Privacy Policy

Effective: June 17, 2026 · Last updated: June 17, 2026

Booked is a scheduling platform operated by Brightstack, a division of Michell + Marteen LLC, Houston, Texas.

1.Information We Collect

1.1 Information you provide directly

Account information: name, email address, password (hashed, never stored in plain text), profile photo (optional).

Calendar and scheduling data: event types, availability schedules, meeting preferences, booking details including invitee names, email addresses, and phone numbers.

Meeting content: video conference links, dial-in numbers, meeting notes, and join instructions.

Billing information: processed by our payment provider; we do not store full payment card numbers.

Communications: messages sent via support or email.

1.2 Information collected automatically

Usage data: pages visited, features used, button clicks, and session duration.

Device and browser data: IP address, browser type, operating system, and referring URL.

Cookies: see our Cookie Policy.

1.3 Information from third parties

Calendar providers: if you connect Google Calendar or Microsoft Calendar, we access only busy/free status and create/update booking events — we do not read existing event content.

OAuth providers: if you sign in with Google or Apple, we receive your name and email from that provider.

2.How We Use Your Information

We use your information to:

  • Operate and provide the Service.
  • Send transactional emails and SMS (booking confirmations, reminders, cancellations).
  • Improve and personalize the Service, including AI scheduling features that learn from your booking patterns.
  • Respond to support requests.
  • Comply with legal obligations.
  • Detect and prevent fraud and security incidents.

We do NOT sell your personal data, use your calendar content to train shared AI models, or share meeting content with other tenants.

3.How We Share Your Information

Service providers: Supabase (database and infrastructure), Twilio (SMS), email delivery provider, and payment processors — each bound by data processing agreements.

Invitees: booking details are shared between host and invitee to operate the Service.

Legal requirements: when required by law or to protect user safety.

Business transfers: with notice to affected users.

4.Data Retention

Account data: retained for the life of your account plus 90 days after deletion.

Booking records: retained for 12 months after the booking date.

Email and SMS logs: retained for 90 days.

You may request deletion at any time.

5.Security

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Row-level security (RLS) ensuring tenant data isolation.
  • Regular security reviews and vulnerability scanning.
  • SOC-2-aligned infrastructure controls.

Report vulnerabilities to security@brightstack.us.

6.Your Rights

All users: access, correction, deletion, portability, and opt-out of marketing communications.

EU/EEA users (GDPR): legal basis is contract performance, legitimate interests, and consent. Right to object, withdraw consent, and lodge a complaint with your data protection authority.

California residents (CCPA/CPRA): right to know, delete, correct, and opt out of sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. No discrimination for exercising privacy rights.

To exercise any right: privacy@brightstack.us. Response within 30 days (GDPR) or 45 days (CCPA).

7.Children's Privacy

Not directed to individuals under 16. Contact privacy@brightstack.us if you believe we have collected data from a child.

8.International Data Transfers

Servers located in the United States. EU/EEA and UK transfers rely on Standard Contractual Clauses (SCCs).

9.Changes to This Policy

Material changes notified by email or in-app notice at least 14 days before taking effect.

10.Contact

Brightstack / Michell + Marteen LLC, Houston, Texas
privacy@brightstack.us · brightstack.us