Privacy Policy

Effective as of February 1, 2026

1. Introduction

Bookwae ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform.

This policy applies to all users of the Bookwae platform, including business owners (outlets), staff members, and customers who make bookings.

2. Information We Collect

2.1 Information You Provide

  • Account data: Name, email address, phone number, password (encrypted)
  • Business data: Business name, address, logo, description, operating hours, photos/gallery
  • Booking data: Appointment date and time, selected services, special notes
  • Payment data: Information required to process transactions (processed by third-party payment gateways)

2.2 Information Collected Automatically

  • Device data: Browser type, operating system, screen resolution
  • Usage data: Pages visited, features used, access times
  • Location data: Approximate location based on IP address (no GPS tracking)
  • Cookies and similar technologies: For authentication, preferences, and analytics

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process bookings and appointments
  • Send appointment-related notifications (confirmations, reminders, changes)
  • Improve and optimize the Service
  • Provide customer support
  • Detect and prevent fraudulent activity or abuse
  • Comply with legal obligations
  • Send promotional information (with your consent)

4. Information Sharing

We do not sell your personal data. We only share information in the following circumstances:

  • Between outlets and customers: Booking data is shared between service providers and customers who make reservations
  • Third-party service providers: Payment gateways, email services, hosting providers (bound by confidentiality agreements)
  • Legal obligations: When required by law, regulation, or applicable legal process
  • Protection of rights: To protect our rights, property, or the safety of our users or the public

5. Data Security

We implement technical and organizational security measures to protect your data, including:

  • Data encryption in transit (HTTPS/TLS)
  • Hashed and salted password storage
  • Authentication tokens (JWT) with limited validity
  • Secure httpOnly cookies for token storage
  • Role-based access control (admin, staff, customer)
  • Regular data backups

While we strive to protect your data, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Cookies

We use cookies and similar technologies for:

  • Essential cookies: Authentication, session security, user preferences
  • Functional cookies: Remembering theme preferences (dark/light mode), language settings
  • Analytics cookies: Understanding how users interact with the Service

You can manage your cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.

7. Data Retention

We retain your data for as long as necessary to provide the Service and fulfill our legal obligations. In general:

  • Active account data: Retained while your account is active
  • Booking data: Retained for 3 years after the appointment date
  • Deleted account data: Removed within 30 days of deletion request (unless required by law)
  • Logs and analytics: Retained for 12 months

8. Your Rights

You have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your personal data
  • Right to data portability: Request your data in a machine-readable format
  • Right to object: Object to data processing for marketing purposes
  • Right to withdraw consent: Withdraw any previously given consent at any time

To exercise any of these rights, please contact us using the information below. We will respond to your request within 30 business days.

9. Third-Party Services

Our Service integrates with third parties that have their own privacy policies:

  • Google OAuth: For authentication via Google accounts
  • Google reCAPTCHA: For protection against bots and spam
  • Payment gateways: For processing payments

We recommend that you review the privacy policies of these third-party services.

10. Children's Privacy

Our Service is not intended for children under the age of 13. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13, we will promptly delete such data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced through the Service or via email. The effective date at the top of this page indicates when this Privacy Policy was last updated.

Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions, complaints, or requests regarding privacy, please contact us:

By using the Bookwae platform, you acknowledge that you have read and understood this Privacy Policy.