Privacy Policy

Last updated: September 5, 2026

BookFreely (“BookFreely”, “we”, “our”, “us”) operates a service marketplace that connects customers with independent service businesses. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. By using BookFreely you agree to the practices described here.

1. Who we are & scope

BookFreely is an online marketplace that connects customers with independent local service providers. Customers browse services, book appointments, and pay securely online; Businesses manage bookings and receive payouts through Stripe Connect. Independent Businesses on the platform are separate data controllers for their own customer relationships (e.g. service delivery, direct communications). This policy covers information we collect through the BookFreely website and payment flows.

2. Eligibility & age requirements

  • Under 13 — Not permitted to create any BookFreely account.
  • Customers 13–17 — Permitted only with the permission and supervision of a parent or legal guardian; the guardian’s name and email must be on file at signup.
  • Customers 18+ — Permitted independently.
  • Business owners 18+ — Permitted independently.
  • Business owners 13–17 — Permitted only with guardian supervision. The guardian is legally responsible for identity verification, taxes, payouts, and compliance.

We collect date of birth at signup to enforce these gates. See Section 3 (Children’s Privacy) for how we protect users under 13.

3. Children's privacy

BookFreely is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Consistent with the U.S. Children’s Online Privacy Protection Act (COPPA) and similar laws worldwide, if we discover or are notified that an account belongs to a child under 13, we will:

  • Suspend the account immediately.
  • Cancel any pending bookings associated with the account.
  • Delete the personal information we hold for that account, except records we are legally required to retain (see Section 15 — Data Retention).

Users aged 13–17 are permitted only with the supervision of a parent or legal guardian, whose name and email are collected at signup. Parents and guardians who believe their child under 13 has provided personal information to BookFreely, or who wish to review, correct, or delete a minor’s information, should contact bookfreely.support@gmail.com. We will act promptly on verified requests.

4. Information we collect

  • Account details: name, preferred name, email, hashed password, account type (customer, business, or BookFreely staff), date of birth (collected at signup to enforce age gates), and — for accounts belonging to users aged 13–17 — the parent or legal guardian’s full name and email.
  • Business profile: business name, description, category, contact phone, website, service location, and uploaded profile photo.
  • Booking data: services requested, scheduled times, deposit amounts, deposit status, and booking status updates.
  • Booking details you provide: your answers to the booking questions the business created for that service (for example vehicle, size, or access details) and any photos you upload with a booking. Private booking photos are available only to you, the business you booked, and authorized BookFreely personnel when access is needed to operate or support the service (see §9).
  • Payment metadata received from Stripe: payment status, last-4, card brand, Stripe IDs, amounts. Full card numbers, CVV, bank account numbers, and identity documents submitted for Stripe KYC are handled by Stripe directly — see §6.
  • Saved-card authorization records for bookings with a balance: the booking ID, the amounts you authorized, the wording you agreed to, its version, and the timestamp. The card itself is stored by Stripe, not by BookFreely, and is used only for that booking’s remaining balance.
  • Device & session data: authentication and security data (used to keep you signed in, protect your account, and recognize trusted devices), IP address, user-agent, cookie preferences.
  • Messages, reviews, reports, and case data submitted through the platform.
  • Optional analytics are currently disabled. No analytics provider loads and no analytics data is collected, even if a visitor accepts analytics cookies. Before enabling analytics in the future, BookFreely will update this policy to accurately explain what is collected and will continue requiring consent.

5. How we use your information

  • Provide the marketplace: accounts, bookings, subscriptions, calendar, reminders.
  • Payments and payouts: process customer deposits and route funds to businesses via Stripe Connect.
  • Safety and moderation: prioritize and investigate reports, run the strike / suspension ladder, prevent fraud (see §7).
  • Communication: transactional emails (booking confirmations, reminders, security alerts) and, if you opt in, product updates.
  • Legal compliance and accounting.

We do not sell your personal information.

6. Identity verification (Stripe Connect KYC)

BookFreely relies exclusively on Stripe Connect for Business identity verification. Government-issued IDs, business formation documents, tax information, and bank details are submitted directly to Stripe, verified by Stripe, and stored by Stripe under Stripe’s privacy policy. BookFreely does not collect, review, or retain government-issued IDs separately from Stripe. A Business’s listing goes live only after identity verification is complete, the subscription is active, and the account is in good standing. There is no separate manual identity review by BookFreely. The same process applies to Businesses that offer in-person services — there is no additional approval workflow.

