Data & API
Zero data retention
Turn on zero data retention so BookingsXP stores no bookings or per-visit data. What it deletes, what pauses, what keeps working and how to turn it off.
Zero data retention (ZDR mode) is one of two privacy modes, next to Full insights. It is a workspace setting that makes BookingsXP keep no bookings and no per-visit data. Each booking passes through BookingsXP in memory on its way to Microsoft Bookings, and your analytics are kept as daily counts. It is on every plan, including Free, and it is off by default.
What ZDR does#
With ZDR on:
-
Bookings are never stored by BookingsXP. The visitor's name, email, phone, notes and answers reach BookingsXP's server, are held in memory only to create the booking in Microsoft Bookings, and are then discarded. The appointment is kept in your Microsoft Bookings, in your own Microsoft 365 tenant.
-
No per-visit data is stored. Funnel analytics are kept only as daily counts per booking page, split by:
- step: viewed, picked a day, picked a time, started details, booked, failed, no availability,
- channel, source and medium, and campaign,
- the page on your site,
- device type (mobile, tablet or desktop),
- service.
The counts hold no session IDs, IP addresses, countries, visitor time zones, appointment times, ad click IDs or anything else about an individual visitor. They are kept for your plan's analytics history: 30 days on Free, 12 months on Pro, 24 months on Business, and as agreed on Enterprise.
-
Saved booking pages tell visitors. Booking pages saved in the workspace show one short line in the booking form: "BookingsXP keeps no copy of your details."
Turn it on#
- In the dashboard, open Settings → Privacy.
- Find Zero data retention and turn it on. Only workspace admins and owners can change it.
- Read the confirmation. It lists what will be deleted for this workspace.
- Confirm.
What happens straight away#
When you confirm, BookingsXP:
- deletes every booking stored in BookingsXP for the workspace,
- deletes all webhook delivery logs,
- turns Store bookings off on every booking page,
- rolls the existing funnel events up into the same daily counts, then deletes the events.
This cannot be undone. Deleted bookings, delivery logs and events cannot be restored. Nothing in Microsoft Bookings is changed: appointments stay where they are.
If you need a copy of your stored bookings, export the booking CSV (Pro and above) before you turn ZDR on.
What pauses#
These features need a copy of the visitor's details, or of each visit, so they pause while ZDR is on:
| Feature | With ZDR on |
|---|---|
| Webhooks | Not sent |
| Slack and Microsoft Teams alerts | Not sent |
| Bookings list in the dashboard | Paused: no bookings are stored |
| Booking CSV export | Paused |
| Erase by email | Paused: there is nothing to erase |
| Bookings in the REST API | Paused |
| Appointment-time heatmap and average lead time | Hidden: they need each visit's appointment time |
| Booking funnel | Built from daily counts instead of individual visits |
For requests about a visitor's appointment, use Microsoft Bookings or Outlook as you do today.
What keeps working#
- The widget and hosted booking pages, every template and style setting, and embeds on any site.
- Tag Manager dataLayer events, GA4 events, and Google Ads, Meta and LinkedIn conversions. These fire in the visitor's browser and go straight to your own accounts; BookingsXP does not store them. See GTM, GA4 and ad conversions.
- UTM and click-ID attribution written into the booking notes inside Microsoft Bookings.
- Thank-you page redirects and add to calendar.
- The analytics dashboard, from daily counts.
- Daily booking caps.
What BookingsXP still stores#
Your own account data and the daily counts above:
- users, team members and the workspace,
- booking page settings, including your Bookings link, template, styling and tracking IDs, and the logos and photos you upload,
- billing records.
On every workspace, booking requests are rate limited on a salted hash of the visitor's IP address that changes daily. Old counters are deleted every day.
Turn it off#
Workspace admins and owners can choose Full insights in Settings → Privacy. From then on:
- BookingsXP records per-visit funnel events again,
- Store bookings is on for every booking page that follows the workspace defaults, so new bookings are stored again and webhooks, alerts, the Bookings list and booking CSV work on the plans that include them. Pages with their own privacy setting keep it.
Nothing that was deleted when ZDR was turned on comes back.
Your privacy notice#
ZDR reduces what BookingsXP holds about your visitors, which can help with data-minimisation obligations. It does not by itself make your business compliant with any law; you stay the controller of your visitors' data. Tags you add to your own page, such as Google Ads with enhanced conversions, still send their data from the visitor's browser to your own accounts, so describe them in your privacy notice as usual.
Related#
- Zero data retention for an overview.
- Privacy & data for what BookingsXP reads, stores and sends with ZDR off.
- Security & data and the privacy policy.
BookingsXP is independent and not affiliated with or endorsed by Microsoft.
Edit or question? hello@bookingsxp.com