Privacy Policy

Last updated: 2026-09-07

TheBooker — Privacy Policy

Last updated: 06/09/2026

This privacy policy explains what personal information we collect, why we collect it, what we do with it, and what rights you have. It covers three groups of people: tradespeople who use our platform, the customers who contact those tradespeople by email, and people who have given us their email address but do not have an account yet.

The values set out in our Constitution (available at https://thebooker.ai/legal/constitution) informed how we wrote this policy. This privacy policy is a transparency notice: it explains how we handle personal data. For the data we process on behalf of tradespeople, the binding terms are set out in our Data Processing Agreement (Schedule 1 to our Terms of Service).


Who we are

THEBOOKER LTD (company number 17014293) is the data controller for the personal information described in this policy.

Registered office: 167-169 Great Portland Street, Fifth Floor, London W1W 5PF, United Kingdom.

Privacy contact: privacy@thebooker.ai

ICO registration number: ZC126942

We are not required to appoint a Data Protection Officer under UK GDPR and have not designated one. For any questions about this policy or your data, please contact us using the details above.


What we do

TheBooker is an AI-powered enquiry management platform for UK tradespeople. Tradespeople forward their business emails to us. Our system classifies those emails, drafts replies using AI, and presents them for the tradesperson to review and approve before anything is sent. We also provide calendar integration so the AI can check availability when drafting replies.


Information we collect from tradespeople (our customers)

Account information

What: Your name, email address, and a password-free login (magic link).

Why: To create and manage your account, authenticate you, and communicate with you about the service.

Lawful basis: Necessary to perform our contract with you (UK GDPR Article 6(1)(b)).

What happens if you don't provide it: We cannot create your account or provide the service.

Business profile

What: Your trade, service area, working hours, and business description.

Why: To configure the AI so it can draft appropriate replies on your behalf.

Lawful basis: Necessary to perform our contract with you (Article 6(1)(b)).

What happens if you don't provide it: The AI cannot draft informed replies, and the core service will not function as intended.

Billing information

What: Your payment details are collected and processed by Stripe, our payment processor. We do not store your card details on our servers. We receive confirmation of payment status, your billing email, and transaction history from Stripe.

Why: To process your subscription payments and maintain billing records.

Lawful basis: Necessary to perform our contract with you (Article 6(1)(b)) for payment processing. Necessary to comply with a legal obligation (Article 6(1)(c)) for retention of billing records for HMRC.

What happens if you don't provide it: We cannot process your subscription and you will not be able to use the service.

Calendar credentials

What: If you choose to connect your Google, Microsoft, Yahoo, or Apple calendar, we store the authentication tokens needed to read your availability.

Why: To inform AI-drafted replies with your real availability.

Lawful basis: Necessary to perform our contract with you (Article 6(1)(b)). Calendar connection is optional but forms part of the service when enabled.

What happens if you don't provide it: The AI will draft replies without knowledge of your availability. You can still use the service.

Technical and usage data

What: Device information for push notifications (browser type, push subscription endpoint), authentication tokens, basic server logs (IP addresses, timestamps, error information), and reports your browser sends us about how the app is running: a diagnostic report when something goes wrong — what broke, the page it happened on, your browser family and device type — together with basic performance measurements from that visit, such as how quickly pages loaded and responded and your connection type. We may also collect those performance measurements from a small sample of visits where nothing has gone wrong. These reports are linked to your account, so we can find the problem you hit.

Why: To deliver push notifications, authenticate your sessions, detect and prevent abuse, debug technical problems, and maintain the security and availability of the platform.

Lawful basis: Legitimate interests (Article 6(1)(f)). Our legitimate interest is in operating a secure, reliable service. We have assessed that this processing is necessary for that purpose, is proportionate (we collect only what is technically required), and does not override your rights — particularly as we do not use this data for profiling, analytics, or advertising, and we delete server and diagnostic logs after 90 days.

What happens if you don't provide it: This data is collected automatically as part of your use of the service. Without it, we cannot deliver notifications, authenticate your sessions, or maintain platform security.


If you've given us your email but don't have an account

What: Your email address, and which thing you were waiting for — for example that we don't yet support your email provider, that you wanted to use your own domain, or that you started connecting an account and didn't finish.

Why: So we can tell you when the thing you were waiting for is ready. We don't add you to a marketing list, we don't use it for anything else, and we don't share it.

Lawful basis: Steps taken at your request before entering into a contract (Article 6(1)(b)).

