Privacy policy
Last updated: August 20, 2026
1. Who We Are
This Privacy Policy explains how BookingMinds Inc., a Delaware corporation (28 Geary St STE 650 PMB 504, San Francisco, CA 94108, USA), handles your personal data when you use the Booking Minds app and website. We are the data controller for this processing. Contact: privacy@bookingminds.app.
2. Information We Collect
Account and profile: name, e-mail address, profession, company, service you offer, bio, profile photo and other photos you post, and your interests.
Location: with your consent, your device location (including background location if you allow it) so you appear on the map and see people, events and needs near you. Instead of granting location access you can place a pin manually. Location sharing can be turned off at any time in your device settings.
Identity verification: to receive payments, you verify your identity with our verification partner Didit (ID document scan, liveness check, and a face match between your ID portrait and profile photo). We receive and store the outcome: your verified name, date of birth, nationality, verification status and match scores. We do not store images of your ID document. The document number is processed into a one-way cryptographic hash used only to enforce one-account-per-document.
Payments: processed by Stripe. We never see or store your card number. We store transaction records (amounts, status, payout history).
Messages and activity: your chats with other members, offers, events, needs, reactions, profile views, and in-app reports.
Device and usage data: device type, app version, push notification token, log and diagnostic data (including crash reports), and – on iOS only with your App Tracking Transparency consent – the advertising identifier used by the Facebook SDK for install attribution.
3. How We Use Your Information
- to operate the map, offers, meetings, events, needs, feed and chat;
- to process payments, holds, refunds and payouts;
- to verify identity and prevent fraud, duplicate accounts and abuse;
- to send push notifications and e-mails about activity that concerns you (offers, messages, payments) – transactional, not marketing spam;
- to improve the Service using aggregated usage and crash data;
- to comply with legal obligations (tax, accounting, lawful requests).
4. Legal Bases (GDPR)
Where the GDPR applies, we process your data on these bases: performance of a contract (account, meetings, payments), consent (location, background location, biometric verification through Didit, iOS tracking), legitimate interests (fraud prevention, service security, improving the app), and legal obligation (financial records). You can withdraw consent at any time without affecting past processing.
5. Who We Share Data With
We share data only with processors we need to run the Service, under data processing agreements:
- Stripe – payment processing and payouts
- Didit – identity verification (ID, liveness, face match)
- Supabase – database and backend hosting
- Expo – delivery of push notifications
- Resend – transactional e-mail delivery
- Mapbox – map display
- Google – sign-in with Google, push delivery on Android, analytics on our website
- Apple – sign-in with Apple, push delivery on iOS
- Meta (Facebook SDK) – app install attribution
Other members see your public profile (name, photos, profession, service, bio, verified badge, nationality flag, approximate map position). We disclose data to authorities only when legally required, and we never sell your personal data.
6. Data Retention
We keep your data while your account is active. When you delete your account in the app, your profile, photos, location and pending activity are deleted; records of completed transactions are retained as required by financial and tax law, and your side of past conversations is detached to an anonymous placeholder. Verification outcomes are kept only as long as needed to enforce one-account-per-document.
7. Your Rights
You have the right to access, correct, delete and receive a copy of your personal data, to object to or restrict processing, and to withdraw consent. EU/EEA residents may also complain to their supervisory authority; California residents have equivalent rights under the CCPA (including the right to know and delete – we do not sell personal information). Write to privacy@bookingminds.app and we will respond within 30 days. Most data can also be managed directly in the app, including full account deletion.
8. Data Security
Data is encrypted in transit, access is protected by row-level security and least-privilege service keys, payments never touch our servers, and we monitor the platform with automated integrity checks. No method of transmission over the Internet is 100% secure, but we treat the security of your data as a first-class engineering concern.
9. Children's Privacy and Child Safety Standards
Booking Minds is not intended for users under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
Child Safety Commitment
Booking Minds is committed to the safety and protection of children. We have zero tolerance for child sexual abuse and exploitation (CSAE) on our platform. We strictly prohibit the use of our app and services for any content, activity, or conduct that sexually exploits or endangers children, including but not limited to:
- Child sexual abuse material (CSAM) of any kind
- Grooming or solicitation of minors
- Sextortion or other forms of exploitation targeting minors
- Trafficking of children
- Any other form of child sexual abuse or exploitation
Reporting and Enforcement
If we become aware of any CSAE content or activity on the Booking Minds platform, we will:
- Immediately remove the content and disable the offending account
- Report the incident to the National Center for Missing & Exploited Children (NCMEC) and relevant law enforcement authorities
- Cooperate fully with law enforcement investigations
Users who encounter any content or behavior that may involve the exploitation of children on Booking Minds should report it immediately to us at safety@bookingminds.app or through our in-app reporting features.
10. International Data Transfers
Our infrastructure is hosted in the United States and the European Union. Where personal data of EU/EEA residents is transferred outside the EEA, we rely on our processors’ safeguards, including Standard Contractual Clauses.
11. Changes to This Policy
We will post any changes here and update the date at the top. For material changes we will notify you in the app or by e-mail.
12. Contact Us
BookingMinds Inc.
28 Geary St STE 650 PMB 504, San Francisco, CA 94108, USA
Privacy: privacy@bookingminds.app · Safety: safety@bookingminds.app · Support: info@bookingminds.app