Draft for legal review. This text hasn't been approved by a lawyer yet and may change before launch.
Last updated: September 25, 2026 · Version 2026-09-beta
עבריתTerms of Service
These Terms are the agreement between [OPERATOR LEGAL NAME] (“Bookfront”, “we”, “us”) and the business that opens a Bookfront account (“the business”, “you”). They cover the Bookfront app, the booking pages we host for you and the messages we send for you. Section 10 is our data processing agreement for your clients’ information.
1. About these Terms
Bookfront is operated by [OPERATOR LEGAL NAME], registration number [REGISTRATION NUMBER], of [ADDRESS]. You can reach us at privacy@getbookfront.com.
Bookfront is a tool for businesses. By creating an account or clicking to accept these Terms, you confirm that you are at least 18, that you are using Bookfront for a business, and that you have authority to accept these Terms for that business. If you don’t agree, don’t use Bookfront.
Our Privacy Policy explains how we handle information about you and the people on your team. Section 10 explains how we handle information about your clients.
2. The beta
Bookfront is in a free, invite-only beta. During the beta:
- Bookfront is free. We don’t ask for payment details.
- Before we charge for anything, we will publish our prices and email you at least 30 days in advance. You will only be charged if you choose a paid plan. If you don’t, you can export your data and close your account before any charge applies.
- Features may change, move or be removed. Features we describe as “coming soon” are plans, not promises.
- We may end the beta. If we do, we will give you at least 30 days’ notice.
3. Your account and your team
- Give us accurate information about your business and keep it up to date.
- You sign in with one-time codes sent to your email address, so keep that inbox secure. You are responsible for what happens in your account.
- You decide who on your team gets access and with which role. Team members accept these Terms when they join, and use Bookfront on your behalf. You are responsible for their use of Bookfront, and for removing access when someone leaves.
- Tell us right away at privacy@getbookfront.com if you think someone has accessed your account without permission.
- We may limit how many businesses one person can create.
4. Acceptable use
You may not use Bookfront to:
- break the law or help anyone else break it;
- publish content that is unlawful, misleading, defamatory, hateful, sexually explicit, or that infringes someone else’s rights;
- pretend to be another business or person, or use a booking link or name that misleads people;
- send marketing or promotional messages. Bookfront only sends messages about appointments (see section 8);
- offer services that are illegal where you or your clients are;
- upload malicious code, probe or test our systems for weaknesses, get around limits or security measures, overload the service, or copy it by automated means; or
- create fake bookings, or collect information about people who didn’t choose to book with you.
We may remove content, reclaim a booking link, or suspend a booking page that breaks these rules (see section 16).
5. Health and other sensitive information
Bookfront is not built to hold medical records or other sensitive information, and we don’t sign business associate agreements.
- Don’t use Bookfront if you are a “covered entity” or “business associate” under the US HIPAA rules, or any similar health provider that must keep patient records to a specific legal standard.
- Don’t put diagnoses, treatment details, medical history, government ID numbers, payment card numbers or similar sensitive information in notes or any other field.
- If a client tells you about something that matters for their service, like an allergy to a product, record only the minimum you need, and only if the client agrees.
6. Your responsibilities to your clients
Your clients’ information belongs to your business. You decide what you collect and why, and privacy laws treat you as responsible for it: the “controller” in most countries, and the controller of the database (בעל השליטה במאגר) under Israel’s Privacy Protection Law. That means:
- You must have a lawful reason to hold your clients’ information and use it only for your relationship with them.
- Your booking page shows clients a standard privacy notice that names your business as responsible for their information. Keep your business name and contact details accurate so the notice is correct. If you collect or use information in other ways, you must tell your clients yourself.
- Only add a client’s phone number or email if they gave it to you for their appointments. Texts go only to clients who ticked the separate SMS consent box on your booking page.
- Follow the laws on messages that apply to you, such as the Israeli Communications Law (section 30A), the US TCPA and CAN-SPAM Act. Don’t use Bookfront to contact people who asked not to be contacted.
- Answer your clients’ requests to see, correct or delete their information. You can edit and delete client records in the app, and we will help as set out in section 10.
- In Israel, keep the records your database needs under the Privacy Protection (Data Security) Regulations, such as a short database definition document and a list of who on your team has access. We provide a template on request.
- Your prices, cancellation rules, deposits and other policies are between you and your clients. You are responsible for following consumer protection law when you set and apply them.
7. Your booking page and content
You keep all rights to the content you add, such as your business name, logo, photos, service descriptions and client records. You give us permission to host, copy, display and process that content only to run Bookfront for you.
