Effective date: 20 August 2026 Last updated: 20 August 2026
Getbooqin (“Getbooqin”, “we”, “us”) makes a booking app for Shopify stores. This policy explains what personal data we handle, why, how long we keep it, and what you can do about it. It applies to the Getbooqin Shopify app, the booking pages it publishes on a merchant’s storefront, and the getbooqin.com website.
We apply the same privacy rights to every person whose data we handle, wherever they live. Where the GDPR, UK GDPR, CPRA or a similar law gives someone a right, we honour it for everyone.
Contact: support@getbooqin.com Operator: Getbooqin, operated from India.
One thing to be clear about up front, because the two are governed very differently: the app and the booking pages carry no analytics or advertising trackers of any kind. Our marketing website, getbooqin.com, does. Section 5 covers the website. Everything before it covers the app.
1. Who controls what
There are two relationships in the app and they are governed differently.
Merchant account data – we are the controller. When you install Getbooqin, we hold your store identifier, your contact details and your plan. We decide how that is used, so we are responsible for it.
Customer booking data – we are the processor. Everything about the people who book with you belongs to you. You are the controller; we process it only to run the app, only on your instructions, and only for as long as you tell us to. If you and Getbooqin need a written data processing agreement, ask at support@getbooqin.com and we will send one.
Shopify is a separate controller for the store data it holds. Its handling of that data is covered by Shopify’s own privacy policy, not this one.
2. What we collect
We ask Shopify for the minimum set of data the app needs to open a slot, hold it, and attach it to an order. Nothing beyond that.
From the merchant’s store
| Data | Why we need it |
|---|---|
| Shop domain, shop ID, store name | Identify the install and scope every record to one store |
| Store timezone, currency, locale | Compute slots in your business timezone and price them correctly |
| Store owner name and email address | Account setup, billing notices, service and security notices |
| Subscription plan and billing status | Apply plan limits and process charges through Shopify Billing |
| Products, variants and prices for bookable services | Add the booking to the cart so it moves through your normal checkout |
| Orders and order line items linked to a booking | Confirm a slot is paid, apply cancellation rules, issue refunds |
| Locations | Run resources, hours and pricing per location on the Multi-location plan |
From the merchant’s customers
We access these fields, which Shopify classifies as protected customer data, only when a booking exists.
| Data | Why we need it |
|---|---|
| Name | Show the merchant who holds the slot; identify the customer on arrival |
| Email address | Send booking confirmation, reminder, reschedule and cancellation notices |
| Phone number | Only if the merchant enables SMS or phone reminders for a service |
| Order ID and booking reference | Link the slot to the payment and honour cancellation and refund rules |
| Booking details – service, add-ons, resource, date, time, duration, notes the customer types | Deliver the booking itself |
| Timezone as reported by the customer’s browser | Render the slot in the customer’s local time |
We do not collect or store payment card numbers, bank details, government identifiers, or any special-category data such as health information. Payments run entirely through your Shopify checkout. Where a customer types free-text notes into a booking form, that content is passed through to you as-is; we ask merchants not to solicit sensitive information in those fields.
From our contact form
When you fill in the contact form at getbooqin.com/contact we receive your name, email address, business name, the plan you are considering, a description of what you want to make bookable, and your message. We use it to answer your enquiry and nothing else – it is not added to a marketing list, and it is not passed to any advertising platform. The form carries an explicit consent checkbox, and consent is the basis on which we contact you back. Ask us to delete an enquiry at any time.
From the app itself
Server logs (IP address, timestamp, request path, user agent, error traces) and app usage events, kept for security, debugging and abuse prevention. Session cookies in the app admin to keep you signed in.
There are no analytics tags, advertising pixels or third-party trackers in the Getbooqin app admin or on any booking page we publish on a merchant’s storefront. We do not load Google Analytics, Google Ads, Meta Pixel or anything comparable into a merchant’s storefront. The trackers described in section 5 run on getbooqin.com only.
