Last updated: July 21, 2026
This Privacy Policy explains how FullDay collects, uses, stores, and discloses personal data when people use the FullDay online booking platform, including:
In this Policy:
This Policy does not govern an Organization's own privacy practices outside FullDay. Organizations may provide additional privacy notices that apply to their relationships with Clients.
FullDay's privacy role depends on the context in which personal data is processed.
FullDay generally acts as a data controller, business, or equivalent responsible party for personal data used to:
For Client records, bookings, schedules, forms, signed documents, operational communications, and similar data that an Organization submits to or collects through FullDay, the Organization generally determines why and how that data is processed. In those circumstances, the Organization is generally the controller or business, and FullDay acts as its processor or service provider.
If you are a Client and wish to exercise rights regarding data controlled by an Organization, contact that Organization first. We will assist the Organization as required by applicable law and our agreement with it.
The data we collect depends on how the Services are used and how an Organization configures its workspace.
We may collect:
Staff accounts use email-and-password authentication. Client identity and sensitive self-service actions may use phone verification and SMS one-time passcodes.
We may collect:
Depending on what a Client or Organization supplies, we may process:
An Organization controls which data it enters, imports, or asks Clients to provide. Free-text fields may contain additional personal data not specifically listed here.
We may process:
An Organization may configure a form to request health information or other sensitive or special-category data. FullDay does not determine the content of Organization-created forms. Organizations are responsible for collecting only data they are legally permitted to collect and for obtaining any required consent.
We may process:
Stripe processes payment-card details for FullDay subscriptions.
We may process:
We may process:
Automated review matching may produce a confidence score and suggested match.
We may collect:
PostHog is used for product analytics and error tracking. FullDay may connect front-end activity with back-end events using authenticated-user and session identifiers. Organizations may also configure a Meta Pixel or similar tracking technology on their Booking Portal.
If you provide personal data about another person, you represent that you are authorized to do so and will provide any notice or obtain any consent required by law.
We collect personal data:
We use personal data for the following purposes:
| Purpose | Examples | Typical legal basis where applicable |
|---|---|---|
| Provide and administer the Services | Create accounts and workspaces; calculate availability; create, reschedule, and cancel bookings; manage records; generate documents and reports | Contract; steps requested before entering a contract; Organization instructions |
| Authenticate users and protect the Services | Sign-in, password reset, phone verification, access control, rate limiting, abuse prevention, audit logging | Contract; legitimate interests; legal obligations |
| Process subscriptions and billing | Manage plans, recurring payments, invoices, and billing support | Contract; legal obligations |
| Send operational communications | Booking confirmations, reminders, receipts, invoices, signed documents, review requests, and service notices | Contract; legitimate interests; Organization instructions; consent where required |
| Support Organizations and Clients | Respond to questions, investigate issues, and maintain service records | Contract; legitimate interests |
| Analyze and improve FullDay | Measure feature usage, diagnose errors, understand booking conversion, develop features, and improve reliability | Legitimate interests; consent where required |
| Support Organization marketing measurement | Run Organization-configured pixels and capture campaign attribution | Consent or another basis selected by the Organization, as required by law |
| Manage feedback and reviews | Collect feedback, send review requests, ingest Google reviews, and suggest links to bookings | Legitimate interests; Organization instructions; consent where required |
| Comply with law and enforce agreements | Tax, accounting, regulatory requests, dispute handling, and fraud prevention | Legal obligations; legitimate interests; establishment or defense of legal claims |
| Protect people, rights, and property | Investigate security incidents and prevent harmful or unlawful activity | Legitimate interests; legal obligations; vital interests where applicable |
The legal bases above are general descriptions. The applicable basis may vary by jurisdiction and context. When FullDay acts as a processor or service provider, the Organization is responsible for selecting and documenting its legal basis.
Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.
