Privacy Policy

Last updated: 07.05.2025.

Welcome to the BookiMy Privacy Policy!

This Privacy Policy explains how BookiMy, owned and operated by Weavrix LLC, collects, uses, and protects personal information provided through the use of our services. BookiMy is headquartered in California, United States, and provides cloud-based scheduling solutions to businesses and individuals.

As a data controller, BookiMy processes personal information related to user interactions on the platform in accordance with applicable data protection laws. This Privacy Policy outlines how we handle such data and the choices users have regarding its use.

Transparency is important to us, so we’ve made this Privacy Policy clear and easy to follow.

Please review this Privacy Policy carefully to ensure you understand and agree with our practices. If you do not agree with this Policy, you should not access or use the BookiMy platform. If you have any questions, feel free to contact us at support@bookimy.com.

All capitalized terms used but not defined herein shall have the meaning set forth in our Terms of Use.

1. Definition

For the purposes of this Privacy Policy, the following terms shall have the meanings set forth below:

Consent:refers to your explicit permission for us to process your personal data.
Cookies:are small data files placed on your device (such as a computer or mobile phone). They help us analyze how visitors use the BookiMy platform and allow us to improve performance and user experience
Controller: means the entity (either solely or jointly with others) that determines the purpose and methods of processing personal data.
Data Subject:refers to any individual who shares personal data with BookiMy.
Employer:refers to the Client who has provided us with your personal data and who utilizes the BookiMy platform.
Employee:means any individual acting on behalf of the Client—whether as a direct employee, contractor, or consultant who is registered on BookiMy for the purpose of delivering services to the Client's customers.
GDPRrefers to the General Data Protection Regulation (EU Regulation 2016/679).
Personal Data" or "Data"means any information that identifies or could identify a natural person. This includes information that directly or indirectly reveals your identity. Information about companies or legal entities is not considered personal data unless it allows the identification of an individual (e.g., a business email like firstname.lastname@company.com). Anonymized information is not included.
Processing:covers any operation or set of operations performed on personal data, such as collecting, recording, organizing, storing, modifying, retrieving, using, disclosing, combining, restricting, deleting, or destroying such data.
Processor:means any natural or legal person that processes data on behalf of the controller.

2. data Controller and Data Processor

With respect to personal data collected through or in connection with the Website and Services, Weavrix LLC (operating as BookiMy) may act either as a Data Controller or a Data Processor, depending on the specific use case.

When acting as a Data Controller, BookiMy defines the purposes and methods of data processing. This means BookiMy is responsible for determining why and how your personal data is processed. A summary of the purposes and legal grounds for processing can be found in [Section 3.1] of this Privacy Policy.

Unless stated otherwise in [Section 3.2], this Privacy Policy focuses on our role as a Data Controller. If you have any questions or wish to exercise any of your rights as a Data Subject under applicable law, you can contact us at:
Weavrix LLC
430 Condor Ave, Brea, CA 92823
United States
Email: support@bookimy.com

Although BookiMy may also act as a Data Processor on behalf of Clients (such as business users managing their bookings and customer data), we remain committed to transparency and clearly explain how we handle data in [Section 3.2]. If your data is being processed by a Client using BookiMy’s services, please reach out directly to that Client to exercise your data protection rights.

For Clients operating under the General Data Protection Regulation (GDPR) or similar laws, a Data Processing Addendum (DPA) is available. When signed, this DPA governs our data handling as a Processor in compliance with the European Commission's Standard Contractual Clauses.

To request a DPA or inquire about data processing under your jurisdiction’s laws, please email us at
support@bookimy.com.

