1. Data Controller
The data controller for this Service is:
Booking Bible ApS
Torvegade 66
1400 København K, Denmark
CVR: 46504666
Email: privacy@bookingbible.com
When studio operators ("Operators") use BOOKING BIBLE to manage their members, the Operator is the data controller for their member data, and BOOKING BIBLE acts as a data processor. This relationship is governed by our Data Processing Agreement.
Client benefits and vendor verification
When you open a client benefit card, BookingBible checks your qualifying membership or appointment service under the vendor’s agreed trigger and validity against the participating venue and vendor agreement. A vendor scanning the card can see the benefit, the providing venue, your member display name and whether you are eligible now. Billing details and private agreement documents are not shown. A verification is not a record of a purchase.
Verification codes are short lived and kept out of analytics. We record benefit access and verification activity to operate the feature and investigate misuse. Partner application contact details and proposals are used to review and manage potential vendor agreements.
2. Data We Collect
Account Data
Name, email address, phone number, date of birth, profile photo, and emergency contact information provided during registration.
Booking and Activity Data
Class bookings, attendance history, check-in records, pass purchases, cancellation history, and class feedback/ratings.
For age-priced guest seats at Vibro Yoga and Vibration Shower, the inviting member supplies the guest’s name and email and, for an under-30 price, their date of birth. Vibro Yoga also records the guest’s postal address for the applicable instruction tax treatment. The guest seat, host link, selected price and tax record can exist even when the guest has no account.
Live Classes and Staff Reports
For online classes, we record admission, playback and departure events, viewing time, and the account, venue and class they belong to. Where supplied, request headers also provide coarse device, operating system, browser, app and app-version information for playback support. These details can be estimates or unknown; they are not a device fingerprint. Requested video quality does not establish the quality actually delivered.
Authorized venue staff can review individual client activity and scoped summaries of memberships, class popularity, viewing and available technical information. Brand reports restrict access to the relevant brand; reviewing studio-pass crossover requires venue administrator access. Contact details retain their separate access restrictions. Reports do not expose raw IP addresses or user agents, and activity or inactivity does not grant marketing permission. Staff report access uses the existing business account and current permissions, with restricted sessions and access audit records.
Payment Data
Payment method details are processed and stored by Stripe. We store transaction records, invoice history, and Stripe customer identifiers. We do not store full card numbers or CVV codes.
Gift and Inventory Operation Recovery
To recover interrupted staff actions without creating another gift or repeating a stock return, we retain the original operation, venue and staff linkage, product quantities, timestamps and outcome. A return reason is restricted to its inventory record. Access exports exclude replay keys, request fingerprints, raw reasons and unrelated staff data.
Business app versions with recovery support also keep the original gift request and confirmation on the device in encrypted operating-system storage. This can include the recipient details and message you entered, amounts, selected delivery channels and gift code. Payment-card details are not included. Physical-return recovery uses local app storage for account/venue/sale identifiers, quantities and a digest of the reason, not the reason text. Web physical-return recovery uses the current tab’s session storage. This operational storage is separate from optional analytics and is not used for marketing.
Failed Renewal Payment Recovery
When a membership renewal payment fails, we retain the original payment operation so a retry, bank authentication or delayed confirmation cannot charge you twice. This includes the venue, pass and payment it belongs to, the member or staff member who started it, timestamps and the outcome. These are payment records and follow the payment-record retention described below. Access exports include the operation’s state and timestamps, not request keys, card or payment-provider identifiers, or other people’s details.
While the outcome is unresolved, the web payment page keeps the original request in the current tab’s session storage. Business app versions with recovery support keep a staff member’s original charge request on the device in encrypted operating-system storage: member, pass, payment and saved-card identifiers and the outcome. Card numbers are not stored. This operational storage is not used for analytics or marketing.
Optional Gift-Card Camera Scanning
Gift-card QR and barcode scanning starts only when you choose the scan button and allow camera access. Images are decoded on your device; the scanner does not upload or retain camera images or record audio. The camera stops when you close the scanner or leave it. Scanning fills the code field only. Checking or redeeming a gift is a separate action that sends its code to the selected venue’s existing gift-card service. You can type or paste the code without using a camera.
Health Data
Responses to health questionnaires required for certain class types (e.g., hot yoga). This data is processed with your explicit consent.
Technical Data
IP address, browser type, device information, pages visited, and interaction events collected for analytics, security, and service improvement.
Communication Data
Email and SMS delivery status, recipient lists, and engagement metrics (opens, clicks) for service communications and consented marketing. Venues can review who received a campaign and prepare a correction for selected recipients. Current consent and unsubscribe choices still apply to a new marketing message.
