Privacy Policy
Effective date: 2025-08-01
This Privacy Policy explains how FullyBooked ("we", "us", "our") collects, uses, discloses, and safeguards personal information when you visit our website or use our booking platform and related services (collectively, the "Services").
Information We Collect
- Account and Profile: name, email, phone number, business details, staff details.
- Booking Data: services booked, dates and times, location, notes, staff assignment, reminders.
- Payments: payment status, amounts, and limited transaction metadata processed via third-party providers. We do not store full card details.
- Usage and Device: IP address, browser and device information, pages viewed, and interactions for security and analytics.
- Support: information you provide in support requests and feedback.
How We Use Information
- Provide, operate, and improve the Services
- Process bookings, reminders, and notifications
- Enable payments and prevent fraud
- Provide customer support and service communications
- Analyze usage to improve performance and features
- Comply with legal obligations and enforce our Terms
Legal Bases (where applicable)
Depending on your location, we process personal data under one or more of the following bases: contract performance, legitimate interests (e.g., security, product improvement), consent (e.g., certain marketing), and legal obligations.
Sharing and Disclosure
- Vendors/Processors: trusted providers for infrastructure, payments, messaging, analytics, and support, bound by contractual obligations.
- Legal and Safety: to comply with law, legal process, or to protect rights, safety, and integrity of users and our Services.
- Business Transfers: in connection with a merger, acquisition, or asset sale, subject to continued protection of personal information.
Data Retention
We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and use case.
International Transfers
Your information may be processed and stored in countries other than your own. Where required, we implement appropriate safeguards for cross‑border data transfers.
Your Rights
- Access, Rectify, Delete: request a copy, correction, or deletion of your personal information.
- Portability: request a portable copy where applicable.
- Consent Management: withdraw consent for optional processing (e.g., marketing) at any time.
- Objection/Restriction: object to or request restriction of certain processing where provided by law.
Requests may be limited by applicable law and our need to protect the rights of others.
Regional Notices
- GDPR (EU/UK): you may have rights to access, erase, restrict, and object; you may lodge a complaint with a supervisory authority.
- CCPA/CPRA (California): you may request access, deletion, and to opt‑out of certain data sharing.
- Australian Privacy Act (APPs): collection notices, access/correction rights, and reasonable security practices apply.
Security
We use administrative, technical, and physical safeguards designed to protect personal information (e.g., HTTPS/TLS, access controls, least‑privilege). No method of transmission or storage is 100% secure.
Children’s Privacy
Our Services are not directed to children under the age required by applicable law. We do not knowingly collect personal information from children without appropriate consent.
Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “Effective date” and will be posted on this page.
Contact
Questions about this Privacy Policy or your data rights? Reach us via the site.