Privacy policy

Last updated September 21, 2026

BookVAO gives appointment-based businesses a booking website, a dashboard and a mobile app. This page explains what personal information that involves, what we do with it, and what we never do. It covers bookvao.com, every booking site hosted on BookVAO, and the BookVAO app for iPhone and Android.

The short version

  • We use personal information to run bookings and nothing else. We do not sell it, rent it, or use it for advertising.
  • There are no ads, no advertising trackers and no analytics SDKs on our sites or in the app.
  • A business's client list belongs to that business. We hold it for them and only they and their team can see it.
  • The mobile app does not read your contacts, location, photos or microphone.

Who is responsible

BookVAO is operated by CEO Family Investments LLC ("we"). For information about the people who run a business on BookVAO (owners and their team), we decide how it is used. For information about a business's clients, the business decides and we process it on their behalf: if you booked with a salon, that salon is who to ask first, and we will help them answer.

What we collect

From businesses and their team: name, email address, a password (stored only as a one-way hash), the business's details (name, address, phone, hours, services, prices, photos they add), and their subscription status. Card payments go directly to Stripe; we never see or store card numbers.

From people who book an appointment: name, phone number, optionally an email address and a note for the business, the appointment itself, a discount code if one was used, whether they asked for text reminders, and the rating or comment they choose to leave afterwards. A client account is optional and has no password: we email a one-time sign-in link.

From the mobile app: the app is for the business's owner and team. It sends the email and password to that business's site to sign in, keeps the resulting login token and an offline copy of bookings in the phone's secure storage (Keychain or Keystore), and, if notifications are allowed, registers a push notification token so new requests can be announced. The name and platform of the device are stored so the owner can see which devices are signed in.

Automatically: our servers keep short-lived technical logs (IP address, time, the page requested) for security and troubleshooting. We use one cookie, to keep a signed-in person signed in. We set no advertising or cross-site tracking cookies.

What we use it for

  • Taking, confirming, changing and cancelling appointments, and showing them to the business.
  • Sending the messages that go with an appointment: confirmations, reminders and a follow-up by email; text messages only to clients who ticked the box asking for them, and to the business's own phone.
  • Push notifications to the team's phones about new requests and cancellations.
  • Billing the business for its subscription.
  • Keeping the service secure, preventing abuse, and fixing problems.

Who receives it

Only the companies that help us run the service, each for its one job, under contracts that limit what they may do with it:

  • Amazon Web Services: hosting and the database, in the United States.
  • Stripe: subscription payments from businesses.
  • Our email delivery provider: sending appointment emails.
  • Twilio: sending text messages to people who asked for them.
  • Google Firebase Cloud Messaging and Apple Push Notification service: delivering push notifications to the app. They receive the device's push token and the notification's text (for example a client's first name and the service booked).

We also disclose information when the law requires it, or to protect someone's safety or our rights. If BookVAO is ever sold or merged, the information moves with the service under these same promises.

How long we keep it

For as long as the business keeps its account, because appointment history is part of what it pays for. A business can delete clients, appointments and team members at any time, and closing the account deletes its data; backups roll off within 35 days. Technical logs are kept for up to 30 days. Signing out of the app removes its login and offline copy from that phone at once.

Your choices

  • See, correct or delete your information. Clients: ask the business you booked with, or write to us and we will pass it on and make sure it is done. Owners and team members: change your details in the dashboard, or write to us to close an account and delete its data.
  • Text messages. Reply STOP to any text, or leave the box unticked when booking.
  • Notifications. Turn them off for the app in your phone's settings; the app keeps working.
  • Where you live may give you more rights (for example under the GDPR or the CCPA), including to object, to take your data elsewhere, and to complain to a regulator. We honour those requests from anyone, wherever they live. We do not sell or share personal information as those laws define it.

Security

All traffic is encrypted (HTTPS). Passwords and app login tokens are stored only as one-way hashes, each business's data is fenced off from every other business's, and a team member's access ends the moment the owner removes them. No system is perfectly secure; if something goes wrong that affects you, we will tell you and the business promptly.

Children

BookVAO is a tool for businesses and is not directed to children under 13. A parent can book for a child using the parent's own contact details.

Changes and contact

If we change this policy in a way that matters, we will say so here and, for businesses, by email before it takes effect. Questions and requests: support@bookvao.com.