Privacy Policy
Last updated: July 28, 2026
BookZync ("we," "us," or "our") operates the website and AI automation services provided to service businesses, including dental and medical practices, medspas, salons, gyms, home service businesses, restaurants, and veterinary clinics. This Privacy Policy explains how we collect, use, and protect your information.
Information we collect
When you visit our website or interact with the BookZync AI assistant, we may collect:
- Personal information, including your name, email address, phone number, and business name when you submit a form.
- Usage data, including conversations with our AI assistant, standard server logs (such as IP address and browser type), and analytics generated while you use our services.
- Lead and booking data: information submitted through your website chat, such as a customer's name, contact details, requested appointment time, and the reason for their inquiry.
In summary, by category:
| Category | Examples | Source | Why we collect it |
|---|---|---|---|
| Account & contact information | Name, email address, phone number, business name | You (signup and contact forms) | Provide, operate, and support the Services |
| Booking & lead data | A customer's name, contact details, requested service, appointment time | Your website visitors, via the chat widget | Deliver bookings and leads to your business |
| Conversation data | Chat and voice conversations with the AI assistant | Website visitors — retained only with their explicit consent | Service continuity for returning customers |
| Usage & technical data | IP address, browser type, pages visited, analytics events | Collected automatically (server logs, analytics) | Security, debugging, and service improvement |
| Payment data | Card details, billing address | Collected by Paddle, our merchant of record | Billing — card data never reaches BookZync systems |
How we use your information
We use the information we collect to:
- Provide, operate, and maintain our website and AI services.
- Communicate with you regarding demos, pricing, and support.
- Improve our AI models and website functionality.
- Send booking confirmations and notify your team about new leads.
How we use AI
The Services generate responses using automated (AI) technologies. The following applies wherever the AI assistant is used:
- AI-generated responses may be inaccurate or incomplete. Bookings proposed by the AI are confirmed by the business's staff before they are final.
- The AI assistant does not provide medical, legal, financial, or other professional advice, and is designed to decline such requests and defer to the business's staff.
- The AI asks before retaining a visitor's details. Only a clear affirmative answer is treated as consent; a declined or unanswered request means the conversation is not retained, and any minimal booking record created without consent is deleted within 24 hours of the visit's completion.
- The AI recalls prior conversations only from records retained with consent.
- Customer and visitor data is not used to train third-party foundation models, per contractual commitments with our AI providers.
- No decision producing legal or similarly significant effects about you is made solely by automated means.
Healthcare data, security & storage
BookZync is designed with healthcare privacy in mind but is not currently HIPAA compliant (HIPAA is a United States law). We are transparent about this on our dental, medical, and medspa industry pages. For Canadian practices, the Services are designed to support you in meeting applicable obligations under PIPEDA and provincial health privacy legislation, including PHIPA where applicable — documentation is available on request from [email protected].
As a visitor browsing our main website, any information you submit via our contact forms or public chat widget is treated as standard B2B communication. Do not submit Protected Health Information (PHI) through our public-facing website or chat widget.
The AI assistant is designed not to collect diagnoses, symptoms, medical history, or other Protected Health Information (PHI). We store only the minimum information needed to complete a booking — name, contact, intent, and requested time. Our customers control the information they request from their own clients and remain responsible for complying with applicable healthcare regulations. Only finalized booking records are retained.
We protect stored records with layered security — encryption in transit and at rest, strict per-business (tenant) isolation, role-based access controls with two-factor authentication, and audit logging. For dental, medical, and medspa practices we apply additional data-minimization and storage safeguards, and continue to strengthen them as part of our healthcare-compliance program. Our Data Processing Agreement describes these measures in full.
Third-party services
We use a small set of third-party services to run BookZync: an AI processing provider, Paddle as our payments provider and merchant of record (you will see Paddle at checkout and on your card statement), an SMS delivery provider, cloud hosting providers, and analytics tools (such as Google Analytics, where enabled). These providers process personal information only as necessary to deliver services on our behalf and are obligated not to disclose or use it for any other purpose.
