The short version
Scope and roles
This policy applies to the Bookhurst website, workspace administration tools, public booking pages, support channels, and related services.
A business that operates a workspace decides why and how its customer, booking, contact, invoice, and communication data is used. For that workspace data, the business is generally the controller or responsible organization, and Bookhurst processes the information to provide the service. Bookhurst is responsible for account, platform security, support, approval, and service-operation data that it collects for its own purposes.
If you booked with a business
Information we handle
The information involved depends on how you use the service:
- Account and workspace data: names, email addresses, organization name, workspace URL, timezone, staff role, verification and approval status, and account preferences.
- Booking and customer data: customer name and contact details, requested dates and times, party size or quantity, booking status, resource, assignee, customer messages, and operational notes.
- CRM and communication data: contact stages, notes, tasks, activity history, email content, templates, delivery status, and related audit information.
- Invoice and payment records: prices, deposits, balances, currency, invoice lines, payment method, refund status, and Stripe identifiers. Full payment-card numbers are handled by Stripe and are not stored by Bookhurst.
- Security and access data: password hashes, one-time token hashes, signed session information, API-token hashes and prefixes, sign-in state, session-revocation counters, rate-limit data, and platform audit records.
- Support data: the contact information, workspace identifier, topic, and message submitted through support.
- Technical data: IP and request information necessarily received by the service, timestamps, error and operational logs, and health or delivery events needed to prevent abuse and diagnose problems.
Please avoid placing sensitive personal information in free-text notes unless it is necessary and lawful for the service being delivered.
Where information comes from
- Directly from workspace applicants, owners, staff members, customers, and support requesters.
- From workspace staff when they add or update contacts, bookings, notes, tasks, invoices, or payments.
- From Stripe when a connected account, Checkout session, payment, fee, or refund changes.
- Automatically from browsers, devices, servers, and security controls when the service is accessed.
How we use information
- Create, review, authenticate, and administer workspaces and staff access.
- Show availability, create and manage bookings, prevent capacity conflicts, and keep calendars current.
- Send account verification, password reset, booking, reminder, invoice, CRM, and support emails.
- Create payment links, reconcile Stripe payment status, record offline payments, and support refunds and disputes.
- Provide CRM, invoice, audit, reporting, demo, and customer-support functionality.
- Detect misuse, enforce access boundaries, rate-limit risky activity, debug errors, and protect the service.
- Meet applicable legal obligations and establish, exercise, or defend legal claims.
Depending on the jurisdiction and context, these activities may rely on performance of a contract, legitimate interests in operating and securing the service, consent, or compliance with law. A workspace must establish its own lawful basis for the customer information it collects.
Retention and deletion
Information is retained while a workspace is active and for as long as reasonably needed to provide the service, maintain security and audit integrity, resolve disputes, and comply with legal, tax, accounting, or payment obligations. Different records may require different periods.
- Workspace staff can delete individual contacts and bookings where the product permits.
- Workspace deletion removes tenant data from the active application database through the platform administration process, subject to records that must be retained independently for security or legal reasons.
- Residual copies may remain temporarily in protected backups or provider systems until their normal rotation or deletion cycle completes.
- One-time authentication tokens expire and are stored as hashes; signed sessions expire or can be revoked through account and workspace security controls.
Contact support to request workspace deletion or to discuss a retention requirement before closing an account.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where processing relies on consent. You may also have a right to complain to a local data-protection authority.
- Workspace staff can update sign-in details in Admin → Account; a new sign-in email must be verified before it becomes active.
- Workspace teams can update or delete many booking and CRM records directly in the administration tools.
- Customers should submit booking-data requests to the business they booked with.
- For platform data or additional assistance, contact support@bookhurst.com. We may ask for information needed to verify identity and authority.
We will not discriminate against a person for exercising an applicable privacy right.
International processing
Service providers and workspace users may operate in countries different from yours. As a result, information can be processed internationally. Where law requires, the responsible party should use an approved transfer mechanism and appropriate contractual or technical safeguards.
Children’s information
The workspace administration service is intended for adults acting for a business and is not directed to children. A business that records information about a minor in connection with a legitimate booking is responsible for obtaining any required parent or guardian authorization and limiting the information to what is necessary.
Security
We use access controls, tenant-scoped authorization, password and token hashing, signed protected cookies, rate limiting, webhook verification, audit records, security headers, and operational checks. No service can promise absolute security.
Our Security page describes current safeguards, shared responsibilities, and how to report a suspected vulnerability.
Changes and contact
We may update this policy as the service, providers, or legal requirements change. The effective date above will be revised, and material changes may also be communicated through the service or by email where appropriate.
Privacy questions and requests can be sent to support@bookhurst.com or submitted through the Support page.