The Services may use cookies, local storage, pixels, and similar technologies to:
FullDay uses PostHog for product analytics and error tracking. The project is configured to use PostHog's EU service endpoints. Organizations may configure a Meta Pixel on their Booking Portal. These technologies may receive device, session, usage, and campaign data as described above.
Where required, non-essential technologies should be used only after valid consent. You may also control certain cookies through browser settings, though blocking necessary storage may affect the Services.
We may disclose personal data to:
An Organization and its Authorized Users may access data in their workspace according to role-based permissions. For example, administrators may manage clients, bookings, specialists, payments, reports, forms, and Organization settings.
We use providers to operate specialized parts of FullDay, including:
These providers process data under their own agreements with FullDay or, in some cases, under an Organization's configuration.
If an Organization enables an integration, we disclose the data needed to provide it. The Organization is responsible for its choice and configuration of third-party integrations.
We may disclose data to auditors, insurers, lawyers, accountants, and other professional advisers subject to appropriate confidentiality obligations. We may also disclose data in connection with financing, due diligence, merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
We may disclose data when we reasonably believe disclosure is necessary to comply with law or legal process; respond to lawful government requests; enforce agreements; investigate fraud or security incidents; or protect the rights, safety, and property of FullDay, Organizations, Clients, or others.
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, follow Organization instructions, meet legal and accounting requirements, resolve disputes, enforce agreements, and protect the Services.
Retention depends on the type of data and context. For example:
When FullDay processes data for an Organization, the Organization controls retention subject to our agreement and applicable law. Deletion requests may be limited where retention is required by law or necessary for legal claims, security, fraud prevention, or other permitted purposes.
We use administrative, technical, and organizational measures designed to protect personal data. Based on FullDay's documented architecture, these measures include authentication, role-based access, Organization-level data separation, audit and security logging, rate limiting, phone verification, encrypted storage of Organization-configured Brevo API keys, and managed infrastructure providers.
No system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur. Users are responsible for protecting their credentials, using secure devices, and promptly reporting suspected compromise.
Depending on where you live and the role in which FullDay processes your data, you may have the right to:
We will not unlawfully discriminate against you for exercising privacy rights.
Contact us using the method described in Contact Us. Describe your request and your relationship with FullDay or an Organization. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, subject to verification.
If an Organization controls the relevant Client data, we may direct your request to that Organization or process it on the Organization's instructions.
Operational messages may be necessary to provide a booking or the Services. Where a message is optional or promotional, you may use the unsubscribe mechanism provided or contact the sender. SMS recipients may also use legally required opt-out keywords where supported by the applicable provider.
Authorized Users may update certain account or Organization data in FullDay. Clients may use enabled self-service features to reschedule or cancel bookings. For other corrections or deletions, contact the relevant Organization or FullDay as described above.
Organizations using FullDay are responsible for:
Organizations must not use FullDay to collect data they are not legally authorized to process.
FullDay is a business booking platform and is not designed as a child-directed service. Organization accounts are intended for persons with authority to act for a business. An Organization's services may, however, involve minors, and an adult may book or provide information on a minor's behalf.
Organizations are responsible for determining whether they may process a minor's data and for obtaining legally required parental or guardian authorization. If we learn that data was collected through FullDay in violation of applicable children's privacy law, we will work with the relevant Organization to address it.
The Services may link to or integrate with third-party services, including payment, messaging, analytics, advertising, and Google review services. A third party's own privacy policy applies when it independently controls data. We encourage you to review those policies. FullDay is not responsible for third-party services that an Organization selects or controls, except as required by law or our contractual obligations.
We may update this Policy to reflect changes to the Services, law, or our practices. We will update the “Last updated” date and provide additional notice when required by law or when changes are material. If consent is required for a new use, we will request it before that use.
Questions, complaints, and privacy requests may be submitted through the support channel made available through the Services.
If your request concerns an appointment, form, or other record controlled by a particular Organization, please also contact that Organization directly.