Skip to content

Privacy Policy for Mobile App

Effective Date: 29-08-2026


This policy explains how Bookora (“we,” “our,” or “us”) handles personal data when you use the Bookora mobile app.

Bookora is the controller of the personal data it needs to provide, secure, support, improve, and promote the app — your account, your subscription status, security and diagnostic data, usage and marketing-measurement data, and your support requests.

Information you enter into Bookora about other people — your clients, and the staff of a business you run (“Client Data”) — is information you decide to collect and use. Bookora stores and processes it in order to provide the app to you and does not use it for its own purposes. Your responsibilities for Client Data are set out in the Terms of Service.

Contact details are in Section 12.

CategoryExamplesWhere it comes from
Account and profileName, contact details, profile photo, language, account preferencesYou
Business and schedulingServices, prices, working hours, addresses, appointments, tasks, booking settingsYou
Client DataClient names and contact details, booking notes, messages you send, and their delivery statusYou, or a device contact you select
TeamMembership, role, invitation status, and actions taken by a team owner. Includes a single-use invitation code when you ask Bookora to generate oneYou and your team owner
SubscriptionWhich plan is active, whether a trial is running, and when access starts or endsApple, Google, or our subscription provider
Technical and usageDevice identifier, IP address, time zone, language, region, User-Agent, app version, crash reports, and performance dataCollected automatically
Advertising and analyticsDevice advertising identifiers — on iOS, the IDFA (only if you grant the tracking permission) and the IDFV; on Android, the Google Advertising ID — an internal identifier we assign to your account, and in-app events such as completing onboarding, opening a feature, or starting a subscriptionCollected automatically; the IDFA only with your permission
SupportThe messages and details you send usYou

Device contacts. With your permission, Bookora copies the name and phone number of the individual contacts you select in order to create client records. Bookora never copies your address book automatically.

Payments. All payments are made to Apple or Google. Bookora does not process payments and does not receive your payment-card details, bank details, or billing address — only the resulting subscription status.

IP addresses. Your IP address is recorded in our server request logs, which we keep for up to 30 days for security, abuse prevention, and troubleshooting. An IP address indicates an approximate region rather than a precise location.

We do not sell personal data and do not show you third-party advertising in Bookora. We do use advertising identifiers to measure our own marketing campaigns, as described in Sections 5 and 8.

Section titled “3. Why We Process It — Purposes and Legal Bases”
PurposeLegal basis
Create and run your account; provide scheduling, client records, online booking, notifications, and supportPerformance of our contract with you
Optional features that ask your permission — device contacts, Google Calendar, profile photo, notification channels where consent is required, and access to the iOS advertising identifier through the App Tracking Transparency promptYour consent (GDPR Art. 6(1)(a)), withdrawable at any time
Security, abuse and fraud prevention, error and crash monitoring, usage analytics, and improving the appOur legitimate interests
Measuring which advertising campaigns bring users to Bookora and how they performYour consent for access to the iOS advertising identifier; otherwise our legitimate interests, using aggregated, privacy-preserving measurement
Tax and accounting records, responding to lawful requests, and establishing or defending legal claimsLegal obligation, or our legitimate interest in legal claims

Withdrawing consent does not affect processing already carried out lawfully, or processing that rests on one of the other bases above.

This section covers only the privacy consequences of each feature. How the features themselves work is described in our documentation, which is linked from each entry.

Turning on online booking publishes a page that anyone can open without a Bookora account. It shows what you chose to make public: your name, and the profile photo, phone number, and Instagram account on your profile; the addresses and services you made bookable; and the free time slots Bookora calculates from your calendar and booking settings.

Only the free slots are published. Bookora reads your calendar to work out when you are busy, but the events themselves — and the clients, prices, and notes attached to them — are not part of the page. Booking details a client submits are not shown publicly either.

Anything on a public page can be viewed, shared, indexed, or cached by other people and services. Removing information updates Bookora’s pages, but Bookora cannot recall copies saved elsewhere. See Online booking.

A profile photo is optional. If you use one while online booking is on, it is visible to anyone who opens your booking page. You can remove or replace it at any time, and it is deleted when your account is deleted. See Profile photo.

If you join a team, the team owner gets full administrative access to your Bookora workspace. In practice the owner can see and change everything you can — your calendar and appointments, your clients together with their contact details and any notes about them, your services and prices, your profile information, and team-managed settings. This is not limited to the online-booking and notification settings the owner also controls: while you are a member of the team, nothing in your workspace is hidden from the owner.

That access begins when you accept the invitation and ends the moment you are removed from the team — including when a smaller subscription no longer covers your seat. Your own sign-in is not affected, and being removed does not delete your separate account or its data.

Generating an invitation code does not add you to a team, does not give an owner access to your account, and does not share your account information beyond what is needed to show a pending invitation. Before you join, the app asks you to confirm the owner-access notice explicitly.

If you are a team owner or a business, you must have a lawful reason for the staff and client information you add, must tell those people how you use Bookora where required, and must use your access only for legitimate business purposes.