3. What Data Do We Process About You And When?

We may collect and receive information about you through various channels, including:

Information you provide while using the BookiMy platform (for example, by creating an account on BookiMy).
Information you voluntarily share when reaching out to us via our support contact options.
Information collected through cookies in accordance with our [Cookie Policy] (for instance, to identify your time zone).
Personal Data We May Collect Automatically

Each time you use BookiMy, we may automatically collect the following types of information:

Usage data, such as the date, time, location, frequency, and duration of your interactions with BookiMy;
Comments, opinions, or feedback submitted to BookiMy regarding your experience with the platform;
Technical data about your device or browser for system diagnostics and optimization, including your IP address, URL clickstream, device identifier, operating system, and browser type;
Information related to your usage of BookiMy, including pages visited, time spent on the platform, and data files uploaded to BookiMy.


This information is collected in part through cookies. To learn more about how we use cookies and how you can manage them, please review our [Cookie Policy].

3.1 TMS As Data Controller

Data we collect

Business URL (which may contain personal data such as name and last name), business email address (which may contain personal data such as name and last name), name, surname, password, profile photo (if the Client decides to provide such personal data).The Client will also obtain the Client ID so that we can identify that Client in the future.

Financial Data such as name, address, bank account and payment card details. The payer may not be the Client subscribing to the Paid Plan, so it is possible to receive the information from another Client.

Additional Data i.e., data you decide to share with us, email address.

Email address If you decide to sign up for our newsletter, we use your email address.

Information necessary for identification

Other personal data

PURPOSE

Creating and maintaining an Account on the Website according to the Terms of Use.

When subscribing to any of the Paid Plans or when changing any Paid Plan in accordance with the Terms of Use, this information is being collected by a third-party processor.

If you send us an inquiry via Contact us page or otherwise request support, we will collect data you decide to share with us.

This newsletter allows us to inform you of the new features of the Service, updates, as well as other news relevant to the company.

To allow Data Subjects from EEA to exercise their rights in accordance with this Privacy Policy, as defined in Section 9.

For the prevention and detection of fraud, money laundering or other crimes or to respond to a binding request from a public authority or court.

legal basic

Processing is necessary for the performance of the Agreement (as defined in Definitions Section of the Terms of Use). Without providing business URL, email address, name, surname and password, the Client may not create the Client Account.

Processing is necessary for the performance of the Agreement.

Processing of personal data is either necessary to provide a Service or part thereof, or the processing is based on your consent.

Processing is based on your consent. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to such withdrawal. You may unsubscribe from receiving a newsletter from us. If you wish to do so, simply follow the instructions found at the end of each email.

Processing is necessary for compliance with a legal obligation which the Controller is subject to.

The processing is necessary to comply with legal and regulatory obligations.

retetion

Until the account is deleted in accordance with the Terms of Use.

We keep only the last four digits of the credit card number under subscription billing info until such Agreement is terminated and for the period necessary to comply with the applicable financial and tax accounting and other statutory obligations in accordance with the applicable law (Section 22 of the Terms of Use).

If the processing is based on your consent, we keep the information until you withdraw your consent or for one year, whichever date comes first.

We may use your email for this purpose until you unsubscribe or until you delete your account.

We keep this information for a period of one year.

In accordance with the applicable statutory deadlines.

3.2 Bookimy As Data Processor

As outlined earlier, when it comes to personal data processed through the BookiMy platform, BookiMy acts as a Data Processor while the Client retains the role of Data Controller. BookiMy processes this data strictly under the Client’s direction, in compliance with our Terms of Use and any applicable Data Processing Agreement (DPA).

The scope of data processing performed by BookiMy includes, but is not limited to:

Scheduling on-site or virtual appointments;
Managing staff and service availability;
Coordinating meetings and events with Customers;
Processing payments; and
Sending automated reminders to Customers and Employees.


BookiMy may only collect, use, share, or otherwise handle personal data as instructed by the Client, Employer, or designated service provider.

3.2.1 Processing Before Using BookiMy

1. Employee Data

The Client (your Employer) provides your email address, full name, and phone number to BookiMy in order to create your access to the platform. They may also include a brief description and profile photo. Additionally, your work hours, days off, and special availability may be shared.
The Client may assign you specific services to be delivered to Customers through BookiMy.
If you have questions regarding the legal basis for this data sharing, please contact the Employer who added you to BookiMy.