What happens if you don't provide it: Nothing else changes — you simply won't hear from us when it's ready. You can ask us to delete it at any time by emailing privacy@thebooker.ai.

Information we process from your customers (the people who email you)

What we receive and where it comes from

When someone emails you and that email is forwarded to TheBooker by your email provider's forwarding rule, we receive the sender's name, email address, the subject line, and the body of their message. This may include their phone number, postal address, or other details they chose to include in their email to you.

Source of this data: We receive it indirectly, via the email forwarding rule you have set up with your email provider. We do not collect it directly from the sender.

Where you use a web enquiry form we host, it works differently: we receive what the sender types into the form directly, at the point they submit it. We handle a form enquiry the same way as an email enquiry, and we remain your data processor for it. Privacy information for the sender is shown on the form itself at the point of collection.

Our role with this data

You, the tradesperson, are the data controller for your customers' personal data. You decide to use TheBooker to manage your enquiries, and you control what happens with the replies. We act as your data processor — we process this data on your behalf, under your instructions, to provide the service you have signed up for. Our terms of service include a Data Processing Agreement that sets out this relationship formally.

What we do with it

We classify the email (is it a booking enquiry, a general question, spam, or part of an existing conversation?), draft a suggested reply using AI, and present it to you for review. We send replies only when you explicitly approve them.

We do not contact your customers independently. We do not use their data for our own marketing. We do not share their information with anyone other than you. We do not redirect their enquiries to other tradespeople.

Your responsibility as controller

Because you are the controller for your customers' personal data, you should let your customers know that you use a third-party service to help manage your enquiries. We recommend including a note in your email signature or on your website. We can provide suggested wording for this on request.


How we handle different types of forwarded email

Because you forward your business email to us, we receive everything that arrives in your inbox — not just customer enquiries. Our system classifies each email and handles it differently depending on what it is. This section explains what happens to each type.

Enquiries and emails relevant to enquiries

Emails that our system classifies as booking enquiries, general questions about your services, or replies within an existing conversation thread are the core of what TheBooker is built for. These are retained within the platform, a draft reply is generated by AI, and they are presented to you for review.

Retention: 24 months from the last activity in a conversation thread, then deleted.

Non-sensitive, non-enquiry emails

Emails that are not related to enquiries and do not contain sensitive or security-related content — for example, newsletters, marketing emails, personal messages from friends or family, adverts, or social media notifications.

These are classified and made visible to you in a filtered view for 14 days, so you can check whether anything was incorrectly filtered. After 14 days, they are deleted (or, only if you have opted in, anonymised). No AI reply is drafted for these emails.

The 14-day window exists as a safety net. Our classifier will not be perfect, and a genuine enquiry could occasionally be miscategorised. This gives you the opportunity to catch and recover those.

Retention: 14 days from receipt, then deleted (or, only if you have opted in, anonymised).

Emails containing password reset links, two-factor authentication codes, login tokens, account verification emails, or other authentication credentials from third-party services. These also include any of our own authentication emails (such as TheBooker magic links) that may arrive via forwarding.

We detect and delete these as soon as they are identified. We do not store, log, index, or process these emails beyond what is necessary to identify and remove them. They are not classified, no AI draft is generated, and they do not appear in your inbox within our platform. Authentication credentials are too sensitive to retain for any duration.

Retention: Deleted immediately on detection.

Emails containing special category data (sensitive personal data)

UK data protection law defines certain types of personal data as "special category data" requiring additional protection. This includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, and data concerning a person's sex life or sexual orientation.

We do not intentionally collect special category data. However, forwarded emails may incidentally contain it — for example, a customer mentioning a health condition that affects the work they need done, or personal circumstances included in a message.

Where a message containing special category data is also a genuine enquiry, it is never ignored or dropped because of the sensitive content. It is handled through the normal enquiry path — retained for 24 months from the last activity in the conversation, an AI draft is generated, and it is presented to you for review — with three extra protections: (1) We flag it to you: the enquiry is marked 'handle with care' in the app. We record only a yes/no marker that the message appears to contain special category data — not which kind — and we do not extract, label, or separately store the sensitive content itself; the marker is part of the enquiry record and is deleted with it. (2) We keep sensitive detail out of the places it doesn't need to be: the AI draft repeats sensitive detail only to the extent needed to respond helpfully, and we keep it out of calendar entries and push notifications. (3) We never use it to improve the system: messages containing special category data are excluded from our anonymised system-improvement data — whether or not they are enquiries, and even if you have opted in.

