Privacy Policy
Last updated: July 5, 2026
This Privacy Policy explains how BOOKINGAPI INC. ("BookingAPI," "we," "us," or "our") collects, uses, discloses, stores, transfers, retains, and protects personal information in connection with our website, business dashboard, APIs, embeddable booking widgets, booking flows, calendar integrations, WhatsApp AI Agent, payment-related features, email communications, security systems, and related services (collectively, the "Service").
BOOKINGAPI INC. is an Ontario corporation.
This Policy is intended to describe our actual data practices and the controls that apply to the Service. Some features described in this Policy may be available only to certain business customers, may depend on the integrations a business enables, or may be unavailable in certain jurisdictions.
1. Our Role
BookingAPI provides booking, scheduling, calendar-sync, messaging, payment-request, business automation, and related software tools to businesses.
Our privacy role depends on how you interact with the Service.
If you are a business customer, account user, demo requester, or website visitor
If you create or manage a BookingAPI account, use our dashboard, connect integrations, purchase tokens or services, contact us, request a demo, or otherwise interact with BookingAPI directly, BookingAPI is responsible for the personal information we collect and use for those purposes.
If you are an end-customer of a business using BookingAPI
If you submit a booking, message a business, or interact with an automated assistant through a business that uses BookingAPI, the business is primarily responsible for its relationship with you and for deciding how your booking or messaging information is used.
BookingAPI acts as a service provider/processor for that business when we process your information to provide the Service to that business. BookingAPI remains responsible for protecting personal information in our custody and for processing it only as described in this Policy, our agreements, and applicable law.
If you are an end-customer and want to access, correct, delete, or otherwise exercise privacy rights over information submitted to a business, you should contact that business first. You may also contact us at privacy@bookingapi.ca, and we will assist or forward your request. If the business does not respond within 30 days, or is no longer operating, we respond to you directly with respect to the personal information in our custody, taking the steps applicable law permits or requires us to take.
If you interact through an automated agent
The Service exposes interfaces (including our booking APIs and agent-accessible endpoints) that third-party AI agents, assistants, or other automated tools can use to make or manage bookings on a person's behalf. If you use such an agent, you are responsible for ensuring it is authorized to act for you and that the personal information it submits is accurate and lawful. Notices and policy links presented to your agent — including this Policy — are made available to you through it, and we process information submitted through supported automated interfaces the same way as information you submit directly. Where a consent or notice is legally required, it must still be valid under applicable law; using an agent does not remove that requirement. Automated agents must interact only through our supported interfaces and in accordance with our terms.
2. PIPEDA Privacy Compliance Commitments
BookingAPI maintains a privacy program designed to support compliance with the Personal Information Protection and Electronic Documents Act and applicable provincial privacy laws.
BookingAPI maintains the following privacy compliance commitments:
- we have designated a Privacy Officer responsible for privacy compliance (Section 22);
- we identify the purposes for collecting personal information before or at the time of collection;
- we obtain meaningful consent for the collection, use, and disclosure of personal information, except where processing without consent is permitted or required by law;
- we limit collection to information reasonably necessary for identified purposes;
- we use, disclose, and retain personal information only for identified purposes, with consent, or as required or permitted by law;
- we take reasonable steps to keep personal information accurate, complete, and up to date for the purposes for which it is used;
- we maintain retention schedules and deletion or anonymization procedures;
- we protect personal information using safeguards appropriate to the sensitivity of the information;
- we make information about our privacy practices publicly available;
- we provide individuals with access to their personal information and correct information that is inaccurate or incomplete, subject only to the limited exceptions the law provides;
- we provide a process for privacy complaints and challenges (Section 22);
- we maintain breach records and notify affected individuals and regulators where required by law.
3. Information We Collect
We collect different categories of information depending on how the Service is used.
Information you provide directly
When you contact us, request a demo, submit the get-started form, create or manage an account, submit a form, communicate with support, or otherwise interact with us directly, we may collect:
- email address;
- phone number;
- company or business name;
- business country;
- business details;
- message content;
- support requests;
- account setup information;
- marketing-communication preferences you choose (including the date, time, and originating IP address of an express marketing consent, kept as the consent record);
- any other information you choose to provide.
Account, profile, and business data
If you use the dashboard, business-facing Service, or API features, we may process:
- Google account identifiers used for sign-in;
- account and authentication information;
- organization and tenant details;
- business locations;
- staff profile details;
- service listings;
- booking settings;
- staff roles and permissions;
- API usage records where API features are used;
- support history;
- administrative settings;
- token, credit, and account status;
- billing and payment-related records.
Dashboard sign-in uses Google sign-in. BookingAPI does not maintain its own password database for dashboard accounts.
Booking and customer data
When appointments are created, managed, approved, denied, rescheduled, cancelled, synced, displayed, or otherwise processed through the Service, we may process booking-related information supplied by business customers or their end-customers, including:
- customer name;
- email address;
- phone number, where provided;
- appointment time and date;
- service selection;
- assigned staff member;
- booking notes;
- booking status history;
- approval, denial, rescheduling, cancellation, and external-change status;
- related booking details.
Business customers are responsible for ensuring they have the right to collect and submit this information through the Service.
WhatsApp AI Agent and messaging data
If a business enables the WhatsApp AI Agent or related WhatsApp messaging features, we may process:
- incoming and outgoing WhatsApp message content;
- recent conversation history;
- WhatsApp display name;
- message timestamps;
- business configuration settings;
- booking details needed to respond to the customer;
- opt-out, pause, consent, and handoff records where applicable.
We do not send the customer's WhatsApp phone number to OpenAI in any form — not as a field, not in the system prompt or conversation context, and not in booking-tool data. The phone number is used server-side only, to route, scope, and manage the conversation and booking workflow.
However, if the phone number or other identifying information appears in message content — typed by the customer or by the business during a conversation — or in user-chosen text such as a WhatsApp display name, it is processed like the ordinary content of that field.
AI onboarding and business-profile generation data
We may use AI to help a business customer set up its BookingAPI profile. For example, if a business provides a website URL for onboarding or profile generation, we may process the website URL, page title, and scraped website page text to help extract business information such as business name, services, hours, and tone. Business-provided URLs are subject to automated format and safety checks before retrieval; these checks restrict the address types and destinations our systems will fetch and do not constitute review or endorsement of the site's content.
This onboarding AI use is separate from end-customer WhatsApp AI conversations.
Connected calendar and integration data
If a business user connects Google Calendar or another supported integration, we process information needed to provide the enabled integration, including:
- Google account identifiers;
- calendar identifiers;
- selected calendar metadata;
- event IDs;
- event titles or summaries;
- event descriptions where needed for sync, booking, availability, troubleshooting, or change detection;
- attendees and organizers where needed for sync, booking, availability, troubleshooting, or change detection;
- event start and end times;
- event status, creation, and update timestamps;
- availability-related information;
- connection status;
- tokens or credentials needed to maintain the connection;
- troubleshooting, sync, archive, and external-change records.