7. AI moderation (human-supervised)

Reports of policy violations are automatically summarized and severity-scored by an AI moderation assistant (Anthropic’s Claude, accessed via a third-party integration provider). The AI is a triage aid only — it never issues warnings, strikes, suspensions, or removals on its own. Every enforcement decision is reviewed and finalized by a member of the BookFreely team. Report content is transmitted to the AI provider solely for triage and is not used for advertising, profiling, or model training on our behalf.

8. Suspension & account enforcement

BookFreely may suspend, restrict, or terminate any account that violates our Terms of Service or Community Guidelines, engages in fraud, threatens safety, or otherwise poses risk to the community. Enforcement actions and their reasons are recorded in our internal audit log so we can respond to appeals and legal requests.

9. Authorized personnel access

Only authorized BookFreely personnel may access account or booking information, and only when necessary for customer support, fraud investigation, dispute resolution, legal compliance, or platform security. Authorized access to sensitive records (payment metadata, private messages, dispute history, business details) may be recorded for security, support, compliance, and accountability. We do not permit casual browsing of user data.

10. Payment processing (Stripe)

All payments and payouts are processed by Stripe, Inc. and by Stripe Connect connected accounts owned by each Business. Card numbers, bank details, and identity documents submitted for Stripe KYC are handled directly by Stripe under their terms and privacy policy (stripe.com/privacy). BookFreely receives only the operational metadata described in §4.

11. Email delivery

Transactional emails are delivered via our email service provider. Recipient email address, subject, and message content are shared with the provider solely for delivery.

12. Cookies, sessions, and Trusted Devices

We use a session token for authentication and an optional “Trusted Device” token so signed-in users on a remembered device can skip step-up verification for up to 30 days. You can review and revoke trusted devices from your account settings. Optional analytics and marketing cookies are controlled from the “Cookie preferences” link in the footer.

13. Sharing your information

  • With the Business you book from: your name and contact phone / email (revealed only after the booking is confirmed) so they can prepare for and, where relevant, contact you about the appointment.
  • With our sub-processors: Stripe (payments and KYC), our transactional email provider, our AI moderation provider (Anthropic Claude), and our hosting provider.
  • When legally required (subpoena, safety emergency, fraud investigation).
  • In connection with a business transfer (merger or acquisition) with continued protection of your information.

14. Your rights and choices

  • Access, correct, or delete your account data from your dashboard.
  • Export your data: Businesses can download a full account export from Business Dashboard → Account.
  • Delete your account: Businesses use the deletion flow (30-day grace period). Customers can request deletion by emailing bookfreely.support@gmail.com.
  • Revoke trusted devices, opt out of marketing emails, adjust cookie preferences at any time.
  • Applicable law may give you additional rights (GDPR, CCPA) — contact us to exercise them.

15. Data retention

We retain personal information only for as long as needed to provide the platform, comply with our legal obligations, resolve disputes, and enforce our agreements. Actual retention periods depend on the type of data and the purpose it was collected for:

  • Active accounts — retained while your account remains active.
  • Deleted customer accounts — profile data is deleted or anonymized promptly after a verified deletion request, except records we must retain for legal, tax, accounting, fraud-prevention, or Stripe reconciliation purposes.
  • Deleted business accounts — profile is hidden immediately and enters a 30-day grace period. After the grace period, profile data is deleted or anonymized, subject to the same legal exceptions above.
  • Booking and payment records — retained for the period required by applicable tax, accounting, consumer-protection, and anti-money-laundering laws (typically up to 7 years).
  • Report, case, and audit-log data — retained for the period necessary to defend against legal claims, respond to appeals, and demonstrate compliance (typically up to 7 years).
  • Marketing preferences and unsubscribe records — retained indefinitely to honor your choices.
  • Backups — deleted data may persist in routine service backups for a limited window until those backups roll over.

When data is no longer needed, we securely delete or anonymize it. Where anonymized, the resulting data is no longer personal information and may be used for analytics.

16. Data security

We take reasonable steps to protect your data, including encryption in transit (HTTPS), salted password hashing, step-up verification for sensitive actions, and access controls on administrative functions. No system is perfectly secure, so please use a strong, unique password and enable step-up verification when prompted.

17. International transfers

Your data may be stored or processed by sub-processors in countries other than your own. Where cross-border transfers occur, we work with sub-processors who commit to appropriate safeguards for such transfers.

18. Changes to this policy

We may update this policy. Material changes will be announced by email or on-platform notice. The “Last updated” date at the top always reflects the current version.

19. Contact

Questions or requests: bookfreely.support@gmail.com.

A quick note about cookies

Essential cookies keep you signed in and your account secure. Functional cookies save your preferences. Optional analytics and marketing cookies are off unless you turn them on — and no analytics provider is currently configured, so accepting analytics does not load one today. Learn more.