2. Customer Data

The Client (your service provider) shares your name, surname, email address, and phone number to help schedule and manage your appointments. In some cases, the Client may also add optional information such as your gender, date of birth, or a short description.
For any legal concerns related to this data sharing, please reach out directly to the service provider that granted you access to BookiMy.

3.2.2 Processing While Using BookiMy

(a) Employee Data

If you choose to accept an invitation to use BookiMy, you will need to create an account. This requires you to share your email address and password.

You control the personal data you share via your account, including your full name, profile photo, and either a personal or work email address.

If you choose to connect your BookiMy account to Google Calendar, Outlook Calendar, or Apple Calendar, your appointments will sync directly with your chosen calendar. This allows you to manage your bookings through Google, Outlook, or Apple Calendar seamlessly.

Once linked, your calendar will display all upcoming appointments scheduled via BookiMy.

To enable this feature, BookiMy will access your calendar to retrieve event data such as free/busy time slots, appointment duration, and event titles. We do not access details such as who you're meeting with, their contact details, or any sensitive event descriptions. Your consent is explicitly required before such integration is activated.

Only you (the Employee) can see your connected calendar events. While Super Admins and Managers may view your appointment schedule via BookiMy, they cannot see the specific content of your personal calendar.

You can disconnect your calendar integration at any time by using the “Disconnect” option within your account settings.

Your Employer (the Client) may use your shared information to create customer-facing appointments. These details typically include your name, the type of service offered, and the scheduled date and time.

BookiMy will also use your registered email address to send appointment reminders.

You may opt out of these emails anytime by clicking the “unsubscribe” link provided in each message or by managing your preferences in the “Account Settings” section.

If you have questions about the legal grounds for this data use, please contact the Employer who registered you on BookiMy.

(b) Customer Data

When booking an appointment through BookiMy, certain personal data will be required:

(1) If you book as a Guest, you will be asked to provide your first name, last name, and email address. Optionally, you may also provide your phone number and apply a coupon. You may choose to sync your appointment with your Google, Outlook, or Apple Calendar.

(2) If you choose to create an account and book as a registered Customer, you will need to provide your first name, last name, email address, and a password. As with guest bookings, you may also opt to sync your appointment with your preferred calendar (Google, Outlook, or Apple).

Your service provider (the Client) may share your personal data in order to facilitate your appointment. This data may include your name, email, phone number, and type of service. In some cases, the Client may also add your gender, date of birth, and a short description.

To keep a history of your usage, BookiMy may store additional data such as the number of appointments you've booked, your most recent appointment, your favorite services, payment information, and the service provider with whom you’ve had the most appointments.

BookiMy will send appointment confirmations and reminders to your registered email address.

You can unsubscribe from BookiMy email communications at any time. Simply follow the “Unsubscribe” link in any message or update your preferences in the “Account Settings” section of your profile.
If you have questions regarding how your data is processed, please contact the Client (i.e., the service provider) responsible for managing your appointments.

4. WHAT WE DO NOT DO

At BookiMy, we are committed to safeguarding your privacy. We will never:
Sell any form of your personal information or data.
Share your information with marketers or third parties not expressly permitted under Section 6 of this Privacy Policy.
Use or process your data in any way that is inconsistent with the terms outlined in this Privacy Policy.

5. PERSONAL DATA SECURITY

At BookiMy, we implement comprehensive administrative, technical, and organizational safeguards to ensure the security and confidentiality of personal data. Our approach to data security takes into account the sensitivity of the personal data, the associated processing risks, and the costs and feasibility of implementing effective security measures appropriate to the context.

Measures we utilize include but are not limited to access authorization controls, classification and handling of sensitive information, encryption protocols, firewalls, data backup systems, and staff training. We emphasize a culture of responsibility regarding data protection among our personnel.