Calendar credentials and calendar-related stored data that contain personal information or integration secrets are protected using application-level or database-field encryption where technically implemented for those records.
Deleted Google Calendar events may be archived in encrypted form before deletion from Google Calendar where needed for recovery, audit, or troubleshooting.
Billing, token, credit, and transaction data
If you purchase paid features, tokens, credits, subscriptions, or related services, or if a business uses payment-related features, we may process:
- billing contact details;
- invoice records;
- purchase history;
- subscription status;
- token or credit balances;
- payment status;
- Stripe customer IDs;
- Stripe connected-account IDs;
- payment intent IDs;
- invoice IDs;
- subscription IDs;
- charge or transaction IDs;
- limited vaulted-card metadata such as card brand and last four digits, where applicable.
We do not store full payment card numbers. Payment card information is collected and processed by Stripe.
Where a business sets up a Stripe connected account, BookingAPI creates the account shell and redirects the business to Stripe's own hosted onboarding. Any identity-verification information Stripe requires there (which may include government-issued identification and ownership details) is submitted by the business directly to Stripe on Stripe's pages, under Stripe's privacy policy — it does not pass through, and is not collected or stored by, BookingAPI. We receive back only the connected-account identifier and its verification status.
Usage, device, diagnostic, and analytics data
We automatically collect technical and usage information such as:
- IP address;
- device and browser details;
- referring URLs;
- page views;
- log data;
- API activity;
- error information;
- approximate location inferred from IP address;
- feature usage;
- session and authentication events;
- security and fraud-prevention signals;
- Cloudflare security data (plus Cloudflare analytics and real-user-monitoring data only if we ever enable those technologies — not currently deployed, see Section 7).
We use this information to operate, secure, troubleshoot, maintain, measure, and improve the Service.
Cookies, local storage, and similar technologies
We use cookies, local storage, session storage, and similar technologies for authentication, session management, payment security, fraud prevention, security, diagnostics, dashboard preferences, core functionality, and remembering Service settings (and for analytics only if we ever enable analytics technologies — not currently deployed, see Section 7).
The booking widget does not use client-side cookies, local storage, or session storage for standard free booking submissions.
The dashboard uses an HttpOnly cookie for authentication. JavaScript cannot read this cookie.
BookingAPI does not store dashboard access tokens, customer data, booking data, tenant secrets, calendar credentials, API keys, or payment data in browser local storage. Browser local storage may be used only for non-sensitive interface preferences or temporary non-secret state.
We do not use cookies or similar technologies for cross-site behavioral advertising, advertising retargeting, or marketing profiling.
4. Sources of Information
We collect information from:
- you directly;
- your use of the Service;
- businesses that use BookingAPI;
- end-customers who submit bookings or messages through businesses using BookingAPI;
- connected integrations that users authorize;
- payment and billing providers involved in transactions;
- service providers that help us operate infrastructure, communications, support, security, payment, and automation functions (and analytics functions only if we ever enable analytics technologies — not currently deployed, see Section 7).
5. How We Use Information
When you interact with BookingAPI directly
When you interact with us directly as an account holder, website visitor, demo requester, prospective customer, or support contact, we use information to:
- provide, operate, maintain, and secure the Service;
- respond to contact requests, demo inquiries, and support messages;
- create, manage, secure, and administer accounts, organizations, tenants, and settings;
- manage tokens, credits, invoices, payments, subscriptions, and billing operations;
- authenticate users;
- prevent fraud, detect abuse, and protect the security of the Service;
- provide customer support;
- diagnose issues and troubleshoot technical problems;
- monitor performance and reliability;
- measure usage and improve the Service;
- create internal reporting, analytics, and service planning information;
- comply with legal obligations;
- enforce our terms, policies, agreements, and rights.
When we process end-customer data for a business
When we process end-customer booking, messaging, or calendar-related data on behalf of a business customer, we use that personal information to:
- provide, secure, maintain, and troubleshoot the Service for that business;
- create, manage, approve, deny, update, reschedule, cancel, and display bookings and related records;
- provide calendar connection, sync, external-change detection, and availability features the business enables;
- provide WhatsApp AI Agent or messaging features the business enables;
- send booking-related, account-related, or service-related messages;
- support business-to-customer payment-related workflows where enabled;
- authenticate users, prevent fraud, detect abuse, and protect Service security;
- provide customer support to the business;
- comply with legal obligations;
- enforce our terms, policies, and agreements.
We do not use end-customer booking content, customer contact details, or WhatsApp conversation content for BookingAPI's independent marketing, advertising, or cross-context behavioral profiling.
We use business customers' own contact information (such as an account owner's email address) for account, service, and support communications. We send marketing to business customers only as described in Section 6.
We may use limited operational metadata, security logs, diagnostic logs, and aggregated or de-identified information to secure, debug, maintain, measure, and improve the Service (plus analytics data only if we ever enable analytics technologies — not currently deployed, see Section 7).
Where we use aggregated or de-identified information, it is handled in a form for which there is no serious possibility that an individual could be identified from it, alone or in combination with other reasonably available information. We remove or generalize direct identifiers and tenant-linkable quasi-identifiers before treating information as de-identified, and we do not attempt to re-identify de-identified information. If information can reasonably be linked to an identifiable individual, we treat it as personal information under this Policy.
6. Operational, Administrative, and Marketing Communications
We send different types of communications.
Operational and administrative messages
We may send messages required to provide or administer the Service, including:
- booking confirmations;
- booking updates;
- booking approval or denial messages;
- rescheduling notices;
- cancellation notices;
- external calendar-change notices;
- security alerts;
- account verification or authentication messages where applicable;
- billing notices;
- payment receipts;
- failed-payment notices where applicable;
- service-continuity notices, such as low-token, subscription, renewal, account-access, or service-paused notices, where limited to the functioning of the Service;
- critical administrative notices.
You cannot opt out of operational or administrative messages while using the Service, because they are necessary for the Service to function. Operational and administrative messages are kept free of promotional content; service-continuity notices (such as low-balance or renewal notices) are limited to factual information about your own account. A message that includes promotional content is treated as a commercial electronic message under this Policy and applicable law.
Sender identification in electronic messages
Emails sent by BookingAPI identify BookingAPI as the sender, and our standard email templates include our legal name and valid mailing address. Where an electronic message is a commercial electronic message under Canada's Anti-Spam Legislation, BookingAPI includes the required identification information, contact information, and unsubscribe mechanism in that message or through a clearly and readily accessible link in that message, and maintains that contact information as valid for at least 60 days after the message is sent.
