Bookings that BookingsXP never keeps

Turn on zero data retention (ZDR mode) and BookingsXP stores no bookings and no per-visit data. Each booking passes through in memory on its way to Microsoft Bookings, which keeps it in your own Microsoft 365 tenant. Your reports run on daily counts.

One switch per workspace, on every plan including Free. Off by default.

  1. 1.

    The visitor's browser

    The visitor picks a time and types their details in your widget or hosted page.

  2. 2.

    BookingsXP, in memory

    The details reach BookingsXP over HTTPS, are used to create the booking, and are then discarded.

  3. 3.

    Microsoft Bookings

    The booking is created in your Microsoft Bookings, in your own Microsoft 365 tenant. BookingsXP keeps no copy.

Alongside this, your GA4, Tag Manager, Google Ads, Meta and LinkedIn tags fire in the visitor’s browser and report straight to your own accounts.

Illustrative. BookingsXP is independent and not affiliated with or endorsed by Microsoft.

What changes when ZDR is on

ZDR is a workspace setting in Settings → Privacy. It applies to every booking page in the workspace at once.
What BookingsXP keeps with zero data retention off and on
DataZDR off (default)ZDR on
Name, email, phone, notes and answersNot stored, unless Store bookings is on for that booking pageNever stored. Held in memory to create the booking in Microsoft Bookings, then discarded
Store bookingsA per-page switch, off by defaultTurned off on every booking page, and stays off while ZDR is on
Funnel analyticsAnonymous per-visit events: step, time, page, source, campaign, device, country, time zone, appointment time and a random per-visit IDDaily counts per booking page only. No per-visit ID, country, time zone or appointment time
Ad click IDsKept with a stored booking when Store bookings is onNot kept. Which click ID was present still goes into the booking notes in Microsoft Bookings
IP addressesNever storedNever stored
Webhooks, Slack and Teams alertsPro and above, for pages with Store bookings onPaused
Bookings list, CSV export, erase by emailAvailable for stored bookingsPaused. There are no bookings to list, export or erase
Bookings in the REST APIBusiness and abovePaused

While ZDR is on, saved booking pages in the workspace tell visitors: “BookingsXP keeps no copy of your details.”

What still works

Everything that runs in the visitor's browser or inside Microsoft Bookings carries on as before.
The widget and hosted pages
Every template and style setting, inline, popup and floating-button embeds on any site, and your bookingsxp.com/book page.
Conversion tracking
Tag Manager dataLayer events, GA4 events, and Google Ads, Meta and LinkedIn conversions. They fire in the visitor's browser and go straight to your own accounts; BookingsXP does not store them.
Source in the booking notes
UTM tags and which ad click ID was present are still written into the booking notes inside Microsoft Bookings, so your team sees where each booking came from.
Thank-you page and add to calendar
Redirects to your own confirmation page and the .ics download work as before.
The analytics dashboard
Views, bookings, conversion rate, missed demand and the funnel, counted from daily totals. Channel, source and medium, campaign, page, device and service reports work the same way on the plans that include them.
Daily booking caps
A booking page still stops offering a day once it has taken the number of bookings you set.

What pauses, and why

These features need a copy of the visitor's details or of each visit, so they pause while ZDR is on. Webhooks and alerts need Store bookings, so after turning ZDR off, switch Store bookings back on for the pages that need them. More in Webhooks and data.
Webhooks
booking.created carries the visitor's name, email and answers. Sending it would mean BookingsXP holding them, so no webhooks are sent.
Slack and Microsoft Teams alerts
Each alert names who booked and when, so alerts pause with webhooks.
Bookings list and CSV export
The list in the dashboard and the booking CSV show stored bookings. With ZDR on there are none.
Erase by email
Nothing about a visitor is held in BookingsXP, so there is nothing to erase. Handle requests about the appointment itself in Microsoft Bookings.
Bookings in the REST API
The API has no stored bookings to return.
Per-visit reports
The appointment-time heatmap and average lead time need each visit's appointment time, so they are hidden. The funnel is built from counts instead of sessions.

How a booking moves with ZDR on

The visitor's details travel from their browser, through BookingsXP's memory, to Microsoft Bookings. BookingsXP is independent of Microsoft and needs no access to your Microsoft 365 tenant.
  1. 01

    The details pass through

    When the visitor books, their name, email, phone, notes and answers go to BookingsXP's server. They are kept in memory only, for as long as it takes to create the booking through your public Bookings page, and then discarded. Nothing about the visitor is written to the BookingsXP database.

  2. 02

    Microsoft Bookings keeps the booking

    The appointment is created in your Microsoft Bookings, in your own Microsoft 365 tenant. Microsoft sends the confirmation and reminders and puts the meeting in Outlook and Teams, exactly as it does without ZDR.

  3. 03

    Your tags report to your accounts

    GA4, Tag Manager, Google Ads, Meta and LinkedIn events fire in the visitor's browser and go directly to your own accounts. BookingsXP does not store them.

  4. 04

    BookingsXP adds one to a daily count

    For your reports, BookingsXP adds the visit to that day's totals for the booking page: which step it reached, its channel, source and medium, campaign, page, device type and service. The total keeps nothing about the individual visit.

What BookingsXP still stores

Your own account data, and counts that say nothing about any one visitor. The full list for every workspace is on Security and data.
Your account and team
The users in your workspace, their roles and sign-in sessions.
Booking page settings
Your public Bookings link, template, styling, tracking IDs, allowed websites and the logos and photos you upload.
Billing
Your plan and subscription status.
Daily counts per booking page
The number of visits that reached each step (viewed, picked a day, picked a time, started details, booked, failed, no availability), split by channel, source and medium, campaign, page on your site, device type and service. Kept for your plan's analytics history: 30 days on Free, 12 months on Pro, 24 months on Business, custom on Enterprise.
Rate-limit counters
On every workspace, booking requests are rate limited on a salted hash of the visitor's IP address that changes daily. Old counters are deleted every day.

Turning it on, and off

Turning ZDR on deletes data straight away. Read the steps in the zero data retention docs before you switch.
Where and who
Dashboard → Settings → Privacy → Zero data retention. One switch for the whole workspace; only workspace admins and owners can change it.
What happens at once
BookingsXP deletes every booking it stored for the workspace and all webhook delivery logs, turns Store bookings off on every booking page, and rolls existing funnel events up into daily counts before deleting the events.
It cannot be undone
Before anything is deleted, the dashboard asks you to confirm and shows what will go. Deleted data cannot be restored. Appointments in Microsoft Bookings are not touched.
Turning it off
From then on BookingsXP records per-visit funnel events again, and admins can turn Store bookings back on. Nothing deleted earlier comes back.

Questions about zero data retention

Let Microsoft Bookings keep the booking

Start free and turn on zero data retention in Settings → Privacy whenever you are ready. It is on every plan.

No Microsoft sign-in or admin consent. Free plan, no card.