Privacy Policy
Effective Date: February 19, 2026
This policy explains how ubooky collects, uses, discloses, and manages personal data when you use our booking management services.
For customer data submitted by each merchant through the platform, the merchant may act as the data controller, while ubooky acts as a platform provider/data processor under merchant instructions.
1) Data Controller and Contact
The ubooky platform operator is the data controller for account-level data and operational data needed to provide the platform. You may contact us regarding personal data through ubooky support channels on the website, our official LINE OA, or the in-app support request menu in the merchant console.
2) Information We Collect
Owner account data: email, profile details, and identity details from login providers (such as Google or LINE when enabled).
Customer booking data: name, phone number, email, notes, LINE User ID (if provided), booking date/time, and service details.
Deposit payment data: amount, payment status, and uploaded payment slip image.
Business and operational data: business/branch/service/staff/resource settings, support request records, reminder configuration and delivery logs, webhook endpoints, and webhook delivery logs.
Technical data: essential authentication cookies, limited local storage, session storage in some flows (such as LINE LIFF), and system logs required for security and auditability.
3) Purposes and Legal Bases
To perform our contract: account provisioning, booking management, confirmation/cancellation, deposit verification, and operation of branches, services, staff, and resources.
For legitimate interests: security monitoring, abuse prevention, operational auditing, and service improvement.
For legal compliance: retaining data required by applicable legal, accounting, tax, or dispute-handling obligations.
Where consent is required (if any), we will request it separately and state clear purposes before processing.
4) Required Data and Consequences
Some fields are necessary to provide the service, such as merchant account details, customer contact details, and booking date/time and service selection. If required data is not provided, we may be unable to create accounts, process bookings, send confirmations/reminders, or provide certain features.
5) Third-Party Sharing
We disclose data only as needed to operate the service, including infrastructure/database providers (such as Supabase), authentication providers (such as Google/LINE), and messaging/email providers (such as Resend, LINE Messaging API, or merchant-configured webhook providers).
Those recipients receive only the data required for each processing purpose and are subject to applicable security and data-processing terms.
6) Cross-Border Transfers
Some service providers may process data on systems located outside your country. We apply appropriate safeguards for cross-border processing in line with applicable law.
7) Cookies and Similar Technologies
We use essential cookies for authentication and core app functionality, and a service worker to support PWA behavior. We currently do not run targeted advertising cookies.
8) Data Retention
We retain data for as long as necessary for service purposes or legal obligations, based on data type and risk profile.
For example, account and business configuration data is retained while the account is active. Booking and transaction records are retained as needed for service operation, auditing, and dispute handling. Data no longer required is deleted or de-identified within a reasonable period.
9) Data Subject Rights
You may have rights under applicable law, including access, rectification, objection, restriction, data portability (where legally applicable), and erasure subject to legal conditions.
Merchant users can edit certain profile data in-product and can delete their account from account settings in the merchant console. For additional rights requests, please contact ubooky support channels.
10) Sensitive Data and Notes Field
Please avoid entering sensitive personal data (for example health data, race, religion, or other unnecessary sensitive details) in free-text notes unless strictly necessary for the service and managed in accordance with applicable law.
11) Security
We apply reasonable technical and organizational safeguards to protect data from unauthorized access, alteration, or disclosure. No system can be guaranteed 100% secure.
12) Changes to This Policy
We may update this policy as the product or legal requirements change. The latest effective date will always appear on this page.