Privacy Policy
Effective date: 1 June 2025 · Last updated: 1 June 2025
Summary: We collect only what we need to run the service. We do not sell your data. You can request deletion at any time by emailing privacy@prebookk.com.
1. Who We Are
Prebookk (“we”, “our”, “us”) operates the platform at prebookk.com. This Privacy Policy explains how we collect, use, share, and protect information about you when you use our services.
This policy applies to both service Providers (who create booking pages) and Customers (who make bookings through those pages).
2. Information We Collect
2.1 From Providers
When you register as a Provider, we collect:
- Account information: Name, email address, mobile number
- Profile information: Display name, bio, business name, city, profile photo, service category
- Payment information: UPI ID, bank account details (processed and stored by Razorpay, not by us)
- KYC information: PAN card number, Aadhaar last 4 digits (submitted to and processed by Razorpay)
- Availability and service data: Your working hours, services, pricing
2.2 From Customers
When you book an appointment, we collect:
- Contact information: Name, mobile number, email address (optional)
- Booking details: Service selected, date and time, any notes provided
- Payment information: Transaction ID (we do not store card numbers, UPI PINs, or CVVs — these are handled entirely by Razorpay)
2.3 Automatically Collected
- Usage data: Pages visited, booking page views, features used
- Device information: IP address, browser type, operating system
- Cookies: Authentication session cookies (required for Provider login), no third-party advertising cookies
3. How We Use Your Information
We use the information we collect to:
- Operate and improve the Prebookk platform
- Create and manage your Provider account
- Display your public booking page to potential Customers
- Process bookings and coordinate between Providers and Customers
- Send booking confirmations, reminders, and status updates
- Facilitate payment processing through Razorpay
- Prevent fraud, abuse, and violations of our Terms of Service
- Comply with legal obligations under Indian law
- Respond to your queries and provide customer support
We do not use your information for targeted advertising, and we do not sell your personal data to third parties.
4. How We Share Your Information
4.1 With Customers (for Providers)
Your public profile information (name, bio, photo, services, city) is visible to anyone who visits your booking page URL. Your email address and full phone number are never displayed publicly.
4.2 With Providers (for Customers)
When you make a booking, the Provider receives your name, phone number, email address (if provided), and any notes you included with your booking.
4.3 With Service Providers
We share data with trusted third-party service providers to operate our platform:
- Supabase (database and authentication) — stores your account and booking data on servers in their infrastructure
- Razorpay (payment processing) — receives payment details and KYC information as required by RBI regulations
- Resend (transactional email) — used to send booking confirmations and reminders
- Vercel (hosting) — serves the web application
All third-party processors are contractually required to protect your data and use it only for the services they provide to us.
4.4 Legal Requirements
We may disclose your information if required by law, court order, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Prebookk, our users, or the public.
5. Data Storage and Security
Your data is stored on Supabase infrastructure. We implement industry-standard security measures including:
- Encryption in transit (HTTPS/TLS) for all data
- Row-Level Security (RLS) on all database tables
- Supabase Auth for secure session management
- No storage of payment card details or UPI PINs on our servers
While we take reasonable precautions, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your information.
6. Cookies
We use the following cookies:
- Authentication cookies: Set by Supabase to keep Providers signed in. Essential for the service to function. Expire when you sign out or after 7 days of inactivity.
- No advertising or tracking cookies are set by Prebookk.
You can clear cookies through your browser settings. Doing so will sign you out of your Provider account.
7. Data Retention
- Provider accounts: Retained while your account is active and for up to 3 years after deletion, as required for financial record-keeping under Indian tax law.
- Booking records: Retained for 7 years as required by Indian accounting and tax regulations.
- Customer information: Retained for as long as a Provider account that has booked with that customer remains active, and for 7 years thereafter for financial compliance.
- Usage logs: Retained for up to 90 days.
8. Your Rights
Under the Information Technology Act, 2000 and applicable Indian data protection principles, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated personal data (subject to legal retention requirements)
- Withdraw consent where processing is based on consent
- Object to processing of your data for certain purposes
To exercise any of these rights, email us at privacy@prebookk.com. We will respond within 30 days.
9. Children's Privacy
Prebookk is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has submitted personal information to us, please contact us immediately at privacy@prebookk.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered Providers of material changes via email at least 14 days before they take effect. The “Last updated” date at the top of this page will always reflect the most recent version.
11. Contact Us
For any privacy-related questions, requests, or complaints:
Prebookk — Privacy Team
Email: privacy@prebookk.com
We aim to respond to all privacy requests within 30 days.