Privacy Policy

Overview

2BookNow is operated by GoGold Apps Inc (“we”, “us”), a company registered in Canada at 5863 Leslie St, Unit 318, North York, Ontario, M2H 1J8. This policy covers our website at https://2booknow.com, the booking pages we host at yourname.2booknow.com, and the 2BookNow mobile app for iOS and Android.

Last updated: 6 September 2026.

The two kinds of people in this policy

Business owners subscribe to 2BookNow and use the app to run their bookings. For their own account data, we are the controller.

Customers book an appointment with one of those businesses. For that booking data the business is the controller and we are its processor — we hold and process it on the business’s instructions, under our Data Processing Agreement. If you are a customer and want your details corrected or removed, ask the business you booked with; we will help them do it.

Information We Collect

From business owners: your name and email address; the sign-in method you chose (email, Google or Apple); your business name, booking handle, address, timezone, currency, contact details, social links and any logo or banner image you upload; your services, prices, working hours and booking rules; your subscription status; and, if you allow notifications, a push token for your device.

From customers who book: name, email address, phone number, the appointment itself, and anything the business chose to ask on its booking form — up to ten questions of its own, an optional address, and an optional photo. Photos are stored privately and are visible only to the business that asked for them.

Recorded by the business about its clients: contact details and private notes. Notes are visible only to the business that wrote them.

Automatically: standard web server logs when you visit our site or a booking page. When a booking is submitted we store a one-way hash of the sender’s IP address and email address — never the values themselves — purely to rate-limit abuse, and these are deleted automatically.

We do not collect payment card numbers, bank details, government identifiers, precise location, your contacts, or advertising identifiers. There is no advertising or third-party tracking in the app.

Cookies and Similar Technologies

Our marketing website uses essential cookies to function and basic analytics to understand which pages people read. Booking pages set no advertising or tracking cookies. You can control cookies through your browser settings, but disabling essential cookies will break parts of the site.

How We Use Your Data

  • To run bookings — showing availability, taking and storing appointments, and sending the confirmation, reminder and cancellation emails a booking generates.
  • To run your account — signing you in, remembering your settings, and answering you when you contact support.
  • To manage subscriptions — confirming with Apple or Google, through RevenueCat, whether a subscription is active. We never see your card.
  • To keep the service working and safe — diagnosing faults, rate-limiting abuse, preventing fraud.
  • To comply with law, and to enforce our Terms.

We do not sell, rent or trade personal information. We do not use business owners’ or customers’ personal data to train machine-learning models. We do not send marketing email to your customers — the only email a customer receives from us is about their own booking.

Payments

2BookNow does not process payments. Subscriptions are bought as in-app purchases through the Apple App Store and Google Play, which bill you directly under their own terms and privacy policies; we receive only the fact that a subscription is active. We never hold, see or store your card details, and we do not process payments between a business and its customers at all.

Health and Wellness Practitioners

2BookNow is a scheduling system, not a medical records system. An appointment with a health or wellness provider can reveal something about a person’s health by inference, so we hold that data under the security measures described below and use it only to run the booking.

We do not offer a Business Associate Agreement and the Service is not HIPAA-compliant. U.S. providers covered by HIPAA should not store protected health information in 2BookNow. Outside the United States, health and wellness practitioners may use the Service, and we ask them to keep clinical records — diagnoses, treatment notes, medication, insurance or health-plan numbers — in a system built for that purpose.

Who We Share It With

We use a small number of service providers, and only for the purposes above:

  • Supabase (on Amazon Web Services) — database, sign-in and file storage. United States (Oregon).
  • ZeptoMail (Zoho Corporation) — sends booking and sign-in emails. Canada.
  • Cloudflare — protects and speeds up our sites. Global edge network.
  • RevenueCat — confirms subscription status. United States.
  • Expo, Apple (APNs) and Google (FCM) — deliver push notifications. United States.
  • Apple and Google — sell and bill the subscription, under their own terms.

Beyond these, we share personal information only where the law requires it, or in the event of a merger or acquisition, in which case this policy continues to apply.

Where Your Data Is Held

Primarily in the United States, with transactional email routed through Canada. If you are in the UK, the EU or another region with data transfer rules, we rely on the standard contractual clauses in our Data Processing Agreement.

Data Security

  • Everything travels over TLS, and the database and file storage are encrypted at rest.
  • The database enforces access row by row, so one business cannot read another’s data even if the app asked it to.
  • Uploaded files sit in private storage buckets with per-business access rules.
  • Passwords, where a business owner has set one, are stored only as a bcrypt hash.
  • Signing in by email uses a single-use six-digit code with a limit on how often one can be requested.
  • Infrastructure is managed and patched by our providers, with least-privilege administrative access.

No system is perfectly secure, and we do not claim otherwise.

How Long We Keep It

Bookings and client records are kept for as long as the business keeps its account, because they are the business’s records. A business owner can delete individual records at any time from the app.

When a business closes its account, we mark it for deletion and permanently erase the business, its bookings, its client records and its uploaded files after a seven-day grace period. This cannot be undone. Rate-limiting hashes and webhook logs are deleted automatically on a short cycle. We keep the minimum records the law requires for tax and accounting.

Children’s Privacy

2BookNow is for businesses and is not directed at children under 13, and we do not knowingly collect their personal information. If a business asks its customers for a child’s details as part of a booking, the business is responsible for having a lawful basis to do so.

Your Rights

Depending on where you live, you have the right to ask for a copy of your personal information, to have it corrected, to have it deleted, to object to how it is processed, to withdraw consent, and to complain to your data protection authority. Business owners can exercise most of these directly in the app — export your data to a spreadsheet, edit any record, or close your account. For anything else, email support@gogoldapps.com and we will respond within the time your law allows.

California residents: we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anyone who exercises their rights.

Changes to This Policy

We will post any update here and change the date at the top. If a change is significant, we will tell business owners in the app or by email.

Contact Us

Email support@gogoldapps.com or use our contact page.
GoGold Apps Inc, 5863 Leslie St, Unit 318, North York, Ontario, M2H 1J8, Canada.