Privacy policy
These terms and this privacy policy describe how Bookly runs today. They are not legal advice and have not been certified as a completed Saudi Personal Data Protection Law review.
Bookly is appointment software for shops. This policy covers shop owners who create an account and people who book or join a waitlist on a shop page.
Who controls the data
The Bookly operator controls owner accounts: login, email confirmation, password reset, billing administration, and the business profile the owner enters. The shop controls customer data collected on its booking page, including name, phone, optional email, appointments, and waitlist entries. Bookly processes that customer data only to provide the page, one-time codes, reminders, waitlist notices, and the owner dashboard. Bookly does not sell customer lists and does not use them to market other shops.
What we store
Owner accounts: name, email, password hash, email-confirmation status, locale, and the time you accepted these policies. Email-confirmation and password-reset tokens are stored only as hashes and they expire. Business profiles: name, contact details, hours, services, branding, and plan. Customers: name, phone, optional email, appointments, notes the shop enters, waitlist entries, and manage-page tokens. One-time booking codes are stored as hashes until they expire. Support forms store the email and message you send. Abuse prevention stores a short-lived count of requests per IP address or per phone or email, not a browsing history.
How we use it
We use this data to run booking, confirm owner email addresses, reset passwords, send appointment and waitlist email when mail is configured, administer plans, and slow abusive traffic. We do not use it for advertising.
Service providers
The app and database are hosted on Railway in Europe. Email is sent through the mail server the operator configures. If error monitoring is turned on, crash reports go to Sentry after cookies and request bodies are removed. We do not use advertising networks. A customer email is sent only for that shop's booking, reminder, or waitlist.
Storage outside Saudi Arabia
Production data is stored in the European Union, not in Saudi Arabia. The Saudi Personal Data Protection Law restricts transfers of personal data outside the Kingdom. This policy states where the data sits. It does not by itself complete a transfer assessment.
Retention and deletion
Live shop, customer, and appointment records stay until the shop is deleted or a verified deletion request is finished. Bookly does not automatically delete old appointments. Email-confirmation links last 24 hours. Password-reset links and one-time booking codes expire and are kept only as hashes. Notification logs keep delivery status. After deletion from the live database, backup copies can remain for the host window: volume snapshots up to 27 days, and point-in-time recovery of about four weeks. A snapshot kept on purpose for operations does not follow that expiry.
Cookies and on-device storage
Bookly does not set advertising or analytics cookies. Owners receive a session cookie so they stay signed in. Choosing Arabic or English sets a locale cookie named NEXT_LOCALE for up to one year. Light or dark mode is saved in this browser under the key bookly-theme, which is local storage, not a cookie. If optional tracking is added later, it will be described here before any non-essential cookie is set.
Access, correction, and deletion
You can ask to access, correct, or delete personal data. Shop owners use Support or the deletion form. A guest should ask the shop first, because the shop controls that appointment. Bookly helps delete or export it once the request is verified. We confirm using the email you provide. We may decline a request we cannot verify, or data we must keep for a legal claim, and we will explain why.
Changes
When this policy or the terms change in a material way, the acceptance version stored at signup changes. This version is dated 27 September 2026.