Legal

Privacy Policy

Last updated: June 22, 2026

This page is maintained by Book4Me to explain what personal data Book4Me collects, why we collect it, who we share it with, and the choices you have. It is not a certification or independent audit.

1. Who we are

Book4Me is operated by Book4Me. For any privacy question or data-subject request, contact us at privacy@book4me.io.

2. Data we collect

  • Account data — name, email, password hash, role, workspace, and authentication identifiers (including Google or Microsoft sign-in IDs).
  • Calendar & meeting data — connected calendar tokens, event titles, times, attendees, free/busy windows, and video-meeting links (Google Meet, Microsoft Teams, Zoom).
  • Contact & CRM data — names, emails, phone numbers, tags, timeline events, and notes you add about your contacts.
  • WhatsApp data — inbound and outbound messages, message media, session state, and template metadata when WhatsApp is enabled.
  • Voice & telephony data — call metadata, DTMF input, call audio, recordings, and transcripts when the voice agent is enabled.
  • AI inputs & outputs — prompts, message context, transcripts, summaries, embeddings, drafts, and classifications generated by AI features you turn on.
  • Event & class registrations — guest name, email, phone (when provided), and answers your guests submit.
  • Usage & device data — IP address, browser, pages visited, error reports, and basic diagnostics.
  • Billing data — plan, subscription state, and customer/subscription identifiers from our payment processor (we do not store full card numbers).

3. Why we use it

  • To provide the booking, calendar, WhatsApp, voice, classes, events, and CRM features.
  • To run AI-assisted features such as drafting messages and event copy, summarizing conversations, classifying intent, and coordinating group bookings.
  • To transcribe call and meeting audio (speech-to-text) and to generate spoken responses (text-to-speech) for the voice agent.
  • To authenticate you, secure the service, and prevent abuse.
  • To send transactional emails (account, confirmations, reminders) and operational notifications.
  • To process payments, manage subscriptions, and produce invoices.
  • To comply with legal obligations and enforce our Terms.

4. Legal bases (GDPR)

We rely on (a) performance of a contract to run your workspace, (b) legitimate interests to keep the service secure and improve it, (c) consent for optional cookies, marketing, and certain AI or recording features, and (d) legal obligations where applicable.

5. Subprocessors and integrations

Book4Me relies on the following service providers to operate the platform. Several are activated only when you enable the related feature or connect the integration.

Infrastructure & platform

  • Lovable Cloud / Supabase — application database, authentication, file storage, and server functions. Hosts the majority of your workspace data.
  • Cloudflare — application hosting and edge runtime for the web app and APIs.
  • Scheduled jobs (pg_cron) — internal automation for reminders, retries, and clean-ups.

AI services

  • Lovable AI Gateway — routing layer that forwards AI requests to the underlying model providers.
  • Google (Gemini models) — chat completions, drafting, summarization, and classification.
  • OpenAI — chat completions and Whisper speech-to-text transcription of call and voice audio.
  • ElevenLabs — text-to-speech voice synthesis for the voice agent and group-booking calls.

AI providers receive only the content needed to perform the requested task (for example a message thread, a call transcript, or a CRM context snippet). We do not use your data to train our own models, and we rely on the providers' own commitments not to use API content for model training by default.

Communications

  • Twilio — voice telephony, call media, and (where used) SMS for the voice agent and notifications.
  • Meta / WhatsApp Business Platform — sending and receiving WhatsApp messages, media, and templates.
  • Resend — transactional and authentication email delivery (confirmations, reminders, password resets).

Calendar, meeting & identity

  • Google — OAuth sign-in, Google Calendar sync, free/busy, and Google Meet link creation.
  • Microsoft — OAuth sign-in, Outlook Calendar sync, free/busy, and Microsoft Teams link creation.
  • Zoom — Zoom meeting link generation when you connect a Zoom account.

Billing

  • Stripe — subscription billing, payment processing, and storage of customer and subscription identifiers.

Each provider processes data under its own privacy terms. Inbound webhooks and public API endpoints (for billing, telephony, WhatsApp, calendar providers, and scheduled jobs) are protected by signature verification or shared secrets.

5a. AI processing

AI features are optional and are activated when you turn them on or use a flow that depends on them. They include — among others — the WhatsApp coordinator, the group-booking voice agent, event and class drafting, CRM/customer-profile context, and intent classification. When these features run we send the strictly necessary content (such as the current message thread, a call transcript, contact context, or event details) to the AI providers listed above via the Lovable AI Gateway, and we store the resulting output (drafts, summaries, transcripts, classifications) in your workspace. You can avoid AI processing for a given workspace by not enabling the related features.

5b. Telephony, recordings & transcripts

When the voice agent is enabled, calls are placed and received through Twilio. Call audio may be transcribed (using OpenAI Whisper or an equivalent model) and spoken responses may be synthesized (using ElevenLabs). Call metadata, transcripts, and any recordings are stored in your workspace and are subject to the retention rules below. You are responsible for providing any call-recording, AI-assistance, or automated-calling disclosures required by the law that applies to you and to your end-users.

6. International transfers

Several of the subprocessors above (notably the AI, telephony, and email providers) are based in the United States and may process data outside the EEA, UK, or your country of residence. Where required, we rely on Standard Contractual Clauses or equivalent safeguards offered by those providers.

7. Retention

We keep account, calendar, CRM, WhatsApp, voice, and AI conversation data for as long as your workspace is active. Call recordings, transcripts, and AI logs follow the same workspace-deletion lifecycle; short-lived diagnostic and security logs are retained for a shorter period. When you delete your account or workspace, we delete or anonymize personal data within a reasonable period, except where we must retain it (e.g. billing records).

8. Your rights

Depending on your jurisdiction, you can access, correct, export, restrict, or delete your personal data, and withdraw consent. To exercise these rights email privacy@book4me.io.

9. Security

We use industry-standard protections including encryption in transit, role-based access, signed webhooks for inbound integrations, and per-tenant row-level isolation in the database. No system is perfectly secure; report concerns to privacy@book4me.io.

10. Cookies

Book4Me uses essential cookies to keep you signed in and to remember your preferences. Optional cookies are loaded only with your consent and you can change your choice any time via the “Cookie preferences” link in the footer.

11. Children

Book4Me is not directed at children under 16. If you believe a child has provided us personal data, contact privacy@book4me.io.

12. Changes

We may update this policy. Material changes will be announced in the portal or by email before they take effect.

13. Contact

Book4Meprivacy@book4me.io.