Fullday Logo
Features Pricing FAQ Help
Book a Free Demo

Table of Contents

  1. 1. Scope
  2. 2. Who We Are and Our Privacy Roles
  3. 3. Personal Data We Collect
  4. 4. How We Collect Personal Data
  5. 5. How and Why We Use Personal Data
  6. 6. Cookies, Analytics, and Marketing Technologies
  7. 7. How We Disclose Personal Data
  8. 8. Data Retention
  9. 9. Security
  10. 10. Your Privacy Rights and Choices
  11. 11. Organization Responsibilities
  12. 12. Children's Privacy
  13. 13. Third-Party Services and Links
  14. 14. Changes to This Policy
  15. 15. Contact Us

FullDay Privacy Policy

Last updated: July 21, 2026

1. Scope

This Privacy Policy explains how FullDay collects, uses, stores, and discloses personal data when people use the FullDay online booking platform, including:

  • the public Booking Portal;
  • the Admin Dashboard and specialist-facing features;
  • account registration and organization workspaces;
  • appointment scheduling and booking management;
  • client records, forms, signed documents, invoices, feedback, and reviews;
  • subscription billing, reporting, and communications; and
  • FullDay websites, documentation, support channels, and related services.

In this Policy:

  • “FullDay,” “we,” “us,” or “our” means the operator of the FullDay platform.
  • “Organization” means a business that subscribes to or uses FullDay to manage its operations.
  • “Authorized User” means an owner, administrator, specialist, staff member, or other person who accesses FullDay for an Organization.
  • “Client” means a person whose information is processed through FullDay in connection with an Organization, including a person who books or receives services from that Organization.
  • “Services” means the FullDay platform and related websites, applications, and support services.

This Policy does not govern an Organization's own privacy practices outside FullDay. Organizations may provide additional privacy notices that apply to their relationships with Clients.

2. Who We Are and Our Privacy Roles

FullDay's privacy role depends on the context in which personal data is processed.

2.1 When FullDay acts for its own purposes

FullDay generally acts as a data controller, business, or equivalent responsible party for personal data used to:

  • create and administer FullDay accounts;
  • manage subscriptions, billing, support, and our relationship with Organizations;
  • secure, maintain, analyze, and improve the Services;
  • meet legal obligations; and
  • communicate about FullDay.

2.2 When FullDay acts on behalf of an Organization

For Client records, bookings, schedules, forms, signed documents, operational communications, and similar data that an Organization submits to or collects through FullDay, the Organization generally determines why and how that data is processed. In those circumstances, the Organization is generally the controller or business, and FullDay acts as its processor or service provider.

If you are a Client and wish to exercise rights regarding data controlled by an Organization, contact that Organization first. We will assist the Organization as required by applicable law and our agreement with it.

3. Personal Data We Collect

The data we collect depends on how the Services are used and how an Organization configures its workspace.

3.1 Account and identity data

We may collect:

  • name, email address, and account identifiers;
  • authentication credentials or their secure representations;
  • Organization membership, role, permissions, invitation status, and account status;
  • profile information, such as a specialist biography; and
  • login, password-reset, and account-security information.

Staff accounts use email-and-password authentication. Client identity and sensitive self-service actions may use phone verification and SMS one-time passcodes.

3.2 Organization and business data

We may collect:

  • Organization name, branding, contact details, and website information;
  • location names, addresses, phone numbers, email addresses, time zones, and business hours;
  • services, categories, descriptions, duration, package configuration, and pricing;
  • specialist assignments, schedules, shifts, breaks, notes, and availability;
  • operational settings, communication preferences, invoicing details, and integration configuration; and
  • bank-account information that an Organization chooses to place on invoices, such as account-holder name, IBAN, and BIC.

