Updated 2026-09-24
Privacy Policy
Last updated: 24 September 2026
About this policy
This policy explains how BookingsXP handles personal data: on the website at https://bookingsxp.com, in the BookingsXP dashboard, and in the booking widget that our customers embed on their own websites.
BookingsXP is a service registered in India. It works alongside Microsoft Bookings and is not affiliated with or endorsed by Microsoft.
If you have booked an appointment through a business's website and want to know what happened to your details, start with the section "If you booked through a BookingsXP widget" near the end of this page.
Who is responsible for what
Data protection law gives different responsibilities to a controller (who decides why and how data is used) and a processor (who handles data on a controller's instructions). BookingsXP plays both roles, for different data:
- BookingsXP is the controller for account data: the details you give us when you sign up, billing records, support conversations, and analytics about how people use
bookingsxp.com. - BookingsXP is a processor for the business that embeds the widget (our "customer") when it handles its visitors' data: anonymous widget analytics, and, if the customer switches on Store bookings, a copy of each booking.
- The customer is the controller for its visitors' data. It decides whether to store bookings, which tracking tools to connect, and how long to keep data within its plan.
- Microsoft is the customer's own provider for the booking itself. Every booking is created in the customer's Microsoft Bookings, under the customer's Microsoft 365 subscription and Microsoft's terms. BookingsXP has no access to the customer's Microsoft 365 tenant, mailboxes or calendars.
What we collect
When you use the website or the dashboard
- Forms you fill in: name, email, the topic and message on the support form, and your email if you subscribe to release notes.
- Product analytics: pages viewed and actions taken, measured with PostHog. Until you accept cookies, PostHog runs without cookies or stored identifiers. If you accept, it may use cookies and local storage and record sessions with form inputs masked. See the Cookie Policy.
- Attribution: if you accept cookies, the page you first landed on, the referring site and any campaign parameters, so we know which pages lead to sign-ups.
- Server logs: IP address, browser, requested page and time, kept by our hosting for security and troubleshooting.
When you have an account
- Account data: name, email, organisation name, team members and their roles, and sign-in sessions.
- Widget settings: your public Microsoft Bookings page link, template, styling, tracking IDs (for example your GA4 measurement ID or Google Ads conversion ID), allowed domains and other settings.
- Billing data: plan, subscription status and invoices. Payments are taken by Dodo Payments, which acts as merchant of record. We do not receive or store your full card number.
- Support and correspondence: what you send us and our replies.
- Audit records: security-relevant actions in your organisation, such as erasing bookings or creating API keys.
When a visitor uses a customer's widget (as processor)
- Anonymous funnel events, always: which step the visitor reached (for example, opened the widget, chose a service, picked a time, booked), the service, the page path and host, referring site, traffic source, medium and campaign, the type of ad click ID present (not the ID itself), device type, approximate country and time zone, and a random session identifier that lives only for that page visit. Funnel events contain no names, emails or IP addresses.
- The booking itself, in transit: when a visitor books, their name, email, phone, notes and answers pass through BookingsXP to create the booking in the customer's Microsoft Bookings, together with the campaign details and a
BXP-reference that the customer has chosen to write into the booking notes. With Store bookings off (the default), BookingsXP does not keep these details after the booking is made. - Stored bookings, only if the customer switches them on: the visitor's name, email, phone, notes, answers, the booking time and service, and attribution (landing page, referrer, UTM parameters, ad click IDs and the page where they booked).
- Webhook deliveries: if the customer adds webhook, Microsoft Teams or Slack endpoints, the payload sent and the delivery result, kept for 30 days so failed deliveries can be seen and retried.
- IP addresses: used only as a hash salted with the current day, to rate-limit booking requests. The raw IP address is not stored.
How the widget handles visitors' browsers
- The widget sets no cookies.
- To credit a booking to the ad or page that brought the visitor, it keeps the first touch (landing page, referrer and campaign parameters) in the visitor's own browser, in
localStorageunderbxp_attr, for 90 days. It usessessionStorageunderbxp_sto tell a new visit from a repeat one. - On the customer's page, it reads the Google Analytics and Meta cookies that the customer's own tags have already set (
_ga,_fbp,_fbc), so conversions can be matched in those tools. - If the customer turns on Google Ads enhanced conversions, the visitor's email is hashed with SHA-256 in the visitor's browser and handed to the customer's own Google tag. BookingsXP does not send it to Google.
