Privacy Policy
Last updated: Sep 4, 2026
This policy explains what AppointIQ does with personal data — the data business owners give us when they open an account, and the data their customers give when they book an appointment. We sell personal data to nobody and we run no advertising trackers. We use one analytics tool, hosted in the EU, and on our marketing pages it only starts once you have said yes.
Who is responsible for your data
AppointIQ is the data controller for account holders and for visitors to this website. Where a business uses AppointIQ to take bookings, that business is the controller of its own customers' data and AppointIQ acts as its processor, handling that data on the business's instructions. You can reach us at support@appointiq.app.
What we collect when you open an account
To create and run your account we store:
- Your name, email address, phone number and the language you chose to work in.
- The businesses you set up — their name, address, contact details, timezone, opening hours, services and team members.
- Your subscription status, plan and billing period. Card details are entered on Stripe's own pages and never reach our servers.
- If you connect Google Calendar, the tokens that let us write your appointments to it. Disconnecting the integration deletes them.
What we collect about the people who book with you
A booking form collects the name, email address and phone number of the person booking, anything else the business chose to ask on its own form, and the appointment itself. That data belongs to the business, not to us. We store and process it so the business can run its bookings, and we put it to no purpose of our own.
If you booked an appointment and want your data corrected or erased, ask the business you booked with — they decide, and we act on their instruction.
What is collected automatically
Our hosting provider logs the technical details every web request carries — IP address, browser and the page requested — to keep the service running and to stop abuse such as repeated booking attempts from one address. We do not build profiles from them.
There are no advertising or marketing cookies anywhere on this site. Product analytics run inside the admin app, which this policy discloses, and on our marketing pages only after you accept them in the banner. They never run on a business's booking pages — nothing at all is stored on your device there.
Inside the admin app we also record account holders' own sessions — the pages, clicks and scrolling of the person signed in — so we can see where the product is hard to use. Those recordings never run on a business's booking pages or on our marketing pages, every field typed into is masked, and the screens showing a business's own customers are cut out of the recording before it is stored.
What we use it for
Personal data is used only for the things the product exists to do:
- Running your account: publishing your booking forms, taking bookings, and keeping two appointments out of one slot.
- Sending transactional email — booking confirmations, reminders, cancellations and reschedules — to you and to the person who booked.
- Signing you in, which is done with a one-time link sent to your email address.
- Taking subscription payments and telling you when a plan limit is reached.
- Answering you when you contact support.
- Rate-limiting, fraud prevention and keeping the service available.
The legal bases we rely on
Under the GDPR, our processing rests on:
- Performance of a contract — everything needed to give you the account you signed up for, and to deliver a booking somebody asked for.
- Legitimate interests — keeping the service secure and available, and preventing abuse.
- Legal obligations — keeping the billing records tax law requires us to keep.
- Consent — for anything optional: connecting your Google Calendar, and analytics on our marketing pages. You can withdraw it at any time. Signed in, the analytics answer is under Settings; signed out, clearing this site's cookies puts the question back.
Who else sees it
We do not sell or rent personal data, and we share it only with the providers that make the product work. Each processes data on our instructions, under a data processing agreement:
- Stripe — subscription payments and card processing.
- Resend — delivery of transactional email.
- Google — only if you connect Google Calendar, and only for the calendar you chose.
- PostHog — product analytics, on their EU servers.
- Sentry — error monitoring, on their EU servers.
- Our hosting and database providers, which run the application and store its data.
- Authorities, where the law obliges us to disclose something.
Some of these providers operate outside the European Economic Area. Where data leaves the EEA it is transferred under the European Commission's Standard Contractual Clauses.
Cookies
The cookies this site sets and what each is for. Only the analytics one waits for your permission:
- A session cookie that keeps you signed in after you follow your sign-in link.
- A cookie remembering the language you chose, so the site opens in it next time.
- A cookie remembering which of your businesses you were last working in.
- A cookie recording whether you accepted or declined analytics on our marketing pages, and — only once you accept — the cookies PostHog sets so that one visit is counted as one visit. Decline and the first is set, the rest never are.
How long we keep it
Account and business data is kept for as long as your account is open. Close it and we delete your account, your businesses and the bookings under them, apart from the billing records tax law requires us to retain. Bookings you cancel or delete inside the product are removed on the schedule the product sets, and unconfirmed booking holds expire on their own.
Your rights
Wherever we are the controller of your data, the GDPR gives you the right to:
- Ask what we hold about you and get a copy of it.
- Have anything inaccurate corrected.
- Have it erased.
- Have its processing restricted, or object to it.
- Receive it in a portable, machine-readable format.
- Withdraw a consent you gave, without affecting what was done before you withdrew it.
Write to support@appointiq.app and we will respond within one month.
You may also complain to your local data protection authority. In Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
How it is protected
Data is transmitted over encrypted connections and stored on managed infrastructure with access restricted to those who need it. Your account has no password to lose — sign-in is by one-time link. No system is perfect, and if a breach ever affects your data we will tell you and the supervisory authority as the law requires.
Children
AppointIQ is a product for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If a business's own booking form asks for a child's details, that business is the controller of them.
Changes to this policy
We may amend this policy. The date at the top always says when it last changed, and we will email account holders before any change that materially affects them takes effect.
Contact us
Questions about this policy, or about the data we hold? Write to support@appointiq.app.