3.3 Client and booking data

Depending on what a Client or Organization supplies, we may process:

  • name, phone number, email address, preferred language, and contact information;
  • billing name, VAT number, street address, city, country, and postal code;
  • a personal identifier included in imported records;
  • client notes, status, history, loyalty information, restrictions, and restriction reasons;
  • appointment location, specialist, service, date, time, duration, price, status, source, and reference number;
  • booking notes, internal staff notes, machine or service parameters, cancellation details, and no-show information;
  • package and multi-session booking information; and
  • legacy information imported by an Organization from another system.

An Organization controls which data it enters, imports, or asks Clients to provide. Free-text fields may contain additional personal data not specifically listed here.

3.4 Forms, signatures, and documents

We may process:

  • form-template content and terms supplied by an Organization;
  • answers entered into dynamic forms;
  • signer name, signer email address, signature, and signing time;
  • generated PDFs and related delivery information; and
  • documents linked to a Client record.

An Organization may configure a form to request health information or other sensitive or special-category data. FullDay does not determine the content of Organization-created forms. Organizations are responsible for collecting only data they are legally permitted to collect and for obtaining any required consent.

3.5 Payment, invoice, and financial data

We may process:

  • FullDay subscription plan, billing cycle, subscription status, and transaction information;
  • billing contact and Organization billing information;
  • Stripe customer, subscription, checkout, or transaction identifiers; and
  • booking-level amounts, payment method category, payment status, refunds, invoices, line items, cash counts, cash adjustments, reconciliation results, and related notes.

Stripe processes payment-card details for FullDay subscriptions.

3.6 Communications data

We may process:

  • email and SMS recipient details;
  • booking confirmations, reminders, receipts, invoices, review requests, and form-delivery messages;
  • SMS content, language, delivery status, provider identifiers, segment count, encoding, and cost;
  • one-time passcodes, verification purpose, attempts, expiration, and delivery status;
  • support requests and other communications with FullDay; and
  • communication preferences and Organization-level sender settings.

3.7 Feedback and review data

We may process:

  • ratings, comments, contact requests, and feedback associated with a booking;
  • review-request status and interaction events;
  • Google review identifiers, reviewer display names, ratings, review text, timestamps, and provider payloads; and
  • inferred or confidence-based links between a Google review and a FullDay booking, Client, specialist, location, or review request.

Automated review matching may produce a confidence score and suggested match.

3.8 Device, usage, analytics, and security data

We may collect:

  • browser, device, and operating-system information;
  • IP address or a hashed representation of it;
  • pages viewed, searches, clicks, feature interactions, booking-funnel progress, and referring pages;
  • session identifiers, event timestamps, and error information;
  • campaign attribution such as UTM source, medium, and campaign;
  • login and account events; and
  • security, rate-limiting, suspected-abuse, and audit-log information.

PostHog is used for product analytics and error tracking. FullDay may connect front-end activity with back-end events using authenticated-user and session identifiers. Organizations may also configure a Meta Pixel or similar tracking technology on their Booking Portal.

3.9 Data about other people

If you provide personal data about another person, you represent that you are authorized to do so and will provide any notice or obtain any consent required by law.

4. How We Collect Personal Data

We collect personal data:

  • Directly from you, such as when you register, book, complete a form, sign a document, contact support, or submit feedback.
  • From an Organization, such as when its staff creates a booking, imports legacy client data, invites a specialist, adds notes, or configures a form.
  • Automatically, through cookies, local storage, logs, pixels, and similar technologies when you use the Services.
  • From integrations and service providers, including Stripe, Brevo, SMS providers, Google services, PostHog, and infrastructure providers.
  • From public or connected sources, such as Google reviews associated with a configured business location.

