Privacy Policy

Effective from: 02.10.2026 · Eesti keeles

This Privacy Policy explains how Babooked Solutions OÜ handles personal data in the Babooked booking platform: the website babooked.ee, the web app at app.babooked.ee, the Babooked apps for Android and iOS, and the booking pages that businesses publish through Babooked.

1. Who we are

Babooked Solutions OÜ (registry code 16706699) runs the Babooked platform. In this policy “we” and “us” mean Babooked Solutions OÜ.

  • Address: Sookase tee 11, Haaslava küla, Kastre vald, 62107 Tartu maakond, Estonia
  • Email: info@babooked.ee
  • Phone: +372 5400 2220

Write to info@babooked.ee with any question about your personal data or this policy.

2. Whose data this covers

Business users. Salons, clinics, sports venues and other businesses use Babooked to run their calendar, staff and bookings. When you create an account for your business, or a business invites you as a staff member, we process your account data as the controller.

People who book. When you book a service on a business’s Babooked booking page, the business receives your booking and decides how to use it. Under our data processing agreement with the business, the business and we are joint controllers of booking data. You can contact either of us about your data.

Website visitors. When you visit babooked.ee, we process limited technical data described in section 8.

3. What data we collect

Account data (business users): name, email address, phone number, password (stored only as a one-way hash), profile picture, language, time zone and other settings.

Business data a business user enters: company name, registry code, address, bank account details, opening hours, services, prices, staff members and their schedules, and the business’s client list.

Booking data: the name, phone number and email address of the person booking, the chosen service, staff member, time and price, notes the person adds, and optionally a birthday or other details the business asks for. Businesses also add clients and bookings themselves, for example from a phone call.

Payment data: when a business asks for a prepayment, you pay through our payment provider Montonio using your bank. We receive the payment status, amount, and the payer’s name and bank account number. We never see your online banking credentials or card details.

Invoices: invoices that businesses issue to their clients through Babooked, and invoices we issue to businesses for the subscription, including the buyer’s name, address and the invoiced services.

Technical and security data: IP address, browser and device type, operating system, and the time of each sign-in. We keep a record of sign-ins and of the IP address used at registration to protect accounts from misuse.

Push notification tokens: if you allow notifications in the Babooked app, your device receives a token from Google (Android) or Apple (iOS). We store this token with your staff profile so we can send notifications about new and changed bookings.

Usage data: which pages and features are used, error reports, and recordings of how the app interface was used (session replays). A session replay shows what was on the screen, which can include names and contact details typed into forms. On booking pages we link usage data to a browser only after the person submits a booking (see section 8).

Messages: emails you send us.

PurposeLegal basis (GDPR)
Creating and running your account, showing your calendar, storing bookings, sending booking confirmations and remindersPerformance of a contract (Article 6(1)(b))
Taking prepayments and issuing invoicesPerformance of a contract (Article 6(1)(b))
Keeping accounting documentsLegal obligation (Article 6(1)(c)), Estonian Accounting Act
Push notifications in the appYour consent, given in your device’s notification prompt (Article 6(1)(a))
Protecting accounts, preventing fraud, fixing errorsOur legitimate interest in a secure, working service (Article 6(1)(f))
Product statistics and session replays to improve the appOur legitimate interest in improving the service (Article 6(1)(f))
Answering your questionsPerformance of a contract, or our legitimate interest in replying (Article 6(1)(b) or (f))

We do not sell personal data. We do not use it for advertising profiles, and we do not make decisions about you by automated means that have legal or similarly significant effects.

5. Who receives the data

The business you book with sees your booking and your contact details. Staff of a business see the data their role in the business allows.

Service providers process data on our behalf under data processing agreements. We name the categories here and send the current list of providers on request:

  • hosting and file storage, with servers in the EU
  • email delivery for booking confirmations, reminders, invoices and password resets
  • push notification delivery: Google for Android devices and Apple for iOS devices
  • payment initiation for prepayments by bank link
  • error monitoring and session recording, to find and fix bugs
  • accounting software, for invoices we issue to businesses

Authorities: we disclose data to courts, the police or other public authorities when Estonian law requires it.

6. Transfers outside the EU

We store our database and files in the European Economic Area. Some providers of hosting, push notifications, error monitoring and session recording are based in the USA and may process data there. For those transfers we rely on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses.

7. How long we keep data

  • Account data: until you delete your account. After you request deletion your account is locked, and the data is deleted permanently 30 days later.
  • Business data and booking data: for as long as the business keeps its Babooked account, or until the business deletes it.
  • Invoices and accounting documents: 7 years, as the Estonian Accounting Act requires. They stay even after an account is deleted.
  • Session replays: 90 days.
  • Email delivery logs: the latest 2,000 emails per business.
  • Push notification tokens: until you sign out of the app, turn notifications off, or the token stops working.
  • Product statistics and sign-in records: for as long as needed for statistics and account security.
  • Emails you send us: as long as needed to handle your request.

8. Cookies and similar technologies

  • Session cookie in the web app keeps you signed in. It is strictly necessary and is set only when you sign in.
  • Booking pages set a cookie named bb_eid when you submit a booking. It contains a random identifier that links the booking funnel statistics and session replay of that browser, and it expires after 180 days.
  • The Android and iOS apps store a random device identifier on the device for session replays.
  • babooked.ee counts page views without cookies, using a daily changing, non-reversible identifier computed on the server. If you pick a colour theme for the demo, the site remembers it in a cookie named bb-demo-theme, which holds only that choice.

You can delete cookies in your browser settings at any time. The web app does not work without the session cookie.

9. The Babooked mobile app

The Babooked app for Android and iOS shows the same web app as app.babooked.ee, so everything in this policy applies to it. The app asks only for internet access and, if you allow it, permission to show notifications. It does not access your location, contacts, camera, microphone or files. You can turn notifications off at any time in your device settings.

10. Your rights

Under the GDPR you have the right to:

  • get a copy of your personal data
  • have incorrect data corrected
  • have your data deleted when there is no longer a reason to keep it
  • restrict how we use your data
  • object to processing based on our legitimate interest
  • receive data you gave us in a machine-readable format
  • withdraw consent at any time, for example by turning notifications off

Send your request to info@babooked.ee. We answer within one month. If your request concerns booking data, we may forward it to the business you booked with.

You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee.

11. Deleting your account

You can delete your Babooked account inside the app: open Settings, scroll to Delete account, and confirm with your password. Step-by-step instructions and an email option for people who cannot sign in are at app.babooked.ee/account/delete.

If you booked through a business’s booking page and want your booking data deleted, contact the business or write to us.

12. Security

Data travels over encrypted HTTPS connections. Passwords are stored only as hashes. Access to personal data within our team is limited to people who need it to run and support the service.

13. Children

Babooked accounts are meant for businesses and their staff, not for children. A parent or guardian can book a service for a child. In that case the parent or guardian provides the child’s data.

14. Changes to this policy

When we change this policy, we publish the new version on this page with a new effective date. We notify business users of material changes by email or in the app.