Privacy Policy
Last updated: September 1, 2026 · Version 2.4
We believe privacy policies should be honest, clear, and easy to understand. We never sell your personal data, we never store passwords, and you always maintain complete ownership of your studio and client records.
1. Overview & Plain-English Commitments
AirBook ("we", "our", or "us") provides a modern, passwordless appointment booking and studio management platform. This Privacy Policy describes how we collect, use, process, and safeguard personal information when you use our website, mobile interface, APIs, and client booking links.
Our 4 Core Privacy Guarantees:
- Zero Password Storage: We authenticate exclusively through biometrics (WebAuthn Passkeys), magic links, and Google OAuth.
- No Data Brokering: We never sell, rent, or trade your or your clients' personal data to advertisers or third-party brokers.
- Data Portability: You can export 100% of your appointments, client profiles, and financial ledger at any moment in open JSON/CSV format.
- Strict Encryption: All data is encrypted in transit via TLS 1.3 and at rest with AES-256 encryption.
2. Information We Collect
We only collect the minimal information necessary to deliver appointment bookings, automated reminders, and payment payouts:
- Studio Account Data: Business name, work email, phone number, physical address, business hours, and service pricing catalog.
- Client Booking Data: Full name, email address, phone number, appointment time, chosen service, and optional booking notes submitted during appointment creation.
- Payment Information: Handled directly by Stripe (PCI-DSS Level 1 compliant). AirBook never receives, handles, or stores full credit card numbers or CVV codes.
- Device & Telemetry Metadata: Browser type, operating system, IP address, and timestamped authentication session tokens to protect against fraudulent access.
3. 100% Zero-Password Identity Architecture
Traditional passwords are the single largest source of database leaks and credential stuffing attacks. AirBook eliminates this vulnerability entirely:
Zero Password Storage Guarantee
We store zero password hashes, salt hashes, or secret security questions in our database. If an attacker were to inspect our database, there are zero user passwords to steal. You authenticate seamlessly via Apple Face ID, Touch ID, Windows Hello, or cryptographic email magic tokens.
4. Your Rights (GDPR, CCPA & Global Protections)
Under the European Union General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), and global privacy laws, you and your clients have the following inalienable rights:
Right to Access & Portability
Download a full JSON/CSV copy of all records associated with your account.
Right to Erasure ("Right to be Forgotten")
Permanently purge your studio or client profile with 1-click account deletion.
Right to Rectification
Update or correct any inaccurate customer notes or contact details at any time.
Right to Restrict Processing
Disable automated SMS/email reminders for specific clients with one toggle.
5. Data Protection Officer & Contact
If you have any questions regarding this Privacy Policy, your personal data, or data processing agreements (DPA), contact our security and legal team directly:
AirBook Legal & Data Protection Office
Email: privacy@getairbook.com
Security Team: security@getairbook.com
Requests for data deletion or exports are acknowledged within 24 business hours.