Privacy policy
Last updated July 25, 2026
This policy explains what personal data BookRails collects, why we collect it, who we share it with, and the rights you have over it. We do not sell personal data.
Who is responsible for your data?
BookRails is the controller for data about business owners who hold a BookRails account, and a processor acting on a business's instructions for data about that business's own customers. Questions go to privacy@bookrails.ai.
TODO: add registered entity name, company number, and registered address before launch.
What data do we collect?
We collect only what the service needs to operate:
- Account data — name, email, and authentication identifiers, handled by Supabase Auth (including Google sign-in, where Google returns your email and profile name).
- Business profile data — business name, address, phone, hours, services, prices, booking policies, and photos that you publish to your BookRails page.
- Calendar availability — where you connect Google Calendar, we read free/busy windows and write bookings we create. We do not read event titles, attendees, descriptions, or the contents of existing appointments.
- End-customer booking data — the name, phone, email, and requested service supplied by a person making a booking, whether through your hosted page or an AI assistant.
- Payment data — where a deposit is required, Stripe Checkout collects and processes card details on Stripe's own systems. Card numbers never reach BookRails servers.
- Usage and device data — pages viewed, referrer (including AI-assistant referrers), and aggregate analytics collected via Google Analytics 4.
- Operational records — visibility scans, generated drafts, publish status, and booking audit logs created on your behalf.
Why do we use it, and on what legal basis?
We use account and business data to provide the service (performance of a contract). We use booking data to create, confirm, and manage appointments on your behalf (performance of a contract, and our legitimate interest in operating a booking platform). We use analytics and scan data to measure and improve the service (legitimate interests). Where consent is required for non-essential cookies, we rely on consent, which you can withdraw at any time.
What do AI assistants see?
Third-party AI assistants connect to BookRails through our MCP server. They can read the same information a visitor to your public booking page can read: services, prices, hours, policies, a reviews summary, and open time slots. They cannot read your other customers, your existing bookings, your calendar event details, or anything else in your account.
A customer's name, phone, and email are collected only at the moment they book, and are passed into that booking only.
Who do we share data with?
We do not sell personal data and we do not share it with advertising networks. We use the following subprocessors:
- Supabase — database, authentication, and storage.
- Microsoft Azure — application hosting and infrastructure.
- Stripe — payment processing for deposits.
- Google — Calendar API (where you connect it) and Google Analytics 4.
- Our AI model gateway — routes the model calls that generate drafts and run visibility scans.
- Email and SMS delivery providers — booking confirmations and notifications.
Where is data stored and transferred?
Data is stored in our cloud provider's regions and may be processed in other countries where our subprocessors operate. Where personal data leaves the UK or EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
TODO: confirm hosting region and the applicable transfer mechanism before launch.
How long do we keep it?
Account and business data is retained while your account is active and for a limited period afterwards to meet legal and accounting obligations. Booking records are retained for the period required by tax and dispute-resolution rules. Analytics data is retained per the retention setting configured in Google Analytics.
TODO: set and publish specific retention periods before launch.
What rights do you have?
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to processing based on legitimate interests. California residents have the right to know, delete, and correct, and the right to opt out of sale or sharing — BookRails does not sell or share personal data as those terms are defined under the CCPA.
To exercise any of these rights, email privacy@bookrails.ai. You can also complain to your local data-protection authority.
How do we protect it?
We encrypt data in transit and at rest, scope database access with row-level security so each business reaches only its own records, store third-party OAuth tokens as encrypted references, apply least-privilege access controls, and keep an audit trail of booking operations.
Children
BookRails is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We will update this page when our practices change and revise the date above. Material changes will be notified by email to account holders.