Legal

Privacy Policy

What BookProof collects, who controls it, and the choices available to businesses and to the people who book with them.

Last updated: 21 July 2026

1. Who we are

BookProof is operated by OMNIAMUS S.R.L., Ploiești, Romania ("BookProof", "we", "us"). Contact us at contact@omniamus.com.

2. Two kinds of people, two different roles

This is the most important thing to understand about this policy. BookProof serves businesses ("providers") who use our app to take bookings, and the clients of those businesses who book through a provider's public booking page.

For a provider's own account data we are the data controller: we decide what we collect and why. For the booking details of that provider's clients we act as a processor on the provider's behalf — the business you booked with is the controller of your data and decides how long it is kept and what it is used for. If you are a client and want your booking data corrected or erased, contact the business directly; we will assist them, but we act on their instructions.

3. What we collect from providers

  • Account details: email address, a hashed password, and your business name.
  • Business configuration: your booking link, timezone, currency, services, prices, deposit amounts, working hours and cancellation window.
  • Subscription and billing status from Stripe. We never see or store your card number.
  • Your Stripe Connect account identifier, so deposits can be routed to you.
  • Technical logs needed to operate and secure the service.

4. What we process about clients

We process this only to run the booking on behalf of the business you booked with: to hold your slot, to send you a confirmation and a reminder, and to let you manage or cancel your booking from the link in that email.

  • The name you enter when booking, and optionally your email address and phone number.
  • Which service you booked, and the date and time of the appointment.
  • The status of the booking, including whether it was completed, cancelled or missed.
  • Whether a deposit was paid and whether it was refunded. Card details are handled by Stripe and never reach our servers.

5. Payments and deposits

Payments are processed by Stripe. Deposits are settled on behalf of the business you booked with, so they appear on your statement under that business's name and the business — not BookProof — is the merchant for that payment. Provider subscriptions to BookProof are charged by us through Stripe. In both cases Stripe processes your card data under its own privacy policy; we receive only the outcome and the last digits or brand of the card where Stripe shows them to us.

6. Emails we send

We send booking confirmations, cancellation notices and a reminder roughly 24 hours before an appointment, using our email provider Resend. These are transactional messages that are part of the booking you made — we do not send marketing emails to clients, and we do not sell or share client contact details with anyone.

7. What we never do

  • We do not sell personal data.
  • We do not use advertising SDKs or advertising identifiers.
  • We do not use one provider's client list for our own marketing.
  • We do not build profiles of clients across different businesses.

8. Service providers

We share data only as necessary with the providers that run BookProof: Railway (application hosting), Neon (database), Vercel (public booking pages), Stripe (payments and subscriptions) and Resend (transactional email). We may also disclose information when legally required, to protect rights and safety, or in connection with a corporate transaction.

9. International transfers

Some providers may process information outside your country, including in the United States. Where required, we rely on safeguards such as the European Commission's Standard Contractual Clauses and applicable adequacy decisions.

10. Retention

Provider accounts and their data are kept until the account is deleted. Deleting a provider account erases that business, its services and its entire booking history from our systems, including the client bookings attached to it. Records we must keep for accounting or tax purposes, and Stripe's own payment records, are retained for the period the law requires.

11. Security

Passwords are stored hashed, never in plain text. Data is encrypted in transit, access is restricted, and booking-management links use unguessable tokens so a booking can only be viewed or cancelled by someone holding the link we emailed. No service can guarantee absolute security.

12. Your rights

Depending on where you live, you may request access, correction, deletion, portability or restriction of your personal data, and object to certain processing. Providers can delete everything themselves from Settings in the app, or email us. Clients should contact the business they booked with, since that business controls the booking data; if you cannot reach them, write to us and we will help. You may also complain to your local data-protection authority.

13. Children

BookProof is a tool for businesses and is not directed to children. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data.

14. Changes and contact

We may update this policy as BookProof evolves. The current version is always published here, and we give additional notice when the law requires it. Privacy questions can be sent to contact@omniamus.com or OMNIAMUS S.R.L., Ploiești, Romania.