- Global Privacy Control: if the visitor's browser sends Global Privacy Control, or the customer's site sets
window.bxpConsent = false, the widget stores nothing in the browser and attribution is reduced to the page and the referring site's origin. - BookingsXP's own marketing analytics (PostHog and any Google tag) are never loaded on embed or hosted booking pages.
Why we use data, and our legal bases
Where the EU or UK GDPR or similar laws apply, we rely on these legal bases for the data we control:
- To provide the service you signed up for (accounts, widgets, dashboard, billing, support): performance of our contract with you.
- To keep the service secure and working (logs, rate limiting, abuse prevention, audit records): our legitimate interest in running a secure service.
- To send service messages (sign-in links, receipts, important changes): performance of contract.
- To send release notes: your consent, which you can withdraw at any time.
- Marketing-site analytics with cookies: your consent through the cookie banner. Before you choose, we measure page use without cookies or stored identifiers, on the basis of our legitimate interest in understanding how the site is used. If you decline, that measurement stops.
- To meet legal obligations (tax, accounting, responding to lawful requests): legal obligation.
For data we process for customers, the customer determines the legal basis for its visitors' data, and we act only on its instructions as set out in our Terms of Service.
We do not sell personal data, and we do not use visitors' booking data to advertise BookingsXP or for any purpose of our own.
How long we keep data
- Stored bookings and widget analytics are deleted automatically when they are older than the customer's plan allows: Free 30 days, Pro 12 months, Business 24 months.
- Webhook delivery logs: 30 days.
- Account data: for as long as your account is open. When you close it, we delete or anonymise it within a reasonable period, except where we must keep records for tax, accounting or legal reasons.
- Support correspondence: as long as needed to help you and to keep a record of what we agreed.
- The first-touch record in a visitor's browser (
bxp_attr) expires after 90 days and can be cleared by the visitor at any time by clearing site data.
Who we share data with
We use a small number of subprocessors to run BookingsXP:
- Cloud hosting: Microsoft Azure. Runs the application, database and background jobs.
- Payments: Dodo Payments. Merchant of record for payments, tax and invoices.
- Transactional email: a transactional email provider. Sends sign-in links, receipts and account notices.
- Product analytics: PostHog. Measures how people use
bookingsxp.comand the dashboard. Never loaded in the widget or on booking pages.
We also share data:
- With tools the customer connects: when a customer connects Google Analytics, Google Ads, Meta, LinkedIn, webhooks, Microsoft Teams or Slack, the widget or our servers send events to those tools on the customer's behalf. Those tools are the customer's choice and run under the customer's accounts.
- With Microsoft, as part of creating the booking in the customer's Microsoft Bookings.
- When the law requires it, or to protect the rights, safety or property of our users or the public.
- If BookingsXP is sold or reorganised, with the new owner, who will be bound by this policy.
International transfers
BookingsXP is operated from India and hosted on Microsoft Azure. Our subprocessors may process data in other countries. Where data protection law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission's standard contractual clauses.
Security
All traffic to BookingsXP is encrypted in transit with HTTPS. API keys are stored only as a hash, webhook payloads are signed, and visitor IP addresses are never stored in raw form. More detail is on our Security page. No system is perfectly secure; if we become aware of a breach that affects your data, we will tell you without undue delay.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how we use it, and to withdraw consent at any time. You can also complain to your local data protection authority.
- For your account data, email hello@bookingsxp.com. We may need to confirm your identity first.
- For customers handling a visitor's request: admins can find and erase every stored booking for an email address from the dashboard (erase by email). Erasing in BookingsXP does not change the appointment in Microsoft Bookings, which the customer manages there.
If you booked through a BookingsXP widget
The business you booked with is responsible for your booking data, and your appointment is held in that business's Microsoft Bookings. Please contact that business to access, correct or delete your details. If you contact us instead, we will pass your request on to the business, because we act on its instructions.
To stop the widget keeping attribution in your browser, turn on Global Privacy Control in your browser, or clear the site data for the website you booked on.
Children
BookingsXP is a business service and is not directed at children. We do not knowingly collect personal data from children under 16 for our own purposes. Customers who take bookings for or about children are responsible for doing so lawfully.
Changes to this policy
We will update this page when our practices change and change the date at the top. If a change materially affects how we use personal data, we will tell account holders by email or in the dashboard before it takes effect.
Contact
Email: hello@bookingsxp.com
Postal address: BookingsXP, 9th Floor, Tower D, Unitech Cyber Park, Sector 39, Gurugram, Haryana 122001, India