BookingAPI does not send commercial electronic messages unless the required CASL identification information is included, including a valid mailing address that remains valid for the required period after the message is sent.
Marketing communications
BookingAPI does not currently operate a marketing newsletter or product-update email program.
Where you give us express consent to receive product updates (for example, an optional checkbox on our get-started form), we record the consent with its date, time, and originating IP address as the consent record, and we will honour it — including your right to withdraw it — before any marketing program begins sending.
If we send marketing or promotional emails in the future, we will do so only where permitted by law and where we have the required consent or other legal permission. Marketing messages will identify BookingAPI and include an unsubscribe mechanism where required.
You can withdraw consent for marketing emails at any time by clicking the unsubscribe link, where provided, or contacting privacy@bookingapi.ca. We give effect to unsubscribe requests without delay and no later than 10 business days. Opting out of marketing will not affect operational or administrative messages.
Business customers who use the Service to send their own messages are responsible for having any required consent and for complying with the anti-spam and telemarketing laws that apply to messages they cause to be sent.
7. Cookies, Analytics, and Similar Technologies
We use cookies and similar technologies for limited Service-related purposes.
Authentication and session technologies
We use first-party cookies, session storage, local storage, and similar technologies to keep users logged in securely, maintain sessions, remember Service settings, and protect account access.
Dashboard local storage
The dashboard may use local storage only for non-sensitive interface preferences or temporary non-secret state. BookingAPI does not store dashboard access tokens, customer data, booking data, tenant secrets, calendar credentials, API keys, or payment data in local storage.
Payment and fraud-prevention technologies
Stripe and related payment services may set cookies or use similar technologies necessary to process payments, prevent payment fraud, maintain payment security, and support Stripe Connect or payment workflows.
Security and infrastructure technologies
Cloudflare may process request metadata, cookies, security logs, and similar technical information to detect malicious actors, protect the Service, operate the Web Application Firewall, evaluate traffic for security purposes, and maintain reliable content delivery.
Cloudflare is configured not to cache dynamic responses containing personal information. Dynamic API responses that contain or may contain personal information are treated as private and non-cacheable and use no-store or equivalent cache-control headers. Only static, non-personal content is eligible for caching.
Analytics and performance technologies
If we enable Cloudflare Web Analytics, real-user monitoring, or similar analytics technologies in the future, they may collect performance and usage data such as page views, request information, browser details, device details, timing data, and approximate location derived from IP address. None of these technologies is currently deployed (see below).
BookingAPI does not use Cloudflare analytics for advertising retargeting or cross-site behavioral advertising.
As of the Last Updated date, BookingAPI does not deploy any non-essential analytics or real-user-monitoring technologies on the Service. If we introduce such technologies where applicable law requires opt-in consent, we will obtain that consent through a clear mechanism (such as a consent banner) before the technology is loaded; where we cannot obtain or manage the required consent in a jurisdiction, we will keep non-essential analytics disabled for users in that jurisdiction or disable the technology entirely.
Meta onboarding technologies
For WhatsApp onboarding and Facebook Login for Business, Meta technologies may be loaded in the onboarding dashboard to support Embedded Signup, authorization, and connection to Meta or WhatsApp Business accounts. These technologies are not used as advertising pixels by BookingAPI.
No advertising tracking
We do not use Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, PostHog, Hotjar, FullStory, Sentry Session Replay, ad retargeting, or affiliate tracking in the Service as of the Last Updated date above.
You can usually control cookies through your browser settings and delete locally stored data through your browser or device. Blocking essential technologies may cause parts of the Service, such as logging in, onboarding, connecting integrations, or completing payments, to function improperly.
8. How We Share Information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We disclose personal information only as described below.
Service providers and subprocessors
We use service providers and subprocessors that help us host, secure, support, bill, communicate, automate, analyze, and operate the Service. The current list — including the exact AI model in production — is maintained at bookingapi.ca/subprocessors and is updated when a provider or the production AI model changes.
| Provider | Purpose | Processing Location / Region |
|---|---|---|
| Meta Platforms | WhatsApp Cloud API, WhatsApp Business onboarding, Facebook Login for Business, Embedded Signup, deauthorization, and Meta data-deletion flows | United States and other Meta processing locations |
| OpenAI | AI processing for WhatsApp AI Agent replies and onboarding/business-profile generation (the exact production model is listed at bookingapi.ca/subprocessors) | United States and other OpenAI processing locations |
| Google sign-in, Google Calendar integration, OAuth, and calendar sync | United States, Canada, and other Google processing locations | |
| Stripe | Payments, billing, invoices, card processing, fraud prevention, Stripe Connect, and connected-account onboarding | United States and other Stripe processing locations |
| Resend | Email delivery for operational and administrative emails | United States and other Resend processing locations |
| Cloudflare | Website and dashboard hosting through Cloudflare Pages, CDN, tunnel (which terminates TLS and applies WAF inspection to traffic in transit), security and traffic protection; performance analytics and real-user monitoring only if enabled (not currently deployed — see Section 7) | Cloudflare's global network; traffic may be routed through points of presence in or outside Canada and the United States based on network conditions and Cloudflare routing |
| Amazon Web Services | Encrypted off-site database backup storage (Amazon S3) and cloud key management (AWS KMS), which wraps and unwraps the master key protecting field-encrypted personal information. Backups stored in S3 are encrypted before upload with a separate key that AWS does not hold, so AWS cannot read backup contents | Canada Central region (ca-central-1) for both S3 and KMS |
Separately from the third-party providers above — and not as a subprocessor — the core of the Service (backend application containers, the PostgreSQL database, internal services, and the local encrypted backup mirror) runs on physical server hardware that BookingAPI owns and operates in Canada. No third party operates these systems or holds administrative access to them. For precision about the providers listed above: Cloudflare handles traffic in transit (its tunnel terminates TLS and applies WAF inspection before requests reach our servers), and AWS KMS performs key wrap/unwrap operations for our encryption master key without any access to our systems or stored data.
Each service provider that processes personal information on our behalf does so under a written agreement — the provider's service terms together with its data-processing terms — that restricts use of the information to providing services to us, addresses confidentiality, retention, deletion, and further disclosure, and requires notification of security incidents, consistent with PIPEDA and Quebec law. We do not engage a provider to process personal information without such terms in place.
Business customers' processing relationship with BookingAPI is governed by our agreements with them; the commitments in this Policy bind BookingAPI's processing in all cases, and we offer business customers a data processing addendum (including the service-provider terms required by applicable privacy laws) on request at privacy@bookingapi.ca.
Cloudflare caching and personal information
Cloudflare is configured not to cache dynamic responses containing personal information. Dynamic API responses containing or likely to contain personal information are treated as private and non-cacheable. Only static, non-personal content is eligible for caching.
