy

Last updated: 19 August 2026

This Privacy Policy explains how Bookmefy (“we”, “us”) collects, uses, stores and shares personal data when you use bookmefy.de, a tenant booking website, the admin panel, or related services.

Bookmefy is online booking software for salons, studios and similar businesses. Businesses (“admins”) run their booking page and calendar in Bookmefy. Their customers (“clients”) book appointments on that page.

1. Who is responsible

The controller for the Bookmefy platform is the operator of bookmefy.de. For appointment data that a business collects from its own clients, that business is typically also a controller. We process such data to provide the booking service to that business.

Questions: bookmefy@gmail.com

2. Data we collect

  • Admin / business account: name, email, password or Google sign-in identifiers, preferred language, company name, booking page address (slug), branding (logo, colours, texts), services, working hours, and subscription status.
  • Clients: name, email, and appointment details (service, date, time, status). Sign-in may use email/password or Google.
  • Bookings and calendar: appointment records, reschedules, cancellations, and related notifications.
  • Technical data: IP address, device/browser type, language, security logs, and cookies needed to run the site.
  • AI assistant: messages you send in the booking-page or admin chat, used to answer questions and help with bookings according to the same rules as the booking form.

3. Google account and Google Calendar

Bookmefy uses Google OAuth in two ways, only after you choose to connect Google.

Google Sign-In: if you sign in or register with Google, we receive your Google account email, name and unique user id (scopes: openid, email, profile) to create or recognise your Bookmefy account. We do not get your Google password.

Google Calendar sync: if an administrator connects Google Calendar in Admin → Integrations, we request access to Google Calendar (scope https://www.googleapis.com/auth/calendar). We use this access only to create, update and delete calendar events that correspond to Bookmefy appointments in the connected calendar.

We store OAuth access and refresh tokens, the connected Google account email, and basic connection metadata, solely to keep calendar sync working. Tokens are stored encrypted. We do not use Google Calendar data for advertising, profiling, or resale. We do not share Google user data with third parties except as needed to operate the service (for example hosting) or if required by law.

You can disconnect Google Calendar at any time in Admin → Integrations. We then stop syncing and delete the stored Google tokens for that connection. You can also revoke access in your Google Account (https://myaccount.google.com/permissions).

Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Why we process data

  • Provide the booking website, admin calendar, notifications and AI assistant.
  • Authenticate users (including Google Sign-In) and keep the service secure.
  • Sync appointments to Google Calendar or Microsoft Outlook when an admin connects those integrations.
  • Process subscriptions via Stripe (we do not store full card numbers).
  • Measure site usage with Google Analytics only after you accept analytics cookies.
  • Comply with legal obligations and protect against abuse.

5. Payments (Stripe)

Paid subscriptions are billed by Stripe. Card details are entered on Stripe’s pages and handled by Stripe. Bookmefy receives subscription status and related billing identifiers, not your full card number.

6. Cookies

We use essential cookies for login sessions, security (CSRF), language and cookie-consent choice. These are required for the site to work.

Analytics cookies (Google Analytics) are used only if you click OK on the cookie notice. You can decline; the product will still work.

7. Sharing

We share data with processors who help us run Bookmefy, including hosting, email delivery, Stripe (payments), Google (sign-in, Calendar API, optional Analytics), and Microsoft (Outlook calendar, if connected). We do not sell personal data.

8. Retention

Account and booking data are kept while the business account is active and as needed for the service, notifications and legal accounting. Google tokens are kept only while the calendar integration is connected. You may ask us to delete data as described below.

9. Your rights

Depending on your location (including the EU/EEA and UK), you may request access, correction, deletion, restriction, portability, or object to certain processing. You may also lodge a complaint with your local data protection authority.

Admins can update business and booking data in the admin panel. Clients can use account and booking tools on the booking page, or contact the business or us.

10. Security

We use HTTPS, access controls, encrypted storage of calendar OAuth tokens, and session security. No method of transmission or storage is 100% secure.

11. Children

Bookmefy is intended for businesses and adult clients. We do not knowingly collect data from children for the purpose of offering the service to them.

12. Changes

We may update this policy. The “Last updated” date above will change. Continued use of Bookmefy after an update means you accept the revised policy.

13. Contact

For privacy requests, including Google data and calendar disconnect questions, email bookmefy@gmail.com or write to us via bookmefy.de.