Bookivea

Privacy Policy

Last updated: 30 June 2026

Bookivea (“we”, “us”, “our”) provides a multi-tenant scheduling and income/expenses platform for appointment-based businesses such as salons. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. It also describes, in detail, the data we access through the optional Google Calendar integration and how our use of that data complies with Google’s requirements.

1. Information we collect

Account information

When you sign up we collect your name, email address, and a securely hashed password. If you sign in with Google, we receive your verified email address and name from Google to create or link your account.

Business data you enter

Within your workspace you create operational records — clients, services and prices, reservations, expenses, receipts and settings. This is your business data; we process it solely to provide the service to you.

Google Calendar data (only if you connect it)

If — and only if — you choose to connect Google Calendar, we access your Google Calendar events through the https://www.googleapis.com/auth/calendar.events scope, and your email address, so we can show which Google account is connected. Connecting is entirely optional and can be disconnected at any time.

Technical data

We log standard technical information (e.g. timestamps, IP address for rate limiting and abuse prevention, and error diagnostics) needed to operate and secure the service.

2. Google Calendar integration

The Google Calendar integration is a one-way sync: when you create, edit or cancel a reservation in Bookivea, we create, update or delete a matching event on the connected owner’s Google Calendar. We do this only with events that represent your Bookivea reservations; we do not read, analyse or modify your other calendar events.

Limited Use disclosure. Bookivea’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, regarding data obtained from Google Calendar, we affirm that we:

We store the minimum needed for the integration to function: an OAuth refresh token and short-lived access token (both encrypted at rest), the connected Google account email, and, on each synced reservation, the identifier of its mirrored Google event. We do not copy or retain the contents of your other calendar events.

3. How we use information

We do not sell your personal information.

4. Storage & security

Each business’s data is isolated from every other tenant at the application layer and backstopped by database row-level security. Passwords are hashed; OAuth tokens and other secrets are encrypted at rest. Access to production systems is restricted and audited. We retain logs only as long as needed for operations and security.

5. Sharing & subprocessors

We share data only with service providers strictly necessary to run Bookivea, under contractual confidentiality and data-protection obligations:

We may also disclose information if required by law or to protect the rights, safety and security of Bookivea, our users, or the public.

6. Retention & deletion

We keep your data for as long as your account is active. You can disconnect Google Calendar at any time from Settings → Integrations; doing so revokes the token with Google and deletes the stored credentials from our systems. When you close your account, we delete or anonymize your personal and business data within a reasonable period, except where retention is required by law.

7. Your choices & rights

8. Contact

Questions about this policy or your data? Email us at [email protected]. We may update this policy from time to time; we will revise the “Last updated” date above and, for material changes, notify you in-app or by email.