A venue may use its commercial relationship with you—for example whether you have a current pass, completed a purchase, or previously used one of its promotions—to include or exclude you from its consented marketing campaigns. A purchase does not provide marketing consent. Health questionnaire answers, attendance, visits, class activity, inactivity, and device fitness data are not used for campaign audience selection.
Venue Website Attribution
On supported branded signup pages, analytics consent allows first and last observed campaign, landing-page and referrer information to accompany account registration. Advertising click identifiers additionally require marketing consent. These snapshots describe the visit leading to signup; they do not establish a person’s location or track later visits. Staff reports show scoped campaign summaries and permitted profile attribution, without exposing click identifiers or full page addresses.
If you grant marketing consent on a venue website, we may retain the first campaign values that brought you there (UTM fields, Google or Meta click identifiers), the landing page path, and only the external referrer’s origin. We do not retain the landing query string, referrer path, IP address, or user agent in this attribution record. It is bound to that exact venue website and may accompany a form submission to the venue’s existing forms and leads systems. If the venue has explicitly connected a NamasteSuite workspace, the same consent-gated campaign fields and query-free page, call-to-action, and scroll events may also be relayed server-to-server to that exact workspace. An accepted form may relay the contact details you submitted there; an unconnected venue sends nothing to NamasteSuite.
Mobile Application Analytics
When you use the Booking Bible mobile app (iOS or Android), and only if you have given explicit consent within the app, we collect app usage data to improve the application. This data is pseudonymous, not anonymous: it may be associated with your account, connected venue, app session, IP address, user agent, and technical device information. This includes:
- Which screens you visit within the app
- Whether you started or completed a class booking through the app
- Whether you enabled push notifications
- Technical information: app version, device platform (iOS/Android)
- Account, venue, session, IP address, and user-agent identifiers
- Crash and performance diagnostics associated with account and venue identifiers
Purpose: Improving the mobile application experience for all users.
Processor: Booking Bible ApS, acting as data processor on behalf of the venue you have connected to. Usage events are stored through Supabase in the EU (eu-central-1, Frankfurt, Germany); crash and performance diagnostics are processed by Sentry. Current provider, region and transfer details are available in our live sub-processor register.
Retention: Usage data is retained for 13 months from collection, then automatically deleted.
Legal basis: Your explicit consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time via Settings → Privacy in the app. Withdrawal does not affect the lawfulness of processing before withdrawal.
No sale or advertising: This data is not sold or used for advertising profiling. It is disclosed only to contracted service providers needed to operate analytics and diagnostics, as listed in our sub-processor register.
3. Purpose and Legal Basis
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the booking service | Art. 6(1)(b) — Contract performance |
| Processing payments | Art. 6(1)(b) — Contract performance |
| Service communications (confirmations, reminders) | Art. 6(1)(b) — Contract performance |
| Health questionnaires | Art. 9(2)(a) — Explicit consent |
| Marketing communications | Art. 6(1)(a) — Consent |
| Venue website first-touch attribution | Art. 6(1)(a) — Marketing consent |
| Analytics and service improvement | Art. 6(1)(a) — Consent for non-essential analytics; Art. 6(1)(f) — Legitimate interest for security and necessary diagnostics |
| Legal compliance (tax, accounting) | Art. 6(1)(c) — Legal obligation |
4. Data Retention
- Account data: Retained while your account is active, deleted within 30 days of account deletion request. See how to delete your account.
- Booking and appointment history: Retained according to the applicable venue, accounting and legal-evidence policy. Your linkage to a past class booking, appointment or combined visit is removed when erasure applies, and is also removed under the platform retention policy once the record is old enough and nothing is still owed on it in either direction. Two records are kept linked to you for longer, on purpose. A recurring appointment stays linked while its recurring arrangement still exists, because that arrangement itself carries your details, and we will not describe a record as disconnected from you while something it points at still names you. A visit made up of several appointments is treated as one record, so it is minimized only when every appointment in it can be. Where a record is minimized the venue keeps what happened; it is no longer connected to you.
- Payment records: Accounting records (invoices and payments) are kept for 5 years from the end of the financial year they relate to, as required by the Danish Bookkeeping Act (bogføringsloven); personal data is minimized or anonymized where the legal hold permits.
- Health questionnaires: Retained for 1 year after last activity, then deleted.
- Analytics data: Identifiable behavioural events follow the current retention policy, with a maximum 13-month window; anonymous mobile events have a shorter window.
- Audit logs: Retained as security and legal evidence, then anonymized under the platform retention policy.
