Privacy Policy

Last updated July 25, 2026 · version 2026-07-25

Bookd is operated by Eidetic Ltd. This policy explains what personal data we collect through bookd.rw, why we collect it, who we share it with, how long we keep it, and the rights you have. It applies to clients who book, to the businesses that take bookings, and to visitors of the site.

1. Who controls your data

Eidetic Ltd (Kigali, Rwanda) is the data controller for the information described in this policy, except where a business uses Bookd to manage its own clients. In that case the business is the controller of its client records, and Eideticacts as its processor: we handle that data only to run the platform and on that business's instructions. If you booked with a business and want your record changed or removed, you can ask either of us and we will coordinate.

2. Information we collect

Directly from you:

  • Account details: name, email address, phone number, preferred language, and a password stored only as a salted hash. If you sign in with Google we receive your name, email, and profile image, never your Google password.
  • Booking details: the business and services you book, date and time, chosen staff member, any notes or answers to a business's custom booking questions, and your cancellation or reschedule history.
  • Business details (for owners): business name, description, category, address and map location, contact details, opening hours, staff records, services and prices, logo, cover, and gallery images.
  • Payments: for business subscriptions, the mobile-money number or payment reference needed to take payment. Card and mobile-money credentials are handled by our payment providers, not stored by us.
  • Loyalty and reviews: points earned or redeemed, redemption codes, star ratings, review text, and any photos you attach.
  • Support and contact: the name, email, and message you send through our contact form or by email.

Automatically, when you use Bookd:

  • Page views on business pages, including approximate referrer and a one-way hashed version of your IP address. We do not store raw IP addresses for analytics.
  • Device and browser information, and coarse location derived from your network, used for security and to keep the site working.
  • Error and performance diagnostics when something goes wrong, so we can fix it.
  • Precise location only if you explicitly allow it, to centre a map or find businesses near you. We do not store it.

3. Why we use it, and our legal basis

  • To create, confirm, remind about, reschedule, and cancel bookings, and to run loyalty, waitlists, vouchers, and reviews. Basis: performance of a contract with you.
  • To operate the business dashboard and give businesses aggregate analytics about their own page. Basis: contract with the business.
  • To take and reconcile subscription payments and issue receipts. Basis: contract and legal obligation.
  • To keep Bookd secure, prevent fraud and abuse, enforce our terms, and debug problems. Basis: our legitimate interest in a safe, working service.
  • To respond to your enquiries and provide support. Basis: legitimate interest, or contract.
  • To send service messages you cannot opt out of while you hold an account (booking confirmations, payment and security notices). Basis: contract.
  • To send product news or marketing, only where you have opted in or where the law allows it for existing customers. You can unsubscribe at any time. Basis: consent or legitimate interest.
  • To comply with legal, tax, and accounting obligations in Rwanda. Basis: legal obligation.

We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.

4. Who we share it with

When you book, the details the business needs to serve you (your name, contact details, chosen service, time, and any notes you added) are shared with that business. Beyond that, we share data only with service providers who process it on our behalf under contract:

  • Cloud hosting and serverless database providers (application and data storage).
  • Email delivery, for confirmations, reminders, and notifications.
  • SMS delivery, where a business has enabled text reminders.
  • Object storage and image delivery, for logos, covers, and gallery photos.
  • Maps and geocoding, to show and search business locations.
  • Payment providers, including mobile money operators, for subscription billing.
  • Error and performance monitoring, to detect and fix faults.

We may also disclose data where required by law or valid legal process, to establish or defend legal claims, to protect the rights and safety of users or the public, or to a successor entity in a merger, acquisition, or sale of assets (in which case this policy continues to apply until you are told otherwise).

5. International transfers

Some of our providers operate outside Rwanda, so your data may be processed abroad. Where that happens we rely on providers that offer an adequate level of protection and contractual safeguards consistent with Rwanda's data protection law, and we transfer only what is needed to deliver the service.

6. How long we keep it

  • Account and business records: for as long as the account is active, then up to 24 months after closure, unless we must keep them longer.
  • Booking, payment, and invoice records: up to 10 years where tax and accounting law requires it.
  • Raw analytics events: a short retention window, after which they are aggregated or deleted.
  • Support and contact-form messages: up to 24 months after the matter is closed.
  • Security logs and audit trails: up to 12 months, or longer if needed for an active investigation.
  • Backups: cycled out on a rolling schedule, so deleted data can persist briefly in backups before being overwritten.

7. Your rights

Subject to the law that applies to you, you can ask us to give you access to your data, correct it, delete it, export a portable copy, restrict or object to certain processing, or withdraw a consent you gave. You can also opt out of marketing at any time using the unsubscribe link.

Email privacy@bookd.rw and we will respond within 30 days. We may need to verify your identity first. If you are unhappy with our response, you can complain to the data protection authority in Rwanda.

8. Security

We protect your data with encrypted connections (HTTPS everywhere), hashed passwords, hashed analytics identifiers, strict tenant isolation so one business can never read another's records, role-based access controls, audit logging of sensitive admin actions, rate limiting, and a restrictive content security policy. Access to production data is limited to staff who need it.

No system is perfectly secure. If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant authority without undue delay. Report a suspected vulnerability to security@bookd.rw.

9. Cookies and similar technologies

Bookd uses strictly necessary cookies to keep you signed in, remember which business dashboard you are viewing, protect forms against abuse, and hold your preferences. We do not use advertising cookies, and we do not allow third-party ad tracking on the site. Blocking essential cookies will stop sign-in from working.

10. Children

Bookd is not intended for children under 18. A parent or guardian may book an appointment on a child's behalf, in which case they are responsible for the details provided. We do not knowingly collect data directly from children; if you believe we have, contact privacy@bookd.rw and we will delete it.

11. Changes to this policy

We may update this policy. We revise the date and version above and, for material changes, give notice by email or in the dashboard before they take effect.

12. Contact

Eidetic Ltd · Kigali, Rwanda. For privacy questions or requests, email privacy@bookd.rw or use our contact page. See also our Terms of Service.