Privacy Policy
How Bookaster (Casablanca, Morocco) handles personal data in Bookaster.
Last updated: 29 July 2026
1. Two kinds of people, two different roles
Business users — the owners and staff who sign up for Bookaster. For their data we are the data controller.
End customers — the people who book an appointment with one of those businesses. That data belongs to the business; we only process it on their instructions to run the booking and reminder features. If you booked an appointment and want your data changed or removed, contact the business directly — or write to us and we will pass it on.
2. What we collect
- Account data: business name, owner and staff names, email address, phone number, password (stored only as a salted hash), language and business type.
- Business content: services, prices, opening hours, staff, locations, appointments, invoices, expenses and the customer records you enter.
- Customer records you enter: name, phone number, email, appointment history, notes and preferred language.
- WhatsApp messages exchanged between the connected business number and its customers, so that bookings, replies and reminders work.
- Technical data: IP address, browser type and log data, used for security, debugging and abuse prevention.
We do not collect or store card numbers. Paid plans are currently arranged directly with us, and we never take card details over email.
3. Why we use it
- To provide the service: bookings, calendar, CRM, invoicing and reporting.
- To send transactional messages on a business's behalf — confirmations, reminders, queue updates and review requests — to that business's own customers.
- To take payment and prevent fraud.
- To provide support, keep the service secure, and meet legal obligations.
Our lawful bases are performance of a contract, our legitimate interest in operating and securing the service, consent where required, and compliance with law.
4. Who we share it with
We do not sell personal data. We share it only with providers that help run Bookaster:
- WhatsApp — delivery of messages sent from the connected business number.
- Our email provider — delivery of transactional email.
- Our hosting provider — servers and backups.
- Authorities, where we are legally required to disclose.
5. Where data is stored, and for how long
Data is stored on servers in the European Union and protected in transit with TLS. We keep account and business data while the account is active. After deletion we remove or anonymise personal data within 30 days, except where we must retain records (for example invoices) to satisfy tax and accounting law.
6. Your rights
Depending on where you live — including under the GDPR if you are in the EU/EEA — you can request access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing. Email contact@bookaster.com and we will respond within 30 days. You may also complain to your local data protection authority.
7. Cookies
We use only the cookies and local storage needed to keep you signed in and remember your language and theme. We do not use advertising or cross-site tracking cookies.
8. Security
Passwords are hashed, traffic is encrypted with TLS, access to production is restricted, and each business's data is isolated per tenant. No system is perfectly secure, but we take reasonable technical and organisational measures and will notify you of a breach affecting your data as required by law.
9. Children
Bookaster is a business tool and is not directed at children under 16.
10. Changes and contact
We will post updates here with a new date above. Questions or requests: contact@bookaster.com. See also our terms of service.