Legal

Privacy Policy

This policy explains how Bookable handles personal data. It covers the data we control (your account and our website visitors) and, at a high level, the data we process on behalf of the businesses that use Bookable.

Version 1.0Effective July 1, 2026Updated July 1, 2026

1. Who we are & scope

This Privacy Policy describes how Worldview Industries LLC, doing business as Bookable (Bookable, we, us) handles personal data across our marketing site, the Bookable application, and the website-builder infrastructure. Contact us about privacy at contact@bookable.co.

2. Our two roles: controller and processor

When you use Bookable to run your business, youare the controller of your customers’ data and Bookable is your processor — that processing is governed by our Data Processing Addendum. This Privacy Policy explains how Bookable handles personal data as a controller: your account and staff data, and data of visitors to our own site.

If you are a customer of a business that uses Bookable(for example, you booked an appointment or filled out a form on that business’s website), that business — not Bookable — is responsible for its own data practices. Please contact the business directly; our DPAdescribes how we process such data on the business’s behalf.

3. Personal data we collect (as controller)

We collect the following categories about our account holders, staff, and site visitors:

CategoryExamplesSourcePurpose
Account identifiersname, email, phoneyouprovide the Service, authenticate, communicate
Credentialspassword (stored hashed), MFA secret (stored encrypted)youauthentication & security
Business & billingbusiness name, legal name, tax/EIN (for messaging registration), Stripe customer id, card brand & last 4 digits (no card number)you / Stripebilling, tax, carrier registration
Device & log dataIP address, user agent, session and audit recordsautomaticsecurity, fraud prevention, audit
Usage & analyticspage views and product eventsautomatic (consent-aware)understand and improve the Service
Support communicationsmessages you send usyouprovide support

We do not collect card or CVC numbers (Stripe handles those), Social Security or national-identity numbers, or special categories of data such as health or biometric data.

4. Data we process on your behalf (as processor)

When you use Bookable, we process personal data about your End Users on your instructions — for example, your CRM contacts, leads captured through your website, booking details, form submissions, and the content of messages you send. We act as your processor for this data under the DPA. If you are an End User, contact the relevant business to exercise your rights; we will assist that business as required.

5. How we use personal data

  • To provide, operate, secure, and improve the Service.
  • To process billing and prevent fraud and abuse.
  • To provide customer support.
  • To send transactional messages (such as verification, security, and billing notices).
  • For our own product analytics and to communicate with account holders about the Service.
  • To comply with legal obligations and enforce our agreements.

6. Cookies & tracking

Our site uses first-party analytics (Google Analytics 4) with Consent Mode; basic first-party analytics is on by default, and advertising signals remain off until you opt in. Websites we host for our customers run each business’s own analytics, for which that business is the controller. For the full detail — including the cookies set and how to control them — see our Cookie Policy.

7. Sale, sharing & targeted advertising

We do notsell personal data for money. We use analytics and, on our own site, consent-gated Google advertising signals; under some state laws, use of such signals for cross-context behavioral advertising may be considered “sharing.” You can opt out using the “Do Not Sell or Share My Personal Information” control in our site footer and in the cookie preferences, and we honor the Global Privacy Control (GPC) browser signal as an opt-out. See Cookie Policy for how to exercise these choices.

8. How we disclose personal data

  • Service providers / subprocessors that help us run the Service (see our Subprocessor List), under contracts that limit their use of the data.
  • Payment processor (Stripe) to process payments; card data goes directly to Stripe.
  • Legal & safety — to comply with law, respond to lawful requests, or protect rights and safety.
  • Business transfers — in connection with a merger, acquisition, or sale of assets.

9. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding personal data we control: to know/access it, to delete it, to correct it, to portability (receive a copy), and to opt out of sale, sharing, targeted advertising, or certain profiling. Several U.S. state laws (including in Virginia, Colorado, and Connecticut) also give you the right to appeal a decision on your request. We will not discriminate against you for exercising these rights.

These rights vary by state (for example, California’s CCPA/CPRA, Virginia’s VCDPA, Colorado’s CPA, Connecticut’s CTDPA, Utah’s UCPA, Texas’s TDPSA, and other comprehensive state privacy laws). We do not process the special categories of sensitive data those laws single out. If you are in the EEA or UK and a business using Bookable controls your data, contact that business; our DPA provides the transfer safeguards.

10. Making a request

To exercise a right, email contact@bookable.co. We will verify your identity before responding and may ask for information to do so. You may use an authorized agent where the law allows. For personal data we process on behalf of a business (as a processor), we will refer your request to that business or act on its instructions; today we fulfil such requests through account-level export and deletion tools together with manual handling.

11. Data retention

We keep personal data for as long as your account is active or as needed to provide the Service, then delete or de-identify it. Specific windows we enforce include:

  • Call recordings: a default of 365 days, then deleted (configurable by the business).
  • Account data exports: available for 7 days, then removed.
  • After an organization is deleted: a 30-day window, then the data is permanently purged.
  • Authentication sessions: expire automatically.

12. Security

We follow industry-standard security practices. Passwords are hashed (bcrypt); certain sensitive fields are encrypted at rest; data is encrypted in transit (TLS); tenant data is logically isolated; we maintain a tamper-evident audit log; and multi-factor authentication is available. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will notify affected parties of a personal-data breach as required by law.

13. Data location & international transfers

We host and process personal data in the United States (Amazon Web Services, US East / Ohio region). If you access the Service from outside the United States, you understand your data will be processed in the United States. For personal data subject to EEA/UK law that a business processes through us, transfers rely on the Standard Contractual Clauses incorporated into our DPA.

14. Children

The Service is for businesses and is not directed to children under 13, and our account holders must be adults. We do not knowingly collect personal data from children under 13; if we learn we have, we will delete it.

15. Changes to this policy

We may update this policy. The version and effective date appear at the top of this page, and we will provide notice of material changes. Payments are processed by Stripe under Stripe’s privacy policy.

16. Contact & complaints

Contact contact@bookable.co or write to Worldview Industries LLC, doing business as Bookable at 3379 Peachtree Rd NE, Suite 700, Office 446, Atlanta, GA 30326. You may also have the right to complain to your state attorney general or another supervisory authority.


Questions about this document? Contact us at contact@bookable.co. See our other policies: Terms, Privacy, Cookies, DPA, Subprocessors, Acceptable Use, Messaging, DMCA.