Business customers: our Data Processing Agreement and the current sub-processor list describe how we handle your customers' data as your processor.
Where your information is stored and processed
BookZync stores and processes information on servers located in the United States, operated by the service providers listed in this policy. Personal Information processed outside Canada may become subject to the laws of the jurisdiction in which it is processed, including lawful access requests made by courts, law enforcement agencies, or other governmental authorities in accordance with applicable law. BookZync applies the safeguards described in this policy wherever the information is processed. Canadian businesses on eligible plans may request storage of their customer records in our Canadian database region. Availability depends on the selected service plan and technical feasibility.
Cookies & analytics
We keep tracking to a minimum. We may use analytics tools such as Google Analytics to understand how visitors use our site (pages visited, approximate location, device type) so we can improve it. Where your local law requires it, we will ask for your consent before setting analytics or advertising cookies.
Cookies used for website analytics are separate from cookies associated with your authenticated application session. The only browser storage this website itself uses is a sign-in token if you log in to the affiliate portal; the customer dashboard is a separate application and uses only the storage needed to keep you signed in.
Data retention
Chat logs and lead data are retained for as long as your subscription is active. On cancellation, we retain data for 30 days for export, then delete it unless we are required to retain certain information longer to comply with legal obligations (e.g., tax records).
Conversations where the visitor declined to have their details saved are not retained; see "How we use AI" above.
Your rights
You have the right to:
- Access the personal information we hold about you.
- Request correction or deletion of your data.
- Export your customer lead and booking history at any time.
- Object to or request restrictions on certain processing activities.
Email [email protected] (our Privacy Officer) to exercise any of these rights, or [email protected] for general questions. If you are not satisfied with our response, you may also contact the privacy regulator in your jurisdiction.
Children's privacy
Our website and Services are intended for businesses and their adult customers. They are not directed to children, and we do not knowingly collect personal information from anyone under 13 years of age (or a higher minimum age where your local law sets one). Where an adult books an appointment on behalf of a minor — for example, a parent booking a child's dental visit — we store the booking contact's details, and the business receiving the booking remains responsible for any consents its own services require. If you believe a child has provided us personal information directly, contact [email protected] and we will delete it.
SMS / text messaging
BookZync sends text messages to holders of a BookZync account — the business owners and staff who use our platform. These are one-time verification codes and account or security notifications. BookZync is the sender, every recipient has a direct account relationship with us, and we do not send these messages on behalf of third parties. They are service messages, not marketing.
- Consent: you receive texts only after you add your own mobile number under Settings > Verify phone and agree to receive them. Consent is stored against your account, and nobody can enrol your number on your behalf. Consent to receive texts is not a condition of any purchase.
- Message frequency varies, based on your own activity — such as signing in or verifying your number.
- Message and data rates may apply, depending on your mobile carrier and plan.
- You can opt out at any time by replying STOP to any message; you will receive a confirmation and no further texts. Reply HELP, or email [email protected], for help.
- Mobile carriers are not liable for delayed or undelivered messages.
We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages.
We do not sell your mobile phone number, SMS opt-in, or consent, and we do not share them with third parties for their own marketing purposes.
The full terms, including the exact consent notice we show you before any message is sent, are on our SMS Consent & Messaging Terms page.
Changes to this policy
When we make material changes to this policy, we will update the date at the top of this page and record the change here.
- July 28, 2026 — Added the categories-of-data table, the "How we use AI" section, the cross-border storage disclosure, the children's privacy section, and this change log. Privacy rights requests now go to [email protected] (Privacy Officer). Canadian health-privacy statement (PIPEDA/PHIPA) added to the healthcare section.
- July 2026 — SMS / text messaging section expanded with the full consent and sharing disclosures.
Contact us
For privacy questions, rights requests, or complaints, contact our Privacy Officer at [email protected]. For anything else about this Privacy Policy, you can also reach us at [email protected].