Skip to content

Privacy Policy

Current version: October 5, 2026.

This policy explains what personal data Bookly collects, why we need it, who we share it with, how long we keep it and what rights you have. It is written in plain language; if anything remains unclear, write to us and we will explain.

Who we are and what this policy covers

Bookly is an online service that lets a business take bookings, keep a client base, sell services and products and publish its own link-in-bio page. The service is operated by sole proprietor Sverediuk O. V. (Ukrainian FOP, tax ID 3423602956) (“Bookly”, “we”).

This policy covers bookly.me and every part of the service: account sign-up and sign-in, the workspace with bookings and clients, the link-in-bio page builder, public booking and review pages, short links, the Telegram bot and the Bookly mobile apps.

For any question about your data, write to privacy@bookly.me.

Two roles: your data and your clients’ data

This distinction decides who is responsible for what.

  • Your data as a Bookly user. We decide why and how it is processed, so we act as the data controller. That processing is what this policy describes.
  • Your clients’ data that you enter into Bookly — names, phone numbers, visit history, notes, submissions from your forms. Here you are the controller: you decide what to collect and why, and we process it only on your instructions, as a processor. You are responsible for having a lawful basis to collect it and for telling your clients how you use it.

What we collect

Account data

  • Email address and name; phone number and profile photo if you add them.
  • A password hash or one-time sign-in codes, and two-factor authentication settings if you enable them.
  • Active sessions and a sign-in log: time, IP address, device and browser type. This lets you see where your account was accessed from and end a session you do not recognise.
  • Your plan, subscription status and the history of plan changes.
  • Payments for your plan: the amount, date and status, the payment provider that took the payment, a masked card number with only the last digits visible, the card type and expiry date and, if your subscription renews by automatic charge, a token for those charges that works only with that payment provider. When you pay, we also record your acceptance of the Public offer: its version, the time, your IP address and browser.

Workspace content

  • Business profile: services, prices, durations, working hours, staff members and their permissions.
  • Bookings and orders, client records, visit history and the notes you add to them.
  • Financial records you keep in the service: income, expenses and staff payouts.
  • Your link-in-bio pages: text, images, video, links, products, forms and design settings.
  • Submissions left by visitors through your forms, and reviews clients leave on your public pages.
  • Files you upload, such as service photos and page covers.

Technical data and statistics

  • IP address, device and browser type, interface language and the pages you open inside the service.
  • Server and security logs, including failed sign-in attempts, which we need to protect accounts.
  • Visits to your public pages and clicks on short links: time, referrer, approximate country and a non-identifying visitor identifier. These events produce the statistics you see in your analytics; we do not use them to identify a visitor.
  • In the mobile apps — a device identifier for push notifications, if you allow them, and crash diagnostics so we can fix errors.

We do not deliberately collect special categories of data such as health, beliefs or biometrics. If your business records something of that kind in client notes, you do so as the controller and at your own responsibility.

  • To provide the service. Create your account and run bookings, the CRM, pages and notifications. Legal basis: performance of our contract with you.
  • To take payment. Handle subscriptions, payments and refunds. Legal basis: performance of a contract and legal obligations.
  • To keep the service safe. Detect and stop abuse, investigate incidents, protect accounts from takeover. Legal basis: our legitimate interest.
  • To support you. Answer your requests and investigate problems. Legal basis: performance of a contract.
  • To improve the product. Analyse aggregated usage statistics. Legal basis: our legitimate interest.
  • To email you. Service notifications about your account are part of the service; marketing emails are sent only with your consent, which you can withdraw with one click in any message.

Who we share data with

We do not sell personal data and do not pass it on for someone else’s advertising. Data reaches only the providers who help the service run, and only as far as they need it:

  • Hosting — Hetzner Online GmbH, data centres in Germany, where Bookly’s servers and databases run.
  • Network and protection — Cloudflare, Inc.: traffic routing, HTTPS encryption, attack filtering.
  • Messaging — email providers, SMS operators and Telegram, when you send clients reminders, booking confirmations or notifications.
  • Payments — payment providers, when you pay for a subscription or accept online payments from clients. A Bookly subscription is currently paid under the Public offer through the payment provider WayForPay, Financial Company “WAY FOR PAY” LLC (Ukraine, EDRPOU 39626179). WayForPay receives what the payment needs: the amount, the order number and description, your email and the page language. You enter your card details only on the payment provider’s page: Bookly never receives or stores full card numbers or CVV codes — from the payment provider we get only the result of the payment and the card details listed above.
  • App stores — Apple and Google, to the extent needed for the mobile apps and push notifications to work.

We may also disclose data where the law directly requires it, or where it is necessary to protect the rights and safety of the service’s users.

Where data is stored and for how long

  • Data is stored on servers in the European Union. Some providers may process data outside the EU; in that case we rely on standard contractual clauses.
  • Account and workspace data is kept for as long as your account exists.
  • After you delete your account we erase or anonymise the data within 30 days. Only records we are legally required to keep, such as accounting documents for payments, and the record of your acceptance of the Public offer are retained longer.
  • We keep the record of your acceptance of the Public offer (its version, the time, your IP address and browser) while the agreement is in force and for 3 years after it ends, so that we can show, if needed, on what terms it was made. The legal basis is our legitimate interest.
  • Server and security logs are kept for a limited period, then deleted or anonymised.
  • Backups are kept for a limited period and overwritten; deleted data disappears from them within that cycle.

Your rights

You may request a copy of your data, correct inaccuracies, have data deleted, restrict or object to processing, and receive your data in a machine-readable format to move it to another service. Where processing relies on your consent, you may withdraw it at any time; this does not affect processing carried out before the withdrawal.

Write to privacy@bookly.me and we will respond within 30 days. You also have the right to lodge a complaint with your data protection authority.

If your request concerns data a business entered about you as its client, contact that business: it decides what happens to that data, we act on its instructions, and we will pass your request on to it.

Cookies

We use cookies the service cannot work without: they keep you signed in, protect forms against cross-site request forgery and remember your chosen language. Public pages may use a cookie to count visits, without identifying the visitor. You can block cookies in your browser, but then signing in and some features will not work.

Security

All traffic runs over HTTPS, passwords are stored as irreversible hashes, and two-factor authentication is available. Staff access to production systems is limited and logged, and backups are taken regularly. That said, no service can promise absolute security, so please use a unique password and turn on two-factor authentication.

Children

Bookly is a business tool and is not intended for anyone under 16. We do not knowingly create accounts for them. If we learn that an account was registered by a child, we will delete it.

Changes to this policy

We may update this policy as the service develops. The date at the top of the page always shows the current version. We announce material changes in the service or by email before they take effect.

How to contact us

Sole proprietor Sverediuk O. V. (Ukrainian FOP), tax ID 3423602956.
Privacy questions: privacy@bookly.me.
General support: support@bookly.me.