Bookyo

Bookyo Privacy Policy

Last updated: 26 July 2026

This Privacy Policy explains how BOOKYO TECHNOLOGIES LIMITED, registration number 9467861 ("Bookyo", "we", "us", or "our"), collects, uses, shares, stores, and protects personal data when you use Bookyo.

This Policy applies to Bookyo's websites, customer applications, business applications, booking services, payment features, communications, support services, and related products (collectively, the "Platform"). It applies to Customers, Business owners, staff members, contractors, website visitors, and other people who interact with Bookyo in Nigeria and Rwanda.

Bookyo's registered address is:

4-8 Remi Taiwo Street
Olorunisola, Ayobo
Lagos State, Nigeria

You can contact us about privacy at info@bookyo.co.

1. Bookyo's role

Bookyo operates a booking and business-management platform for salons, barbershops, spas, beauty and wellness Businesses, independent professionals, and similar service providers ("Businesses").

Bookyo determines how personal data is used for Platform accounts, security, payments, Platform communications, support, analytics, and administration. For those activities, Bookyo acts as a data controller.

Businesses also receive and use Customer information to manage appointments, provide services, maintain Customer relationships, handle disputes, and comply with their own legal obligations. A Business may be a separate data controller for those activities. In some circumstances, Bookyo processes information on a Business's behalf.

Businesses are responsible for their own privacy practices. Questions about a Business's use of Customer information should normally be directed to that Business. Bookyo remains responsible for personal data used for Bookyo's own purposes or processed within systems controlled by Bookyo.

2. Personal data we collect

The information we collect depends on how you use the Platform.

2.1 Account and identity information

We may collect:

  • First and last name;
  • Telephone and WhatsApp numbers;
  • Email address;
  • Password in securely hashed form;
  • Profile photograph;
  • City and country;
  • Account role, status, permissions, and verification status;
  • One-time verification codes and verification timestamps;
  • Google or Facebook account identifiers if social sign-in is offered and used; and
  • Account creation, update, and last-login dates.

2.2 Customer and booking information

We may collect:

  • The Business, location, service, and staff member selected;
  • Appointment dates, times, duration, status, and booking reference;
  • Booking source, such as the Bookyo app, telephone, WhatsApp, walk-in, or social media;
  • Prices, deposits, discounts, tips, travel fees, and booking totals;
  • Customer instructions, booking notes, cancellation reasons, and rescheduling information;
  • Waitlist preferences and responses;
  • Group-booking participant names, telephone numbers, and attendance status;
  • Booking, cancellation, completed-visit, and no-show history;
  • Customer preferences and communication settings; and
  • For mobile or at-home services, the service address, approximate or precise coordinates, access instructions, and travel-quote information.

Please provide only information that is reasonably necessary for the requested service. Do not include identity documents, financial credentials, medical records, or other highly sensitive information in free-text booking fields.

2.3 Sensitive information

Customers may voluntarily provide allergy, sensitivity, accessibility, or similar health-related information when it is relevant to a requested service. A Business may also record relevant service preferences or notes.

This information can be sensitive personal data. We process it only where permitted by law, such as with explicit consent, to protect a person's vital interests, or where another lawful condition applies. Customers may choose not to provide it, but a Business may be unable to perform a service safely without relevant information.

Businesses must not enter sensitive information unless it is necessary, lawful, accurate, and protected by appropriate permissions.

2.4 Business and staff information

We may collect:

  • Business and legal names, registration information, tax identifiers, and Business type;
  • Business email addresses, telephone numbers, billing contacts, websites, and descriptions;
  • Shop addresses, map links, geographic coordinates, operating hours, service types, and policies;
  • Owner, administrator, manager, accountant, contractor, and staff account details;
  • Staff role, title, biography, specialisations, experience, work locations, schedules, time off, availability, permissions, and activity history;
  • Business verification information and supporting documents; and
  • Subscription, billing, payout, and settlement information.

Some Business profile information is intended to be public, including Business names, descriptions, contact information, locations, opening hours, services, staff profiles, photographs, and policies. The Platform will indicate when information is intended for a public listing.

2.5 Payment and payout information

When a Customer pays or a Business receives a payout, we may collect or generate:

  • Payment amount, service amount, Bookyo processing fee, provider cost, currency, and payment method;
  • Transaction, booking, provider, refund, payout, and reconciliation references;
  • Payment, refund, settlement, dispute, and chargeback status;
  • Customer telephone number and email address associated with the transaction;
  • Bank or mobile-money provider, account holder name, encrypted payout destination, and masked account or telephone number;
  • Payment-provider responses and fraud or verification signals; and
  • Transaction IP address, device information, country, city, and timestamps.

