Privacy Policy
Plain-language summary: Waypoint Booking runs inside your BigCommerce control panel and doesn't store your customers' names, emails, or phone numbers at all — booking records reference BigCommerce's own order/customer IDs, and any personal detail we ever display is fetched live from BigCommerce at the moment it's needed, never cached.
This document describes our actual technical data practices. It's written to be accurate to how the app works today, not boilerplate — but it isn't legal advice, and we'd recommend a lawyer review it against your own jurisdiction's requirements before you rely on it as your store's official policy.
1. Who this applies to
Two different people interact with Waypoint Booking, and this policy covers data about both:
- Merchants — the BigCommerce store owners and staff who install the app and use its dashboard.
- Shoppers — the merchant's own customers, who use the storefront booking widget to reserve a slot.
For shopper data, the merchant is the data controller and we act as a processor on their behalf — the same relationship as any other app a merchant installs on their store.
2. Information we collect
From the merchant
| Data | Why |
|---|---|
| Store hash & OAuth access token | Identifies your store and authorizes API calls on your behalf. The token is encrypted at rest (AES-256-GCM) — never stored in plain text. |
| Resources, services, availability rules | What you've configured as bookable — staff/rooms/equipment, offerings, opening hours. No personal data of yours or your customers'. |
| Dashboard settings | Hold duration, timezone default, widget layout, notification webhook URL — your own configuration choices. |
| Staff BigCommerce user ID | Recorded against your store so multiple staff logins can open the app; not a separate account of ours. |
From shoppers, via the storefront widget
| Data | Why |
|---|---|
| Booking time & resource | What slot was reserved — the core of what the app does. |
| BigCommerce order ID or customer ID | Links the booking back to a real BigCommerce order or account. We read the shopper's name/email/phone live from BigCommerce, at the moment it's genuinely needed (e.g. showing your bookings list, or sending your configured notification webhook) — it's never written to our database. |
| Hold session token | A random value issued when a slot is held mid-checkout, used only to prove that browser session owns that hold. Not personally identifying on its own. |
What we deliberately don't collect
- Shopper names, email addresses, or phone numbers at rest, in our database
- Payment or card details of any kind — checkout is handled entirely by BigCommerce
- Analytics, advertising identifiers, or third-party tracking pixels on the storefront widget
- Browsing history or behavior outside of the booking flow itself
3. How we use this information
- Operating the booking engine — checking availability, holding a slot, confirming it into a booking once an order is placed.
- Displaying your dashboard — the bookings list, calendar, and "Needs attention" panel.
- Sending the outbound notification webhook events you've configured (see below) — a booking confirmed, cancelled, or a reminder coming due.
- If you've connected Google or Microsoft calendar sync, keeping a mapped resource's external calendar in sync (pushed events contain only the service and resource name — never a shopper's name or email).
- Operating the app itself — Cloud Scheduler jobs that expire stale holds, retry failed webhook deliveries, and send reminders.
5. How we protect it
- Encryption at rest for BigCommerce access tokens (AES-256-GCM), the one credential that grants real store access.
- Encryption in transit — every connection to and from the app is HTTPS.
- Tenant isolation — every query is scoped to your store; one merchant's data is never visible to another's.
- Signed webhooks — both the BigCommerce webhooks we receive and the notification webhooks we send are signed (HMAC-SHA256), so tampered or forged deliveries can be detected.
- Database-level safeguards against double-booking and race conditions, independent of application code — not a privacy control exactly, but part of the same "don't trust a single layer" posture.
6. Data retention & deletion
- Holds (a slot reserved mid-checkout) expire automatically and are cleaned up within a short window — typically well under an hour.
- Bookings are kept as your business records for as long as you use the app, the same way order history lives in BigCommerce itself. We don't have an automatic time-based purge for these, since they're your operational data, not something we hold independently.
- Uninstalling the app starts a 30-day deletion window. When you remove Waypoint Booking from your store, the app immediately loses access to your store and any connected Google or Microsoft calendar is disconnected (the stored sign-in tokens are deleted). Your store record and the resources, services, bookings, and settings tied to it are then kept for 30 days, so that reinstalling the app restores your setup. If you haven't reinstalled by the end of those 30 days, all of it is permanently deleted.
7. Your rights
If you're a shopper and want to know what a merchant's Waypoint Booking installation holds about you: in almost every case, the honest answer is "nothing beyond what BigCommerce itself already has" — we don't keep a separate copy of your name, email, or booking history outside of live lookups against BigCommerce's own records. For anything specific to a booking, the merchant you booked with is the right first point of contact, since they control the store.
If you're a merchant and want a copy of your store's data, or want it deleted sooner than the 30-day window after uninstalling, contact us using the details below.
8. Changes to this policy
If our data practices change in a way that affects this policy, we'll update this page and change the "last updated" date above. Material changes will be communicated to installed merchants directly.
9. Contact
Questions about this policy or how Waypoint Booking handles data: info@waypointbooking.co.uk.