Last updated: 25 August 2026
BookdIn ("BookdIn," "we," "us," or "our") provides booking, scheduling, CRM, payments, and AI-assisted operations tools (including an AI office assistant and an AI voice receptionist) to service businesses ("Business," "you," when referring to our direct customer) and, through them, to their end customers ("Customers"). This policy explains what data we collect, why, and how it's handled.
This policy covers two groups: businesses that sign up for a BookdIn account to run their operations, and the customers of those businesses who interact with a Business through BookdIn — for example by booking a service online or calling a phone number answered by a BookdIn voice agent.
From Businesses: account and contact details (name, email, phone), business details (name, address, services, pricing), team member information, and any third-party account connections you choose to authorize (for example Google Ads, Stripe, or a phone/SIP provider).
From Customers, via a Business's use of BookdIn: name, contact details, service address, booking history, payment information (processed by Stripe — BookdIn does not store full card numbers), and, if a Business enables the AI voice agent, call audio, transcripts, and call metadata (phone number, duration, outcome).
Automatically: standard technical data such as device/browser information and usage logs, used for security, debugging, and improving the product.
We rely on trusted subprocessors to operate BookdIn, including: Supabase (database and authentication), Stripe (payments), Vapi and its underlying speech/AI providers — currently Deepgram (speech-to-text), ElevenLabs and/or OpenAI (voice), and Anthropic and/or OpenAI (conversation intelligence) — for the voice agent, Anthropic (AI office assistant), and Google (for businesses that connect Google Ads). Each handles data only as needed to provide their respective service to us, under their own security and privacy commitments.
Where a Business connects a Google Ads account, BookdIn's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only access to advertising performance data for the sole purpose of displaying it back to the connected Business, and we do not use this data for advertising or sell it to third parties. A Business can disconnect this access at any time from BookdIn's Settings, or directly from their Google Account permissions page.
We retain data for as long as a Business's account is active, and for a reasonable period afterward to meet legal, accounting, or dispute-resolution obligations. Call recordings and transcripts are retained to support quality review and record-keeping, and can be deleted on request.
Depending on where you're located, you may have rights to access, correct, export, or delete your personal information. Businesses can manage most Customer data directly within BookdIn. To make a request regarding your own data, contact us using the details below.
We use industry-standard safeguards — encryption in transit and at rest for sensitive fields, access controls, and least-privilege service credentials — to protect the data we hold. No system is completely secure, and we encourage Businesses to use strong, unique passwords and enable available account protections.
We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page.
Questions about this policy or your data can be sent to jonathan.sarandis@gmail.com.