Where an email containing special category data is not an enquiry, it follows the same 14-day path as other non-enquiry emails — it remains viewable in the app so you can check whether it was correctly classified. After 14 days, the email is deleted. We do not retain anonymised versions of emails containing special category data for system improvement: even if you have opted in, these emails are always deleted and are never added to our improvement data.

Lawful basis for processing special category data: Customers sometimes volunteer sensitive information in their enquiries — most often a health condition relevant to the work they need done. Where that happens, we process it solely so that you can respond to that person, and for no purpose of our own. You, the tradesperson, are the data controller for your customers' data; we act as your data processor under your documented instructions, as set out in our Data Processing Agreement (Schedule 1 to our Terms of Service). The 'handle with care' marker exists only to apply the protections described above. We never use messages containing special category data for system improvement.


How AI is used and automated decision-making

We use AI (provided by Amazon Web Services Bedrock) to classify emails and draft replies. The AI processes the content of forwarded emails to do this.

Our AI runs on Amazon Bedrock. Under our agreement with AWS, your content and your customers’ content is not used to train the underlying AI models, and is not shared with the model providers for their own purposes.

No automated decisions are made under Article 22 of UK GDPR that produce legal effects or similarly significantly affect you or your customers. Specifically:

How AI actions are controlled:

By default, the AI drafts replies and presents them to you for review. You approve, edit, or dismiss every draft before it is sent. You are the human in the loop.

We may introduce features in future that allow the AI to take certain actions on your behalf without requiring approval for each one — for example, automatically sending a reply to confirm a booking, or filtering obvious spam. If and when we do this:

We will update this policy before introducing any such features.

Google user data. Where you connect a Google account (Gmail or Google Calendar), TheBooker’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.


Who we share your data with

We share personal data with the following service providers. Unless otherwise stated, they act as our data processors (or sub-processors where we are acting as your processor for end-customer data).

Amazon Web Services (AWS): Our infrastructure provider. Our primary data storage and processing takes place in the AWS eu-west-2 (London) region. Some AWS services, including AI inference (via Amazon Bedrock), may process data in other AWS regions, including regions in the United States, depending on service availability. Where this involves a transfer of personal data outside the UK, it is covered by appropriate safeguards as described in the International Data Transfers section below.

Stripe: Our payment processor. Stripe processes your billing information to handle subscription payments. For some aspects of payment processing and fraud prevention, Stripe acts as an independent data controller under its own privacy policy (https://stripe.com/privacy). Stripe is certified under the UK Extension to the EU-US Data Privacy Framework.

Email and calendar providers you connect: If you choose to connect an email or calendar account — such as Google, Microsoft, Yahoo, or Apple (iCloud) — we use their APIs for the specific purposes you authorise (for example, reading your calendar availability, or sending replies through your email provider's authenticated API). The underlying provider continues to operate under its own terms and privacy policy.

Google Maps Platform: When we show a map for a job or estimate drive times, we send the postcode or address of the booking location to Google Maps Platform. We do not send enquiry contents, your billing data, or your customers’ contact details beyond that location.

Amazon Comprehend (an AWS service): used to detect and strip out personal data when we create anonymised samples to improve the system. It processes email content only for that PII-detection step.

Google Workspace: our internal business email on the thebooker.ai domain (for example, our support and privacy inboxes). If you email us, or we email you about support, onboarding, or a breach, Google Workspace processes that correspondence. It is not used to receive, send, or store the enquiry email you forward into the platform.

We maintain a current list of our sub-processors at https://thebooker.ai/legal/sub-processors and will keep it up to date. You can also request the current list at any time by emailing privacy@thebooker.ai.

We do not sell your data to anyone. We do not share your data with advertisers. We do not share your customers' data with other tradespeople or with any third party beyond what is described above.

Business transfers. If TheBooker is involved in a merger, acquisition, restructuring, sale of its business or assets, or insolvency, personal data may transfer to the successor entity as part of that transaction. We will require the successor to continue honouring this privacy policy, and we will notify you (by email or in-app notice) before your personal data becomes subject to a materially different policy.


International data transfers

Our primary data storage is in the United Kingdom, in AWS's London (eu-west-2) data centre region.

Some processing may take place in the United States — either through our service providers (Stripe) or through AWS services that operate in US regions (such as AI inference via Amazon Bedrock, where specific models may only be available in certain regions).

