End customers
Privacy and data
BookFlow takes privacy seriously. This page explains exactly what we store, who can see it, and how to take it back.
What we store about you
When you book without an account
- First and last name
- Email (for confirmations)
- Phone number (for SMS, if you provided it)
- Booking history: services, dates, prices, staff, notes
- Payment records: the deposit amount and last 4 digits of the card, never the full card
- IP address (for fraud prevention)
When you create an account
- Everything above, plus:
- Password (hashed with PBKDF2-SHA256, 100,000 iterations, per-password random salt — we can't read it)
- Time zone, notification preferences
- Default notes (e.g. allergies)
- Session tokens in our database (revocable)
Who can see your data
- The business you booked: they see your name, email, phone, the booking details, and your notes for that booking. They do NOT see your bookings at other businesses.
- Stripe: they handle payment processing. BookFlow sends them your card details directly; BookFlow never sees the card.
- NetWit (BookFlow's operator): limited access for support cases. All access is logged in an audit log.
- Law enforcement: only with a valid subpoena.
- Nobody else. We don't sell your data. We don't share it for marketing.
No spam, ever
We don't add you to marketing lists. The only emails you get are confirmations, reminders, and (if you have an account) a weekly activity summary you can turn off.
How long we keep your data
- Bookings: 7 years (for tax/audit purposes)
- Payment records: 7 years (legal requirement)
- Account data: until you delete your account
- IP addresses in logs: 90 days
- Sessions: 30 days max
Your rights
- See your data: visit /me/profile for account data, or email hello@netwit.ca for a full export.
- Delete your account: visit /me/profile → "Delete account". This anonymizes your bookings (the business keeps a record of the service, date, and amount for tax purposes, but not your name or email).
- Correct your data: edit in /me/profile, or email us to fix anything we got wrong.
- Opt out of SMS: reply STOP to any SMS, or turn it off in your profile.
- Opt out of emails: tap "Unsubscribe" at the bottom of any email, or turn it off in your profile.
Security
- All traffic is HTTPS. Card data goes to Stripe over TLS 1.3.
- Passwords are hashed with PBKDF2-SHA256, 100,000 iterations, with a 16-byte per-password salt. We can't read them.
- API rate limits prevent brute-force attacks.
- Worker secrets are encrypted at rest in Cloudflare.
- Data is stored in Cloudflare D1 (encrypted at rest) and KV (encrypted at rest).
- Two-factor authentication is available for business owners and required for platform admins.
Cookies
BookFlow uses only essential cookies: a session token (so you stay logged in) and a CSRF token (for security). We don't use advertising cookies or third-party trackers. The marketing site (https://booking.netwit.ca) uses Plausible Analytics, which is cookieless.
Contact
Questions or concerns: hello@netwit.ca or +1-604-206-8169. NetWit responds in 1 business day.
Need a human?
Email hello@netwit.ca or call +1-604-206-8169. NetWit responds in 1 business day.