Privacy notice

Last updated 25 September 2026

This notice explains what BookBase stores, why we store it, and how to have it removed. It is written in plain English on purpose.

Two different people are covered here. A seller is a business that signs up and publishes a booking page. A client is someone who sends that seller a booking request. If you filled in a booking form, you are a client, and the seller you contacted is the person who decides what happens with your booking.

1.Who we are

BookBase is run from Lahore, Pakistan. It gives independent sellers a booking page and a place to keep track of their bookings. We are not a party to any booking, and we never take payment for one.

2.What we store about a seller

  • Your name, phone number and email address.
  • Your page: business name, link, tagline, bio, city and service area, logo and cover photo, opening advance policy, and the payment details you type in for your own clients to see.
  • Your services and prices, portfolio photos, reviews and FAQs, and the update you post at the top of your page, with the day it comes down.
  • The WhatsApp message templates you write, and the other sellers you choose to recommend.
  • Which plan you are on and when it was activated.

3.What we store about a client

A booking record holds what a client sent, and what the seller wrote down about the booking:

  • Name and phone number.
  • Event date, occasion, area or address text, and anything typed into the note field.
  • The price and the advance amount the seller recorded, and the history of every status change on the booking.
  • If she arrived through one of the seller's own links, such as the seller's WhatsApp auto-reply or Instagram bio link, which one it was.
  • If the seller uses the optional Deal Room, the messages and quotes in that conversation, and the event details given when it was opened.
  • If she writes a review when the seller asks for one, the name she gives, her rating and her words. The seller's page can show these publicly.

4.A client's event, and signing in

When a seller confirms a booking, we open a private record for the client's event. It holds the date and a copy of the phone number on the booking, so that only she can claim it later. It is never shown to anyone.

A client can sign in with her email address to keep track of her event and the sellers booked for it. We then store that email address, the name she gives, her event's title, and the sellers she adds to it: from a booking, or by typing a seller's name, with a phone number and how far she has got with them (contacted, booked, advance paid) if she adds them.

5.What we do with it

We store it so the seller can run her business. We do not sell it, rent it, share it for advertising, or use it to market anything to anyone. We do not build a profile of a client across different sellers.

6.What we never store

  • No card numbers, bank account credentials or wallet credentials. There is no payment gateway in the product, so there is nowhere for them to go.
  • No payment screenshots. Clients cannot upload files at all — the only uploads in the product are a seller's own logo, cover photo and portfolio images.
  • No third-party analytics or advertising product, and no tracking scripts from anyone else. What we count ourselves is described under What we count on a seller's page and Free tools below.

7.What we count on a seller's page

So a seller can see whether her page is working, we count a few things on it. They are daily totals for her page, not a record of who did what.

  • How many times her page was opened each day.
  • When a visitor arrived through one of the links we gave the seller (her auto-replies, her Instagram bio link, her story link): the opens through each link, and the taps on her WhatsApp button that followed.
  • So one visit is counted once, the visitor's browser remembers, for that visit only, that the page was counted and which link she came by. This lives in the browser's session storage, which is cleared when the tab is closed. It is not a cookie.
  • To stop spam and inflated counts, our server keeps a scrambled form of the visitor's internet address: a one-way hash mixed with a secret, never the address itself. It is deleted after 7 days.

8.Free tools

The quote generator needs no account, and nothing you type into it is sent to us. The quote you are writing and the rates you save stay in your own browser, on the device you are using, and clearing your browsing data removes them.

We do count how the tool is used, so we can tell whether it is worth keeping. Those counts are deliberately thin.

  • What we record: a random installation id your browser creates for itself, which step happened (opened, quote composed, message copied, message shared, rate saved, rate inserted), how many lines a quote had, and when.
  • What we never record: your business name, a client's name, a date, a note, a line description, any amount, any total, or any phone number. There is nowhere in that table to put them.
  • The installation id is not linked to an account, an email address or any other device, and clearing your browsing data replaces it with a new one.

9.Where a client's phone number does not appear

A client's phone number is never shown on a public seller page, never part of a page address, never included in a link preview shared on WhatsApp, and never written to our server logs. It is visible to the seller she contacted, including in the email that tells the seller about a new request, and to us when we are helping that seller or looking into a fault.

10.When we help a seller

To set up a seller's page or fix a problem for her, we can open her dashboard as her. Anything we do there is saved as if she had done it. Each of those visits is recorded, with when it started and when it ended, and that record is how we can tell our changes from hers.

11.Cookies

We use cookies only for these. There are no advertising or tracking cookies.

  • To keep a signed-in seller, or a signed-in client, signed in.
  • To remember the language you chose, on any page where you choose one.
  • For sellers: to remember whether she has collapsed her sidebar, and which of her auto-replies she has marked as set up.
  • While we are helping a seller from inside her dashboard, to mark that visit.

12.The private conversation link

If a seller uses the Deal Room, her client is given a private web address for that conversation. That address is the key to it: anyone who has the link can open the conversation and read it. Treat it like a password — do not post it publicly. If it is shared by mistake, tell us and we will retire it.

13.Where the information is kept

Our database is hosted by Supabase and the website by Vercel, both on infrastructure outside Pakistan. We use Sentry to find faults: it receives a report when something breaks, and timings for a sample of page loads. Phone numbers, email addresses and private conversation links are stripped out of both before they are sent.

Emails are sent through Resend, for the alerts a seller gets about her bookings and the sign-in links we send sellers, and through Supabase, for the sign-in links clients ask for. An alert about a new request carries what the client sent, because the seller needs it to reply.

14.How long we keep it

A seller's bookings, client list, reviews and messages are never deleted automatically, because that record is the point of the product. They stay for as long as her account exists. The daily totals under What we count stay with them, as part of her page's history.

Some working records are cleared on a schedule: the scrambled internet addresses after 7 days, the record of which alert emails were sent after 90 days, and the quote tool's usage counts after 180 days. If you want something removed sooner, ask.

15.Getting a copy, or having it deleted

  • Sellers: use Request account deletion in Settings. Your page goes offline immediately and the request is recorded the moment you make it. The removal itself is done by hand, normally within 7 days, and you can cancel it from the same screen until it is carried out.
  • Clients: the seller you contacted holds your booking, so ask her first — she can delete a booking or your client record herself. If you cannot reach her, or you signed in and want your account removed, contact us and we will act on it.
  • Either way, ask us and we will send you a copy of the information we hold about you.

16.Children

This is a product for businesses. It is not intended for anyone under 18.

17.Changes to this notice

If this notice changes, the date at the top changes with it. We email sellers about anything material.

To reach us about anything on this page, use the contact details on the seller page you came from, or reply to any email we have sent you.