Skip to content

Privacy Policy

Last updated: 23 May 2026

This Privacy Policy explains how Exabook ("we", "us") collects, uses, and protects personal data when you use our booking platform (the "Service"). We care about handling health-related information responsibly and only collect what is needed to run the Service.

1. Who is responsible for your data

For information about a business's own staff accounts and how the Service operates, Exabook is the controller. For customer information that a business collects and enters through the Service, the business is the controller and Exabook acts as a processor on the business's behalf.

2. Information we collect

  • Account data — name, email, and password (hashed) for business staff who register, plus business details such as name, location, and settings.
  • Customer booking data — entered by customers or staff: customer name, phone number, selected service, booking times, and any optional note. Customers do not create accounts.
  • Usage data — basic technical information such as device, browser, and log data used to operate and secure the Service.

3. How we use information

  • to provide and maintain the booking and business-management features;
  • to recognize returning customers within a business by phone number;
  • to secure the Service, prevent abuse, and troubleshoot issues;
  • to communicate with business account holders about the Service.

4. WhatsApp and customer messaging

We do not send messages to customers automatically. When business staff choose to contact a customer, the Service opens WhatsApp with a pre-filled message that the staff member sends from their own device and account. We do not operate a messaging gateway and do not transmit those messages through our systems.

5. How we share information

We do not sell personal data. We share data only with service providers who help us run the platform (such as hosting and infrastructure providers), under appropriate confidentiality and data-processing obligations, and where required by law. Each business's data is scoped to that business and is not shared with other businesses.

6. Data retention

We retain account and customer data for as long as a business's account is active and as needed to provide the Service. Businesses may request export or deletion of their data, subject to any legal retention obligations. When data is no longer needed, we take steps to delete or anonymize it.

7. Security

We use reasonable technical and organizational measures to protect personal data, including encryption in transit and access controls scoped per business. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident.

8. Your rights

Depending on applicable law, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing. Customers should direct such requests to the business that collected their information; businesses can contact us to help fulfill them. To exercise rights regarding your own account data, contact us using the details below.

9. International processing

Our infrastructure providers may process data in locations outside your country. Where this happens, we take steps to ensure an appropriate level of protection for the data consistent with this policy and applicable law.

10. Children

The Service is intended for use by businesses and their staff. Where a business takes bookings for minors, it is responsible for obtaining any consent required from a parent or guardian.

11. Changes to this policy

We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, take reasonable steps to notify affected business account holders.

12. Contact

For privacy questions or requests, email hello@exabook.app or use our contact page.