Privacy Policy

Last Updated: May 29, 2026

Important: Your Consent

By creating an account and using DITA Booking, you explicitly consent to:

  • The collection and use of your personal information (name, email, phone number, address) as described in this policy
  • Sharing your contact information with service providers when you book appointments
  • Receiving appointment confirmations, reminders, and service-related communications via SMS and email
  • Processing of your payment information through our secure payment processor (Stripe)

You can withdraw your consent at any time by deleting your account through the app settings or contacting us at ditabookingsupport@datadita.com.

1. Information We Collect

We collect the following types of information:

Information You Provide Directly:

  • Account Information: Name, email address, phone number, and password (encrypted)
  • Business Information: Business name, category, address, service area, operating hours, and timezone (for service providers)
  • Appointment Details: Service type, date, time, customer information, and special requests
  • Payment Information: Processed securely through Stripe (we do not store full credit card numbers)
  • Communication Preferences: Email and SMS notification settings

Information Collected Automatically:

  • Usage Data: Pages visited, features used, time spent in the app
  • Device Information: Device type, operating system, browser type, IP address
  • Location Data: Approximate location based on IP address (not precise GPS location)

📅 When You Book an Appointment (Customer Data Collection)

If you are booking an appointment with a business using DITA Booking, here's exactly what information is collected and how it's used:

What We Collect When You Book:

  • Your Name: First and last name to identify your appointment
  • Phone Number: To send appointment confirmations, reminders, and allow the business to contact you
  • Email Address: To send booking confirmations and appointment details
  • Service Address (Optional): Street address, city, state, and ZIP code if the service is performed at your location
  • Special Instructions (Optional): Any notes or requests you provide about the service
  • Appointment Details: Service selected, date, time, and assigned staff member
  • Payment Information: If payment is required, processed securely through Stripe (we never see or store your full credit card number)

How Your Booking Data Is Used:

  • Shared with the Business: Your contact information and appointment details are shared with the business you're booking with so they can provide the service
  • Shared with Staff: The assigned staff member will see your name, contact info, service address, and appointment details
  • Appointment Reminders: We send SMS and email reminders 24 hours before your appointment (you consent to this when booking)
  • Booking Confirmations: Immediate confirmation sent via SMS and email with your appointment details and confirmation number
  • Service Updates: Notifications when staff is on the way, appointment status changes, or rescheduling
  • Stored in Database: Your information is stored securely in our database to maintain appointment records and enable rescheduling or cancellation

Your Consent When Booking:

When you book an appointment, you are explicitly asked to consent to:

  • SMS Notifications: Receiving transactional text messages (confirmations, reminders, updates)
  • Email Notifications: Receiving booking-related emails
  • Data Collection & Use: Collection and use of your personal information as described above

All three consents are required to complete a booking. You can opt out of future communications by replying STOP to SMS or clicking unsubscribe in emails.

Who Has Access to Your Booking Data:

  • The Business Owner: Full access to all your booking information
  • Assigned Staff Member: Access to your appointment details and contact info
  • DITA Booking Platform: We store and process your data to provide the booking service
  • Third-Party Services: Twilio (SMS), SendGrid (email), and Stripe (payments) process your data on our behalf

How to Manage Your Booking Data:

  • Cancel Appointment: Use the cancellation link in your confirmation email or contact the business directly
  • Reschedule: Contact the business or use the rescheduling link if provided
  • Request Data Deletion: Contact the business owner or email us at ditabookingsupport@datadita.com to request deletion of your booking data
  • Opt Out of Communications: Reply STOP to SMS or click unsubscribe in emails (note: this may prevent you from receiving important appointment updates)

3. How We Collect Your Information

  • Direct Input: When you create an account, book appointments, or update your profile
  • Automated Technologies: Through cookies and similar tracking technologies when you use our website or mobile app
  • Third-Party Services: From payment processors (Stripe) when you make payments
  • Business Partners: When service providers share customer information for appointment management

4. How We Use Your Information

We use your information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our appointment booking platform
  • Appointment Management: To process, confirm, and manage your appointments
  • Communications: To send appointment confirmations, reminders, and updates via email and SMS
  • Payment Processing: To process payments and prevent fraud
  • Customer Support: To respond to your inquiries and provide assistance
  • Analytics: To understand how users interact with our platform and improve user experience
  • Legal Compliance: To comply with legal obligations and enforce our terms of service
  • Marketing: To send promotional communications (only with your consent, and you can opt out anytime)

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist us:
    • Stripe (payment processing)
    • Twilio (SMS notifications)
    • SendGrid (email communications)
    • Neon Database (data storage)

    Third-Party Data Protection: All third-party service providers are contractually required to:

    • Maintain the same level of data protection as outlined in this policy
    • Use your data only for the specific services they provide to us
    • Implement appropriate security measures to protect your information
    • Comply with applicable data protection laws (GDPR, CCPA, etc.)
    • Notify us immediately of any data breaches
  • Business Partners: When you book an appointment, we share your contact information and appointment details with the service provider
  • Legal Requirements: When required by law, court order, or government regulation
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (users will be notified)
  • With Your Consent: When you explicitly authorize us to share your information

6. Data Security

We implement industry-standard security measures to protect your personal information:

  • Passwords are encrypted using Argon2 hashing algorithm
  • Data transmission is secured using SSL/TLS encryption
  • Payment information is processed through PCI-DSS compliant Stripe
  • Access to personal data is restricted to authorized personnel only
  • Regular security audits and updates

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Data Retention and Deletion

How Long We Keep Your Data:

  • Active Accounts: We retain your information for as long as your account is active
  • Appointment Records: Kept for 7 years for business and tax purposes
  • Payment Records: Retained as required by financial regulations (typically 7 years)
  • Marketing Data: Deleted within 30 days of opting out
  • Deleted Accounts: Personal data is permanently deleted within 30 days of account deletion request

How to Request Deletion: You can delete your account at any time through the mobile app (Account → Delete Account) or by contacting ditabookingsupport@datadita.com. Upon deletion, we will permanently remove your personal information, except where retention is required by law.

8. Your Privacy Rights

You have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Update or correct inaccurate information through your account settings
  • Deletion: Request deletion of your account and personal data (see Section 6)
  • Opt-Out: Unsubscribe from marketing emails (click "unsubscribe" in any email) or SMS (reply STOP)
  • Data Portability: Request your data in a machine-readable format
  • Revoke Consent: Withdraw consent for data processing at any time (may limit service functionality)
  • Object to Processing: Object to certain types of data processing

How to Exercise Your Rights: Contact us at ditabookingsupport@datadita.com or use the in-app account deletion feature. We will respond to your request within 30 days.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Keep you signed in
  • Remember your preferences
  • Understand how you use our platform
  • Improve platform performance

You can control cookies through your browser settings. Disabling cookies may limit some functionality.

10. Children's Privacy

Our services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at ditabookingsupport@datadita.com, and we will delete it.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this privacy policy.

12. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending an email notification to your registered email address
  • Displaying a prominent notice in the app

Your continued use of our services after changes are posted constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

  • Email: ditabookingsupport@datadita.com
  • In-App: Account → Help & Support

We will respond to your inquiry within 5 business days.

14. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell your information)
  • Right to non-discrimination for exercising your privacy rights

15. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including those listed in Section 7, plus:

  • Right to lodge a complaint with a supervisory authority
  • Right to restrict processing in certain circumstances
  • Legal basis for processing: consent, contract performance, legal obligation, or legitimate interests