Business customers
For end-customer bookings and messages, information is made available to the business with which the end-customer is interacting. The business is responsible for its own use of that information outside BookingAPI.
Integrations you authorize
We share information with integration partners you choose to connect, such as Google Calendar, Meta, WhatsApp, Stripe, or other supported providers, to provide the enabled feature.
Payment processors and connected accounts
Where payment features are enabled, payment information may be processed by Stripe. For business-to-customer payment features, a business may use its own connected Stripe account. In those cases, the business and Stripe may separately process payment information according to their own terms and policies.
Professional advisers
We may disclose information to lawyers, accountants, auditors, insurers, security consultants, financing counterparties, or other professional advisers where reasonably necessary.
Legal, safety, and compliance
We may disclose information to law enforcement, regulators, courts, government authorities, or other parties where required by law or reasonably necessary to protect rights, safety, security, users, businesses, or the Service.
Business transfers
We may disclose or transfer information to a buyer, investor, successor, or other relevant party in connection with a merger, acquisition, financing, reorganization, bankruptcy, asset sale, or sale of all or part of our business. In any such transaction, we require — by agreement, as PIPEDA's business-transaction provisions contemplate — that the recipient use personal information only for the purposes described in this Policy (or for evaluating the transaction itself) and protect it with safeguards comparable to those described here, unless applicable law requires otherwise.
9. Google Calendar and Google Sign-In Data
BookingAPI uses Google sign-in for account identification and dashboard access. BookingAPI also supports Google Calendar integrations for businesses that choose to connect a calendar.
Google sign-in scopes
For Google sign-in and account identification, BookingAPI may request basic identity scopes such as:
openid;email;profile, where required for the applicable sign-in or invitation flow.
These scopes are used for authentication, account identification, account security, and cross-tenant isolation.
Google Calendar scopes
If you authorize Google Calendar access, BookingAPI may request:
https://www.googleapis.com/auth/calendar.events;https://www.googleapis.com/auth/calendar.readonly.
How we use Google Calendar data
We use Google Calendar access to:
- connect and verify your selected calendar;
- read calendar metadata and availability-related information needed for scheduling;
- read event IDs, titles or summaries, descriptions, attendees, organizers, start and end times, status, creation timestamps, and update timestamps where needed for sync, change detection, troubleshooting, or availability;
- create booking events;
- update booking events when appointments change;
- delete booking events when appointments are cancelled or deleted;
- archive deleted calendar-event data in encrypted form before deletion where needed for recovery, audit, or troubleshooting;
- detect external calendar changes;
- troubleshoot or restore calendar connections you ask us to support;
- secure and maintain calendar-enabled features.
Restrictions on Google data use
We do not request Gmail, Google Drive file access, or Google Contacts access through the BookingAPI Google Calendar connection.
We do not use the Google Calendar connection to:
- access Google data unrelated to the booking, sync, and availability features described in this Policy;
- sell Google Calendar data;
- use Google Calendar data for advertising;
- build marketing profiles;
- train generalized artificial intelligence or machine learning models.
BookingAPI does not send raw Google Calendar event objects to OpenAI for WhatsApp AI replies. Where the WhatsApp AI Agent needs scheduling information, it receives only the minimum booking or availability information needed to help with the booking flow, not the user's raw Google Calendar event records.
BookingAPI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting Google Calendar
You can stop future Google Calendar access at any time by disconnecting the calendar inside the Service or by revoking BookingAPI access in your Google account permissions. Disconnecting a calendar inside the Service deletes the stored calendar credentials from our active systems and revokes the grant with Google.
Revoking access prevents future access but does not automatically delete historical booking records created through the integration. If you want us to delete other stored connected-calendar integration data from active systems, contact privacy@bookingapi.ca. Data held in your own Google account remains under Google's controls and is managed through Google's own privacy and deletion tools.
Deleting a calendar connection does not necessarily remove booking, billing, audit, security, or account records that we must retain for legitimate business or legal reasons.
10. AI Assistant and Automated Processing
Businesses may enable the BookingAPI WhatsApp AI Agent to respond to customers, answer questions, help with bookings, and allow business users to take over conversations.
Businesses must obtain any end-customer opt-in required by Meta's WhatsApp Business terms and applicable law before initiating WhatsApp messages to a customer (such as template messages outside a customer-initiated conversation). Conversations the AI Agent participates in are customer-initiated; business-initiated messaging without the required opt-in is prohibited.
BookingAPI uses OpenAI as its AI provider for these features. The exact production model is listed — and kept current — at bookingapi.ca/subprocessors. If we materially change the AI provider, or use a materially different AI model in a way that materially changes how personal information is processed, we will update this Policy or provide appropriate notice.
WhatsApp AI Agent
When the WhatsApp AI Agent is enabled, incoming customer messages, recent conversation history, the customer's WhatsApp display name, business configuration details, the tenant's configured prompt, business name, timezone, today's date, available booking tools, and booking context needed to respond are sent to OpenAI to generate replies and help with bookings.
This processing is automated, and automated actions remain reviewable by people: the assistant creates and manages booking requests, but booking approvals and denials are controlled by the business (its staff or the approval rules the business configures); a person at the business can take over any conversation immediately on request; and end-customers can contact the business, or us, to have an automated action reviewed, corrected, or reversed. Review requests made to the business are handled in the course of the booking itself; review requests made to us are handled within the response timelines in Section 17.
We do not send the customer's WhatsApp phone number to OpenAI in any form — not as a field, not in the system prompt or conversation context, and not in booking-tool data. The only ways the number can reach OpenAI are if it appears in message content — typed by the customer or by the business during a conversation — or in user-chosen text such as a WhatsApp display name; in either case it is processed like the ordinary content of that field.
BookingAPI stores customer inbound WhatsApp messages and final reply text in its messaging database for the retention period described in this Policy. BookingAPI does not store the assembled OpenAI prompt, OpenAI tool traffic, or OpenAI tool payload as a separate prompt log. Token usage may be stored as counts without message content.
Onboarding and business-profile generation
If a business uses AI-assisted setup or profile generation, BookingAPI may send the business-provided website URL, page title, and scraped website page text to OpenAI to extract or suggest business information such as business name, services, hours, and tone. Business-provided URLs are subject to automated format and safety checks before retrieval.
AI training and provider retention
BookingAPI does not use WhatsApp AI Agent conversations or booking data to train BookingAPI-owned generalized artificial intelligence or machine learning models.
OpenAI states that data sent to the OpenAI API is not used to train or improve OpenAI models unless the customer explicitly opts in. BookingAPI does not opt in to training on API data.