See Team accounts, Team invitations, and Switching accounts.

Google Calendar sync is optional and off until you enable it in Bookora Settings. The legal basis is your consent under GDPR Art. 6(1)(a), given through the Google OAuth consent screen and withdrawable at any time.

Bookora’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • https://www.googleapis.com/auth/calendar.calendarlist.readonly“See the list of Google calendars you’re subscribed to.” We use this so you can pick which calendar to sync.
  • https://www.googleapis.com/auth/calendar.events.owned“See, create, change, and delete events on Google calendars you own.” We use this to run a two-way sync on the single calendar you select. Google restricts this scope to calendars you own.
  • https://www.googleapis.com/auth/userinfo.email“See your primary Google Account email address.” We use this to label which Google account is linked to your Bookora account.

The integration is a two-way sync limited to the single Google calendar you select. We read events on that calendar — including events you or other apps created — and write events from Bookora into it. We store an OAuth refresh token to run the sync in the background.

We do not access any other calendar, do not access calendars shared with you by other Google users, do not change any calendar’s sharing settings, and do not access Gmail, Drive, Contacts, or any other Google product.

Google Calendar data is used solely to power the sync. We do not use it for advertising, profiling, or training machine-learning models, and we do not sell, rent, share, or transfer it to any third party. Humans do not read your Google data except with your explicit consent for a specific support request, where required by applicable law, or for security investigations of suspected abuse.

OAuth refresh tokens are encrypted at rest with AES-GCM, calendar event data lives in your account record in our primary database, and all traffic to Google APIs uses TLS 1.2 or higher. Google Calendar data is processed on servers in the United States; transfers from the EEA or UK rely on the EU–US Data Privacy Framework and Standard Contractual Clauses where applicable.

If you have joined a team, calendar information synced into Bookora is available to your team owner through the team access described above. The owner does not receive your Google login or any direct access to your Google account.

To disconnect, open Bookora Settings and tap “Disconnect.” Bookora then revokes its access with Google, deletes its encrypted copy of the refresh token, and removes the events that Bookora itself created in your Google Calendar. Events that originated in your Google Calendar are left alone. Removing events from Google is best-effort: if Google’s API returns a transient error, a small number may remain — reconnecting and disconnecting again retries the cleanup.

Your event records inside Bookora are preserved, so your schedule and history are not lost.

Revoking access from your Google Account at myaccount.google.com/permissions stops further Google API calls but does not by itself delete data Bookora already holds. To clear that data, disconnect from Bookora Settings or delete your Bookora account.

Being removed from a team, or a subscription change that withdraws Premium access, may also disconnect the integration. It must then be connected again; it is not restored automatically. See Google Calendar.

We share personal data only where it is needed to provide Bookora, or where law permits or requires it. Recipients may include:

  • The specialist or business responsible for a booking, and an authorised team owner as described in Section 4.
  • Apple and Google, for purchases and subscription status, under their own privacy policies.
  • Google, for the optional Calendar integration you enable.
  • Amplitude, Inc., for the product analytics described below.
  • AppsFlyer Ltd., for the install attribution and marketing measurement described below.
  • Service providers that support hosting and storage, message delivery across the channels described in Notifications, email, log storage, error monitoring, usage analytics, subscription management, security, and customer support. We have data processing agreements in place that require them to protect the data and use it only for the purposes we specify.
  • Authorities, professional advisers, or a business successor, where legally necessary and subject to appropriate safeguards.

We use Amplitude, a product analytics service provided by Amplitude, Inc., to understand how Bookora is used so we can improve it. When you use the app, we share with Amplitude:

  • an internal identifier we assign to your account;
  • the actions you take in the app — for example, completing onboarding, opening a feature, or starting a subscription;
  • device and technical information, such as device model, operating system version, app version, language, time zone, and approximate location derived from your IP address.

We do not share your name, email address, or the contents of your business records — such as your clients’ names, contact details, or appointments — with Amplitude. Amplitude processes this information on our behalf. You can review Amplitude’s privacy policy at amplitude.com/privacy.

Advertising attribution and marketing measurement

Section titled “Advertising attribution and marketing measurement”

We use AppsFlyer, a mobile measurement service provided by AppsFlyer Ltd., to understand which marketing campaigns and channels bring users to Bookora and how those campaigns perform. For this purpose, we share with AppsFlyer:

  • device identifiers: on iOS, the Identifier for Advertisers (IDFA) — only if you grant the tracking permission described in Section 8 — and the Identifier for Vendors (IDFV); on Android, the Google Advertising ID;
  • technical information, such as IP address, device model, operating system version, app version, language, and time zone;
  • app events, such as first launch, account registration, onboarding completion, and viewing subscription offers;
  • subscription events — such as trial start, purchase, and renewal — including the product identifier and price, which our subscription management provider forwards to AppsFlyer on our behalf;
  • an internal identifier we assign to your account.

