Draft for legal review. This text hasn't been approved by a lawyer yet and may change before launch.
Last updated: September 26, 2026 · Version 2026-09
עבריתPrivacy Policy
This policy explains what personal information Bookfront collects, why, who receives it, how long we keep it and the rights people have over it.
Booked an appointment through a Bookfront booking page? Go straight to For clients who book through Bookfront.
1. Who this policy covers
Bookfront is operated by [OPERATOR LEGAL NAME], registration number [REGISTRATION NUMBER], of [ADDRESS] (“Bookfront”, “we”, “us”). We play two different roles:
- For businesses that use Bookfront, their team members and visitors to our website, we decide how their information is used. We are responsible for it (the “controller”, and in Israel the controller of the database, בעל השליטה במאגר). Sections 3 to 13 cover this.
- For the clients of those businesses, the business is responsible and we handle the information on its behalf, as its service provider (in Israel, the holder, מחזיק). Section 2 covers this.
You can contact us about privacy at any time at privacy@getbookfront.com.
2. For clients who book through Bookfront
Who is responsible for your information
The business you book with is responsible for your information. Its name and contact details are on its booking page and in the messages you receive. Bookfront hosts the booking page and keeps the booking for the business. We use your information only for the business and as this section describes.
What is collected
- Your name and mobile phone number.
- Your email address, if you give it or the business asks for it.
- Your booking: the service, the team member, the date and time, the price, and its status (for example booked, changed or cancelled).
- Whether you ticked the box to get text messages, when you did, and whether you later opted out.
- What the business adds: notes about your visits and your history with that business.
- If the business stops taking your bookings online (for example after missed visits), your phone number and email on its blocked list, with a short private note. The booking page then asks you to contact the business.
- Messages sent to you: when, to which number or address, and whether they were delivered.
- Your IP address, used only to stop abuse of the booking form. We store it in a scrambled (hashed) form that can’t be turned back into the address, and delete it within 30 days. If bot protection is switched on, Cloudflare also checks your browser (see who receives it).
- If a booking page shows a live map, the map loads from Google when it appears on your screen, which on a short page can be as soon as the page opens. On some pages, and on devices set to save data, it loads only after you tap Show map. Google receives your IP address and browser details and may set its own cookies, under Google’s Privacy Policy; your use of the map is subject to the Google Maps/Google Earth Additional Terms of Service. Bookfront sends Google nothing about you or your booking. A business can turn its live map off.
Why it is used
- to book, change or cancel your appointment and put it in the business’s calendar;
- to send you a confirmation, reminders and notices about changes by email, and by text only if you agreed;
- to let the business contact you about your appointment and keep a record of your visits; and
- to protect the booking page from abuse and keep the service secure.
Your information is not used for advertising and is not sold. Bookfront does not send marketing messages, for us or for the business.
Do you have to give it?
No law requires you to give this information; it’s your choice. But the business needs your name and phone number to book you online. Without them you can’t book through the page, though you can still contact the business directly. Email is optional, unless the business asks for it, in which case you need it to book online. Agreeing to texts is always optional: it is a separate box that isn’t ticked for you, you can book without it, and you can change your mind at any time.
Who receives it
- the business, and the members of its team it gives access to;
- Bookfront, only to host, support and secure the service;
- the providers that run the service for us, such as hosting, database and message delivery companies (see our subprocessors); and
- authorities, if the law requires it.
Other businesses on Bookfront never see your information.
Where it is stored
In the European Union (Frankfurt, Germany). Some providers handle it in other countries, including the United States. See where information is stored.
How long it is kept
- Your bookings and client record stay with the business for as long as it has a Bookfront account, unless it deletes them sooner. If it closes its account, they are deleted within 30 days, and from backups within a further 30 days.
- Your phone number or email address in the log of messages sent to you is erased within 180 days.
- The scrambled IP records are deleted within 30 days.
- If you ask to stop texts, your phone number stays on a do-not-text list, even after your client record is deleted, so that no business on Bookfront texts it again. It comes off the list when you text START to our US number or ask us to remove it.
- A phone number or email a business blocked from online booking stays on its list until the business removes it, even after your client record is deleted; the note about you is deleted with the record.
Your rights
You have the right to see the information held about you and to ask for it to be corrected or deleted. In Israel these rights come from sections 13 and 14 of the Privacy Protection Law. You can also withdraw your consent to texts at any time: choose “Stop texts” on the page linked in every text, reply STOP to a US text, ask the business (it can record your request in Bookfront), or write to us at privacy@getbookfront.com.
To use your rights, contact the business first; its details are on its booking page. You can also email us at privacy@getbookfront.com. We will pass your request to the business and help it respond. If you aren’t satisfied, you can complain to the Israeli Privacy Protection Authority or the data protection authority where you live.
Your booking link
The messages you get include a link to manage your booking. Anyone with that link can see and change the booking, so don’t share it.
3. What we collect from businesses and their teams, and why
- Account and sign-in: your email address, the one-time codes we send you, and your sessions. We use them to sign you in and keep your account secure.
- Business profile: business name, booking link, phone, address, business email, description, logo, cover photo, colours, opening hours, services and prices. Much of this is shown on your public booking page. We use it to run your account and booking page.
