Privacy Policy

Last updated: 21 July 2026

1. Introduction

Allsorts Bookings ("we," "our," or "us") is operated by Allsorts Web Designers, a company based in South Africa. This Privacy Policy explains how we collect, use, disclose, and safeguard information when a business ("you" or your "organization") and its customers use our appointment booking platform (the "Service").

We are committed to protecting privacy and complying with applicable data protection laws, including the Protection of Personal Information Act (POPIA) of South Africa.

2. Information We Collect

2.1 Business Account Information

When you create an organization account, we collect:

  • Your name, email address, and optional cellphone number
  • Password (stored in encrypted/hashed form)
  • Business name and contact phone number, shown on your public booking page
  • Billing information for paid subscriptions (processed by PayFast — we don't store card numbers)

2.2 Your Business Data

We store the data you and your staff enter, including:

  • Services, prices, and durations you offer
  • Staff members and their working availability
  • Your own PayFast merchant credentials and/or EFT banking details, if you choose to accept online payments (encrypted at rest)
  • Allsorts CRM and QR Code Pro API keys, if you choose to connect those integrations (encrypted at rest)

2.3 Your Customers' Booking Data

When someone books an appointment through your public booking page, we collect their name, email address, phone number, and any notes they provide, along with the service and time they booked. This is personal information about a third party (your customer) that you, as the business, are responsible for having a lawful basis to collect and use. We act as the data processor on your behalf for this data. If you have connected an Allsorts CRM API key, the customer's name, email, and phone are also sent to your own CRM account to create a contact there.

2.4 Technical Data

We automatically collect:

  • IP addresses (used for rate limiting and security, not stored long-term for analytics)
  • Browser type and version, device type
  • Cookies required for authentication and session management

3. How We Use Your Information

We use the information we collect to:

  • Provide our Service: operate the booking calendar, compute real open slots, and send booking confirmations and reminders
  • Process payments:handle your subscription billing through our own PayFast merchant account, and — separately — route your customers' payments to your own connected PayFast merchant account or display your EFT details, when you require payment for a service
  • Communicate with you: send service updates, security alerts, and support messages
  • Ensure security: detect and prevent fraud, abuse, and security threats (rate limiting, lockouts, audit logs)
  • Comply with legal obligations: meet regulatory and legal requirements

4. AI Assistant

Allsorts Bookings includes an optional in-app AI assistant that sends relevant data — such as your typed question, or the details needed to create or look up a booking — to a third-party AI provider (Groq, and optionally OpenRouter as a fallback) to generate a response. This feature is used only when you explicitly open and use the assistant; nothing is sent automatically in the background.

AI provider API keys are configured at the platform level, not per-organization, and stored encrypted. We do not control how third-party AI providers process or retain data sent to their APIs beyond what their own terms describe.

5. Data Sharing and Disclosure

We may share information with:

5.1 Service Providers

Trusted third parties who assist in operating our Service, including our hosting provider, Resend for transactional email, PayFast for payment processing (both our own platform billing and, separately, any payments you accept from your customers via your own connected merchant account), and AI providers (Groq, OpenRouter) when the AI assistant is used.

5.2 Your Own Connected Products

If you connect an Allsorts CRM or QR Code Pro API key, relevant data (a new booking's customer details, or your booking page URL) is sent to your own account on those products, under your own control.

5.3 Legal Requirements

We may disclose information when required by law, court order, or government request, or when necessary to protect our rights, property, or safety.

We do not sell your personal information, or your customers' personal information, to third parties.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS/SSL)
  • Secure password hashing using bcrypt
  • Encrypted storage of PayFast merchant credentials and integration API keys (AES-256-GCM)
  • Rate limiting and account lockout on repeated failed logins
  • Security headers and access controls

However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but strive to protect data using commercially acceptable means.

7. Data Retention

We retain data as follows:

  • Account, service, staff, and booking data:retained while your organization's account is active, and for 30 days after a deletion request to allow recovery from accidental deletion
  • Billing records: retained for 7 years as required by law

8. Your Rights

Under POPIA, you have the right to:

  • Access: request a copy of your personal data
  • Correction: correct inaccurate or incomplete data
  • Deletion: request deletion of your data, subject to legal retention obligations
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: withdraw previously given consent at any time

To exercise these rights, contact us at [email protected]. If you are a customer of one of our business users and want to exercise these rights over a booking you made, please contact that business directly first — they are the party responsible for your booking data.

9. Cookies

We use cookies for:

  • Essential cookies: required for authentication and session security — the Service cannot function without these

We do not use third-party advertising or tracking cookies. You can manage cookie preferences through your browser settings, though disabling essential cookies will prevent you from logging in.

10. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by email or prominent notice on our platform. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related inquiries or to exercise your rights:

Allsorts Web Designers

Trading as Allsorts Bookings

Email: [email protected]

East London, Eastern Cape, South Africa

You have the right to lodge a complaint with the Information Regulator of South Africa if you believe your privacy rights have been violated.