boina
← Back to home

Privacy Policy

Last updated: September 6, 2026

This Privacy Policy explains how boina handles personal data when a Business (barbershop, salon, spa, or dental clinic) uses our scheduling platform, and when that Business's own clients ("End Customers") book appointments through it.

1. Scope of this policy

boina acts in two roles. For a Business's own account data, boina is the data controller. For the personal data a Business collects about its own End Customers through boina (names, contact details, appointment history), boina acts as a data processor, handling that information only on the Business's behalf and instructions.

2. Data we collect from administrators

When a Business signs up and its administrators or staff use the platform, we collect:

  • Account information: name, email address, phone number, and role within the Business.
  • Business information: business name, industry, address, services, pricing, and staff roster.
  • Billing information needed to manage the subscription plan.
  • Usage data such as login activity and actions taken within the admin panel, used to keep the account secure and to improve the product.

3. Data collected on behalf of a Business

When someone books an appointment through a Business's personalized link, we collect the information needed to complete and manage that booking on the Business's behalf:

  • The End Customer's name, email address, and/or WhatsApp/phone number.
  • Appointment details: service selected, chosen staff member, date, time, and status (confirmed, completed, cancelled, no-show).
  • Optional notes the End Customer or the Business adds to a booking.

This data belongs to the Business's relationship with its own client. boina does not use it to market its own products, and does not sell it to third parties.

4. WhatsApp numbers and email addresses

WhatsApp numbers and email addresses are among the most sensitive fields we store, since they are direct communication channels to real people. We apply the following practices to protect them:

  • They are used strictly to send appointment confirmations, reminders, and changes related to a booking made through the Business's link — never for unrelated marketing.
  • Messages are sent through vetted messaging providers (such as the WhatsApp Business API) under data processing agreements that restrict how those providers may use the data.
  • Access within boina is limited to the Business that owns the booking and to boina personnel who need it to operate or support the service.
  • Contact fields are encrypted in transit and at rest, and are never displayed publicly on a booking page.
  • An End Customer can ask their Business, or boina directly, to correct or delete their contact information at any time.

5. How this data is used

We use personal data to operate the booking flow (checking availability, creating and updating appointments), send confirmations and reminders, generate reports for the Business (such as appointment history and occupancy), secure accounts against fraud and abuse, and comply with legal obligations.

6. How data is stored and protected

We follow standard digital security practices to safeguard the data we hold, including encryption in transit (HTTPS/TLS) and at rest, role-based access controls so staff only see data relevant to their Business, routine backups, and monitoring for unauthorized access. No system is completely immune to risk, and we work to reduce it continuously.

7. Data retention

We retain account and appointment data for as long as the Business's account is active, and for a reasonable period afterward to comply with legal, accounting, or dispute-resolution needs. A Business or End Customer may request earlier deletion of specific personal data, subject to any legal retention requirements.

8. Who we share data with

We share personal data only with service providers that help us run the platform — such as cloud hosting, messaging (email/WhatsApp), and payment processors — under agreements that require them to protect it and use it only for the agreed purpose. We do not sell personal data, and we only disclose it further if required by law or to protect the rights, safety, or property of boina, a Business, or an End Customer.

9. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. A Business administrator can exercise these rights from their account settings; an End Customer can contact the Business that booked their appointment, or reach out to boina directly, and we will route the request accordingly.

10. Cookies

Our website and booking pages use essential cookies to keep sessions working correctly, and may use limited analytics cookies to understand how the platform is used and to improve it. You can control cookies through your browser settings.

11. Children's data

boina is intended for use by business administrators and their adult clients. We do not knowingly collect personal data from children, and a Business should not use boina to schedule or store data about minors without appropriate parental or guardian consent as required by applicable law.

12. Changes to this policy

We may update this Privacy Policy as our platform or legal obligations evolve. We will update the "Last updated" date above and, for material changes, notify Business administrators directly.

13. Contact

For privacy questions or to exercise your data rights, contact us at privacy@boina.app.