Booketjust book it

Privacy Notice

Effective June 26, 2026

Plain-language draft, pending legal review. This notice describes how Booket actually handles data. It is not legal advice and has not yet been reviewed by an attorney. Items in [brackets] are decisions to be finalized with counsel (entity, representative, transfer mechanism) before relying on this document — especially CCPA/CPRA (California), GDPR/UK-GDPR (EU/UK), and CAN-SPAM (email).

1. Who we are & our role

Booket (“we,” “us”) — [Booket legal entity, based in Costa Rica with a U.S. (Texas) pilot; to be set with counsel] — provides an AI-presence service for local businesses. This notice covers personal information of business owners/representatives, agency users, and people who request a free AI Visibility Report.

For your account and business data, Booket is the data controller. For your customers' booking details that pass through Booket to your scheduler, you are the controller and Booket acts as your processor (see §8).

2. Information we collect

  • ·Account & contact — your name, email, and (if provided) phone, used to run your account, sign you in (passwordless magic link or Google), and communicate about billing and reports.
  • ·Business profile — name, address, phone, category, hours, services, pricing, description, photos, and links. You may type these, or we may retrieve them from Google Places and similar public sources to auto-fill your profile (including review counts and ratings).
  • ·Free-report (lead) details — the email and shop details you submit for a free AI Visibility Check, used to generate and send your Report and related follow-ups.
  • ·Usage & attribution — page views and, on your Booket-hosted page or tracked links/numbers, resulting clicks, calls, and bookings — to power your ROI dashboard.
  • ·Customer booking details — for booking-ready shops, the limited customer info needed to pass a booking to your scheduler (see §8).
  • ·Billing — handled by our payment processor (Creem). Booket does not store card numbers; we receive a subscription status and customer ID.
  • ·Essential cookies — see §6.

3. How we use it

  • ·Publish and maintain your machine-readable profile across AI-accessible surfaces (your public page, agent profile, schema.org markup, and related endpoints).
  • ·Run AI visibility checks on your behalf and produce your reports.
  • ·Help you request genuine reviews and keep your data accurate where AI reads it.
  • ·Process your subscription and send account, billing, and transactional notices.
  • ·Send marketing/follow-up emails you can opt out of at any time (§12), and improve and secure the service.

Where GDPR/UK-GDPR applies, our legal bases are performance of a contract (running the service), legitimate interests (improving and securing Booket, measuring results), consent (marketing where required), and legal obligations.

4. The AI Visibility Report

To produce automated Reports we send buyer-style queries about your category and area to third-party web-grounded model providers (currently OpenAI, Google, and Perplexity models, routed through OpenRouter) and record whether your business — and competitors — appear. Separately labeled guarantee verification may be completed in the named consumer-facing assistant. We may display competitor business names returned by those checks. We share only the search queries and your publicly available business details, not your account credentials.

5. Sources of data

We collect data directly from you, automatically from your use of the service (usage/attribution, cookies), and from public sources and integrations you authorize — notably Google Places (profile auto-fill), your connected scheduler, and the AI platforms we query for your Report. Before signup, we also record first-party funnel events, an anonymous browser-session identifier, device class, referring site origin, and campaign parameters so we can understand whether the free check works. We do not use this data for cross-site advertising.

6. Cookies & similar technologies

Booket uses a small number of essentialcookies: a sign-in session cookie (Auth.js), a short-lived “claim” cookie that carries your shop details from a report into setup, an operator impersonation cookie (internal support, audit-logged), and a referral cookie when you arrive via a referral link. We do not use third-party advertising or cross-site tracking cookies.

7. How we share it

We share personal information only with service providers under contract who help us run Booket, and only as needed:

  • ·Hosting/infrastructure — our self-hosted stack and database provider.
  • ·Payments — Creem (Merchant of Record; handles card data and applicable sales tax/VAT).
  • ·Email & SMS — our transactional email provider and, where you enable it, our SMS provider.
  • ·AI & search APIs — the AI platforms we query for your Report and the Places API for profile data.
  • ·Photo storage — object storage for your uploaded or cached business photos, where enabled.
  • ·Scheduling — your connected scheduler (e.g., Square); credentials are stored encrypted and used only to serve availability and bookings.

We do not sell your personal information or business data, and we do not share it for cross-context behavioral advertising. We may disclose information if required by law or to protect rights and safety.

8. Your customers’ booking data

For booking-ready shops, Booket processes the limited customer details needed to pass a booking to your scheduler. Youare the controller of your customers' data and are responsible for your own privacy obligations to them (including any required notices and consents). Booket acts as your processor for that data and uses it only to facilitate the booking.

9. Data retention

We keep your data while your account is active and for a reasonable period afterward in case you reactivate, plus as needed for legal, accounting, and security purposes. After that we delete or anonymize it. You can request deletion at any time (§10).

10. Your rights & choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to opt out of marketing.

California (CCPA/CPRA):you have the right to know, delete, and correct your information, and to opt out of “sale” or “sharing” — Booket does not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights.

EU/UK (GDPR/UK-GDPR): you also have rights to restrict or object to processing and to lodge a complaint with your supervisory authority. Our [EU/UK representative and DPO, if required — to be set with counsel].

To exercise any right, email privacy@booket.ai. We may need to verify your identity first.

11. Security

We use reasonable technical and organizational measures to protect your data, including HTTPS in transit, access controls, and encryption at rest for sensitive credentials (e.g., scheduler tokens). No method of transmission or storage is perfectly secure, but we work to protect your information and respond to incidents.

12. Marketing communications

We send report follow-ups and occasional product updates. Every marketing email has a one-tap unsubscribe, and we honor opt-outs promptly (consistent with CAN-SPAM and similar laws). Transactional messages (billing, bookings, security) continue while you have an account.

13. International transfers

Booket operates from [Costa Rica] with a U.S. pilot and uses providers in multiple countries, so your information may be processed outside your home country. Where required, we rely on appropriate safeguards [e.g., Standard Contractual Clauses — to be confirmed with counsel].

14. Children

Booket is a business tool not directed to children, and we do not knowingly collect personal information from anyone under 18.

15. Changes to this notice

We may update this notice. If we make material changes we'll update the date above and, where appropriate, notify you by email or in your dashboard.

16. Contact

Questions or requests? Email privacy@booket.ai.