Privacy Policy

Last updated:

Draft pending legal review. This document accurately describes what the software does today. It has not yet been reviewed by a lawyer.

Who is responsible for your data

BARB is booking software used by independent businesses. When you book an appointment, the business you booked with decides what data is collected about you and why — they are the controller. BARB stores and processes that data on their behalf, under their instructions — we are the processor.

In practice this means: to see, correct, or delete the details attached to your appointments, contact the business directly. They can do all of that from their dashboard. BARB is the controller only for the accounts of the business owners and staff who sign in to the software.

What is collected

When a customer books an appointment

  • Name and email address, which are required to make a booking.
  • Phone number, if supplied. It is stored both as typed and in normalised international format so reminders can be sent reliably.
  • Any notes you add to the booking, in free text.
  • If you tick the box to receive text reminders, the time at which you did so, as the record of your consent.

Added by the business about its own customers

  • Birthday, tags, internal notes, and where the record came from. Businesses can enter these by hand or import them in bulk from a spreadsheet or document.

When a business owner or staff member signs up

  • Name, email address, and a password (stored hashed, never in readable form), or a Google sign-in.
  • The business details entered during setup: shop name, address, contact details, opening hours.

Automatically, while the service runs

  • IP addresses, used transiently to rate-limit booking and lookup requests so the service cannot be flooded. These are used as short-lived counter keys and expire automatically; they are not part of any customer record.
  • Error diagnostics when something breaks, with personal data removed before the report is sent.

Who else processes it

BARB uses the following providers. Each receives only what its function requires, and none is permitted to use the data for its own purposes.

  • Neon — database hosting. Holds all stored records.
  • Vercel — application hosting. Processes every request in transit.
  • Resend — transactional email: booking confirmations, reminders, cancellations, password resets. Receives the recipient address and message content.
  • Twilio — text messages, where the business has enabled them and the customer has opted in. Receives the recipient phone number and message content.
  • Cloudflare R2 — storage for images a business uploads to its own public site.
  • Upstash — short-lived rate-limiting counters keyed by IP address.
  • Anthropic — only when a business owner uses the AI import feature, and only the contents of the file they choose to upload. It is not used for booking, and customer records are never sent to it in the ordinary course of using BARB.
  • Sentry — error monitoring, with personal data scrubbed before reports leave the application.

BARB does not sell personal data, and does not share it with advertisers.

Text message opt-outs

Replying STOP to a text from BARB stops texts to that number from every business using BARB, not only the one that sent it. This is deliberate: the request is about the number, and honouring it only for one shop would be an obvious way to keep texting someone who asked to stop. The opt-out is stored against the phone number itself for that reason.

Cookies

BARB sets two cookies, both strictly necessary for the software to work:

  • barb.session_token — keeps a signed-in owner or staff member signed in.
  • barb-active-tenant — remembers which business a staff member is currently working in, when they belong to more than one.

There are no analytics cookies and no advertising cookies. That is why you are not asked to accept a cookie banner: there is nothing to consent to beyond the cookies required to run the service.

How long it is kept

Appointment and customer records are kept until the business deletes them or closes its account. Businesses can delete individual customer records at any time from their dashboard. Deleting a customer does not delete the appointment history attached to them, because a business needs its own record of work performed; that history is removed when the account is closed.

Your rights

Depending on where you live you may have rights to access, correct, delete, or receive a copy of your personal data, and to object to its processing.

  • If you are a customer of a business using BARB: contact that business. They control your data and can action all of these directly. If they need our help to do so, we will provide it.
  • If you have a BARB account: contact us at the address below. You can export your account's data or close the account entirely.

Security

Data is encrypted in transit. Passwords are stored hashed. Access to each business's data is scoped to that business throughout the software, and staff access can be revoked by the owner at any time.

Children

BARB is not directed at children and we do not knowingly collect data from them. A business may book appointments on behalf of a minor; in that case the business is responsible for having the appropriate consent.

Changes

If this policy changes materially we will update the date at the top and, for account holders, notify you by email.

Contact

Questions about this policy, or about data BARB holds as controller, can be sent to [CONTACT_EMAIL].