Privacy

Privacy, without the fog.

This policy explains what information Bookhurst handles, why it is needed, who controls it, and the choices available to workspace teams and their customers.

Effective and last updated .

The short version

We use personal information to run the service, secure accounts, deliver booking communications, support connected payments, and provide help. We do not sell personal information or use it for third-party advertising.
01

Scope and roles

This policy applies to the Bookhurst website, workspace administration tools, public booking pages, support channels, and related services.

A business that operates a workspace decides why and how its customer, booking, contact, invoice, and communication data is used. For that workspace data, the business is generally the controller or responsible organization, and Bookhurst processes the information to provide the service. Bookhurst is responsible for account, platform security, support, approval, and service-operation data that it collects for its own purposes.

If you booked with a business

Contact that business first for questions about a booking or its customer records. The workspace owner is best placed to verify you and act on the request. We will support the workspace when needed.
02

Information we handle

The information involved depends on how you use the service:

  • Account and workspace data: names, email addresses, organization name, workspace URL, timezone, staff role, verification and approval status, and account preferences.
  • Booking and customer data: customer name and contact details, requested dates and times, party size or quantity, booking status, resource, assignee, customer messages, and operational notes.
  • CRM and communication data: contact stages, notes, tasks, activity history, email content, templates, delivery status, and related audit information.
  • Invoice and payment records: prices, deposits, balances, currency, invoice lines, payment method, refund status, and Stripe identifiers. Full payment-card numbers are handled by Stripe and are not stored by Bookhurst.
  • Security and access data: password hashes, one-time token hashes, signed session information, API-token hashes and prefixes, sign-in state, session-revocation counters, rate-limit data, and platform audit records.
  • Support data: the contact information, workspace identifier, topic, and message submitted through support.
  • Technical data: IP and request information necessarily received by the service, timestamps, error and operational logs, and health or delivery events needed to prevent abuse and diagnose problems.

Please avoid placing sensitive personal information in free-text notes unless it is necessary and lawful for the service being delivered.

03

Where information comes from

  • Directly from workspace applicants, owners, staff members, customers, and support requesters.
  • From workspace staff when they add or update contacts, bookings, notes, tasks, invoices, or payments.
  • From Stripe when a connected account, Checkout session, payment, fee, or refund changes.
  • Automatically from browsers, devices, servers, and security controls when the service is accessed.
04

How we use information

  • Create, review, authenticate, and administer workspaces and staff access.
  • Show availability, create and manage bookings, prevent capacity conflicts, and keep calendars current.
  • Send account verification, password reset, booking, reminder, invoice, CRM, and support emails.
  • Create payment links, reconcile Stripe payment status, record offline payments, and support refunds and disputes.
  • Provide CRM, invoice, audit, reporting, demo, and customer-support functionality.
  • Detect misuse, enforce access boundaries, rate-limit risky activity, debug errors, and protect the service.
  • Meet applicable legal obligations and establish, exercise, or defend legal claims.

Depending on the jurisdiction and context, these activities may rely on performance of a contract, legitimate interests in operating and securing the service, consent, or compliance with law. A workspace must establish its own lawful basis for the customer information it collects.

05

When information is shared

We disclose information only as needed for the following purposes:

  • Workspace access: owners and authorized staff can access information according to their role and assigned responsibilities.
  • Payment processing: Stripe receives information needed to connect accounts, host Checkout, process payments, and administer refunds or disputes.
  • Email delivery: Brevo receives recipient and message information needed to deliver transactional and CRM emails.
  • Infrastructure: hosting, database, cache, network, and operational providers process information needed to run and secure the service.
  • Legal and safety: information may be disclosed when required by valid legal process or reasonably necessary to protect rights, safety, users, or the service.
  • Business changes: information may transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice requirements.

We do not sell personal information, rent customer lists, or disclose workspace data for third-party behavioral advertising.

06

Cookies and local storage

Bookhurst uses essential, signed session cookies for workspace and platform-administrator authentication. They are HTTP-only, use SameSite protections, and are marked Secure in production. A short-lived cookie is also used while completing administrator two-factor authentication. The public demo uses the same session mechanism with a signed demo restriction that limits which records it can change.

Browser local storage remembers convenience settings such as the last workspace, calendar view and timezone, and whether the admin sidebar is collapsed. These preferences stay in the browser and can be cleared through browser settings.

No advertising cookies

The current service does not use third-party advertising or cross-site behavioral tracking cookies. If that changes, this policy and any required consent controls will be updated first.
07

Retention and deletion

Information is retained while a workspace is active and for as long as reasonably needed to provide the service, maintain security and audit integrity, resolve disputes, and comply with legal, tax, accounting, or payment obligations. Different records may require different periods.

  • Workspace staff can delete individual contacts and bookings where the product permits.
  • Workspace deletion removes tenant data from the active application database through the platform administration process, subject to records that must be retained independently for security or legal reasons.
  • Residual copies may remain temporarily in protected backups or provider systems until their normal rotation or deletion cycle completes.
  • One-time authentication tokens expire and are stored as hashes; signed sessions expire or can be revoked through account and workspace security controls.

Contact support to request workspace deletion or to discuss a retention requirement before closing an account.

08

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where processing relies on consent. You may also have a right to complain to a local data-protection authority.

  • Workspace staff can update sign-in details in Admin → Account; a new sign-in email must be verified before it becomes active.
  • Workspace teams can update or delete many booking and CRM records directly in the administration tools.
  • Customers should submit booking-data requests to the business they booked with.
  • For platform data or additional assistance, contact support@bookhurst.com. We may ask for information needed to verify identity and authority.

We will not discriminate against a person for exercising an applicable privacy right.

09

International processing

Service providers and workspace users may operate in countries different from yours. As a result, information can be processed internationally. Where law requires, the responsible party should use an approved transfer mechanism and appropriate contractual or technical safeguards.

10

Children’s information

The workspace administration service is intended for adults acting for a business and is not directed to children. A business that records information about a minor in connection with a legitimate booking is responsible for obtaining any required parent or guardian authorization and limiting the information to what is necessary.

11

Security

We use access controls, tenant-scoped authorization, password and token hashing, signed protected cookies, rate limiting, webhook verification, audit records, security headers, and operational checks. No service can promise absolute security.

Our Security page describes current safeguards, shared responsibilities, and how to report a suspected vulnerability.

12

Changes and contact

We may update this policy as the service, providers, or legal requirements change. The effective date above will be revised, and material changes may also be communicated through the service or by email where appropriate.

Privacy questions and requests can be sent to support@bookhurst.com or submitted through the Support page.