Payment card numbers, mobile-money credentials, and similar payment authentication data are generally collected directly by the relevant payment provider rather than stored by Bookyo. Payment providers process this information under their own terms and privacy notices.

2.6 Device, log, and security information

When you use the Platform, we may automatically collect:

  • IP address;
  • Browser, operating system, device type, and device name;
  • User-agent string;
  • Session and device identifiers;
  • Approximate location derived from an IP address;
  • Login, authentication, and account activity;
  • Pages viewed and Platform features used;
  • Referral source, landing page, and campaign information;
  • Push-notification endpoint and device token;
  • Error, performance, fraud-prevention, and security logs; and
  • Audit records showing important account, booking, staff, or payment changes.

2.7 Communications, reviews, and support

We may collect:

  • Messages sent to Bookyo or a Business through the Platform;
  • Contact-form name, email address, Business name, topic, and message;
  • Support-ticket descriptions, replies, attachments, and resolution records;
  • Telephone, SMS, WhatsApp, email, push-notification, and delivery-status information;
  • Ratings, written reviews, and service-quality feedback; and
  • Survey, product-feedback, partnership, or complaint information.

Messages and free-text fields may contain information supplied by the sender. Please avoid including unnecessary sensitive data.

2.8 Business-private Customer records

A Business may maintain private notes, block status, reasons for blocking, visit statistics, spending history, and other Customer-relationship information. These records are restricted to that Business and its authorised staff and are not shared with unrelated Businesses.

Bookyo may access these records when needed to operate the Platform, provide support, investigate misuse, comply with law, or protect users.

3. How we collect personal data

We collect personal data:

  • Directly from you when you register, make or manage a booking, pay, contact support, configure preferences, or otherwise use the Platform;
  • From a Business or authorised staff member when they create or manage a booking, Customer record, staff account, service note, or payment;
  • From another user, such as an organiser who adds a participant to a group booking;
  • From payment, communication, authentication, fraud-prevention, analytics, and infrastructure providers;
  • Automatically from browsers, devices, servers, cookies, local storage, and similar technologies; and
  • From public or lawful sources when reasonably necessary to verify a Business or prevent fraud.

If you provide another person's information, you must have authority to do so and must give them any legally required privacy information.

4. Why we use personal data

We use personal data for the following purposes and lawful grounds.

PurposeTypical lawful ground
Create and administer accountsPerforming a contract or taking requested pre-contract steps
Create, confirm, manage, cancel, and reschedule bookingsPerforming a contract
Share booking information between a Customer and the selected BusinessPerforming a contract
Process payments, fees, refunds, payouts, and reconciliationsPerforming a contract and complying with legal obligations
Send confirmations, reminders, receipts, security alerts, and service noticesPerforming a contract and legitimate interests in operating the Platform
Provide support and resolve Platform or payment issuesPerforming a contract and legitimate interests
Verify Businesses, accounts, and payout destinationsLegal obligations and legitimate interests in preventing fraud
Secure the Platform, detect abuse, maintain audit logs, and enforce our TermsLegal obligations and legitimate interests in protecting Bookyo and its users
Provide Business reports, analytics, and operational insightsPerforming a contract and legitimate interests
Improve Platform functionality and reliabilityLegitimate interests or consent where required
Conduct optional browser analyticsConsent
Send marketing or promotional communicationsConsent or another ground permitted by local law
Establish, exercise, or defend legal claimsLegal obligations and legitimate interests
Respond to regulators, courts, or lawful government requestsLegal obligations

Where we rely on consent, you may withdraw it at any time. Withdrawal does not make earlier lawful processing unlawful. It may prevent us from providing a feature that depends on the relevant information.

Where we rely on legitimate interests, we consider whether the processing is necessary and balance those interests against your rights and reasonable expectations.

5. How we share personal data

We do not sell personal data.

We may share personal data with the following recipients when reasonably necessary.

5.1 Businesses and their authorised users

When a Customer interacts with a Business, we share relevant identity, contact, booking, payment-status, preference, and service information with that Business and its authorised personnel.

The Business may contact the Customer about the booking, provide the requested service, maintain service records, and address disputes. Bookyo uses roles and permissions to limit Business access, but each Business is responsible for how its authorised users handle information they can access.

5.2 Service providers

Depending on the country and features used, we may use:

  • Paystack, MTN Mobile Money, Airtel Money, banks, card networks, and other payment partners to process payments, refunds, verification, and payouts;
  • Brevo to deliver email;
  • Termii or MTN to deliver SMS;
  • Meta's WhatsApp Business services to deliver WhatsApp messages;
  • Firebase or another push provider to deliver mobile push notifications;
  • Cloudflare, including hosting, security, R2 storage, and Turnstile anti-abuse services;
  • PostHog for consent-based product analytics and feature measurement; and
  • Google or Meta if social authentication or connected services are enabled and selected by the user.