3. What we do with it, and what we never do
We use the data described above only for the purposes listed: providing the booking functionality, notifying people about their bookings, billing merchants, supporting merchants who contact us, keeping the service secure, and meeting legal obligations.
With merchant and customer data, we do not:
- sell it, share it for advertising, or disclose it to any advertising platform or data broker;
- use it to train machine learning models;
- use it for our own marketing, or contact a merchant’s customers for anything other than the booking they made;
- make automated decisions that produce legal or similarly significant effects on anyone.
Where a customer has opted out of a category of data processing through Shopify’s customer privacy controls, we apply that decision. Where processing rests on consent, it can be withdrawn at any time without affecting what was lawful before.
Separately, our marketing website uses advertising and analytics cookies, which under the CPRA may amount to “sharing” personal information for cross-context behavioural advertising in respect of website visitors only. Section 5 explains this and how to opt out. It never involves merchant account data or a merchant’s customer data.
Legal bases (GDPR / UK GDPR). Merchant account and billing data: performance of a contract. Customer booking data: processed on the merchant’s documented instructions under Article 28. Security logs and abuse prevention: legitimate interests. Optional channels such as SMS reminders: consent, collected by the merchant. Contact form enquiries, and website analytics and advertising cookies: consent.
4. Who else touches app data
We keep the list short on purpose.
| Sub-processor | Role | Location |
|---|---|---|
| Hostinger International Ltd. | Application hosting, database, backups, transactional email delivery | EU / global data centres |
| Shopify Inc. | Source of the store and order data; host of the checkout and the Shopify Billing charge | Canada / global |
That is the complete list for the app. No analytics vendor, no CRM, no advertising platform, no data broker receives merchant or customer data. If we add a sub-processor we will update this table and email merchants at least 30 days before the change takes effect, so there is time to object.
We may also disclose data where the law requires it – a valid court order or lawful government request – or to establish or defend a legal claim. If we receive such a request for a merchant’s data, we will tell the merchant unless we are legally barred from doing so.
5. Cookies and tracking on getbooqin.com
This section is about our marketing website only. None of it applies to the app or to booking pages on merchant storefronts.
When you visit getbooqin.com we use the following services. They may set cookies or similar identifiers in your browser and receive your IP address, pages viewed, referring URL, device and browser information, and the actions you take on the site.
| Service | Provider | Purpose | Type |
|---|---|---|---|
| Google Analytics 4 | Google Ireland Ltd. / Google LLC | Understand which pages people read and where visitors come from, in aggregate | Analytics |
| Google Ads tag | Google Ireland Ltd. / Google LLC | Measure which ads led to a signup, and build remarketing audiences | Advertising |
| Google Search Console | Google Ireland Ltd. / Google LLC | See how the site performs in search results. Uses a verification token; sets no visitor cookies | Search performance |
| Meta Pixel | Meta Platforms Ireland Ltd. | Measure which Facebook and Instagram ads led to a signup, and build remarketing audiences | Advertising |
Consent. Where the law requires consent – the EEA, the UK and comparable jurisdictions – the analytics and advertising services above load only after you accept them in our cookie banner. Strictly necessary cookies, which keep the site working and remember your consent choice, load without consent because the site cannot function otherwise. You can change or withdraw your choice at any time from the cookie settings link in the site footer.
Opting out. Beyond our banner you can opt out at the source: Google Analytics via the Google Analytics opt-out add-on, Google advertising via Google Ads Settings, and Meta advertising via your Facebook or Instagram ad preferences. Most browsers also let you block or delete cookies. California residents may exercise the right to opt out of sale or sharing by rejecting advertising cookies in our banner or by emailing support@getbooqin.com.
What these services never receive. No merchant account data, no booking data, and no personal data belonging to a merchant’s customers is sent to Google or Meta. These tags exist on our marketing pages and nowhere else.
Where the data goes. Google and Meta process this data as independent controllers under their own privacy policies, and may transfer it outside the EEA and the UK. We do not control their subsequent use of it.
