Booking Shepherd
Setup guideBack to website
Pilot preview · data handling

Your booking information.

This page explains how the current Booking Shepherd pilot works. A final operator privacy policy and contact address must be added before a commercial launch.

Information you provide

The booking form collects your name, email, phone number, chosen service and add-ons, preferred time, answers to service questions, and messaging preferences. Quote forms collect contact details and a description of the requested work. The business uses these details to review and manage your request.

Business accounts store owner/staff names and emails, password hashes, business and service configuration, invitations and authentication sessions. Account recovery and verification use hashed, expiring tokens and a separate encrypted email queue; those private links do not appear in the shared business message history. Message threads may contain text and uploaded photos.

Booking forms record a random form-session identifier and successful submission events for business reports. These events are not advertising profiles. Payment requests store amounts, status and provider references, not card numbers.

Who can see it

Booking information is available in the business’s authenticated workspace for its owner and active staff. A private management link gives its holder access to that appointment and its payment requests. Treat that link as private.

When messaging is enabled, the necessary recipient details and message content are sent to the configured email provider and Twilio for delivery. Connected payments use Stripe Checkout, where the customer enters card details. The app does not use advertising trackers.

Signed delivery receipts store provider references, event times and delivery outcomes, not the complete incoming receipt payload. Email bounces and spam complaints can suppress further email to that address across the shared sending account, including private account notices. This is separate from your business follow-up preferences. The app does not add email open or click tracking.

Your communication choices

Text updates are optional. Follow-up messages and review invitations use a separate opt-in. Reply STOP to stop texts. Your appointment management page also lets you stop service reminders and review messages to that email from the business, without cancelling the appointment or stopping essential appointment notices. You can also contact the service business about your preferences.

Hosting and retention

The deployment uses the database configured by the operator. Data residency depends on the operator’s hosting configuration. Appointment, contact, message, photo and call-summary records remain stored until the operator removes them. Provider photo links expire after seven days, but that does not erase the stored photo bytes. Automatic retention and self-service data deletion are not yet available. Providers and backups may have their own retention, which the operator must document before launch.

For a real booking, contact the service business shown on your booking page to request access, correction, or removal of your information. The operator should establish its legal identity, privacy contact, retention policy, and launch terms before onboarding live customers.