Providers may receive identifiers, contact information, message content, transaction information, device data, or other information needed to perform their services. They may also process information under their own legal obligations and privacy notices.

5.3 Professional advisers and authorities

We may disclose information to auditors, lawyers, insurers, accountants, security specialists, regulators, law-enforcement agencies, courts, or other authorities where reasonably necessary to obtain advice, comply with law, respond to lawful requests, protect rights and safety, or investigate fraud.

5.4 Corporate transactions

If Bookyo is involved in a merger, financing, reorganisation, acquisition, sale of assets, or similar transaction, personal data may be disclosed under appropriate confidentiality and data-protection safeguards.

5.5 Aggregated information

We may use and share statistics or insights that have been aggregated or de-identified so they do not reasonably identify an individual. We do not attempt to re-identify properly de-identified information.

6. Cookies, local storage, and analytics

Bookyo uses cookies, browser storage, and similar technologies for:

  • Authentication and session continuity;
  • Security and request verification;
  • Remembering settings and preferences;
  • Preventing fraud, spam, and automated abuse;
  • Measuring performance; and
  • Optional analytics.

Essential technologies are used because the Platform cannot operate securely without them.

Bookyo uses PostHog for browser analytics only after the user grants analytics consent. PostHog may then store an analytics identifier in local storage and receive page paths, user or account identifiers, device information, and selected product events. Bookyo disables automatic form capture and session recording in its current analytics configuration and does not intentionally send form entries or payment credentials to PostHog.

You may accept or decline optional analytics through Bookyo's consent prompt. Withdrawing analytics consent stops further browser analytics and resets the local PostHog identity. You can also clear Bookyo cookies and local storage through your browser settings, although clearing essential data may sign you out or reset preferences.

Cloudflare Turnstile may process device, browser, interaction, and network information when you use a protected form to distinguish legitimate requests from automated abuse.

7. Communications and marketing choices

Bookyo may send operational messages needed to provide the Platform, including verification codes, booking confirmations, reminders, cancellations, payment receipts, refund notices, payout updates, and security alerts.

You can manage available email, SMS, WhatsApp, and push-notification preferences in the Platform. Some operational messages cannot be disabled while you use the relevant service because they are necessary to complete a booking, payment, or security process.

We send promotional messages in accordance with applicable law. You may withdraw marketing consent through the available preference setting, unsubscribe instruction, or by contacting us.

8. International data transfers

Bookyo operates for users in Nigeria and Rwanda and uses providers that may process data in other countries. As a result, personal data may be transferred to or accessed from a country other than the country where it was collected.

Where required, Bookyo relies on a legally recognised transfer ground and appropriate safeguards. These may include an adequacy decision, contractual protections, consent, necessity to perform a contract, or another transfer mechanism permitted under Nigerian or Rwandan law.

We assess the nature of the information, the purpose of the transfer, the recipient, available legal protections, and appropriate technical and organisational safeguards.

9. Data retention

We keep personal data only for as long as reasonably necessary for the purposes described in this Policy. The appropriate period depends on:

  • Whether an account or Business relationship remains active;
  • The duration of a booking, subscription, payment, support, or dispute relationship;
  • Tax, accounting, payment, employment, consumer-protection, and regulatory requirements;
  • Fraud-prevention, safety, security, and audit needs;
  • Applicable limitation periods and the need to establish or defend legal claims; and
  • Backup and disaster-recovery cycles.

In general:

  • Session, verification, and temporary security data are retained for short periods connected to their expiry and security purpose;
  • Push-subscription data is retained until the subscription is removed, expires, or is no longer associated with an active account or device;
  • Account and profile data is retained while the account is active and then reviewed for deletion, anonymisation, or legally required retention;
  • Booking, payment, refund, payout, tax, and dispute records may be retained for the applicable statutory recordkeeping or claims period;
  • Marketing preferences are retained for as long as needed to respect the user's choice, including a record of an opt-out; and
  • Security, audit, support, and fraud records are retained for a period proportionate to the relevant risk or legal requirement.

When retention is no longer necessary, we delete, anonymise, or securely isolate the information. Information may remain temporarily in restricted backups until those backups are overwritten through normal cycles.

Closing or deleting an account does not require Bookyo to erase records that must be retained for payments, refunds, fraud prevention, legal compliance, disputes, or the rights of another person.

