Waypoint Booking
Legal

Privacy Policy

Last updated October 2, 2026 · Applies to the Waypoint Booking BigCommerce app, its dashboard, and its storefront widget.

Plain-language summary: Waypoint Booking runs inside your BigCommerce control panel and doesn't store your customers' names, emails, or phone numbers at all — booking records reference BigCommerce's own order/customer IDs, and any personal detail we ever display is fetched live from BigCommerce at the moment it's needed, never cached.

This document describes our actual technical data practices. It's written to be accurate to how the app works today, not boilerplate — but it isn't legal advice, and we'd recommend a lawyer review it against your own jurisdiction's requirements before you rely on it as your store's official policy.

1. Who this applies to

Two different people interact with Waypoint Booking, and this policy covers data about both:

For shopper data, the merchant is the data controller and we act as a processor on their behalf — the same relationship as any other app a merchant installs on their store.

2. Information we collect

From the merchant

DataWhy
Store hash & OAuth access tokenIdentifies your store and authorizes API calls on your behalf. The token is encrypted at rest (AES-256-GCM) — never stored in plain text.
Resources, services, availability rulesWhat you've configured as bookable — staff/rooms/equipment, offerings, opening hours. No personal data of yours or your customers'.
Dashboard settingsHold duration, timezone default, widget layout, notification webhook URL — your own configuration choices.
Staff BigCommerce user IDRecorded against your store so multiple staff logins can open the app; not a separate account of ours.

From shoppers, via the storefront widget

DataWhy
Booking time & resourceWhat slot was reserved — the core of what the app does.
BigCommerce order ID or customer IDLinks the booking back to a real BigCommerce order or account. We read the shopper's name/email/phone live from BigCommerce, at the moment it's genuinely needed (e.g. showing your bookings list, or sending your configured notification webhook) — it's never written to our database.
Hold session tokenA random value issued when a slot is held mid-checkout, used only to prove that browser session owns that hold. Not personally identifying on its own.

What we deliberately don't collect

  • Shopper names, email addresses, or phone numbers at rest, in our database
  • Payment or card details of any kind — checkout is handled entirely by BigCommerce
  • Analytics, advertising identifiers, or third-party tracking pixels on the storefront widget
  • Browsing history or behavior outside of the booking flow itself

3. How we use this information

4. Who we share information with

PartyWhat they receiveWhen
BigCommerceAPI calls to confirm bookings, resolve customer names for display, register the storefront widget/webhooks.Always — the app can't function without it.
Your own notification webhook endpointBooking event payloads, which may include the shopper's name and email resolved from BigCommerce for that event.Only if you've configured a webhook URL in Settings. You control what your own system does with it from there.
Google Calendar / Microsoft GraphEvent title (service + resource name only, no shopper data), start/end time.Only if you've connected an account under the Advanced tab's two-way calendar sync.
Cloud hosting providersEncrypted data at rest, as part of running the app's infrastructure (application server and database).Always, as our sub-processors — never sold or used for anything beyond running the app.

We don't sell data, and we don't share it with anyone for advertising or marketing purposes.

5. How we protect it

6. Data retention & deletion

7. Your rights

If you're a shopper and want to know what a merchant's Waypoint Booking installation holds about you: in almost every case, the honest answer is "nothing beyond what BigCommerce itself already has" — we don't keep a separate copy of your name, email, or booking history outside of live lookups against BigCommerce's own records. For anything specific to a booking, the merchant you booked with is the right first point of contact, since they control the store.

If you're a merchant and want a copy of your store's data, or want it deleted sooner than the 30-day window after uninstalling, contact us using the details below.

8. Changes to this policy

If our data practices change in a way that affects this policy, we'll update this page and change the "last updated" date above. Material changes will be communicated to installed merchants directly.

9. Contact

Questions about this policy or how Waypoint Booking handles data: info@waypointbooking.co.uk.