OpenAI may retain API inputs and outputs for abuse monitoring, security, legal compliance, or other purposes according to OpenAI's applicable API terms, data processing terms, and policies. OpenAI's public API data controls state that abuse-monitoring logs are retained for up to 30 days by default unless longer retention is required by law or necessary to protect OpenAI's services or third parties. BookingAPI uses OpenAI's standard API data controls and has not been approved for OpenAI's Zero Data Retention or Modified Abuse Monitoring programs.
BookingAPI uses OpenAI under OpenAI's API terms and applicable data processing terms.
Automated assistant notice and human takeover
At or near the start of an automated WhatsApp conversation, customers are told that they are chatting with an automated AI assistant, that the assistant is powered by BookingAPI, that their messages are processed by BookingAPI and our AI provider, OpenAI, to generate replies and manage booking requests, and that a person can take over if requested.
The required automated-assistant disclosure is controlled by BookingAPI server-side and must not be removed or blanked out by a business customer. Businesses may customize the wording only if the required disclosure elements remain present; BookingAPI validates customizations and blocks, resets, overrides, or rejects disclosure text that removes or obscures the required automated-assistant, BookingAPI, OpenAI, or human-takeover disclosures. A blanked or non-conforming disclosure is automatically replaced with BookingAPI's default disclosure.
The default notice says:
"🤖 Heads up — you're chatting with an automated AI assistant for [Business Name], powered by BookingAPI. I can answer questions and help you book. Your messages are processed by BookingAPI and our AI provider, OpenAI, to generate replies and manage booking requests. Ask anytime if you'd like a person to take over. More: bookingapi.ca/privacy"
The notice links to this Policy, which discloses (Sections 10 and 14) that our AI provider may retain message content for up to 30 days for abuse monitoring — the layered-notice approach recommended by the OPC's meaningful-consent guidance.
A person can take over by pausing AI for a contact in the dashboard or by disabling the bot at the tenant level. Customers may also ask to reach a person.
11. Sensitive Information and Regulated Use Cases
BookingAPI is designed for general business booking, scheduling, messaging, payment-request, and automation workflows.
BookingAPI is not designed to be used as a system of record for highly sensitive or regulated information, including protected health information, medical records, therapy or mental-health records, legal advice records, financial account information, insurance records, government identifiers, children's information, or sexually explicit/adult-entertainment records, unless BookingAPI has expressly agreed in writing and appropriate legal, contractual, security, and configuration requirements are in place.
BookingAPI does not currently offer a HIPAA Business Associate Agreement or act as a PHIPA agent or health information network provider. Providers subject to those laws must not use the Service to collect, store, or process patient or health information unless and until such an agreement has been offered by BookingAPI and signed by both parties. New business accounts are reviewed by BookingAPI before activation, and accounts that appear to involve patient or health information without the required written agreement are refused or suspended.
Business customers must not use the Service to collect sensitive information, health information, financial account information, government identifiers, children's information, or other regulated data unless they have the legal right to do so and have configured the Service appropriately.
Do not submit sensitive information, such as health details, financial details, government-ID numbers, or special-category data, in booking notes, WhatsApp messages, support messages, or other free-text fields unless it is necessary and lawful. (Government identification a business provides to Stripe during payment-account verification is collected directly by Stripe on Stripe's pages, as described in Section 3 — BookingAPI does not collect or store it.)
If sensitive information is submitted anyway, we process it only to provide, secure, support, or maintain the Service and do not use it for unrelated marketing, advertising, or profiling.
Business customers are responsible for obtaining any consent, parental consent, guardian consent, authorization, or other legal basis required for information they collect through BookingAPI.
12. Children's Privacy
Our business-facing Service is not intended for use by account holders under 18.
Our booking and messaging tools are not intended to be directed primarily to children under 13.
Child-oriented use of the Service is not enabled through standard onboarding. Every new business account is reviewed by BookingAPI before activation, and accounts that appear to be directed to children without having completed our child-oriented onboarding are refused or suspended. Businesses that provide family, youth, tutoring, children's haircut, children's activity, party, or similar child-oriented services must identify that use case to BookingAPI and complete our child-oriented onboarding by contacting hello@bookingapi.ca before using booking or messaging tools for those services. For child-oriented services, bookings must be made by a parent or guardian: our booking tools are directed to the adult booking on a child's behalf, not to children. Such businesses are responsible for obtaining any required parental or guardian consent and for complying with applicable children's privacy laws.
The Service must not be used to knowingly collect personal information directly from children under 13 without required parental or guardian consent.
We do not independently verify the age of every end-customer, but we review accounts flagged or identified as child-oriented and reserve the right to review, suspend, restrict, or terminate accounts that we believe are collecting information from children in violation of applicable law or without appropriate parental or guardian consent.
If we become aware that we have collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it.
13. International Data Transfers
BookingAPI operates from Canada and is intended for businesses in Canada and the United States.
The service providers we use may process information in Canada, the United States, or other jurisdictions where they maintain operations.
When personal information is transferred outside Canada, it may be subject to the laws of those jurisdictions and may be accessible to courts, law enforcement, government agencies, or national security authorities in those jurisdictions, including under laws such as the United States CLOUD Act.
Before communicating personal information outside Quebec, where Quebec law applies, we assess and document the sensitivity of the information, the purposes of the communication, and the protections available in the receiving jurisdiction.
When we transfer personal information to service providers, we remain responsible for personal information in our custody or control. We use contractual, technical, and organizational safeguards intended to provide a level of protection comparable to that required under Canadian privacy law.
14. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Server logs, error logs, and API logs
System journals are retained for no longer than 90 days. Application and infrastructure container logs rotate on size-bounded schedules that in normal operation retain substantially less than 90 days of entries. Delivered-email dispatch records are trimmed from the outbound queue within 90 days of delivery or failure. Longer retention applies only where needed for security, fraud prevention, investigation, legal, or compliance purposes.
We work to minimize personal information in logs.
Audit logs
Administrative audit logs and security-relevant records may be retained while the business account is active and for up to 7 years after account closure where needed for security, fraud prevention, investigation, legal, compliance, audit, or dispute purposes. Audit records of erasure and deletion actions are retained so that erasures can be re-applied after any backup restoration.
Booking records and customer data
Booking records and customer data are retained while the business account is active and as needed to provide the Service, support the business, maintain audit records, resolve disputes, and meet legal obligations.
Business customers may delete bookings or request deletion where permitted, and BookingAPI maintains deletion and erasure workflows for verified requests.
Inactive free-tier accounts with no booking activity for 12 months or more are identified for review and are subject to account closure and to deletion or anonymization of personal booking/customer data through the closure process described below, unless retention is documented as necessary for legal, security, tax, accounting, dispute, fraud-prevention, or compliance purposes. Before an inactive account is closed for deletion, we attempt to notify the account's contact email and provide at least 30 days to reactivate the account or export its data.