10. Data security

Bookyo uses technical and organisational measures designed to protect personal data. These measures include, where appropriate:

  • Encryption in transit;
  • Secure password hashing;
  • Encryption or hashing of sensitive payout details;
  • Role-based access controls and shop-level separation;
  • Session expiry and authentication controls;
  • Audit logging, monitoring, and rate limiting;
  • Payment-provider verification and webhook security;
  • Restricted administrative access; and
  • Backup, incident-response, and recovery procedures.

No online service can guarantee absolute security. Users must protect their credentials, use secure devices, and notify Bookyo promptly if they suspect unauthorised account access.

If a personal data breach occurs, Bookyo will investigate, mitigate the risk, and notify affected people and relevant authorities when notification is required by law.

11. Children's privacy

A person must be at least 18 to create or administer a Business account.

Customers under 18 may use Bookyo only with the involvement and permission of a parent or legal guardian. A parent or guardian may make a booking for a child and provide information reasonably necessary for that service.

Where Bookyo knows that personal data belongs to a child under 16 in Rwanda, we will obtain consent from a holder of parental responsibility unless another legal exception applies. We apply any additional child-consent requirement mandated by Nigerian law.

If you believe a child provided personal data without the required authorisation, contact info@bookyo.co.

12. Automated processing

Bookyo may use automated rules to support appointment availability, reminders, fraud detection, payment verification, account security, reporting, and feature personalisation.

Bookyo does not intend to make a decision based solely on automated processing that produces a legal or similarly significant effect on a person without an appropriate legal basis and required safeguards. Where applicable, you may request human review, provide additional information, or challenge such a decision.

13. Your privacy rights

Depending on your location and the circumstances, you may have the right to:

  • Be informed about how your personal data is processed;
  • Ask whether we process your personal data and request access to it;
  • Request a copy of your personal data;
  • Correct inaccurate or incomplete personal data;
  • Request deletion of personal data where no lawful reason requires continued retention;
  • Restrict processing in certain circumstances;
  • Object to processing based on legitimate interests or to direct marketing;
  • Withdraw consent at any time;
  • Receive eligible data in a structured and commonly used format or request portability;
  • Request information about recipients and international transfers;
  • Object to or seek review of certain automated decisions; and
  • Complain to the appropriate data-protection authority.

Rwandan data subjects may also have the right to designate an heir to personal data as provided by Rwandan law.

To exercise a right, email info@bookyo.co with the subject line "Privacy Request" and describe your request. We may ask for information reasonably necessary to verify your identity and authority. Do not send a full identity document unless Bookyo specifically requests it through a secure channel.

We will respond within the period required by applicable law. For requests governed by Rwandan law, this will generally be within 30 days where that period applies. Some rights are subject to legal exceptions, including the rights and freedoms of others, legal obligations, fraud prevention, and legal claims. If we cannot fulfil a request, we will explain the reason where required.

You may also complain to:

  • The Nigeria Data Protection Commission at ndpc.gov.ng; or
  • Rwanda's Data Protection and Privacy Office at dpo.gov.rw or complaint@dpo.gov.rw.

We encourage you to contact Bookyo first so we can investigate and try to resolve the concern.

14. Business obligations

Businesses and their authorised users must:

  • Access Customer data only when needed for legitimate Business activities;
  • Give Customers any additional privacy information required for the Business's own processing;
  • Use appropriate permissions and promptly remove access for former staff;
  • Keep Customer information accurate and confidential;
  • Obtain required consent before direct marketing;
  • Avoid entering unnecessary or excessive sensitive information;
  • Respond appropriately to privacy requests concerning the Business's own records;
  • Notify Bookyo promptly of suspected unauthorised access involving the Platform; and
  • Comply with applicable Nigerian or Rwandan privacy law.

A Business must not use Bookyo data to profile, discriminate against, harass, or exploit a Customer.

15. Third-party sites and services

The Platform may link to a Business website, map, social-media page, payment page, or other third-party service. This Policy does not govern a third party's independent processing. Review that third party's privacy notice before providing information directly to it.

16. Changes to this Policy

We may update this Policy to reflect changes in law, technology, providers, or Platform features.

We will post the updated Policy and revise the "Last updated" date. If a change materially affects how we use personal data, we will provide additional notice where required, such as through the Platform, email, or another appropriate channel.

17. Contact us

Questions, complaints, and privacy requests may be sent to:

BOOKYO TECHNOLOGIES LIMITED
Registration number: 9467861
4-8 Remi Taiwo Street
Olorunisola, Ayobo
Lagos State, Nigeria
Email: info@bookyo.co
Website: https://www.bookyo.co