Data Use Policy

Effective: June 17, 2026 · Last updated: June 17, 2026

This policy explains specifically how Booked uses calendar, scheduling, and meeting data. It supplements the Privacy Policy.

1.Calendar and Availability Data

When you connect a calendar: we read busy/free status only to calculate available slots — we do NOT read event titles, descriptions, attendees, or content of existing events.

We write, update, and delete booking events on your calendar.

Calendar access tokens are encrypted at rest and never shared.

2.Booking and Meeting Data

Booking records stored per-tenant with row-level security — accessible only to your organization.

Meeting links, dial-in numbers, and join instructions transmitted to the invitee and stored on the booking record. Booking data never shared across tenants.

3.AI Scheduling Features

AI models learn from patterns within your account only — your data is never mixed with other customers.

We do not use meeting content to train general-purpose AI models. AI suggestions are generated using your account data and not stored as training data.

4.Invitee Data

Invitees' name, email, and phone are collected on your behalf. You are the data controller; we are your data processor.

Invitees may request deletion via privacy@brightstack.us.

Invitees who reply STOP to SMS are added to a suppression list and will not receive further SMS — required by carrier regulations and cannot be overridden.

5.Data Isolation and Security

Every query scoped by tenant_id using row-level security — one organization cannot access another's data.

All data encrypted in transit (TLS 1.2+) and at rest (AES-256).

Staff access requires MFA and is audit-logged.

SOC-2-aligned controls reviewed annually.

6.Data Export and Deletion

Export: all booking data available from Settings → Data.

Deletion: account deletion removes all data within 90 days.

Selective deletion: individual bookings and event types deletable from the dashboard at any time.

7.Third-Party Processors

Supabase, Inc. (database, storage, auth), Twilio, Inc. (SMS), email delivery provider, payment processor — each under a Data Processing Agreement. Full list: privacy@brightstack.us.

8.Contact

privacy@brightstack.us · 30 days (GDPR), 45 days (CCPA)
Michell + Marteen LLC / Brightstack, Houston, Texas