Where personal data is transferred to the United States, this is protected by one or more of the following safeguards:

We keep our data within the UK wherever service availability allows. If we begin transferring personal data to a country not covered by the safeguards described above, we will update this policy, put appropriate safeguards in place before any transfer occurs, and notify you of the change.


How we protect your data

We protect personal data with specific technical and organisational measures. This section explains what they are.

Encryption in transit. Every connection to TheBooker - from your browser, and between our systems and the third-party services listed above - is encrypted using TLS. We do not accept unencrypted connections.

Encryption at rest. Data held in our database, our file storage, and our backups is encrypted at rest using AES-256.

Extra protection for connected account credentials. The tokens that let us send email or read your calendar on your behalf are protected beyond the storage encryption above. Before a token is written to the database it is separately encrypted using AES-256-GCM, under a key held in a managed secret store that is isolated from the database and never appears in our application code. Each token is cryptographically bound to the specific connection it belongs to, so a token record lifted out of its context cannot be decrypted anywhere else. We never receive or store your email or calendar password.

Least-privilege access. Each component of our system is granted only the permissions it needs to do its job, and administrative access to production systems is restricted to named, individually authenticated accounts. We do not access the contents of your mailbox or calendar except as needed to provide the service described in this policy.

We ask for the narrowest access that works. We request only the permissions the service actually needs from each provider you connect, and no more.

Google user data. Where you connect Gmail or Google Calendar, the following applies.

Sending email. We request send-only access (gmail.send). This permission does not allow us to read, search, or modify your mailbox. Enquiries reach us through the forwarding rule you set up, not through the Gmail API.

Calendar. We request access to your calendar events (calendar.events) to check your availability and to write a confirmed booking, and read-only access to your list of calendars (calendar.calendarlist.readonly) so that we check every calendar you keep rather than only your primary one. The calendar list permission gives us the names of your calendars, not their contents.

Your account address. We request your Google account email address (userinfo.email) so we can confirm you connected the account you intended to.

Where availability reaches our AI. When drafting a reply, the AI may be given your free/busy times so it can suggest slots that are genuinely open. It receives times only - not event titles, attendees, or descriptions.

Protecting these credentials. The tokens for these connections are protected as described above.

Your control. You can disconnect at any time in Settings, or revoke our access directly in your Google account at https://myaccount.google.com/permissions. On disconnection or account deletion we delete the stored tokens.

Limited Use. TheBooker's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train generalised AI models.

Special category data. Where a forwarded email incidentally contains special category data, additional protections apply - see How we handle different types of forwarded email above.

If something goes wrong. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you without undue delay where the risk to you is high.

Using your data to improve the system

We may wish to use anonymised data derived from email classifications to improve how the system works — for example, to make our email classifier more accurate over time. If we do this, two things will always be true:

  1. We will ask you first, in plain English, with a genuine choice. This will be a separate, specific opt-in request — not something buried in a terms update. You can say no, and that will be the end of it.

  1. The data will be fully anonymised before any such use. Names, email addresses, phone numbers, postcodes, business names, monetary amounts, dates, and anything else that could identify you or the people who contact you will be permanently stripped out. Once anonymised in this way, the data is no longer personal data under UK data protection law and falls outside the scope of UK GDPR.

Creating anonymised samples in this way is processing we carry out for our own purpose (improving the system), for which we act as controller on the basis of our legitimate interests (Article 6(1)(f) UK GDPR), with your opt-in as the trigger. Once a sample is fully anonymised it is no longer personal data.

If you opt in and later change your mind, you can withdraw your consent at any time by contacting us. We will stop using your data for this purpose going forward.

What happens to anonymised samples when you delete your account. Samples that were anonymised while you were opted in are no longer personal data — they contain nothing that identifies you or the people who contacted you. For that reason they remain part of the system's learning even after you withdraw consent or delete your account: withdrawal and deletion stop us creating any new samples and sever the last tie between the existing samples and you, but they do not retroactively remove samples that have already been anonymised. If you ask for a copy of your data, we will confirm that such samples exist, but because they are no longer personal data they are not included in the export.

We will never sell your data, your customers' data, or anything derived from them to third parties.


