How Bookabee handles your customers' personal data, and what you need to do on your side.
Parents who book through Bookabee trust you with their personal data — names, contact details, sometimes children's allergies and medical information. This article explains the data protection setup behind Bookabee and the small amount of work you need to do on your side to stay compliant under UK GDPR.
Under UK GDPR you, the activity provider, are the data controller for your bookers' personal data. Bookabee is the data processor — we hold the data on your behalf and process it only on your instructions. We are the controller for your own dashboard account data (your name, email, login).
Note
Practically: bookers should contact you first about their data, and you should mention Bookabee as a processor in your own privacy policy.
While the database is in the UK, some sub-processors that handle data in flight (Vercel for hosting, Stripe for payments, Resend for email, Google for analytics) are headquartered in or operate from the United States. Where personal data is transferred outside the UK we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. The full sub-processor list is in our privacy policy.
Bookabee is multi-tenant: only members of your company can see your bookers' data. Other Bookabee customers cannot. Every database query is scoped to your company id, enforced both in the application layer and through our access controls.
When you email all confirmed participants of a class from the Email tab, we send a separate individual email to each recipient. No participant ever sees another participant's email address — there are no shared To, Cc, or Bcc fields between bookers. This protects against the most common accidental data leak in group emails and is how we make sure mass communication doesn't breach data-minimisation principles.
Medical conditions, allergies, dietary requirements, and SEND information are special category data under GDPR. They need an extra lawful basis on top of the normal one — typically explicit consent.
Booker data is kept for as long as you have an active Bookabee account so your bookings, customer history, and reporting stay intact.
Bookers have the right to access, correct, delete, restrict, port, and object to processing of their data, and to withdraw consent. Under UK GDPR you have one calendar month to respond to a data subject access request.
Tip
Bookabee is registered with the UK ICO under registration number ZC133968. Our full privacy policy is available at bookabee.co/privacy-policy. If you'd like a Data Processing Agreement countersigned, email hello@bookabee.co.