If a business account is closed or terminated, personal booking/customer data is deleted or anonymized after a 90-day post-closure grace period, on the next deletion cycle, unless retention is documented as necessary for legal, security, tax, accounting, dispute, fraud-prevention, or compliance purposes. Records retained for those documented purposes (for example, invoices and tax records) are kept for the periods described in this Policy.
Signup and demo leads
Lead records from our get-started and demo forms are retained while we work the inquiry. Leads that do not become business customers are reviewed at least quarterly and are deleted or anonymized within 12 months of the last interaction — except the record of an express marketing consent, which follows the consent-record schedule below.
WhatsApp AI Agent messages
When a business enables the WhatsApp AI Agent, customer message content is retained in BookingAPI active systems for up to 90 days and then deleted from active systems by a scheduled deletion process.
Contact records, CRM metadata, opt-out records, pause records, suppression records, and aggregate statistics may be retained as needed to operate the Service, honour customer choices, prevent abuse, and comply with legal obligations. Contact records are retained while the business's WhatsApp service remains connected and are deleted through the account-closure and Meta data-deletion processes described in this Policy.
Consent and preference records
Records evidencing a consent (including its date, time, and originating IP address) are retained for as long as the consent remains in effect — because they are the proof the law requires us to keep while we rely on the consent — and for 3 years after the consent is withdrawn or last relied upon, matching the limitation period under Canada's Anti-Spam Legislation. They are then securely deleted. Where we have never relied on an express marketing consent (no marketing has been sent under it) and the person has not become a business customer, the consent lapses 24 months after collection; once lapsed, we do not send under it, and the consent record and any associated lead record are deleted at the next quarterly retention review, with fresh consent sought rather than reliance on the lapsed record. The same treatment applies where such a never-relied-upon consent is withdrawn before it lapses: we stop treating it as active immediately and delete its record and any associated lead record at the next quarterly retention review — the 3-year retention above applies only to consents we have relied upon. Opt-out and suppression records are retained for as long as needed to keep honouring the opt-out.
OpenAI may retain API inputs and outputs according to OpenAI's applicable API terms, data processing terms, and policies, as described in the AI section of this Policy.
AI prompt and response records
BookingAPI does not store the assembled OpenAI prompt, OpenAI tool traffic, or OpenAI tool payload as a separate prompt log.
Customer inbound WhatsApp messages and final reply text follow the WhatsApp message retention rule above. Token usage may be stored as counts without message content.
Connected calendar credentials and integration metadata
Connected-calendar credentials are retained while the connection remains active.
When a calendar is disconnected inside the Service, the stored calendar credentials are deleted from active systems as part of the disconnect process and the grant is revoked with Google, subject to backup expiration and legal, security, support, or compliance limitations.
Calendar sync, archive, and change-detection records are retained while the business account remains active, to provide, secure, troubleshoot, audit, and support the calendar-enabled features. Archived deleted-event content is stored encrypted and is redacted through the erasure and account-closure processes described in this Policy.
Account, billing, token, credit, and transaction records
Account, billing, invoice, payment, subscription, token, credit, and transaction records may be retained for up to 7 years to support legal, tax, accounting, audit, dispute, and compliance obligations.
If you submit a deletion request, we will delete personal information from these records that is not subject to a legal retention obligation and retain only the specific records or data elements we are required or permitted to keep.
Backups
BookingAPI maintains encrypted backups for disaster recovery, security, and business continuity.
BookingAPI maintains operational database backups on a tiered retention schedule, enforced by automated rotation with these maximums (each subject only to a documented legal hold for a specific backup):
- daily backups are retained for up to 14 days;
- weekly backups are retained for up to 56 days (8 weeks);
- monthly backups are retained for up to 365 days.
Full-database backups containing personal information — including pre-change operational backups — are not retained beyond a 365-day maximum, subject only to a documented legal hold for a specific backup.
Individual records are not deleted from inside historical encrypted backup snapshots. When we erase information from active systems, the erased information remains in existing encrypted backups until those backups expire through the automated rotation schedule above (365-day maximum, subject only to a documented legal hold), and those backups are not restored to active systems except for disaster recovery — in which case erasures are re-applied before the restored system returns to production use, as described below.
Erased information drops out of the backup set automatically: because backups are full snapshots of the active database, the first backup taken after an erasure no longer contains the erased information, and older snapshots expire through the rotation schedule above. (Individual records cannot be selectively removed from inside an encrypted, integrity-protected backup snapshot; expiry through rotation is how erasure reaches the backup set.) If a backup containing previously erased information is restored, BookingAPI re-applies applicable deletion, suppression, opt-out, and erasure records as part of the restoration process before restored systems are returned to normal production use. Backup restoration procedures, including the erasure re-application step, are tested at least annually or after material backup-system changes.
When data is no longer required, we delete, de-identify, or anonymize it.
15. Security
We use administrative, technical, and organizational safeguards designed to protect information handled by the Service.
These safeguards include:
- HTTPS/TLS (TLS 1.2 or higher, with TLS 1.3 supported) through Cloudflare;
- Cloudflare Web Application Firewall and security controls;
- access controls;
- role-based access controls at the application level;
- tenant-isolation controls;
- PostgreSQL Row-Level Security on tenant data tables where tenant isolation is required — the application connects only through non-privileged database roles that cannot bypass it, and FORCE ROW LEVEL SECURITY is additionally enabled on the primary isolation-bearing tables as defense in depth;
- automated tenant-isolation tests;
- application-level or database-field encryption, using industry-standard authenticated encryption (AES-based), for personal information, booking customer contact details, calendar credentials, invoice personal information, selected calendar-event data, selected integration records, and other sensitive records where field-level encryption is appropriate;
- field-encryption keys managed through a cloud key-management service (the master key is never stored in plaintext on production disks); the key that can decrypt backups is held offline, separately from any cloud provider (see Section 8);
- HMAC blind indexes or similar techniques for selected encrypted fields where lookup or erasure functionality is required;
- encrypted database backups;
- off-site encrypted backup storage in AWS S3;
- administrative and security-relevant access logging;
- environment-specific credential handling;
- least-privilege database roles and access practices;
- internal security testing, code review, and adversarial testing practices;
- production infrastructure controls.
Production systems that store personal information are protected using a combination of application-level and database-field encryption for sensitive records, access controls, network controls, no-store cache controls for dynamic personal-data routes, and encrypted backups.
Cloudflare is configured not to cache dynamic responses containing personal information. Dynamic API responses containing or likely to contain personal information use private, no-store, or equivalent cache-control headers. Only static, non-personal content is eligible for caching.
Not every operational record, log entry, table, or metadata field is encrypted at the application-field level, but BookingAPI uses safeguards appropriate to the sensitivity and function of the information.
