Privacy Policy
What we collect, why, who it is shared with, and how to get a copy of it or have it deleted.
EZBookings · Last updated
1. What this covers
This policy covers EZBookings - our marketing site, the booking pages we host for appointment businesses, the booking status pages, and the dashboards businesses use. It does not cover a business's own website, its social accounts, or anything it does with your details outside our service.
EZBookings is a trading name of blueobsidian.io LLC, 11000 W McNichols Rd, Ste 323, Detroit, MI 48221, United States, which operates ezbookings.shop. Where this policy says we decide what happens to your data, blueobsidian.io LLC is the company that decides. You can reach us at [email protected] or (313) 246-3280.
2. Who is responsible for your data
Two different answers, depending on which data you mean.
| Data | Who decides what happens to it | Our role |
|---|---|---|
| Your appointment, phone number, name, and messaging consent at an appointment business | That business | We process it on their instructions |
| Your account with us, our billing records, security logs, and aggregate platform statistics | Us | We decide |
If you want a business to forget you, ask the business - it is their list, and we will help them do it. If you want us to delete an account you hold with us, ask us.
The client list belongs to the business. We do not sell it, rent it, share it with other businesses on the platform, or use it to market anything of our own to you.
3. What we collect
- Appointment details - the service booked, who it is with, the date and time, the price, any deposit, any note you added, and the business you booked with.
- Contact details - your name, email address and phone number. The business uses them to recognize you and to reach you if the appointment has to change; the email address is where your confirmation and reminder are sent.
- Email preferences - whether you have unsubscribed from a business's emails, and when. We keep that record because an unsubscribe has to be provable, and it is what stops the messages coming back.
- Payment status - whether a charge succeeded, the amount, and the last four digits and brand of the card. We never receive or store your full card number; Stripe handles the card itself.
- Account details - if you sign in with Google or Apple, the name, email address and stable identifier those providers return. We never receive your password with them.
- Usage analytics - pages viewed on a business's booking page, how long a visit lasted, and whether it ended in a booking. See section 5.
- Support messages - anything you send us through the contact form or a support ticket.
- Technical data - IP address, browser and device type, and timestamps, kept for security and fraud prevention.
We do not collect precise device location, and we never sell personal information. If you booked with a business, nothing about you is shared for advertising: there are no third-party trackers on any business's booking page, and there is no setting anywhere that turns them on. The one exception applies only to visitors of our own marketing site, where we advertise to business owners - see section 6.
4. Why we use it
| Purpose | Data used | Basis |
|---|---|---|
| Taking and holding your appointment | Appointment, contact, payment status | Performance of a contract |
| Confirmations and reminders by email | Email address, appointment | Performance of a contract |
| Giving a business the client list built from its own appointments | Email address, phone, appointment history | Our and the business's legitimate interests. What the business then does with that list is theirs, and they are responsible for it |
| Fraud prevention and platform security | Technical data, booking patterns | Our legitimate interests |
| Improving the product and reporting to businesses | Usage analytics, aggregated | Our legitimate interests |
| Tax, accounting and dispute records | Appointment and payment records | Legal obligation |
5. Analytics, and what we deliberately do not do
We measure how booking pages are used so owners can see which services get looked at and where people give up. Three limits are built into how this works, not just promised here:
- 1.The identifier used to group a visit is random, generated in your browser, different for every business, and never joined to your client record. It tells a business that one person visited four times rather than four people visited once, and nothing else. It is not a fingerprint and we do not attempt device fingerprinting.
- 2.Analytics events carry a fixed set of typed fields. There is no free-form field, deliberately, so a phone number or a note you left when booking cannot end up in an analytics table and from there into every backup.
- 3.Businesses see their own numbers. We see platform totals and per-business summaries. No business can see another business's data.
6a. Text messages
We do not send text messages, and nothing on this site asks for your mobile number in order to text you.
A business asks for your phone number when you book so that they can reach you if your appointment has to change. That number is theirs, held for that purpose, and we do not message it. We do not sell, rent or share mobile numbers with anyone for their own marketing.
7. How long we keep it
| Data | Kept for |
|---|---|
| Appointment and payment records | 7 years, for tax and dispute purposes |
| Email unsubscribe records | Kept indefinitely - an unsubscribe record has to outlive the address it applies to, or the person gets re-added |
| Analytics visits and events | 13 months, then deleted |
| Support tickets and contact messages | 3 years |
| Security and access logs | 12 months |
| Your account | Until you delete it, then 30 days |
8. Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some uses, or ask us not to sell or share it. We never sell it. The only sharing we do for advertising is on our own marketing site, and you can switch that off yourself from the Cookie choices link in the footer without emailing anyone.
Email [email protected] and say which business you booked with. We answer within 45 days, usually much sooner, and we will not treat you differently for asking. If you ask us to delete data a business controls, we pass the request to them and confirm when it is done.
If you are in the EU or UK: our legal bases are in section 4, you may lodge a complaint with your supervisory authority, and where data is transferred outside your region we rely on Standard Contractual Clauses.
9. Children
The service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has given us information, email [email protected] and we will delete it.
10. Security
Data is encrypted in transit and at rest. Passwords are stored hashed, never in a recoverable form. Access to production data is limited to staff who need it and is logged. Each business's data is separated at the query layer so one cannot read another's.
No system is perfect. If you find a vulnerability, email [email protected] rather than disclosing it publicly, and we will not pursue you for a good-faith report.
11. Changes
We update this page when what we do changes. The date at the top changes with it. Material changes get notice through the service before they take effect.
12. How to contact us
Privacy questions, requests for a copy of your data, and deletion requests: [email protected].
blueobsidian.io LLC, 11000 W McNichols Rd, Ste 323, Detroit, MI 48221, United States. Telephone (313) 246-3280.
Questions about this policy? Email [email protected] or use the contact form. See all policies at /legal.