6. How long we keep it
| Data | Retention |
|---|---|
| Active bookings and customer records | For as long as the app is installed, plus any longer period the merchant sets for their own records |
| Cancelled or completed bookings | 24 months by default, so merchants keep booking history and can settle disputes |
| Merchant account and billing records | 7 years where tax or accounting law requires it |
| Server and security logs | 90 days |
| Support correspondence and contact form enquiries | 24 months from the last message |
| Website analytics data (GA4) | 14 months |
| Website advertising identifiers | Per Google and Meta retention defaults; cleared when you delete cookies or withdraw consent |
On uninstall. Shopify sends us a shop/redact request 48 hours after the app is uninstalled. On receiving it we delete all shop and customer data for that store, and it is fully purged from live systems and backups within 30 days. Nothing is retained for reuse.
On a customer erasure request. Shopify sends customers/redact when a store owner asks us to delete a specific customer’s data. We complete the deletion within 30 days and confirm it. Where a booking is tied to a paid order we may be required to keep the minimum transaction record for tax purposes; in that case the personal fields are erased and only the anonymised record remains.
On a customer data request. Shopify sends customers/data_request when a customer asks to see what we hold. We return the data to the store owner within 30 days for them to pass on.
We verify every one of these webhooks against Shopify’s HMAC signature and reject anything that fails.
7. How we protect it
- All data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest.
- Database backups are encrypted and access to them is logged.
- Test and production environments are fully separated. Production customer data is never copied into a test or development environment.
- Access to protected customer data is limited to the named staff who need it to run the service, granted on a least-privilege basis and reviewed on a schedule.
- Staff accounts require strong unique passwords and two-factor authentication. Access to production systems is logged and the logs are retained for audit.
- We operate a data loss prevention strategy covering exports, downloads and third-party transfers of customer data.
- We maintain a written security incident response policy. If a breach affects a merchant’s data, we will notify that merchant without undue delay and in any event within 72 hours of becoming aware of it, with what we know about scope, cause and remedy.
No system is perfectly secure, and we will not claim otherwise. Report anything you find to support@getbooqin.com with “Security” in the subject line, and we will respond within one working day.
8. International transfers
Getbooqin is operated from India and our infrastructure sits with Hostinger. Personal data originating in the EEA, the UK or Switzerland may therefore be transferred outside those regions. Those transfers are made under the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with the technical measures in section 7. A copy of the clauses is available on request. Website analytics and advertising data is transferred by Google and Meta under their own transfer mechanisms.
9. Your rights
Anyone whose personal data we hold can ask us to:
- access it and receive a copy;
- correct it if it is wrong or incomplete;
- delete it;
- restrict or object to processing;
- port it to another provider in a machine-readable format;
- withdraw consent where consent is the basis, including cookie consent;
- opt out of sale or sharing – for website advertising cookies, as described in section 5. We never sell or share merchant or customer data.
We will not discriminate against anyone for exercising a right.
If you are a customer who booked with a store, the store is your first point of contact, because they control your data. Ask them, or write to support@getbooqin.com and we will route your request to them and help them answer it.
If you are a merchant or a website visitor, write to support@getbooqin.com. We respond within 30 days and will not charge for a reasonable request. We may need to verify identity before acting.
If you think we have handled your data badly, tell us first – we would rather fix it. You also have the right to complain to your local data protection authority.
10. Children
Getbooqin is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If a merchant’s booking flow is used to collect a minor’s details, the merchant is responsible for obtaining the consent their law requires. If you believe we hold a child’s data without that consent, write to support@getbooqin.com and we will delete it.
11. Changes to this policy
We will post any change here with a new “last updated” date. For a change that materially affects how we handle personal data, we will email merchants at least 30 days before it takes effect. Continuing to use the app after that date means the updated policy applies.
12. Contact
Everything – support, privacy requests, data requests, security disclosures: support@getbooqin.com
For a security report, put “Security” in the subject line. We reply to every message within one working day.