No method of transmission over the internet or method of electronic storage is completely secure, so we cannot guarantee absolute security.
Business customers are responsible for maintaining the confidentiality of their account credentials, restricting staff access appropriately, and using the Service in a lawful and secure manner.
16. Breach Notification and Breach Records
If we discover a breach of security safeguards involving personal information under our control and determine that it poses a real risk of significant harm to individuals, we will notify affected individuals, affected business customers, and the Office of the Privacy Commissioner of Canada as required by PIPEDA, without unreasonable delay.
We also comply with applicable US state breach notification laws, including notifying relevant state attorneys general or regulatory authorities where required by the applicable state's statute.
Where Quebec's private-sector privacy law applies, we also notify the Commission d'accès à l'information du Québec and affected individuals of confidentiality incidents that present a risk of serious injury, and we record confidentiality incidents in an incident register.
We maintain records of breaches of security safeguards involving personal information under our control as required by PIPEDA, including breaches that do not meet the threshold for notification, and retain each record for at least 24 months after determining that the breach occurred.
17. Your Rights and Choices
Depending on your location and how you interact with the Service, you may have rights to request:
- access to personal information;
- correction of inaccurate personal information;
- deletion or erasure of personal information;
- portability of certain personal information;
- restriction of certain processing;
- objection to certain processing;
- withdrawal of consent where processing is based on consent.
These rights are subject to legal, security, fraud-prevention, accounting, tax, dispute, contractual, and technical limitations. Because we do not engage in targeted advertising, sale of personal information, or profiling that produces legal or similarly significant effects, requests for restriction or objection are evaluated case by case and honoured where required by law.
How to make a request
To make a privacy request, contact us at privacy@bookingapi.ca.
We may need to verify your identity before completing a request. If you are an end-customer of a business using BookingAPI, we may direct you to the business or coordinate with the business because the business is usually the primary organization responsible for your booking relationship.
We respond to access, correction, and privacy requests within the time required by applicable law. Where PIPEDA applies, we respond within 30 days of receiving a request. Where portability applies, we provide the information in a structured, commonly used technological format — JSON, or CSV on request. Where Quebec law applies, you may also ask us to communicate computerized personal information collected from you directly to another person or organization, and we will do so unless the transfer raises serious practical difficulties. In the limited circumstances where PIPEDA permits an extension, we may take up to 30 additional days; if so, we will, within the first 30 days, send you written notice of the extension and its reason, together with a reminder of your right to complain to the Office of the Privacy Commissioner of Canada. Access is provided at minimal or no cost, and we will inform you of any minimal cost before proceeding.
Non-discrimination
We will not discriminate against you for exercising privacy rights.
Do Not Sell or Share
We do not sell personal information and we do not share personal information for cross-context behavioral advertising — so there is no sale or sharing to opt out of. If we ever begin these activities, we will provide the required opt-out mechanisms (including honouring universal opt-out signals) and update this Policy first.
Appeals
Where applicable law provides a right to appeal our decision on a privacy request, you may appeal by contacting privacy@bookingapi.ca with the subject line "Privacy Request Appeal." We will respond within the timeframe required by applicable law.
18. Data Deletion, Meta Integrations, and Third-Party Links
The Service may contain links to or integrations with third-party websites, platforms, or services, such as Meta, WhatsApp, Facebook, Google Calendar, Stripe, OpenAI, Cloudflare, or other providers.
We do not control and are not responsible for the broader privacy practices of those third parties. Your use of third-party services is subject to their terms and privacy policies.
Meta data deletion
If you connected a WhatsApp Business or Facebook Login for Business integration, you may revoke access from within our dashboard or through your Meta settings.
BookingAPI maintains a Meta data deletion callback at:
https://wa.bookingapi.ca/webhooks/data-deletion
This callback is used for automated Meta platform data deletion requests and verifies Meta's signed request before acting. BookingAPI also maintains a public instructions page for users who want to request deletion manually at bookingapi.ca/meta-data-deletion.
When Meta sends us a valid data deletion request through the callback, we process the request, delete applicable Meta-connected data from active systems where required, and provide a deletion status link.
To request deletion manually, email privacy@bookingapi.ca with the subject line "Data Deletion Request."
We process verified deletion requests within 30 days, subject to legal, security, fraud-prevention, accounting, tax, dispute, contractual, and technical limitations.
Residual copies remain in encrypted backups until those backups are rotated out under the schedule in Section 14 (365-day maximum, subject only to a documented legal hold) and are re-erased if ever restored.
Account deletion
BookingAPI users may request deletion of their account and associated data by emailing privacy@bookingapi.ca with the subject line "Data Deletion Request."
We honour verified deletion requests, subject to legal, security, fraud-prevention, accounting, tax, dispute, contractual, and technical limitations.
End-customer deletion requests
If you interacted with a business through BookingAPI and want your booking data, conversation history, or phone number deleted, please contact that business directly because the business is usually the primary organization responsible for your booking relationship.
You may also contact us at privacy@bookingapi.ca, and we will assist or forward your request where appropriate.
Google Calendar events
When we receive a verified erasure request for an end-customer's booking data and we are able to process it, we delete applicable copies from our active systems, including applicable encrypted calendar-event archive records where deletion is required and technically feasible.
The corresponding event in the business's own connected Google Calendar resides in the business's Google account and is under that business's control. The business is responsible for deleting that event from its own calendar if required.
19. Canada and United States Focus; EEA and UK Restrictions
BookingAPI is intended for businesses in Canada and the United States.
BookingAPI does not offer business accounts to businesses established in the EEA or UK unless BookingAPI expressly approves that use in writing and the required legal, contractual, and product controls are in place. (Signup requests are made online, but every account is reviewed by BookingAPI before activation — there is no instant self-service provisioning.)
BookingAPI uses business-location screening to enforce this: the signup form collects the business's country together with a confirmation that the business is located there, and signup requests from EEA or UK countries are rejected. Business customers must accurately identify their business location during onboarding and must not use the Service from the EEA or UK, or intentionally direct the Service to EEA or UK individuals, unless BookingAPI has expressly approved that use in writing.
BookingAPI may block registration, dashboard access, API access, widget deployment, or other Service access from unsupported jurisdictions where required to enforce this section, and may suspend, restrict, or terminate accounts that appear to be using the Service from unsupported jurisdictions or in ways that create legal or regulatory obligations that BookingAPI has not agreed to support.
BookingAPI does not market to or direct the Service at the EEA or UK.
If individuals in other jurisdictions access or use the Service, their privacy rights may depend on their location and the way they interact with the Service.
Business customers are responsible for ensuring that their use of BookingAPI complies with the laws that apply to their business, their customers, and their locations.
