- Who holds what
- A business using VoltsBook is the controller of its customers’ data; we process it on their behalf. Every business’s records are isolated at the database level — by a policy the database enforces, not by a WHERE clause somebody remembered to write.
- What we store
- Names, contact details, appointments, payments, and any answers your customers give to your booking forms. Card numbers are never among them: those go straight to Stripe, PayPal or Square and never reach our servers.
- Getting it back
- A business can export every record it holds at any time, and a customer can request their own copy through the booking page. Both produce a complete file rather than a summary.
- Deleting it
- Erasing a customer removes their identifying details and leaves the appointment history anonymised, because a business still has to be able to account for the money it took.
- Secrets
- Passwords are hashed and payment-gateway credentials are encrypted at rest. Neither is ever shown again after it is entered, and neither is ever written to a log.
- Who else touches it
- The payment gateway you choose, the mail and messaging providers you connect, and our hosting provider. Nobody else, and nothing is sold to anyone.