Privacy Policy

Privacy Policy

Last updated: September 2025

1. Data Collection

We collect the following information to provide our services:

For Studio Clients (End Users):

  • Contact data: Email address, first name, last name
  • Contact data: Phone number (when requested by the studio)
  • Booking data: Session dates, attendance, cancellation history
  • Course packages: Purchased course packages, remaining credits, validity periods
  • Payment data: Transaction history (processed by Stripe/PayPal)

For Studio Managers (Admin Users):

  • Account data: Email address, password (encrypted), organization details
  • Business data: Studio information, room details, coach profiles
  • Analytics data: Usage statistics, performance metrics

Note: Some studios may request additional information (e.g., health data) with your consent. This is collected under their sole responsibility.

Important: Bookday itself does not specifically require or process sensitive health data. Any such information collected by a studio is under their sole responsibility.

2. How We Use Your Data

  • To provide and maintain our booking services
  • To process payments and manage course packages
  • To send booking confirmations and reminders
  • To notify you when spots become available (waitlist)
  • To provide customer support and respond to inquiries
  • To improve our services and develop new features

3. Security and Hosting

Your data security is our priority:

  • Hosting: Bookday is hosted on Heroku (Salesforce), in the EU Region, with the following certifications: ISO 27001, SOC 2, PCI-DSS
  • Encryption: All data is encrypted in transit (HTTPS) and at rest
  • Access control: Strict access controls and authentication measures
  • Regular audits: Security assessments and penetration testing

4. Authentication

  • Studio Clients: Passwordless login via secure email links
  • Studio Managers: Admin users authenticate via a secure login system with encrypted credentials

5. Data Sharing

We do not sell, trade, or rent your personal information. Data is shared only in these specific cases:

  • With your studio: To manage your bookings and course packages
  • Payment processors: Stripe and PayPal (for transaction processing)
  • Legal requirements: When required by law or to protect rights

6. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a structured format
  • Objection: You also have the right to object to the processing of your data in certain cases

7. Data Retention

  • Active accounts: Data retained while account is active
  • Inactive accounts: Data deleted after 2 years of inactivity
  • Legal requirements: Some data may be retained longer for legal compliance

8. Contact Information

For privacy-related questions or to exercise your rights:

  • Email: privacy@bookday.io
  • Address: 10 RUE DE PENTHIEVRE, 75008 PARIS
  • Response time: We will respond within 30 days

9. Updates to This Policy

We may update this Privacy Policy periodically. Significant changes will be notified via email or through our platform. Continued use of our services constitutes acceptance of the updated policy.