How long we keep your data

Data type

Retention period

Reason

Account and business profile

While your account is active, plus a grace period (normally around 30 days) after deletion for recovery

Contract performance

Enquiry emails (forwarded emails, drafts, sent replies)

24 months from the last activity in a conversation thread

Contract performance; proportionate to the service purpose

Non-enquiry, non-sensitive emails (newsletters, adverts, personal)

14 days from receipt, then deleted (or, only if you have opted in, anonymised)

Safety net for misclassification; deleted promptly once no longer needed

Authentication and security emails (2FA, password resets, login links)

Deleted immediately on detection

Too sensitive to retain; no operational need beyond identification

Emails containing special category data (non-enquiry)

14 days from receipt, then deleted

Same safety net as other non-enquiry emails; always deleted and never anonymised or added to system-improvement data, even if opted in

Enquiries containing special category data

Same as enquiry emails (24 months); the yes/no 'handle with care' marker is deleted with the enquiry

Flagged to you for careful handling; sensitive content is not separately extracted or stored; never anonymised or added to system-improvement data, even if you have opted in

Billing records

6 years after the end of your subscription

Legal obligation (HMRC requires retention of accounting records)

Fully anonymised system-improvement samples (if opted in)

Retained indefinitely; the tie to your account and personal identity is removed on account deletion

Once fully anonymised it is no longer personal data; retained to improve the system under your consent

Server logs

90 days

Legitimate interest in security and debugging

Push notification subscriptions

While your account is active; stale subscriptions auto-removed

Contract performance

Calendar authentication tokens

While the calendar connection is active; revoked on disconnection or account deletion

Contract performance

Bookings we've added to your connected calendar

While your calendar is connected we keep them in step with your bookings, so cancelling a booking removes it. Once you disconnect your calendar or close your account, we leave them in place.

They're not ours to delete: they're your own business records, in your own calendar account, which we can't reach once you disconnect. They include your customers' names, contact details and any notes about the job, so it's up to you to look after them, including after you close your account.

Waitlist sign-ups from people without an account

12 months from when you first joined, then deleted automatically. Joining again doesn't extend it.

Steps taken at your request before a contract; deleted once the interest has gone stale

If you ask us to delete your data, we will do so within one month, in line with UK data protection law, except for billing records we are legally required to retain, and any fully anonymised system-improvement samples (if you opted in), which carry no identifying information and remain in the system without any ability to reconnect these anonymous samples to you or your customers' identity. In each case we remove your data from live systems within that period; residual copies in encrypted backups are not accessible for ordinary use and expire within 35 days. This doesn't reach bookings we've already added to your own calendar. Those are in your calendar account, which we can't reach once you disconnect, and whether you keep or delete them is up to you.


Your rights

Under UK data protection law, you have the following rights:

Right of access (Article 15): You can ask us for a copy of all the personal data we hold about you. We will provide it in a commonly used, machine-readable format.

Right to rectification (Article 16): If any of your data is inaccurate or incomplete, you can ask us to correct it.

Right to erasure (Article 17): You can ask us to delete your data. We will do so unless we have a legal obligation to keep it (such as billing records for HMRC).

Right to restrict processing (Article 18): You can ask us to stop processing your data in certain circumstances — for example, while we verify its accuracy or consider an objection you have raised.

Right to data portability (Article 20): You can ask us to provide your data in a structured, commonly used, machine-readable format so you can transfer it to another service.

Right to object (Article 21): You can object to processing that we carry out under legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to withdraw consent (Article 7(3)): Where we rely on your consent (such as for system improvement), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

To exercise any of these rights, email privacy@thebooker.ai. You do not need to fill in a special form or cite a regulation. Just tell us what you need. We will respond within one month. If your request is complex, we may extend this by a further two months, but we will tell you within the first month and explain why.

There is no fee for exercising your rights in most circumstances.


Cookies

We use only strictly necessary cookies — specifically, authentication cookies that keep you logged in when you use the platform. These are essential for the service to function and do not require your consent under the Privacy and Electronic Communications Regulations 2003 (PECR).

We do not use analytics cookies, advertising cookies, social media cookies, or tracking pixels. We do not use any third-party cookies.


Children's data

TheBooker is a business service for tradespeople. It is not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe a child's personal data has been processed by us, please contact us and we will delete it promptly.


Changes to this policy

If we make material changes to this policy, we will notify you directly by email or in-app notification before the changes take effect, giving you reasonable time to review them. We will clearly explain what has changed and why.

We will update this policy whenever we make significant changes to our processing activities.


Complaints

If you are unhappy with how we have handled your personal data, please contact us first at privacy@thebooker.ai. We will do our best to resolve your concern.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

← Back to thebooker.ai