Bookings that BookingsXP never keeps
Turn on zero data retention (ZDR mode) and BookingsXP stores no bookings and no per-visit data. Each booking passes through in memory on its way to Microsoft Bookings, which keeps it in your own Microsoft 365 tenant. Your reports run on daily counts.
One switch per workspace, on every plan including Free. Off by default.
1.
The visitor's browser
The visitor picks a time and types their details in your widget or hosted page.
2.
BookingsXP, in memory
The details reach BookingsXP over HTTPS, are used to create the booking, and are then discarded.
3.
Microsoft Bookings
The booking is created in your Microsoft Bookings, in your own Microsoft 365 tenant. BookingsXP keeps no copy.
Alongside this, your GA4, Tag Manager, Google Ads, Meta and LinkedIn tags fire in the visitor’s browser and report straight to your own accounts.
What changes when ZDR is on
| Data | ZDR off (default) | ZDR on |
|---|---|---|
| Name, email, phone, notes and answers | Not stored, unless Store bookings is on for that booking page | Never stored. Held in memory to create the booking in Microsoft Bookings, then discarded |
| Store bookings | A per-page switch, off by default | Turned off on every booking page, and stays off while ZDR is on |
| Funnel analytics | Anonymous per-visit events: step, time, page, source, campaign, device, country, time zone, appointment time and a random per-visit ID | Daily counts per booking page only. No per-visit ID, country, time zone or appointment time |
| Ad click IDs | Kept with a stored booking when Store bookings is on | Not kept. Which click ID was present still goes into the booking notes in Microsoft Bookings |
| IP addresses | Never stored | Never stored |
| Webhooks, Slack and Teams alerts | Pro and above, for pages with Store bookings on | Paused |
| Bookings list, CSV export, erase by email | Available for stored bookings | Paused. There are no bookings to list, export or erase |
| Bookings in the REST API | Business and above | Paused |
While ZDR is on, saved booking pages in the workspace tell visitors: “BookingsXP keeps no copy of your details.”
What still works
- The widget and hosted pages
- Every template and style setting, inline, popup and floating-button embeds on any site, and your bookingsxp.com/book page.
- Conversion tracking
- Tag Manager dataLayer events, GA4 events, and Google Ads, Meta and LinkedIn conversions. They fire in the visitor's browser and go straight to your own accounts; BookingsXP does not store them.
- Source in the booking notes
- UTM tags and which ad click ID was present are still written into the booking notes inside Microsoft Bookings, so your team sees where each booking came from.
- Thank-you page and add to calendar
- Redirects to your own confirmation page and the .ics download work as before.
- The analytics dashboard
- Views, bookings, conversion rate, missed demand and the funnel, counted from daily totals. Channel, source and medium, campaign, page, device and service reports work the same way on the plans that include them.
- Daily booking caps
- A booking page still stops offering a day once it has taken the number of bookings you set.
What pauses, and why
- Webhooks
- booking.created carries the visitor's name, email and answers. Sending it would mean BookingsXP holding them, so no webhooks are sent.
- Slack and Microsoft Teams alerts
- Each alert names who booked and when, so alerts pause with webhooks.
- Bookings list and CSV export
- The list in the dashboard and the booking CSV show stored bookings. With ZDR on there are none.
- Erase by email
- Nothing about a visitor is held in BookingsXP, so there is nothing to erase. Handle requests about the appointment itself in Microsoft Bookings.
- Bookings in the REST API
- The API has no stored bookings to return.
- Per-visit reports
- The appointment-time heatmap and average lead time need each visit's appointment time, so they are hidden. The funnel is built from counts instead of sessions.
How a booking moves with ZDR on
- 01
The details pass through
When the visitor books, their name, email, phone, notes and answers go to BookingsXP's server. They are kept in memory only, for as long as it takes to create the booking through your public Bookings page, and then discarded. Nothing about the visitor is written to the BookingsXP database.
- 02
Microsoft Bookings keeps the booking
The appointment is created in your Microsoft Bookings, in your own Microsoft 365 tenant. Microsoft sends the confirmation and reminders and puts the meeting in Outlook and Teams, exactly as it does without ZDR.
- 03
Your tags report to your accounts
GA4, Tag Manager, Google Ads, Meta and LinkedIn events fire in the visitor's browser and go directly to your own accounts. BookingsXP does not store them.
- 04
BookingsXP adds one to a daily count
For your reports, BookingsXP adds the visit to that day's totals for the booking page: which step it reached, its channel, source and medium, campaign, page, device type and service. The total keeps nothing about the individual visit.
What BookingsXP still stores
- Your account and team
- The users in your workspace, their roles and sign-in sessions.
- Booking page settings
- Your public Bookings link, template, styling, tracking IDs, allowed websites and the logos and photos you upload.
- Billing
- Your plan and subscription status.
- Daily counts per booking page
- The number of visits that reached each step (viewed, picked a day, picked a time, started details, booked, failed, no availability), split by channel, source and medium, campaign, page on your site, device type and service. Kept for your plan's analytics history: 30 days on Free, 12 months on Pro, 24 months on Business, custom on Enterprise.
- Rate-limit counters
- On every workspace, booking requests are rate limited on a salted hash of the visitor's IP address that changes daily. Old counters are deleted every day.
Turning it on, and off
- Where and who
- Dashboard → Settings → Privacy → Zero data retention. One switch for the whole workspace; only workspace admins and owners can change it.
- What happens at once
- BookingsXP deletes every booking it stored for the workspace and all webhook delivery logs, turns Store bookings off on every booking page, and rolls existing funnel events up into daily counts before deleting the events.
- It cannot be undone
- Before anything is deleted, the dashboard asks you to confirm and shows what will go. Deleted data cannot be restored. Appointments in Microsoft Bookings are not touched.
- Turning it off
- From then on BookingsXP records per-visit funnel events again, and admins can turn Store bookings back on. Nothing deleted earlier comes back.
Questions about zero data retention
Let Microsoft Bookings keep the booking
Start free and turn on zero data retention in Settings → Privacy whenever you are ready. It is on every plan.
No Microsoft sign-in or admin consent. Free plan, no card.