Bookout Privacy Policy
DRAFT — NOT YET IN EFFECT. Working draft prepared without legal review. A qualified lawyer must review this document before it is published or relied on. Placeholders in [brackets] must be filled in first.
Version: 1.0-draft-2026-07-25 · Effective date: [TBD]
This policy explains how [Operator legal name] ("Bookout", "we") handles
personal data on bookout.studio and on sites hosted by Bookout.
1. Two roles: controller and processor
- For Owner accounts and platform data (owner email, name, login,
billing/fee records, platform emails) we are the data controller.
- For Member and visitor data collected through an Owner's site (names,
emails, phone numbers, booking requests and notes, contact messages,
journal subscriptions, order records) the Owner is the controller and
we are a processor acting on their instructions under our
Data Processing Addendum. Privacy questions about an Owner's
site should go to that Owner first.
2. What we collect
| Data | Who it belongs to | Why |
|---|---|---|
| Email, name, password (hashed by Supabase Auth) | Owners and Members | Accounts and sign-in |
| Site content, branding, photos | Owners | Operating the Owner's site |
| Booking requests, notes, contact messages, journal subscriptions | Members/visitors | Delivering the Owner's services |
| Order and subscription records (amounts, Stripe IDs — never card numbers) | Members, Owners | Payments, receipts, fee accounting |
| Terms-acceptance records (version, timestamp, IP, browser user-agent) | Owners | Proof of contract acceptance |
| Server logs (IP, request path, user-agent) | All | Security and debugging |
Card details go directly to Stripe; we never see or store card numbers.
We use a session cookie (ms_session) to keep you signed in. We do not use
advertising trackers.
3. Legal bases
Where GDPR or similar law applies: performance of a contract (accounts,
bookings, payments), legitimate interests (security, logs, fee accounting),
legal obligation (tax/accounting records), and consent where we ask for it
(e.g. journal email subscriptions, which you can leave via the unsubscribe
link in every email).
4. Who we share data with (sub-processors)
We share data only with the providers that run the platform:
- Supabase — database, authentication, storage
- Stripe — payment processing (Owner's own Stripe account + our platform fee)
- Bunny.net — hosting, CDN, media storage
- Resend — transactional and journal email
- Google — calendar sync, only for Owners who connect Google Calendar
We do not sell personal data. We disclose data if the law requires it.
5. International transfers
Our providers may process data in the United States and other countries.
Where required, transfers rely on the providers' standard contractual
clauses / Data Privacy Framework certifications. [Confirm transfer
mechanism per provider before go-live.]
6. Retention
Retention periods are listed in the Data Retention Policy.
In short: account data for the life of the account, tenant-site data until
the Owner deletes it or closes their site, financial records as long as tax
law requires, logs and backups on short rolling windows.
7. Your rights
You can ask us (or the relevant Owner, for their site's data) for access,
correction, deletion, or a copy of your data, and you can object to or
restrict processing where the law provides. Contact
[privacy@bookout.studio]. If we are the processor we will refer the request
to the Owner and help them answer it. You may also complain to your data
protection authority.
8. Children
Bookout is not directed at children. Owners must be 18+. Do not use the
platform if you are under 16.
9. Changes
We will post changes here and email Owners about material changes at least
30 days before they take effect.
10. Contact
[Operator legal name] · [postal address] · [privacy@bookout.studio]