Skip to main content

Privacy Policy

Last updated: August 23, 2026

This Privacy Policy explains how Bookibles ("we", "us", or "our") collects, uses, and shares information when you use our website and booking services. We aim to collect only what we need to run the Service.

1. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, password hash, and (for businesses) profile details such as description, category, location, hours, and photos.
  • Booking information — the services you book or offer, appointment times, and messages exchanged about a booking.
  • Google Calendar information (optional)— when a business owner connects Google Calendar, OAuth authorization data, calendar-list metadata, selected calendars' free/busy intervals, and identifiers for the calendar and booking events Bookibles creates. Section 4 explains this integration in detail.
  • Payment information — handled by our payment processor; we do not store full card details.
  • Usage and device data — basic analytics such as pages visited and general performance metrics, used to improve the Service.

2. How we use your information

We use information to:

  • Provide, maintain, and improve the Service.
  • Enable bookings, messaging, and notifications between customers and businesses.
  • Process subscriptions and prevent fraud or abuse.
  • Communicate with you about your account, bookings, and updates.
  • Operate optional Google Calendar sync by managing booking events in a Bookibles-created calendar and using selected calendars' busy times to avoid offering occupied times.

3. Public content

Business profile information is public and may be indexed by search services. We may hide or remove content that violates our Terms, exposes personal data, is fraudulent, or creates legal or safety risk.

4. Optional Google Calendar integration

A business owner may choose to connect a Google account for calendar sync. This is separate from using Google to sign in. To provide the integration, Bookibles:

  • Reads the Google calendar list so the owner can choose which calendars affect availability. Bookibles stores each listed calendar's identifier, title, and whether it is the primary calendar.
  • Queries free/busy availability for the calendars the owner selects and stores their busy start and end times. This does not provide Bookibles with event titles, descriptions, attendees, or locations from those selected calendars.
  • Creates a separate Google calendar named for the business and creates, updates, or deletes Bookibles booking events in that calendar. Bookibles sends the business name and time zone when creating the calendar. Booking events contain the service name, customer name, booking date, and, when applicable, start and end times and time zone.

Google provides short-lived access tokens and a refresh token after the owner grants permission. Bookibles uses them on its servers to run sync when the owner is not present. The refresh token is stored in encrypted form; short-lived access tokens are not stored. The authorization code and its verification secret are deleted after the connection attempt finishes.

Disconnecting Google Calendar in Bookibles stops future sync, deletes stored OAuth credential material, and removes imported busy-time intervals. Limited connection and synchronization history remains under the retention terms below, including a connected-account label when returned by Google, calendar identifiers and cached titles, and identifiers linking Bookibles bookings to the corresponding Google events. The separate calendar and booking events already written to Google remain in the Google account until they are removed there. Disconnecting in Bookibles does not separately revoke Bookibles in the owner's Google Account settings.

Bookibles uses Google Calendar data only to provide and improve the calendar-sync feature. We do not sell this data, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models. Bookibles' use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. Service providers

We share data with third parties only as needed to operate the Service. These include cloud database hosting, authentication providers (such as Google and Facebook when you choose to sign in with them), Google Calendar when a business owner chooses to connect it, our payment processor (Lemon Squeezy), file/image hosting, real-time messaging infrastructure, and email delivery. Each processes data on our behalf under their own terms.

6. Cookies

We use essential cookies to keep you signed in and to remember preferences such as your theme. We may use limited analytics to understand aggregate usage. You can control cookies through your browser settings.

7. Data retention

We keep personal data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account at any time.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the details below.

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from them.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above.

11. Contact

Questions about your privacy or this policy? Reach us through our contact page.