- Campaign delivery evidence: Resolved delivery records and correction lists are minimized under the notification retention policy. Evidence needed to resolve an uncertain send is retained while the outcome remains unresolved. Minimal pseudonymous records prevent an old request from sending the same message again; these records are not described as anonymous.
- Password recovery security records: Pseudonymous recovery challenges and security events are retained for up to 90 days. Verification attempts and rate-limit counters are deleted no later than one day after their expiry.
Operation recovery data
In app versions with recovery support, unresolved gift and physical-return attempts stay on the device until their original result is resolved; signing out does not discard them or start a replacement operation. Confirmed gift recovery details are removed when you acknowledge the result, and a verified return receipt clears its local attempt. Once an account-erasure request is accepted, the app clears that account’s recovery payloads on this device. If device storage is unavailable, it shows a local retry and resumes cleanup on launch or foreground. A minimal account-linked deletion marker remains to prevent delayed writes from restoring the cleared data. This does not claim that a lost or offline device can be remotely wiped, or that server financial records were erased.
Server-side gift, inventory and audit evidence follows the applicable financial, inventory and dispute-hold policies. Direct personal details are minimized where those obligations permit; immutable staff attribution may require operator review before erasure. A notification retention window does not delete the evidence needed to prevent a duplicate gift or stock return.
Feature-related data retention
When a customer disables a paid feature or downgrades to a tier that no longer includes a feature, data created with that feature (automations, scheduled communications, knowledge entries, etc.) is preserved during a grace period and then deleted. See our Terms of Service §5a for current grace-period durations.
5. Your Rights
Under GDPR, you have the following rights:
- Right of Access (Art. 15) — Request a copy of your personal data.
- Right to Rectification (Art. 16) — Correct inaccurate personal data.
- Right to Erasure (Art. 17) — Request deletion of your data ("right to be forgotten").
- Right to Data Portability (Art. 20) — Receive your data in a machine-readable format.
- Right to Object (Art. 21) — Object to processing based on legitimate interest.
- Right to Restrict Processing (Art. 18) — Request limitation of processing.
- Right to Withdraw Consent (Art. 7) — Withdraw consent at any time for consent-based processing.
To exercise your rights, email privacy@bookingbible.com or use the data export/delete features in your account settings. To delete your account, follow the steps on Delete your account. We will respond within the period required by GDPR.
7. Third-Party Processors
We use the following third-party services to provide the Service:
| Service | Purpose | Location |
|---|---|---|
| e-conomic | Danish accounting integration for venue payouts | DK |
| Anthropic | Claude AI for Studio Manager + customer agents | US |
| PostHog Cloud EU | Product analytics — funnels, retention, cohorts, experiments, session replay | EU |
| BunnyCDN | Legacy media CDN (sunsetting) | EU |
| Supabase | Postgres database, Auth, Storage, Realtime | EU (project region) |
| Upstash Redis | Distributed rate-limiting + hot-path cache | EU available |
| Resend | Transactional + marketing email delivery | US |
| Vercel | Application hosting, edge functions, CDN | US edge |
| ClassPass | Class-discovery network for fitness venues | US |
| Cloudflare Turnstile | Bot protection on signup and other public forms | Global edge |
| GitHub | Source control + CI / CD | US |
| Zapier | Workflow automation (varies per Zap) | US |
| BetterStack Uptime | External synthetic uptime monitoring + public status page | EU |
| Sentry | Error monitoring + performance tracing | EU available — currently US |
| Adyen | Enterprise multi-region payment processing | EU (Netherlands) |
| Mollie | European payment processing (alternative to Stripe Connect) | EU (Netherlands) |
| Reepay | Danish-native subscription billing (alternative to Stripe) | DK |
| Stripe | Card + MobilePay processing, Connect marketplace | US + EU |
| Gateway API | Transactional SMS delivery (DK + global) | DK |
| Cloudflare Stream | Live video ingestion, encoding, recording and playback for venues configured to use Cloudflare Stream | Global Cloudflare network; Stream storage region unverified |
| Mux | Live streaming + recording for online classes | US |
The complete sub-processor registry — including data categories, SOC 2 / ISO 27001 posture, sub-sub-processors, and signed DPA links — is published at /legal/sub-processors.
Where data is transferred outside the EU/EEA, we ensure appropriate safeguards through Standard Contractual Clauses (SCCs) or adequacy decisions.
8. Data Protection Officer
For data protection inquiries, contact our Data Protection Officer:
Email: dpo@bookingbible.com
Booking Bible ApS
CVR 46504666
Torvegade 66, 1400 København K, Denmark
9. Supervisory Authority
You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet):
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby, Denmark
Phone: +45 33 19 32 00
Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email and a notice on the Service. The "Last reviewed" date in the hero above reflects the most recent revision.