- Team members: the email address you invite them with, their role and their sign-in records. Other details your business adds about its team, such as names, photos and working hours, are handled for your business under section 10 of our Terms.
- Terms acceptance: which version of the Terms you accepted and when, as a record of our agreement.
- Support: what you write to us by email or WhatsApp and the contact details you use, so we can help you.
- Security logs: IP address, browser and device type, time, pages requested and errors, to protect the service, investigate problems and prevent abuse. To limit wrong sign-in codes, we keep a scrambled (hashed) record of your email and IP address for up to 30 days.
We use this information to perform our agreement with your business, to meet our legal obligations, and because we have a legitimate interest in keeping Bookfront secure and working. We email you about your account, bookings, security and changes to our Terms. We will only send you marketing emails if you agree to them, and every one will let you unsubscribe.
4. Do you have to give us this information?
No law requires it. But we need an email address to sign you in, and your business details to create your booking page. Without them we can’t give you an account. What you tell our support team is up to you.
6. Where information is stored
Our database is in the European Union (Frankfurt, Germany), and our server code runs there too. Some of our providers are US companies or handle information in other countries: for example, our hosting provider serves pages through a global network, and US text messages go through a US provider. We transfer information out of Israel only as the Privacy Protection (Transfer of Data to Databases Abroad) Regulations allow: to countries whose law gives an adequate level of protection, such as EU member states, or to recipients who have committed in writing to protect it and not pass it on. For information from the EU, the UK or Switzerland, we rely on adequacy decisions (including the EU’s decision for Israel) or standard contractual clauses.
7. How long we keep it
- Account and business profile: while the account is open. After it closes, we delete them within 30 days, and from backups within a further 30 days.
- Terms acceptance records: for as long as we may need them to prove our agreement, and no more than 7 years after the account closes.
- Sign-in records: at least 24 months, as the Israeli Data Security Regulations require for access logs, and no longer than we need them for security. Request and error logs at our hosting provider are kept for the short period that provider sets.
- Support conversations: up to 24 months after the last message.
- Scrambled records used to limit repeated booking and sign-in attempts: up to 30 days.
8. How we protect it
Information is encrypted in transit and at rest. Each business’s data is kept separate by rules in the database itself, and team roles limit what each person can see. Sign-in uses one-time codes, so there are no passwords to steal. Only the people who need it can reach our systems, and our logs leave out phone numbers, email addresses and message contents. We follow a written security procedure under the Israeli Privacy Protection (Data Security) Regulations. No system is completely secure, so if something goes wrong we will act quickly and notify the people and authorities the law requires.
9. Your rights
You can ask to see the personal information we hold about you, to correct it, or to delete it. In Israel these rights come from sections 13 and 14 of the Privacy Protection Law. If you are in the EU or the UK, you can also ask us to restrict or stop using your information, or to give it to you in a portable format.
Email privacy@getbookfront.com from the address on your account, so we can confirm it’s you. We will reply within 30 days. If you aren’t satisfied with our answer, you can complain to the Israeli Privacy Protection Authority or to the data protection authority where you live.
Clients of a business on Bookfront should see section 2.
11. Children
Bookfront accounts are for adults running a business. Booking pages are not aimed at children, and a parent or guardian should book for a child. We don’t knowingly collect personal information from children under 13. If we learn that we have, we will work with the business to delete it.
12. Text messages and mobile information
Mobile numbers given on booking pages are used as described in section 2, and text messages go only to people who agreed to them. We do not sell, rent or share mobile numbers, or text message opt-in data and consent, with third parties or affiliates for marketing or promotional purposes. The only companies that receive them are the providers that run our service and deliver the messages (see our subprocessors). See our SMS terms.
13. Notice for US residents
This section adds to the rest of the policy for residents of California and other US states with privacy laws.
- What we collect about businesses and their teams: identifiers (name, email address, phone number, IP address), business contact and profile details, internet activity (sign-in and security logs), and professional information (your business and role). Account sign-in details count as sensitive personal information; we use them only to sign you in and keep your account secure. The sources, purposes and retention periods are in sections 3 to 7.
- Who receives it: for business purposes, our service providers, professional advisers and authorities, as described in section 5.
- No sale or sharing: we have not sold personal information or shared it for cross-context behavioural advertising in the last 12 months, and we don’t do so for anyone, including people under 16. We treat Global Privacy Control signals as a request to opt out, although there is nothing to opt out of. We don’t track visitors across other websites.
- Your rights: to know what we collect and how we use it, to access, correct and delete it, and not to be treated differently for using these rights. Send requests to privacy@getbookfront.com. An authorised agent may ask for you with your signed permission; we will confirm the request with you.
- Clients of a business: for information about clients, the business is responsible and we are its service provider. Send requests to the business, or to us and we will pass them on.
14. Changes to this policy
We will post any change here and update the date at the top. If a change is important, we will email account holders before it takes effect.
15. Contact
[OPERATOR LEGAL NAME], [ADDRESS]. Privacy questions and requests: privacy@getbookfront.com. Anything else: hello@getbookfront.com.