This policy explains how BookingForNow (hereinafter, “the Platform”) processes personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Data controller
- Controller: David Suárez Marra
- Tax ID (NIF/CIF): 53504952Y
- Address: Calle José Hierro 6, portal 1, 5.º A, 28702 San Sebastián de los Reyes (Madrid), España
- Contact email for data protection matters:[email protected]
2. Data we process
About the person or company that subscribes to the Platform: business name, your name if you provide it when signing up (used to greet you and as the first professional in the calendar), email address, password (stored encrypted by our authentication provider), business sector if provided, the account’s language, country, time zone and currency (inferred from your browser), and service usage data.
About the end clients managed by the business: the contact and appointment details that the business enters or that are collected through its online booking page. For this data, the business acts as the data controller and the Platform as the data processor, processing it solely on the business’s instructions.
Payment data: subscription payments are processed entirely through Stripe. The Platform does not store card numbers or financial payment details; we only keep the identifiers and subscription status needed for billing.
3. Purposes and legal basis
- Providing the service and managing the account — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Billing and management of subscription payments — legal basis: performance of a contract and compliance with legal obligations (Art. 6(1)(b) and 6(1)(c) GDPR).
- Operational and support communications (service notices, reminders) — legal basis: performance of a contract and legitimate interest (Art. 6(1)(f) GDPR).
- Security and prevention of fraud and abuse — legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Aggregate measurement of site usage (see section 4) — legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Compliance with legal obligations — legal basis: Art. 6(1)(c) GDPR.
4. First-party analytics, without cookies
We measure visits with our own system, hosted on our servers: we do not use Google Analytics or any third-party tool, and we do not set cookies or persistent identifiers for this purpose. For each page visited we record the path (without parameters), the referring domain, the browser language, the approximate country, the device type (mobile, tablet or computer), the campaign parameters (UTM) and, only when you are signed in, the business the account belongs to.
To count unique visitors per day, the server calculates an anonymous fingerprint from a key that changes every day, the IP address and the browser. The IP address is not stored, and the fingerprint cannot be used to recognise the same person from one day to the next or to reconstruct their identity.
This measurement is automatically disabled if your browser sends the Do Not Track or Global Privacy Control signal.
5. Recipients and data processors
To provide the service we rely on the following providers, which act as data processors under their respective data processing agreements:
- Supabase — database and authentication (hosting of account and appointment data).
- Stripe — payment processing and subscription management.
- Resend — sending of transactional emails.
- Vercel — hosting of the web application.
- Cloudflare — content delivery network (CDN) and anti-bot verification (Turnstile).
We do not sell or disclose personal data to third parties for advertising purposes.
6. Data retention
We keep the data while the account remains active and, after it is cancelled, for the legally required periods (for example, tax and accounting obligations). Once those periods have elapsed, the data is deleted or anonymised. In addition, the Platform automatically applies the following periods:
- Log of emails sent (confirmations, reminders and other notices): after 12 months each entry is anonymised (the recipient, subject and other details are removed), and after 3 years it is deleted. Trial-period notices sent to the account holder are not anonymised earlier, because they are used to avoid sending them twice, and are also deleted after 3 years.
- Audit log (which changes were made to the account and by whom): deleted after 3 years.
- Backups: automatic daily backups are kept for 14 days, and those created right before a restore for 30 days. They are stored encrypted.
- End clients deleted by the business: they are not physically deleted; instead, their record is anonymised (their name, contact details, address, the general remarks on their record and attached documents are removed, their email address is removed from the email logs, and their future appointments are cancelled). Their appointment history, clinical notes and signed consent forms are kept, linked to the anonymised record, because of the legal obligation to retain clinical documentation.
7. Rights of data subjects
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability, and withdraw any consent you have given. To exercise them, write to us at [email protected] stating the right you wish to exercise. You also have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with the regulations.
If you are an end client of a business that uses the Platform, please address your requests to that business, which is the controller of your data.
8. International transfers
Some of our providers may process data outside the European Economic Area. In such cases, the transfers are covered by the safeguards provided for in the GDPR, mainly the Standard Contractual Clauses (SCCs) approved by the European Commission and any appropriate supplementary measures.
9. Contact
For any question regarding this policy, you can write to us at [email protected]. See also our Cookie policy.