Sign up, take 3 bookings, get $25. Set up in about 9 minutes.
← All policies

Privacy Policy

What we collect, why, who it is shared with, and how to get a copy of it or have it deleted.

EZBookings · Last updated


1. What this covers

This policy covers EZBookings - our marketing site, the booking pages we host for appointment businesses, the booking status pages, and the dashboards businesses use. It does not cover a business's own website, its social accounts, or anything it does with your details outside our service.

EZBookings is a trading name of blueobsidian.io LLC, 11000 W McNichols Rd, Ste 323, Detroit, MI 48221, United States, which operates ezbookings.shop. Where this policy says we decide what happens to your data, blueobsidian.io LLC is the company that decides. You can reach us at [email protected] or (313) 246-3280.

2. Who is responsible for your data

Two different answers, depending on which data you mean.

DataWho decides what happens to itOur role
Your appointment, phone number, name, and messaging consent at an appointment businessThat businessWe process it on their instructions
Your account with us, our billing records, security logs, and aggregate platform statisticsUsWe decide

If you want a business to forget you, ask the business - it is their list, and we will help them do it. If you want us to delete an account you hold with us, ask us.

The client list belongs to the business. We do not sell it, rent it, share it with other businesses on the platform, or use it to market anything of our own to you.

3. What we collect

  • Appointment details - the service booked, who it is with, the date and time, the price, any deposit, any note you added, and the business you booked with.
  • Contact details - your name, email address and phone number. The business uses them to recognize you and to reach you if the appointment has to change; the email address is where your confirmation and reminder are sent.
  • Email preferences - whether you have unsubscribed from a business's emails, and when. We keep that record because an unsubscribe has to be provable, and it is what stops the messages coming back.
  • Payment status - whether a charge succeeded, the amount, and the last four digits and brand of the card. We never receive or store your full card number; Stripe handles the card itself.
  • Account details - if you sign in with Google or Apple, the name, email address and stable identifier those providers return. We never receive your password with them.
  • Usage analytics - pages viewed on a business's booking page, how long a visit lasted, and whether it ended in a booking. See section 5.
  • Support messages - anything you send us through the contact form or a support ticket.
  • Technical data - IP address, browser and device type, and timestamps, kept for security and fraud prevention.

We do not collect precise device location, and we never sell personal information. If you booked with a business, nothing about you is shared for advertising: there are no third-party trackers on any business's booking page, and there is no setting anywhere that turns them on. The one exception applies only to visitors of our own marketing site, where we advertise to business owners - see section 6.

4. Why we use it

PurposeData usedBasis
Taking and holding your appointmentAppointment, contact, payment statusPerformance of a contract
Confirmations and reminders by emailEmail address, appointmentPerformance of a contract
Giving a business the client list built from its own appointmentsEmail address, phone, appointment historyOur and the business's legitimate interests. What the business then does with that list is theirs, and they are responsible for it
Fraud prevention and platform securityTechnical data, booking patternsOur legitimate interests
Improving the product and reporting to businessesUsage analytics, aggregatedOur legitimate interests
Tax, accounting and dispute recordsAppointment and payment recordsLegal obligation

5. Analytics, and what we deliberately do not do

We measure how booking pages are used so owners can see which services get looked at and where people give up. Three limits are built into how this works, not just promised here:

  1. 1.The identifier used to group a visit is random, generated in your browser, different for every business, and never joined to your client record. It tells a business that one person visited four times rather than four people visited once, and nothing else. It is not a fingerprint and we do not attempt device fingerprinting.
  2. 2.Analytics events carry a fixed set of typed fields. There is no free-form field, deliberately, so a phone number or a note you left when booking cannot end up in an analytics table and from there into every backup.
  3. 3.Businesses see their own numbers. We see platform totals and per-business summaries. No business can see another business's data.

6. Who we share it with

  • The business you booked with - the appointment, your name and your contact details, so they can hold the time, perform the service and reach you if it has to change.
  • Service providers who run parts of the platform for us. The current list, and what each one receives, is on the Subprocessors page.
  • Law enforcement or regulators, where we are legally required to, and only to the extent required.
  • A buyer, if the business is sold or merged - with notice to you beforehand, and with this policy continuing to apply until it is replaced.

That is the whole list for anyone who booked an appointment. We do not share your data with advertisers, data brokers, or other businesses.

Visitors to our own marketing site are the single exception, and it does not reach anyone booking an appointment. If you accept cookies on that site, Google and Meta receive the pages you viewed and a random identifier so we can tell which of our adverts brought a business owner to us. Under US state privacy laws that counts as sharing for cross-context behavioral advertising. Declining the cookie notice, or sending a Global Privacy Control signal, stops it before anything loads, and you can change your mind from the Cookie choices link in the footer at any time. None of this happens on a business's booking page, whether or not you accepted anything on ours.

6a. Text messages

We do not send text messages, and nothing on this site asks for your mobile number in order to text you.

A business asks for your phone number when you book so that they can reach you if your appointment has to change. That number is theirs, held for that purpose, and we do not message it. We do not sell, rent or share mobile numbers with anyone for their own marketing.

7. How long we keep it

DataKept for
Appointment and payment records7 years, for tax and dispute purposes
Email unsubscribe recordsKept indefinitely - an unsubscribe record has to outlive the address it applies to, or the person gets re-added
Analytics visits and events13 months, then deleted
Support tickets and contact messages3 years
Security and access logs12 months
Your accountUntil you delete it, then 30 days

8. Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some uses, or ask us not to sell or share it. We never sell it. The only sharing we do for advertising is on our own marketing site, and you can switch that off yourself from the Cookie choices link in the footer without emailing anyone.

Email [email protected] and say which business you booked with. We answer within 45 days, usually much sooner, and we will not treat you differently for asking. If you ask us to delete data a business controls, we pass the request to them and confirm when it is done.

If you are in the EU or UK: our legal bases are in section 4, you may lodge a complaint with your supervisory authority, and where data is transferred outside your region we rely on Standard Contractual Clauses.

9. Children

The service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has given us information, email [email protected] and we will delete it.

10. Security

Data is encrypted in transit and at rest. Passwords are stored hashed, never in a recoverable form. Access to production data is limited to staff who need it and is logged. Each business's data is separated at the query layer so one cannot read another's.

No system is perfect. If you find a vulnerability, email [email protected] rather than disclosing it publicly, and we will not pursue you for a good-faith report.

11. Changes

We update this page when what we do changes. The date at the top changes with it. Material changes get notice through the service before they take effect.

12. How to contact us

Privacy questions, requests for a copy of your data, and deletion requests: [email protected].

blueobsidian.io LLC, 11000 W McNichols Rd, Ste 323, Detroit, MI 48221, United States. Telephone (313) 246-3280.


Questions about this policy? Email [email protected] or use the contact form. See all policies at /legal.

We use cookies to keep you signed in and, if you accept, to measure which adverts bring salon owners here. Decline and only the sign-in ones are set. This is our own site only, never a salon's booking page. What we store