When a user creates an account on the BookiMy platform, access to their personal data is protected by a password chosen by the user. This password is securely encrypted in transit and while stored on our servers. For security reasons, users should never share their password. If there is any suspicion that a password has been compromised, users are advised to notify us immediately.

All data submitted via BookiMy is encrypted during transmission using industry-standard protocols, such as Transport Layer Security (TLS), to prevent unauthorized access. The data is stored securely in restricted systems accessible only to authorized personnel under strict confidentiality agreements.

Important: Do not send sensitive personal data via email. BookiMy will never request such information through email. If a suspicious request is received, please report it immediately by emailing support@bookimy.com.

6. WITH WHOM DO WE SHARE YOUR PERSONAL DATA?

BookiMy works with trusted external processors and sub-processors to support specific operational and technical processing functions. We conduct thorough data audits to identify, classify, and document all instances in which personal data is processed externally. Each processing purpose, processor role, and legal justification for data sharing is clearly recorded and made accessible when appropriate. All sub-processors are subject to prior approval by the Client.

Prior to engaging any third-party processor, BookiMy follows a rigorous due diligence process. This includes evaluating relevant certifications, company credentials, references, and ensuring the processor demonstrates sufficient safeguards to handle data securely and lawfully.

We also monitor and audit the performance of these processors during the term of our agreement, verifying that they operate in accordance with applicable data protection laws and any required codes of conduct or regulatory frameworks.

Below is a list of processors and sub-processors with whom BookiMy may share your personal data:

This section should be followed by an updated list of processors/sub-processors such as Stripe (for payments), Google (calendar integration), Amazon AWS (cloud storage), etc., depending on your current service integrations..

PROCESSOR

ROLE

SEAT

The Rocket Science Group, LLC (MailChimp)

Cloud-based Email Services

USA

Google, Inc.

Analytics

USA

SUB-PROCESSORS

ROLE

SEAT

Stripe, Inc.

Payment Processing

USA

PayPal, Inc.

Payment Processing

USA

This list may be updated periodically. We encourage users to revisit this section for the most up-to-date information.

Additional Disclosures

In addition to our listed processors and sub-processors, BookiMy may share your personal data with trusted third-party professionals such as:
Accountants
Legal counsel
Auditors
We may also disclose your personal information when required by law, including but not limited to:
Compliance with legal obligations or regulatory authorities
Prevention or detection of fraud or crime
Prevention or detection of fraud or crime

Furthermore, in the event of a merger, acquisition, consolidation, sale of assets, or strategic alliance, your personal data may be transferred as part of the business assets involved in such a transaction.

Please note, we do not maintain a public list of every third party your data may be shared with, as it depends on your specific use of our Services. If you would like detailed information about third-party data sharing related to your use, you may contact us at help@bookimy.com.

7. INTERNATIONAL TRANSFER OF YOUR PERSONAL DATA

We may transfer your personal data to countries outside the country you reside in. BookiMy applies appropriate technical and organizational safeguards to ensure that your data is protected at a level that aligns with global privacy standards.

If the GDPR applies to the Client, we ensure the transfer occurs only under the following conditions:

1.
Sell any form of your personal information or data.
2.
To countries that the European Commission has determined offer adequate protection;
3.
To countries not covered by points 1 or 2, but only with sufficient safeguards, such as the use of Standard Contractual Clauses (SCCs) approved by the European Commission.

If further clarification on these safeguards is required, please reach out to us at help@bookimy.com

Note: Your personal data is securely stored on servers located in Germany.

8. HOW LONG DO WE KEEP YOUR DATA?

The duration for which BookiMy retains your personal data depends on the specific purpose for which it was collected, as outlined in Section 3. We retain data only for as long as reasonably necessary to fulfill our legal, business, and contractual obligations.

In determining the appropriate retention period, we consider:
Applicable laws (as referenced in Section 22 of our Terms of Use);
The terms of service agreements with our Clients and Customers;
Regulatory and compliance requirements.

