Last updated October 5, 2026.
DayO Book (“DayO Book,” “we,” “us”) is a scheduling platform used by businesses (“business owners,” “you”) to manage bookings, and by their customers (“end customers”) to book appointments. This policy explains what data we collect across the whole platform — the business owner's account, the booking widget their customers use, and the internal tools we use to run DayO Book itself — and what we do with it.
If a business owner connects a third-party account (like Google Calendar) to DayO Book, that connection is covered specifically in Google user data below, in addition to everything else in this policy.
When someone books an appointment through a business's DayO Book widget, we collect the name, email, phone number (if provided), and appointment details they enter. This data is collected on behalf of, and controlled by, the business the customer booked with — DayO Book acts as their service provider for this data, not an independent owner of it.
A customer with a DayO Book account can keep a profile of their own, such as their pets' names, breeds, birthdays, and vaccine dates, and choose to share it with a business when they book. For this profile the customer is in control. We store it on their behalf, and no business can see it unless the customer ticks the consent box for that business at booking. When they do, we save a copy of the details they chose with that business, and the business then handles that copy like its other customer records. Private notes are never shared. A customer can edit or delete their profile at any time in their account, and can stop sharing with a business at any time. Stopping, or deleting the profile, ends any future copies and erases the profile from DayO Book, but a copy a business already received stays with that business.
We collect standard technical data when you use our site or product — pages visited, general device/browser information, and product usage events (e.g., which booking-widget steps a visitor completes) — to keep the service running and understand how it's used. See Cookies & analytics for the specific tools involved.
If you use the DayO Book mobile app, we store a push-notification token for your device so we can notify you when something happens in your business, such as a new booking. A notification can include the guest's name and the service booked. We use the token only to deliver those notifications. The app also keeps your sign-in session in your device's secure storage so you stay signed in until you sign out. You can turn notifications off at any time in your phone's settings, or by signing out of the app, which removes your device's token from our systems. The mobile app does not use advertising or third-party analytics tools. If you enable notifications in your web browser, we similarly store that browser's notification subscription.
DayO Book offers two optional integrations with Google, each requiring you to explicitly connect your own Google account through Google's own consent screen. Neither is required to use DayO Book.
A business owner can connect their Google Calendar in Settings → Integrations to enable two-way sync: bookings made in DayO Book are created as events on the connected calendar, and busy times on that calendar are pulled in (via Google's FreeBusy API) to block matching availability in DayO Book. We access only the connected calendar's event data and free/busy status — nothing else in the connected Google account.
DayO Book's own team can optionally connect a Gmail account, for the sole purpose of sending outreach email as themselves from within our internal tools. This uses Google's send-only Gmail scope — it can send a message on the connected user's behalf, and cannot read, search, or otherwise access anything already in that mailbox.
DayO Book's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We retain account and booking data for as long as an account is active, plus a reasonable period afterward for legal, tax, and billing recordkeeping. A business owner can delete a business entirely from Settings, which removes that business's data including its booking history. Disconnecting a Google integration immediately removes the associated tokens and cached calendar data. To request deletion of your account or data beyond what self-service tools provide, contact us using the details below.
Passwords are stored as one-way salted hashes, never in plaintext. Data is encrypted in transit (HTTPS/TLS) throughout the product. Access to production data is limited to what's needed to operate the service. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below and we'll respond within a reasonable time.
DayO Book is intended for business use and is not directed at children. We don't knowingly collect personal data from children under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us with personal data, contact us and we'll remove it.
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above; continued use of DayO Book after a change constitutes acceptance of the updated policy.
Questions about this policy, or a data request? Email privacy@dayobook.com.