Booked is a scheduling platform operated by Brightstack, a division of Michell + Marteen LLC, Houston, Texas.
1.Information We Collect
1.1 Information you provide directly
Account information: name, email address, password (hashed, never stored in plain text), profile photo (optional).
Calendar and scheduling data: event types, availability schedules, meeting preferences, booking details including invitee names, email addresses, and phone numbers.
Meeting content: video conference links, dial-in numbers, meeting notes, and join instructions.
Billing information: processed by our payment provider; we do not store full payment card numbers.
Communications: messages sent via support or email.
1.2 Information collected automatically
Usage data: pages visited, features used, button clicks, and session duration.
Device and browser data: IP address, browser type, operating system, and referring URL.
Cookies: see our Cookie Policy.
1.3 Information from third parties
Calendar providers: if you connect Google Calendar or Microsoft Calendar, we access only busy/free status and create/update booking events — we do not read existing event content.
OAuth providers: if you sign in with Google or Apple, we receive your name and email from that provider.
2.How We Use Your Information
We use your information to:
- Operate and provide the Service.
- Send transactional emails and SMS (booking confirmations, reminders, cancellations).
- Improve and personalize the Service, including AI scheduling features that learn from your booking patterns.
- Respond to support requests.
- Comply with legal obligations.
- Detect and prevent fraud and security incidents.
We do NOT sell your personal data, use your calendar content to train shared AI models, or share meeting content with other tenants.
3.How We Share Your Information
Service providers: Supabase (database and infrastructure), Twilio (SMS), email delivery provider, and payment processors — each bound by data processing agreements.
Invitees: booking details are shared between host and invitee to operate the Service.
Legal requirements: when required by law or to protect user safety.
Business transfers: with notice to affected users.
4.Data Retention
Account data: retained for the life of your account plus 90 days after deletion.
Booking records: retained for 12 months after the booking date.
Email and SMS logs: retained for 90 days.
You may request deletion at any time.
5.Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Row-level security (RLS) ensuring tenant data isolation.
- Regular security reviews and vulnerability scanning.
- SOC-2-aligned infrastructure controls.
Report vulnerabilities to security@brightstack.us.
6.Your Rights
All users: access, correction, deletion, portability, and opt-out of marketing communications.
EU/EEA users (GDPR): legal basis is contract performance, legitimate interests, and consent. Right to object, withdraw consent, and lodge a complaint with your data protection authority.
California residents (CCPA/CPRA): right to know, delete, correct, and opt out of sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. No discrimination for exercising privacy rights.
To exercise any right: privacy@brightstack.us. Response within 30 days (GDPR) or 45 days (CCPA).
7.Children's Privacy
Not directed to individuals under 16. Contact privacy@brightstack.us if you believe we have collected data from a child.
8.International Data Transfers
Servers located in the United States. EU/EEA and UK transfers rely on Standard Contractual Clauses (SCCs).
9.Changes to This Policy
Material changes notified by email or in-app notice at least 14 days before taking effect.
10.Contact
Brightstack / Michell + Marteen LLC, Houston, Texas
privacy@brightstack.us · brightstack.us