Overview
At BookEase, we are committed to protecting your privacy and ensuring that your personal data is handled responsibly. This Data Retention Policy outlines how long we retain different types of data, the reasons for retention, and the measures we take to secure and eventually dispose of your information.
Our data retention practices comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional privacy frameworks.
Data Retention Periods
The table below outlines the categories of data we collect and the corresponding retention periods. If a specific retention period is not listed, we will retain the data for no longer than necessary to achieve the purpose for which it was collected.
| Data Category | Retention Period | Purpose / Legal Basis |
|---|---|---|
| Booking Records | Duration of service + 12 months | Service fulfillment, dispute resolution |
| Payment Information | 7 years | Tax compliance, financial auditing |
| User Account Data | Until account deletion + 30 days | Account management, user experience |
| Communication Logs | 2 years | Customer support, quality improvement |
| Analytics & Usage Data | 14 months | Product improvement, aggregated analytics |
| Security Logs | 6 months | Security monitoring, threat detection |
| Marketing Preferences | Until consent withdrawn | Direct marketing, user preferences |
| Legal & Compliance Data | As required by law | Legal obligations, regulatory compliance |
What Data We Collect
BookEase collects various types of data to provide and improve our booking services. This includes:
- Personal Identifiers: Name, email address, phone number, billing address.
- Booking Details: Service type, date, time, location, special requests.
- Payment Data: Transaction records, billing information (processed securely via PCI-compliant providers).
- Technical Data: IP address, browser type, device information, log files.
- Usage Data: Pages visited, features used, interaction timestamps.
- Communications: Email correspondence, support tickets, feedback.
Data Storage & Security
We implement industry-standard security measures to protect your data throughout its lifecycle, including:
- Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access Controls: Strict role-based access controls limit who can view or modify personal data.
- Regular Audits: We conduct periodic security assessments and vulnerability testing.
- Data Residency: Data is stored in secure, compliant data centers. Specific regions are disclosed in our Privacy Policy.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data under certain conditions.
- Right to Portability: Receive your data in a structured, machine-readable format.
- Right to Restrict Processing: Limit how we use your data in specific circumstances.
- Right to Object: Object to processing for direct marketing or other legitimate interests.
To exercise any of these rights, please contact our Data Protection Officer using the information provided below.
Data Deletion & Anonymization
When data reaches the end of its retention period, we securely delete or anonymize it using the following methods:
- Secure Deletion: Digital data is overwritten and removed from active systems and backups.
- Anonymization: Where useful for analytics, data is irreversibly anonymized so it can no longer identify an individual.
- Physical Destruction: Any physical records are shredded or destroyed securely.
Please note that some data may be retained beyond these periods if required for legal disputes, regulatory investigations, or fraud prevention.
Questions About Data Retention?
If you have any questions about this policy, want to exercise your rights, or need clarification on how we handle your data, please reach out to our privacy team.
✉️ privacy@bookease.comOr mail us to:
BookEase Data Protection Officer
123 Innovation Drive, Suite 400
San Francisco, CA 94107, USA