When personal data is no longer needed or when a valid deletion request is made (and legally permissible), we will securely delete or destroy the data.

Exception: In certain situations, such as legal disputes, your data may be retained beyond standard retention periods for the purpose of establishing, exercising, or defending claims or counterclaims, even after the retention period mentioned in Section 3 has expired.

9. YOUR RIGHTS

At BookiMy, transparency is a core value, and we recognize the rights of individuals ("Data Subjects") concerning their personal data. These rights may be exercised when BookiMy operates as a Data Controller.

If your request or inquiry relates to data processed by a Client (such as your service provider or employer) in their role as the Data Controller, as outlined in Section 3.2, we advise you to contact the respective Client directly.

In instances where BookiMy receives a rights request related to data controlled by a Client, we are required to notify the Client before taking any action or issuing a response

9.1 YOUR DATA SUBJECT RIGHTS UNDER BOOKIMY

In alignment with our core values of transparency and accountability, BookiMy recognizes and upholds the following rights of individuals ("Data Subjects") concerning their personal data, when BookiMy acts as a Data Controller:

Right of Access

Data Subjects have the right to request a copy of the personal data held about them. Upon such a request, BookiMy will provide this information in a clear, transparent, and intelligible format, free of charge. Verification of identity may be required to ensure data security.

Responses will be delivered at the earliest convenience, and no later than 30 days from receipt of the request. In complex or delayed cases, this period may be extended by up to two additional months, with proper notice provided.

Right to Object to Processing

You have the right to object to the processing of your personal data where such processing is carried out on the basis of BookiMy’s legitimate interests. In such cases, BookiMy will cease processing your personal data unless compelling legitimate grounds can be demonstrated that override your objection.

Right to Rectification

If the personal data we hold about you is inaccurate or incomplete, you have the right to request correction. Upon validation, BookiMy will rectify the data within 30 days and inform relevant third parties (if data was previously shared) of the corrections made.

Right to Erasure (Right to Be Forgotten)

You have the right to request the deletion of your personal data under specific circumstances, including when:
The data are no longer necessary for the purposes for which they were collected;
You withdraw consent (where processing is based on consent);
You object to processing and there are no overriding legitimate grounds for continuation;
The data have been unlawfully processed; or
Deletion is required to comply with a legal obligation.
This right may not apply in cases where processing is necessary:
To comply with legal obligations; or
For the establishment, exercise, or defense of legal claims.

If you select the “Delete personal data” option in your BookiMy account settings, please note that BookiMy acts as a data processor and must notify the responsible Data Controller (e.g., your employer or service provider). Deletion will only proceed upon the Data Controller’s approval.

Right to Restriction of Processing

You may request a restriction on processing of your personal data in circumstances where:
You contest the accuracy of the data (pending verification);
The processing is unlawful and you oppose erasure;
BookiMy no longer requires the data, but you need it for the establishment, exercise, or defense of legal claims;
You have objected to processing and the verification of overriding legitimate grounds is pending.

Right to Data Portability

Where BookiMy processes personal data based on your consent or a contract and the processing is carried out by automated means, you have the right to:
Receive a copy of your data in a structured, commonly used, and machine-readable format; and
Request that such data be transferred directly to another controller, where technically feasible.

Right to Withdraw Consent

If you have provided consent for the collection, processing, or transfer of your personal data, you have the right to withdraw that consent at any time—either partially or fully. Once BookiMy receives your notice of withdrawal, we will cease processing your data for the purposes to which you originally consented, unless another legal basis exists for continuing the processing.

Right to Lodge a Complaint

If you have any concerns or requests related to your personal data, you may contact us at support@bookimy.com. We will acknowledge and respond to your inquiry as promptly as possible, and no later than 30 days from receipt.

10. Changes to Our Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page, and where appropriate, we may notify you via email or provide a notice upon your next login to BookiMy. Continued use of the platform following any updates signifies your acceptance of the revised Privacy Policy.