Privacy Policy

Last updated: June 2026

This Privacy Policy explains how Green Candle Digital Studio ("we", "us", "our") collects, uses, stores, and shares personal data in connection with the Bookky platform. It applies to:

  • Business owners and staff who use the Bookky admin dashboard ("Clients")
  • Customers who book appointments through a Bookky-powered booking page ("End Users")

We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who Is the Data Controller?

Green Candle Digital Studio is the data controller for:

  • Client account data (business owner and staff personal data)
  • Platform usage data collected for security and service improvement

For End User personal data (name, email, phone, booking details collected during a booking), the Client (the business)is the data controller and Green Candle Digital Studio acts as a data processor on the Client's behalf. Clients are responsible for their own privacy notices to End Users.

Contact our data protection point of contact: [email protected]

2. What Personal Data We Collect

2a. Client / Admin Users

Name:Provided at registration
Email address:Provided at registration; used for login and communications
Password:Stored as a bcrypt hash via Supabase Auth — never in plaintext
Business information:Business name, address, phone, logo, timezone, and settings
Stripe account data:Connected Stripe account ID (we do not store full card details)
Staff records:Name, working hours, services — as entered by the Client

2b. End Users (booking customers)

Name:Required for booking confirmation
Email address:For booking confirmation and reminders
Phone number:For booking confirmation; may be used for SMS reminders (if enabled)
Custom fields:Any additional fields configured by the Client (e.g. notes, vehicle reg)
Payment tokens:Stripe payment intent IDs only — no card data stored on our servers

2c. Automatically Collected Data

IP address:Logged for security and fraud prevention
Browser / device type:Collected by Vercel edge analytics
Session tokens:Stored in an HttpOnly cookie for authentication (Supabase)
Audit log:Timestamped record of booking create / cancel / modify events

3. How and Why We Use Personal Data

We process personal data for the following purposes and legal bases:

PurposeLegal basis (UK GDPR)Applies to
Providing the Platform and booking serviceContract (Art. 6(1)(b))Clients & End Users
Sending booking confirmations and remindersContract / Legitimate interestsEnd Users
Processing payments and issuing receiptsContract (Art. 6(1)(b))Clients & End Users
Account management and supportContract (Art. 6(1)(b))Clients
Security, fraud prevention, and audit loggingLegitimate interests (Art. 6(1)(f))All
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))All
Product improvement and analyticsLegitimate interests (Art. 6(1)(f))Clients
Marketing and product updates (opt-in only)Consent (Art. 6(1)(a))Clients

4. Sub-processors and Third-Party Sharing

We do not sell personal data. We share data only with the following sub-processors, each bound by data processing agreements:

Supabase

Database, authentication, and file storage

Data location: EU (Frankfurt)

Privacy policy ↗

Stripe

Payment processing and Stripe Connect for Clients

Data location: USA (EU SCCs in place)

Privacy policy ↗

Resend

Transactional email (booking confirmations)

Data location: USA (EU SCCs in place)

Privacy policy ↗

Vercel

Platform hosting, edge CDN, and access logs

Data location: USA / EU edge (EU SCCs in place)

Privacy policy ↗

We may disclose personal data to law enforcement, regulators, or courts where we are legally obliged to do so, or to protect the rights, property, or safety of Green Candle Digital Studio, our Clients, or others.

In the event of a business sale, merger, or acquisition, Client Data may be transferred to the successor entity. We will give reasonable notice and ensure equivalent protections are maintained.

5. International Transfers

Stripe, Resend, and Vercel are based in the USA. We transfer personal data to them under UK International Data Transfer Agreements (IDTA) or Standard Contractual Clauses (SCCs) approved under the UK GDPR adequacy framework. Supabase data is stored within the EU and does not involve a third-country transfer.

6. Data Retention

We retain personal data only for as long as necessary:

Data typeRetention period
Client account dataDuration of Subscription + 30 days after termination
Booking records (financial)7 years (HMRC / Companies Act requirement)
End User contact detailsAs directed by the Client (controller); default 2 years from last booking
Security / access logs90 days
Audit log (booking events)7 years

7. Cookies

We use strictly necessary cookies only:

sb-access-token:Supabase session token. HttpOnly, Secure, SameSite=Lax. Session duration.
sb-refresh-token:Supabase refresh token. HttpOnly, Secure, SameSite=Lax. 60 days.

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. Under PECR and UK GDPR, a cookie consent banner is not required for strictly necessary cookies.

8. Your Rights Under UK GDPR

You have the following rights in relation to your personal data. To exercise any of them, email [email protected]. We will respond within one calendar month (extendable by two further months for complex requests, with notice).

  • Right of access (Art. 15) — obtain a copy of the personal data we hold about you and information about how we process it.
  • Right to rectification (Art. 16) — have inaccurate or incomplete data corrected.
  • Right to erasure (Art. 17) — request deletion of your data where there is no compelling reason for continued processing. Note: we may retain data where legally required (e.g. financial records).
  • Right to restriction (Art. 18) — request that we limit how we use your data in certain circumstances.
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format (applies to data processed by automated means on the basis of consent or contract).
  • Right to object (Art. 21) — object to processing based on legitimate interests. We will cease unless we can demonstrate compelling legitimate grounds.
  • Withdraw consent — where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.

We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.

9. Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • TLS encryption in transit for all data
  • AES-256 encryption at rest (Supabase managed)
  • Row-level security (RLS) in the database ensuring multi-tenant isolation
  • Access to production systems restricted to authorised personnel on a need-to-know basis
  • Regular dependency and security reviews

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Articles 33–34.

10. Children

The Platform is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us immediately at [email protected] and we will delete it promptly.

11. Changes to This Policy

We will post any updates to this page and update the "Last updated" date. For material changes, we will notify registered Clients by email at least 14 days before the change takes effect. Continued use of the Platform after that date constitutes acceptance of the updated policy.

12. Complaints

If you have concerns about how we handle your personal data, please contact us first at [email protected]. If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office · Wycliffe House · Water Lane · Wilmslow · SK9 5AF
ico.org.uk/make-a-complaint · 0303 123 1113

This document was last reviewed June 2026. This is not a substitute for independent legal advice.

Terms & Conditions · Cookie Policy · Back to sign in