Skip to content
bookling

Privacy notice

Last updated: 3 September 2026.

This notice covers two things: the bookling.co website, and the hosted bookling service that runs booking pages and the embeddable booking widget.

Who is responsible

Growth Path Agency S.R.L. ("Growth Path", "we", "us") operates bookling and is the controller of personal data processed through this website.

Registered office: Str. Drumul Putnei nr. 38-42, Et. 4, Ap. 33, Sector 3, Bucuresti, Romania. Trade Registry: J2025042918007. Unique Registration Code (CUI): RO51980049.

Contact: hello@bookling.co.

Two different roles. For this website we are the controller. For a booking made through a customer's bookling workspace, that customer is the controller of the booking and we are their processor: they decide what to ask for and what to do with it, and we handle it on their instructions under a data processing agreement. Where the booking is made on our own workspace, we are the controller of it.

What we collect on this website

Hosting logs. Our hosting provider records technical metadata when you load a page: IP address, user-agent string, timestamps and response status. These help us investigate errors and detect abuse.

Aggregate site analytics. We count page views with Umami, which we host ourselves on our own hardware. It sets no cookies and stores nothing on your device. It counts unique visitors with a salted hash of IP plus user-agent; the salt rotates monthly, so the identifier changes every month and is specific to this site. It cannot follow you anywhere else, and because we host it, no third party receives this data.

The waitlist form. When you ask for an invitation we collect the email address you type and the fact that you ticked the box. Vercel BotID invisibly checks that the submission came from a real browser. The address goes to our own email platform, which we host, and it sends you one message asking you to confirm. Nothing is added to any list until you click the link in it, and if you never do, the pending record is all that ever existed. Every message we send afterwards carries an unsubscribe link.

This site sets no cookies. It loads three scripts, all from this domain: the analytics one above, the one that submits the waitlist form without reloading the page, and the booking widget on the homepage.

The demo booking. The widget on the homepage is the real product, not a picture of it. Booking a time there is an ordinary booking in our own workspace, so what happens to what you type is the section below rather than this one, and you get a real meeting in your calendar. Availability is read from our servers at cal.bookling.co; nothing about you is sent until you submit the booking.

What the booking service collects

From the person booking. The name and email address they type, the answer to the one optional question a workspace may ask, the time they picked and the timezone their browser reported. If they arrive through a link carrying campaign parameters, those are stored with the booking.

Why. To create the calendar event, to put the guest on it, to send the confirmation that carries their reschedule and cancellation link, and to let them use that link later. A workspace may also have connected its own CRM, in which case the booking is pushed there on the workspace owner's instructions.

The latest meeting data bookling has received. The original person who booked, their answers and the campaign information above remain booking history. They are kept separate from the latest calendar attendee list, so adding or removing a guest in Google does not rewrite who made the booking.

From the workspace owner. Their name and email address, the Google account they connected, and an encrypted refresh token for it. Credentials for any integration they add are encrypted before they are stored.

Google Calendar data

Connecting a Google account is what makes bookling work, so here is exactly what the consent screen asks for and what we do with each one. Five permissions, and no others:

calendar.events.owned: permission to see and change events on the calendars the account owns. bookling uses it to create, update and cancel the events it made for a booking. It does not read the events on those calendars for any other purpose, and Google offers no narrower write permission than this one.

calendar.events.freebusy: to read busy and free intervals so a time that is already taken is not offered. This returns time ranges, not event titles, guests or descriptions.

calendar.calendarlist.readonly: to list the calendars on the account so the owner can choose which ones to check for conflicts and which one to write bookings to.

openid and email: to know which Google account was just connected, so the workspace shows the owner which account their calendar comes from and a second grant replaces the right connection rather than adding a duplicate. We do not request the profile permission, so no name or picture is read.

bookling holds free/busy results in memory for up to sixty seconds, so opening the same page twice does not make the same call twice. Separately, it stores the latest versioned organizer-event state it has received only when that event is already linked to a bookling booking. That copy contains the event identity and version, title, description, exact time and timezone, Busy or Free setting, attendees and their responses, guest permissions, organizer, current calendar, location, conference details and lifecycle state. It is the bounded record bookling uses when handling that meeting.

bookling does not build a copy of the connected calendar. Unrelated calendar events are discarded without being stored or logged, including their titles, descriptions and guest lists. The stored organizer-event copy contains normalized meeting fields rather than the raw response from Google.

