Privacy policy
Last updated: July 22, 2026
Diny Booking (“Diny”, “we”, “us”) is an online scheduling platform available at booking.diny.dev. This policy explains what personal information we collect, how we use it, and the choices you have. It applies to business owners and staff who hold Diny accounts (“merchants”) and to people who book appointments or send enquiries through a merchant’s booking page (“clients”).
Information we collect
From merchants
- Account details: your name, email address and a password (stored only as a salted hash).
- Business configuration: services, availability, branding, forms and notification settings.
- Billing details for your Diny subscription, handled by Stripe (see Payments below).
From clients, on behalf of merchants
- Booking details: your name, email address, phone number, appointment time, and answers to the merchant’s intake form. The merchant you book with controls this data; Diny processes and stores it to provide the booking service to that merchant.
- Enquiries you submit through a merchant’s contact or callback form.
Automatically
- Standard technical logs (IP address, browser type, pages requested) used for security, rate limiting and troubleshooting.
Google user data
Merchants can optionally connect a Google account so that appointments sync with Google Calendar. When you connect Google, Diny requests two permissions (OAuth scopes):
- Manage events on calendars you own (
calendar.events.owned): used solely to create, update and delete calendar events that correspond to appointments booked, rescheduled or cancelled through Diny, on the calendar you connected. - Read free/busy information (
calendar.freebusy): used solely to read the times you are busy so those times are not offered as bookable slots. We read only busy/available intervals — never the titles, descriptions, attendees or other contents of your existing events.
We store the OAuth tokens Google issues encrypted at rest (AES-256-GCM) and use them only for the purposes above. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide the calendar sync you requested, to comply with law, or as part of a merger or acquisition with equivalent protections. Our staff do not read Google user data except with your explicit permission (for example, to resolve a support issue), where necessary for security, or to comply with law.
You can disconnect Google Calendar at any time from your Diny settings, which deletes the stored tokens, or revoke Diny’s access from your Google account permissions. Diny’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Payments
Payments are processed by Stripe. Card numbers are entered directly into Stripe’s payment elements and never touch Diny’s servers; we store only payment status, amounts and Stripe reference IDs.
Communications
We send transactional email (booking confirmations, reminders, receipts, password resets) via Resend, and — where a merchant has enabled it — SMS via Twilio. These messages are part of the booking service; reminder timing is controlled by the merchant.
Analytics and advertising pixels on booking pages
Merchants may configure their own analytics or advertising tags (such as Google Analytics or the Meta pixel) on their booking pages. Those tags are controlled by the merchant and are covered by the merchant’s own privacy policy. Where a merchant enables server-side conversion reporting, identifiers such as email addresses are hashed (SHA-256) before being sent to the ad platform.
Service providers
We use a small set of infrastructure providers to run Diny:
- Vercel — application hosting and file uploads
- Neon — database hosting
- Stripe — payment and subscription processing
- Resend — transactional email delivery
- Twilio — SMS delivery (where enabled)
- Google — calendar sync (only if a merchant connects Google Calendar)
- Klaviyo — marketing automation (only if a merchant connects their own Klaviyo account)
Each provider receives only the data needed for its function. We do not sell personal information to anyone.
Cookies
Diny sets a session cookie when merchants sign in to the admin dashboard. Public booking pages do not set Diny advertising cookies; any tags a merchant adds to their own pages are described above.
Data retention and deletion
Merchant and booking data is retained while the merchant’s account is active, because appointment history is part of the service. Merchants can delete clients and appointments from their dashboard, and can request full account deletion by contacting us. Clients who want their data removed can ask the merchant they booked with, or contact us directly and we will action it with the merchant. Encrypted Google tokens are deleted immediately when Google Calendar is disconnected.
Security
All traffic is encrypted in transit (TLS). Each merchant’s data is isolated at the database layer with row-level security. Credentials, API tokens and integration secrets are encrypted at rest. Passwords are stored only as salted scrypt hashes.
Your rights
Depending on where you live (including under the Australian Privacy Act 1988 and the GDPR), you may have rights to access, correct, export or delete your personal information, and to complain to a supervisory authority. Contact us and we will respond within a reasonable period.
Changes and contact
We will update this page when our practices change and revise the date above. Questions or requests: support@diny.dev.
