Data Retention Policy

How we manage, retain, and protect your personal data in accordance with applicable laws and regulations.

Last Updated: January 15, 2025

Overview

At BookEase, we are committed to protecting your privacy and ensuring that your personal data is handled responsibly. This Data Retention Policy outlines how long we retain different types of data, the reasons for retention, and the measures we take to secure and eventually dispose of your information.

ℹ️
Key Principle: We only retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or regulatory requirements.

Our data retention practices comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional privacy frameworks.

Data Retention Periods

The table below outlines the categories of data we collect and the corresponding retention periods. If a specific retention period is not listed, we will retain the data for no longer than necessary to achieve the purpose for which it was collected.

Data Category Retention Period Purpose / Legal Basis
Booking Records Duration of service + 12 months Service fulfillment, dispute resolution
Payment Information 7 years Tax compliance, financial auditing
User Account Data Until account deletion + 30 days Account management, user experience
Communication Logs 2 years Customer support, quality improvement
Analytics & Usage Data 14 months Product improvement, aggregated analytics
Security Logs 6 months Security monitoring, threat detection
Marketing Preferences Until consent withdrawn Direct marketing, user preferences
Legal & Compliance Data As required by law Legal obligations, regulatory compliance

What Data We Collect

BookEase collects various types of data to provide and improve our booking services. This includes:

  • Personal Identifiers: Name, email address, phone number, billing address.
  • Booking Details: Service type, date, time, location, special requests.
  • Payment Data: Transaction records, billing information (processed securely via PCI-compliant providers).
  • Technical Data: IP address, browser type, device information, log files.
  • Usage Data: Pages visited, features used, interaction timestamps.
  • Communications: Email correspondence, support tickets, feedback.

Data Storage & Security

We implement industry-standard security measures to protect your data throughout its lifecycle, including:

  • Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Access Controls: Strict role-based access controls limit who can view or modify personal data.
  • Regular Audits: We conduct periodic security assessments and vulnerability testing.
  • Data Residency: Data is stored in secure, compliant data centers. Specific regions are disclosed in our Privacy Policy.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your data under certain conditions.
  • Right to Portability: Receive your data in a structured, machine-readable format.
  • Right to Restrict Processing: Limit how we use your data in specific circumstances.
  • Right to Object: Object to processing for direct marketing or other legitimate interests.

To exercise any of these rights, please contact our Data Protection Officer using the information provided below.

Data Deletion & Anonymization

When data reaches the end of its retention period, we securely delete or anonymize it using the following methods:

  • Secure Deletion: Digital data is overwritten and removed from active systems and backups.
  • Anonymization: Where useful for analytics, data is irreversibly anonymized so it can no longer identify an individual.
  • Physical Destruction: Any physical records are shredded or destroyed securely.

Please note that some data may be retained beyond these periods if required for legal disputes, regulatory investigations, or fraud prevention.

Questions About Data Retention?

If you have any questions about this policy, want to exercise your rights, or need clarification on how we handle your data, please reach out to our privacy team.

✉️ privacy@bookease.com

Or mail us to:
BookEase Data Protection Officer
123 Innovation Drive, Suite 400
San Francisco, CA 94107, USA