5. How and Why We Use Personal Data

We use personal data for the following purposes:

Purpose Examples Typical legal basis where applicable
Provide and administer the Services Create accounts and workspaces; calculate availability; create, reschedule, and cancel bookings; manage records; generate documents and reports Contract; steps requested before entering a contract; Organization instructions
Authenticate users and protect the Services Sign-in, password reset, phone verification, access control, rate limiting, abuse prevention, audit logging Contract; legitimate interests; legal obligations
Process subscriptions and billing Manage plans, recurring payments, invoices, and billing support Contract; legal obligations
Send operational communications Booking confirmations, reminders, receipts, invoices, signed documents, review requests, and service notices Contract; legitimate interests; Organization instructions; consent where required
Support Organizations and Clients Respond to questions, investigate issues, and maintain service records Contract; legitimate interests
Analyze and improve FullDay Measure feature usage, diagnose errors, understand booking conversion, develop features, and improve reliability Legitimate interests; consent where required
Support Organization marketing measurement Run Organization-configured pixels and capture campaign attribution Consent or another basis selected by the Organization, as required by law
Manage feedback and reviews Collect feedback, send review requests, ingest Google reviews, and suggest links to bookings Legitimate interests; Organization instructions; consent where required
Comply with law and enforce agreements Tax, accounting, regulatory requests, dispute handling, and fraud prevention Legal obligations; legitimate interests; establishment or defense of legal claims
Protect people, rights, and property Investigate security incidents and prevent harmful or unlawful activity Legitimate interests; legal obligations; vital interests where applicable

The legal bases above are general descriptions. The applicable basis may vary by jurisdiction and context. When FullDay acts as a processor or service provider, the Organization is responsible for selecting and documenting its legal basis.

Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.

6. Cookies, Analytics, and Marketing Technologies

The Services may use cookies, local storage, pixels, and similar technologies to:

  • keep users signed in and preserve security settings;
  • remember preferences and maintain sessions;
  • measure page views, searches, feature usage, and booking conversions;
  • diagnose errors and improve performance; and
  • support Organization-configured marketing measurement.

FullDay uses PostHog for product analytics and error tracking. The project is configured to use PostHog's EU service endpoints. Organizations may configure a Meta Pixel on their Booking Portal. These technologies may receive device, session, usage, and campaign data as described above.

Where required, non-essential technologies should be used only after valid consent. You may also control certain cookies through browser settings, though blocking necessary storage may affect the Services.

7. How We Disclose Personal Data

We may disclose personal data to:

7.1 Organizations and Authorized Users

An Organization and its Authorized Users may access data in their workspace according to role-based permissions. For example, administrators may manage clients, bookings, specialists, payments, reports, forms, and Organization settings.

7.2 Service providers and subprocessors

We use providers to operate specialized parts of FullDay, including:

  • Convex for backend database, real-time application functions, and file storage;
  • Cloudflare for web hosting, delivery, and related infrastructure;
  • Stripe for subscription billing and recurring payments;
  • Brevo for transactional email delivery and Organization-configured email workflows;
  • PostHog for product analytics and error tracking;
  • Google services for Google Places or Business Profile review ingestion where configured; and
  • Organization-configured SMS providers for text-message delivery and phone verification.

These providers process data under their own agreements with FullDay or, in some cases, under an Organization's configuration.

7.3 Third-party integrations selected by an Organization

If an Organization enables an integration, we disclose the data needed to provide it. The Organization is responsible for its choice and configuration of third-party integrations.

7.4 Professional advisers and corporate transactions

We may disclose data to auditors, insurers, lawyers, accountants, and other professional advisers subject to appropriate confidentiality obligations. We may also disclose data in connection with financing, due diligence, merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.

7.5 Legal, safety, and rights-related disclosures

We may disclose data when we reasonably believe disclosure is necessary to comply with law or legal process; respond to lawful government requests; enforce agreements; investigate fraud or security incidents; or protect the rights, safety, and property of FullDay, Organizations, Clients, or others.

8. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, follow Organization instructions, meet legal and accounting requirements, resolve disputes, enforce agreements, and protect the Services.

Retention depends on the type of data and context. For example:

  • account and subscription records may be retained for the life of the account and for a period afterward;
  • booking, client, invoice, payment, cash-reconciliation, form, signature, and document records may be retained according to the Organization's instructions and applicable legal requirements;
  • one-time passcodes and booking-attempt records should be retained for shorter operational or security periods;
  • security and audit records may be retained as needed to investigate incidents and demonstrate compliance; and
  • backups may retain data for a limited period before secure deletion or overwriting.