Limited Use. bookling's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising, and we do not use it to train generalised models. Humans do not read it, except with the account owner's explicit permission to debug a specific problem, or where the law requires it.

An account owner can disconnect at any time from their bookling settings, or revoke our access from their Google account permissions page. Revoking stops all calendar access and further updates immediately; existing events stay in their calendar, because they are theirs. The latest organizer-event copy already attached to a retained booking stays with that booking under the retention rule below.

Legal bases

Hosting logs run on Art. 6(1)(f) GDPR: our legitimate interest in operating a working, abuse-free site. Processing a booking runs on Art. 6(1)(b): steps taken at the request of the person booking, so the meeting they asked for can happen. The waitlist runs on Art. 6(1)(a), the consent you give by ticking the box and confirming through the link we email you, withdrawable at any time through the unsubscribe link in any message or the contact address above. Where we act as a processor for a customer workspace, the legal basis is the one that customer relies on.

Processors and recipients

A short list, and each of them runs part of the service:

Vercel Inc.: hosting for this website and its logs. DPA

Railway Corporation: hosting for the booking service and its database, and for the email platform behind the waitlist, deployed in Amsterdam. Railway also operates in the US. DPA

Amazon Web Services EMEA SARL: delivery of confirmation and cancellation email through Amazon SES in Ireland. GDPR Center

Google Ireland Limited: the calendar a booking is written to, when the workspace owner has connected one. Privacy policy

Cloudflare, Inc.: authoritative DNS. DPA

Sentry (Functional Software, Inc.): server-side error reports. Paths that carry a booking's management token are scrubbed before a report leaves the server. DPA

A workspace owner may connect their own CRM or email provider, in which case bookings in that workspace also reach the provider they chose, on their instructions.

International transfers

Railway and Sentry have primary operations in the US. Those transfers are covered by Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Vercel, Cloudflare, AWS and Google may also process operational data outside the EEA under the clauses in their own agreements. You can ask us for a copy of the relevant safeguards.

Retention

We keep a booking, including its current organizer-event copy, while the workspace it belongs to needs it. The person who booked can cancel from the link in their confirmation email, which removes the calendar event; the cancelled record itself is kept so that link cannot be replayed. On our own workspace we delete booking records and their organizer-event copies within 36 months of the meeting. A waitlist address is kept until you unsubscribe or until it is no longer needed, after which we keep a minimal suppression record so your choice is not silently reversed. An address that never confirms is deleted with the rest of the pending records. Hosting logs are short-lived operational data, error reports expire on the provider's default schedule, and analytics aggregates are deleted after 24 months.

Your rights

You can request access, rectification, erasure, restriction or portability, and you can object to processing based on legitimate interest. Email hello@bookling.co and we respond within 30 days (Art. 12(3) GDPR). If your booking was made through someone else's bookling workspace, they are the controller: we will pass your request to them and help them answer it.

You can also complain to the Romanian supervisory authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucuresti, Romania.

Cookies

This site stores nothing non-essential on your device, so no consent banner is required (Art. 5(3) of Directive 2002/58/EC, transposed by Legea 506/2004). Nothing here is analytics-for-advertising, and nothing is shared with anyone. BotID may keep short-lived first-party state on your device while you submit the waitlist form; that is spam defence for a thing you asked to do, not tracking.

The booking widget stores nothing while somebody books. Opening the manage link from a confirmation email is the one exception: the server exchanges the token in that link for a session cookie and redirects, so the address bar and the browser history stop carrying a token that would still work. That cookie is HttpOnly, so no script can read it; it expires when the browser closes; and it is scoped to the manage page, so it never rides along with anything else. It is strictly necessary for the page the visitor asked for, which is the Art. 5(3) exemption, and it does nothing else.

Other things worth knowing

We have not appointed a Data Protection Officer; our processing does not meet the thresholds in Art. 37 GDPR or Law 190/2018. We do not process special-category data, we do not sell personal data, and we do not knowingly collect data from anyone under 16. When this notice changes we update this page and the date at the top.

Back to the homepage

© 2026 Growth Path Agency S.R.L.

PrivacyTermshello@bookling.co