AppsFlyer uses this information to attribute app installs to advertising campaigns and to measure campaign performance for us and for the advertising networks we work with (such as Apple Ads, Google Ads, and TikTok), in attributed or aggregated form. As with analytics, we do not share your name, email address, or the contents of your business records with AppsFlyer. AppsFlyer’s privacy policy, including how to opt out of its measurement, is available at appsflyer.com/legal/services-privacy-policy.

Error monitoring. We configure our error monitoring so that it does not receive your name, email address, or other directly identifying account details. Crash and performance reports still contain technical information such as device type, operating system, app version, and the error itself.

Service providers may use the information only to perform their services for Bookora or as otherwise permitted by law, and they have their own privacy policies governing their operations.

DataRetention
Account, profile, scheduling, and Client DataWhile your account is active, until you delete it
Account after a deletion requestSeven-day grace period, then removal from active systems; complete within 30 days
BackupsUntil the backup cycle completes, within 30 days of deletion
Invitation codesDeleted automatically once used or expired
Diagnostic and troubleshooting logsUp to 30 days
OAuth callback audit logs (no token contents)90 days
Records we are required to keep by law, or need for legal claimsFor the period required
Irreversibly anonymised or aggregated dataMay be retained, as it no longer identifies you

Deleting your account. You can request deletion from the app’s settings. You are signed out immediately, and a seven-day grace period begins during which signing back in cancels the request. After that, we delete the account from our active systems, delete the account’s profile photo, disconnect optional integrations such as Google Calendar, and end the account’s team relationships — a member is removed from their owner’s team, and an owner’s team is dissolved so each member continues as an independent account. Deleting an owner’s account does not delete a member’s separate account or their own data. We also initiate deletion requests with the third-party services that hold your data — including AppsFlyer and Amplitude — though their own retention policies may apply. After 30 days the deletion is complete and irreversible. See Account deletion.

You can remove a profile photo separately, without deleting your account. If Bookora-hosted content is still reachable after it should have been removed, contact us.

Bookora’s infrastructure and some of our service providers are located outside the European Economic Area and the United Kingdom. When personal data is transferred out of the EEA or UK, we rely on one of the following safeguards:

  • Adequacy decisions issued by the European Commission or the UK Government for the destination country.
  • EU Standard Contractual Clauses (2021/914) and, for UK transfers, the UK International Data Transfer Addendum or IDTA.
  • Additional technical and organisational measures — including encryption in transit and at rest and access controls — where the destination country has no adequacy decision.

You can request a copy of the safeguards in place by contacting us.

You can update most of your account, profile, and public booking information in the app, and you choose whether to upload a photo, select a device contact, publish a booking page, connect Google Calendar, or allow access to your device’s advertising identifier.

Your tracking choices. On iOS, we ask for your permission through Apple’s App Tracking Transparency framework before accessing your device’s advertising identifier (IDFA). If you decline, we do not access the IDFA, and advertising measurement is performed using aggregated, privacy-preserving methods (such as Apple’s SKAdNetwork) that do not identify you or your device. You can change your choice at any time:

  • iOS: Settings → Privacy & Security → Tracking;
  • Android: delete or reset your Advertising ID in your device’s Google settings;
  • you may also opt out of AppsFlyer’s measurement directly with AppsFlyer, as described in AppsFlyer’s privacy policy.

Withdrawing the tracking permission does not affect Bookora’s functionality.

Depending on where you live, you have the right to access your personal data, correct inaccurate information, request erasure, receive a copy in a machine-readable format, object to processing based on legitimate interests, restrict processing in certain circumstances, and withdraw consent. You may also complain to your data-protection authority.

To exercise a right, email support@bookora.me. We may need to verify your identity. Because most of our processing is necessary to provide the app, exercising certain rights may require deleting your account. If a request concerns Client Data that a specialist or business is responsible for, we may direct the request to them or work with them to respond.

Automated decisions. We do not make decisions about you solely by automated means that produce legal effects concerning you or similarly significantly affect you, and we do not profile you in ways that have such effects. Automated parts of the service — such as calculating free time slots from your calendar or applying the seat limit of your team’s plan — carry out the settings you or your team owner chose, and are not decisions of this kind. Neither are the analytics and campaign measurement described in Section 5.

We implement industry-standard technical and organisational measures to protect personal data, including encryption of data in transit, encryption at rest for credentials such as OAuth tokens, access controls that restrict data to authorised personnel, regular security review, and ongoing data protection training. Please also protect your device and account credentials, and sign out of any team session you no longer need.

No method of transmission over the internet or electronic storage is 100% secure. In the event of a personal data breach we will act in accordance with applicable data protection laws, which may include notifying the relevant supervisory authorities and affected individuals as required.

We do not knowingly collect personal information from children under 16, and Bookora is not intended for independent use by anyone under 16. If you believe a child has provided us with personal information, contact us so we can remove it.

We may update this policy when Bookora or legal requirements change. We will publish the current version and its effective date on this page and give additional notice where required by law.

For questions about this policy, privacy requests, or complaints:

Email: support@bookora.me