When FullDay processes data for an Organization, the Organization controls retention subject to our agreement and applicable law. Deletion requests may be limited where retention is required by law or necessary for legal claims, security, fraud prevention, or other permitted purposes.

9. Security

We use administrative, technical, and organizational measures designed to protect personal data. Based on FullDay's documented architecture, these measures include authentication, role-based access, Organization-level data separation, audit and security logging, rate limiting, phone verification, encrypted storage of Organization-configured Brevo API keys, and managed infrastructure providers.

No system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur. Users are responsible for protecting their credentials, using secure devices, and promptly reporting suspected compromise.

10. Your Privacy Rights and Choices

Depending on where you live and the role in which FullDay processes your data, you may have the right to:

  • request access to or a copy of your personal data;
  • request correction of inaccurate data;
  • request deletion of personal data;
  • request restriction of or object to certain processing;
  • receive certain data in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of certain sale, sharing, targeted advertising, or profiling activities;
  • limit certain uses or disclosures of sensitive personal data;
  • appeal a decision concerning a privacy request; and
  • lodge a complaint with a privacy or data-protection authority.

We will not unlawfully discriminate against you for exercising privacy rights.

10.1 How to submit a request

Contact us using the method described in Contact Us. Describe your request and your relationship with FullDay or an Organization. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, subject to verification.

If an Organization controls the relevant Client data, we may direct your request to that Organization or process it on the Organization's instructions.

10.2 Communication choices

Operational messages may be necessary to provide a booking or the Services. Where a message is optional or promotional, you may use the unsubscribe mechanism provided or contact the sender. SMS recipients may also use legally required opt-out keywords where supported by the applicable provider.

10.3 Account and record controls

Authorized Users may update certain account or Organization data in FullDay. Clients may use enabled self-service features to reschedule or cancel bookings. For other corrections or deletions, contact the relevant Organization or FullDay as described above.

11. Organization Responsibilities

Organizations using FullDay are responsible for:

  • providing Clients and Authorized Users with legally required privacy notices;
  • establishing a lawful basis for data they collect and process;
  • obtaining valid consent where required, including for sensitive form fields, SMS, email, and marketing pixels;
  • configuring access permissions and integrations appropriately;
  • responding to Client rights requests as controller or business;
  • setting lawful retention periods and deleting data when no longer needed;
  • ensuring imported or uploaded data was lawfully obtained;
  • securing their credentials and connected accounts; and
  • complying with laws applicable to their services and industry.

Organizations must not use FullDay to collect data they are not legally authorized to process.

12. Children's Privacy

FullDay is a business booking platform and is not designed as a child-directed service. Organization accounts are intended for persons with authority to act for a business. An Organization's services may, however, involve minors, and an adult may book or provide information on a minor's behalf.

Organizations are responsible for determining whether they may process a minor's data and for obtaining legally required parental or guardian authorization. If we learn that data was collected through FullDay in violation of applicable children's privacy law, we will work with the relevant Organization to address it.

13. Third-Party Services and Links

The Services may link to or integrate with third-party services, including payment, messaging, analytics, advertising, and Google review services. A third party's own privacy policy applies when it independently controls data. We encourage you to review those policies. FullDay is not responsible for third-party services that an Organization selects or controls, except as required by law or our contractual obligations.

14. Changes to This Policy

We may update this Policy to reflect changes to the Services, law, or our practices. We will update the “Last updated” date and provide additional notice when required by law or when changes are material. If consent is required for a new use, we will request it before that use.

15. Contact Us

Questions, complaints, and privacy requests may be submitted through the support channel made available through the Services.

If your request concerns an appointment, form, or other record controlled by a particular Organization, please also contact that Organization directly.

Company

FeaturesPricing

Resources

InsightsReviewsBlogDocumentation

Legal

Privacy PolicyTerms of Service

Stay connected

Facebook icon Instagram icon
FullDay logo

FullDay is designed to revolutionize how businesses operate.

© 2026 FullDay. All rights reserved