Your booking page is public: anyone with the link can see it. Only add photos, text and logos that you own or have permission to use, and add descriptions to images where it helps people who use screen readers.
8. Emails and texts we send for you
Bookfront sends messages about appointments on your behalf: confirmations, reminders, and notices when an appointment is changed or cancelled, with a link that lets the client manage their booking. We also email you about new online bookings and changes your clients make.
- Messages are rolling out during the beta. Until email or texts are switched on for your country, nothing is sent.
- We write the message templates. Messages carry your business name and are strictly about appointments. We don’t send marketing for you.
- Texts are sent only to clients who opted in, and every client can opt out at any time (for example by replying STOP in the US). We honour opt-outs, and you may not ask us to text someone who opted out.
- In the US, texts come from a toll-free number registered to Bookfront. In Israel, they come from a sender name. Phone carriers and message providers have their own rules and may delay, filter or block messages.
- Delivery is not guaranteed. Don’t rely on messages alone for anything critical.
- To protect clients and control costs, we may limit how many messages go to one number and send texts only to countries we support.
The SMS terms explain text messages to your clients.
9. Availability, support and changes to the service
We work to keep Bookfront available and secure, but we can’t promise it will always be available or free of errors, especially during the beta. We may need to pause it for maintenance, security or reasons outside our control.
We improve Bookfront all the time and may change or remove features. Where a change removes something you rely on, we will try to tell you in advance.
For help, email hello@getbookfront.com or message us on WhatsApp at [SUPPORT WHATSAPP].
10. Data processing agreement
This section applies whenever we handle personal information about your clients and your team for you (“Client Data”). If it conflicts with anything else in these Terms, this section wins for Client Data.
10.1 Roles
You are the controller of Client Data and we are your processor. Under Israeli law you are the database controller (בעל השליטה במאגר) and we are the holder (מחזיק). Under US state privacy laws we are your “service provider” or “processor”.
10.2 What we process
- People: your clients and people who book with you, and the members of your team.
- Information: names, phone numbers, email addresses, appointment details (service, team member, date and time, price, status, how it was booked), notes you add, SMS consent and opt-out records, records of messages sent, and team members’ names, photos, working hours and time off.
- Purpose: to provide Bookfront to you: hosting your booking page, storing and showing your appointments and client records, sending the messages described in section 8, keeping the service secure, and support.
- Duration: while your account exists, plus the deletion periods in 10.10.
10.3 Your instructions
We process Client Data only to provide Bookfront according to these Terms and your instructions. Your settings and actions in the app are instructions. We will also process it where the law requires us to, and will tell you first unless the law forbids it. If we believe an instruction breaks the law, we will tell you.
We will not sell Client Data or share it for cross-context behavioural advertising. We will not use it for our own marketing, or keep, use or disclose it for any purpose other than providing Bookfront to you. We will not combine it with information from other sources, except as needed to run and secure the service (for example, stopping abuse across booking pages). We will tell you if we can no longer meet these duties, and you may then take reasonable steps to stop any unauthorised use.
10.4 Confidentiality
Only people who need access to run, secure or support Bookfront can reach Client Data, and they are bound to keep it confidential.
10.5 Security
We keep appropriate security measures in place, including:
- encryption in transit (HTTPS) and at rest;
- database rules that keep each business’s data separate, so one business can’t see another’s;
- roles within each business, so team members only get the access their role allows;
- sign-in with one-time codes, with no passwords to leak;
- server keys held only by the people who need them, with the least access that works;
- rate limits on public forms, and bot protection where it is switched on;
- logs that leave out phone numbers, email addresses and message contents; and
- a written security procedure under the Israeli Privacy Protection (Data Security) Regulations, reviewed at least once a year.
10.6 Subprocessors
You authorise us to use the providers on our subprocessors page. We bind each one to data protection terms at least as protective as this section, and we stay responsible for them. We will email you at least 14 days before adding or replacing a subprocessor. If you object on reasonable data protection grounds, we will try to find a solution; if we can’t, you may close your account and we won’t charge you for the period after the change.
10.7 Where data is stored and transfers
Client Data is stored in the European Union (Frankfurt, Germany). Some providers handle it in other countries, including the United States (see the subprocessors page). We transfer Client Data outside Israel only as the Privacy Protection (Transfer of Data to Databases Abroad) Regulations allow: to countries whose law gives an adequate level of protection, such as EU member states, or to recipients who have committed in writing to protect the data and not pass it on further. For information from the EU, the UK or Switzerland, we rely on adequacy decisions (including the EU’s decision for Israel) or standard contractual clauses.