20. Region-Specific Notices
Canada
BookingAPI operates from Ontario, Canada. Our handling of personal information is governed by the Personal Information Protection and Electronic Documents Act and applicable provincial privacy laws.
We are accountable for personal information in our possession or custody, including personal information transferred to service providers for processing.
We identify the purposes for which we collect personal information, limit collection to what is reasonably necessary, use safeguards appropriate to the sensitivity of the information, and retain personal information only as long as reasonably necessary for the purposes described in this Policy or as required by law.
#### Quebec
Where Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25) applies to personal information we hold:
- our Privacy Officer (Section 22) is the person in charge of the protection of personal information, and their contact information is published in this Policy;
- we conduct and document privacy assessments for projects involving the acquisition, development, or overhaul of information systems that handle personal information, and before communicating personal information outside Quebec — taking into account the sensitivity of the information, the purposes of the communication, and the protection available in the receiving jurisdiction;
- where a decision about an individual is based exclusively on automated processing, we inform the individual and provide an opportunity to submit observations and to have the decision reviewed by a person. Booking actions taken by the AI assistant are subject to the business's approval workflow and to human takeover, as described in Section 10;
- we notify the Commission d'accès à l'information du Québec and affected individuals of confidentiality incidents presenting a risk of serious injury, and we keep a register of confidentiality incidents (Section 16);
- consent for a minor under 14 is given by the person having parental authority or the tutor, except where the law permits collection that is clearly for the minor's benefit;
- where the law provides a right to cessation of dissemination or de-indexing, individuals may exercise it through the request process in Section 17 — BookingAPI does not publicly disseminate end-customer personal information in the ordinary operation of the Service;
- you may complain to our Privacy Officer and to the Commission d'accès à l'information du Québec.
United States
Where applicable, residents of California and other US states with comprehensive privacy laws may have the following rights and disclosures.
For end-customer booking and messaging data processed on behalf of a business, BookingAPI acts as a service provider/processor. The business you interacted with is the party responsible for responding to consumer-rights requests about that data, and we support businesses in doing so.
#### Categories of personal information collected
We may collect:
- identifiers, such as name, email address, phone number, account identifiers, IP address, Google account identifiers, Stripe identifiers, and device identifiers;
- commercial information, such as billing records, invoice records, token or credit purchase history, and subscription status;
- internet or network activity, such as logs, cookies, API activity, page views, and diagnostic data (plus Cloudflare analytics data if we ever enable it — not currently deployed, see Section 7);
- approximate geolocation data inferred from IP address;
- professional or business information, such as company name, staff profile details, business settings, and service offerings;
- customer records, such as booking details and contact details;
- calendar information where a business connects Google Calendar;
- message content, where submitted through support, booking, or WhatsApp AI Agent features;
- sensitive personal information only where users, businesses, or end-customers choose to submit it in booking notes, messages, support communications, or similar free-text fields.
#### Categories of sources
We collect personal information:
- directly from you;
- automatically from your use of the Service;
- from business customers;
- from end-customers through booking flows or messaging features;
- from connected integrations you authorize;
- from service providers.
#### Business or commercial purposes
We use personal information to:
- provide the Service;
- manage accounts;
- process bookings;
- provide customer support;
- provide calendar and messaging integrations;
- secure the Service;
- prevent fraud and abuse;
- manage billing, subscriptions, tokens, credits, payments, and invoices;
- maintain and improve the Service;
- comply with legal obligations;
- enforce our terms and agreements.
When we process end-customer booking or messaging data on behalf of a business, we use that data only as described in this Policy and our agreement with the business.
#### Categories of third parties disclosed to
We may disclose personal information to:
- service providers and subprocessors;
- integration partners you authorize;
- business customers in connection with their end-customer relationships;
- payment processors;
- communications providers;
- professional advisers;
- legal, regulatory, law enforcement, or government authorities;
- parties involved in business transfers or legal proceedings.
#### Sensitive personal information
We do not intentionally collect sensitive personal information except where users, businesses, or end-customers choose to submit it in booking notes, messages, support communications, or similar free-text fields.
We do not use sensitive personal information to infer characteristics, create advertising profiles, or conduct unrelated profiling.
#### Your state-law rights
Depending on your state, you may have the right to know and access the personal information we hold about you, to correct inaccurate personal information, to delete personal information, to obtain a portable copy, and to appeal a decision on your request. Retention periods for the categories listed above follow the schedules described in Section 14 of this Policy.
#### Sale or sharing; universal opt-out signals
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not process personal information for targeted advertising. Because we do not engage in these activities, we do not currently offer a sale/share/targeted-advertising opt-out, and universal opt-out signals such as the Global Privacy Control do not change our practices. If we ever begin selling or sharing personal information, we will provide the required opt-out mechanisms, honor the Global Privacy Control and similar recognized signals as a valid opt-out without requiring further action by the consumer, and update this Policy first.
#### How to exercise rights
Submit a request by emailing privacy@bookingapi.ca. We will verify your identity before responding.
#### Non-discrimination
We will not discriminate against you for exercising privacy rights.
#### Appeals
Where applicable law provides a right to appeal, you may appeal by emailing privacy@bookingapi.ca with the subject line "Privacy Request Appeal."
EEA, UK, and other jurisdictions
BookingAPI is not currently offered to business customers in the EEA or UK except where expressly approved in writing by BookingAPI.
If you are located in the EEA, UK, or another jurisdiction with privacy rights that apply to your interaction with BookingAPI, you may contact us at privacy@bookingapi.ca.
If you are an end-customer whose information was submitted to one of our business customers through a booking flow, messaging flow, or integration, your request should generally be handled by that business as the primary organization responsible for your booking relationship.
21. Changes to This Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will provide at least 30 days' advance notice by posting a prominent notice on our website and, where we have an account email address, by email or through the Service — except where a shorter period is required to comply with law or to protect users or the Service, in which case we will give as much advance notice as reasonably possible.
The "Last updated" date at the top of this Policy indicates when it was last revised.
22. Accountability and Contact Us
BookingAPI has designated a Privacy Officer responsible for overseeing compliance with this Policy and applicable privacy laws, including as the person in charge of the protection of personal information under Quebec law. The Privacy Officer can be reached using the contact information below.
Privacy complaints are acknowledged, investigated under the direction of the Privacy Officer, and answered within the timelines described in Section 17. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or your local privacy regulator.
If you have questions about this Policy, want to make a privacy request, or want to submit a privacy complaint, contact us at:
BOOKINGAPI INC. 375 University Avenue Suite 3347 Toronto, ON M5G 2J5 Canada
Privacy Officer: privacy@bookingapi.ca General Support: hello@bookingapi.ca
Mail sent to this address is monitored on a regular schedule; for privacy requests, email is the fastest and preferred way to reach us.