10.8 Security incidents
If we become aware of a security incident affecting your Client Data, we will tell you without undue delay, and no later than 48 hours after confirming it. We will explain what happened, what information was involved, the likely consequences and what we are doing about it, and we will update you as we learn more. We will help you meet your own duties to notify authorities, such as the Israeli Privacy Protection Authority, and affected people. We will report to authorities directly where the law requires us to.
10.9 Helping you
- Requests from people: you can view, correct, export and delete client records in the app. If that isn’t enough to answer a request to see, correct or delete information, we will help. If a client contacts us directly, we will pass the request to you and let the client know we have done so.
- Assessments: we will give you reasonable information to help with risk assessments and with dealing with regulators.
- Audits: once a year, or after a security incident, we will answer a reasonable written security questionnaire and share a summary of our security procedure. Where the law requires more, we will allow an audit by an independent auditor bound by confidentiality, at your cost, on reasonable notice.
10.10 Retention, return and deletion
- Appointments and client records stay in your account until you delete them or close your account.
- Phone numbers and email addresses in the log of sent messages are erased within 180 days.
- Scrambled records used to limit repeated booking and sign-in attempts are deleted within 30 days.
- You can export your data at any time, in the app or by asking us. When your account is closed, we delete Client Data from our live systems within 30 days, and backup copies are overwritten within a further 30 days, unless the law requires us to keep something longer.
11. Fees
Bookfront is free during the beta. If we introduce paid plans, section 2 applies: we publish prices, give you at least 30 days’ notice, and charge only if you choose a paid plan. Prices will say whether they include tax.
12. Ownership and feedback
Bookfront, its software, design and brand belong to us or our licensors. These Terms give you the right to use Bookfront for your business while your account is open, and nothing more. If you send us ideas or feedback, we may use them without owing you anything.
13. Disclaimers
Bookfront is provided “as is” and “as available”, especially during the beta. To the extent the law allows, we give no warranties beyond what these Terms say, including warranties that the service will be uninterrupted, error-free or fit for a particular purpose. Keep your own copy of anything you can’t afford to lose, and have a way to contact clients if the service or a message fails.
14. Limitation of liability
To the extent the law allows:
- neither of us is liable for indirect or consequential loss, or for lost profits, revenue, bookings or goodwill; and
- each party’s total liability under these Terms is limited to the greater of the amount you paid us in the 12 months before the claim and USD 100 (or its equivalent in Israeli shekels).
These limits don’t apply to fraud, wilful misconduct, your obligations in section 15, or anything else the law doesn’t allow us to limit.
15. Your indemnity
If someone makes a claim against us because of content you added, messages you asked us to send, your treatment of your clients or their information, or your breach of these Terms or the law, you will cover our reasonable costs and losses from that claim. We will tell you about the claim promptly and let you take part in handling it.
16. Suspension, closing an account and termination
- You can stop using Bookfront and close your account at any time, in the app or by emailing us.
- We may suspend a booking page or an account right away if it breaks these Terms or the law, puts other people or the service at risk, or if a court or authority requires it. Where it’s safe and lawful, we will tell you why and give you a chance to fix the problem.
- We may also end these Terms for any other reason with at least 30 days’ notice, including when the beta ends.
- Unless we closed your account for a serious breach, you will have at least 30 days after notice to export your data. Section 10.10 then applies to deletion.
- Sections that by their nature should continue, such as 10, 13, 14, 15 and 17, continue after the Terms end.
17. Governing law and disputes
These Terms are governed by the laws of the State of Israel, without regard to its conflict of laws rules. The competent courts in Tel Aviv-Jaffa have exclusive jurisdiction over any dispute about them. Either party may still ask any competent court for urgent relief, such as an injunction.
18. Changes to these Terms
We may update these Terms. For important changes, we will email you at least 30 days before they take effect and ask you to accept the new version in the app. Changes required by law, or that only fix errors or describe new features, can take effect sooner. If you don’t agree to a change, you can close your account before it takes effect. The version number and date at the top of this page show which version is current.
19. General
- These Terms, with the Privacy Policy and the pages they link to, are the whole agreement between us about Bookfront.
- You may not transfer these Terms without our written consent. We may transfer them as part of a merger, acquisition or sale of our business, and will tell you if we do.
- If part of these Terms can’t be enforced, the rest still applies. Not enforcing a right is not a waiver of it.
- We send notices to the email address on your account. You can send notices to privacy@getbookfront.com or to our address above.
- These Terms are published in English and Hebrew. If the two versions differ, the version in the language your business uses in Bookfront applies.
20. Contact
[OPERATOR LEGAL NAME], [ADDRESS]. Email privacy@getbookfront.com for legal and privacy matters, or hello@getbookfront.com for everything else.