1. Scope and controller
This notice applies to bookablecheck.com and the BookableCheck HubSpot application. “BookableCheck,” “we,” and “us” refer to the service operator, Bigbee Solutions LLC, 3202 N 27th St., Phoenix, Arizona 85016, United States.
2. Data we collect
Website data
The public website does not use analytics, advertising pixels, or cookies. Infrastructure providers may process basic request information such as IP address, user agent, requested URL, timestamp, and security signals to deliver and protect the site.
HubSpot installation and account data
We process HubSpot portal ID, app installation state, granted scopes, encrypted OAuth credentials, portal timezone, signed user ID, signed user email when required for alert self-subscription, and signed permission context.
Scan and remediation data
The free service stores aggregate deactivated-user and risky-link counts, scan status, and timestamp. Pro may store owner identifiers and limited profile fields, scheduling-page identifiers and metadata, finding classifications and states, replacement mappings, offboarding cases and tasks, scan history, and audit events.
To enforce the one-Free-scan limit across uninstall and reinstall, we separately retain only the HubSpot portal ID and the timestamp when that portal first completed its Free scan. This entitlement record contains no scan counts, findings, user identities, scheduling-page data, or meeting data.
If HubSpot conditional meeting access is enabled and an administrator separately authorizes it, future-meeting detection and owner reassignment use the conditionally authorized crm.objects.contacts.read and crm.objects.contacts.write scopes even though BookableCheck calls only Meetings and Scheduler endpoints. We never call a Contacts endpoint or retrieve contact records. We store meeting ID, owner ID, start and end times, outcome, replacement-event status and ID, and a portal-level HubSpot Meetings navigation link. When an administrator asks BookableCheck to create a replacement event, we transiently retrieve the source title, body, location, activity type, internal attendee-owner IDs, and associated contact IDs only to send that event to HubSpot. We do not persist or log that invite content, attendee list, or those contact associations.
Billing, email, and support data
Stripe processes payment details. We receive customer and subscription identifiers, portal linkage, billing email, invoice and status information, and relevant webhook events. For alerts, we process subscriber consent, email address, suppression state, and delivery events. Support messages contain the information a sender chooses to provide.
3. How we use data
- Authorize, operate, secure, and troubleshoot the service.
- Detect supported scheduling pages that reference deactivated users.
- Present findings, guide remediation, verify results, and maintain short-term history.
- When the conditional meeting feature is enabled, apply administrator-confirmed CRM meeting-owner updates.
- Send opted-in service alerts and required account or billing notices.
- Manage subscriptions, prevent duplicate portal subscriptions, and support cancellation or reinstall.
- Comply with legal, accounting, security, and fraud-prevention obligations.
4. Legal bases
Where applicable law requires a legal basis, we rely on performance of a contract; the customer’s and our legitimate interests in operating, securing, and preventing misuse of the service; consent for optional alert enrollment where required; and compliance with legal obligations. Where processing is based on consent, consent may be withdrawn without affecting processing that occurred before withdrawal.
5. Service providers and sharing
We use the following service providers:
| Provider | Purpose |
|---|---|
| Cloudflare | Website and application hosting, relational storage, queue processing, networking, security, and operational logs |
| HubSpot | OAuth authorization, source owner and scheduling-page data, conditionally authorized minimal meeting data and confirmed CRM meeting-owner updates, native app interface, and installation lifecycle |
| Stripe | Checkout, subscriptions, invoices, tax configuration, Customer Portal, and payment processing |
| Twilio SendGrid | Transactional alerts, required account notices, delivery events, and suppression handling |
We do not sell personal information or use application data for targeted advertising. We may disclose information when required by law, to protect the service and its users, or as part of a properly governed business transaction.
6. Retention and deletion
- Current and open Pro operational state is kept while the portal remains installed and entitled.
- Resolved findings, closed cases, completed scan history, and minimal meeting records are generally removed after 90 days. Records needed for open findings or cases may remain while the portal is installed and entitled.
- On paid downgrade, detailed operational data is deleted from active systems within 24 hours, leaving aggregate status.
- On confirmed uninstall, HubSpot credentials, recipients, scan data, snapshots, findings, cases, and aggregate results are deleted from active systems within 24 hours.
- The minimal Free-scan entitlement record (HubSpot portal ID and first completion timestamp) is retained while BookableCheck offers the one-Free-scan entitlement so uninstall and reinstall cannot reset it.
- Cloudflare D1 Time Travel may retain recoverable encrypted database states for up to 30 days, subject to the service configuration.
- Minimal Stripe-linked billing records are retained separately as needed to schedule and process cancellation, recognize any remaining paid term, and meet accounting, dispute, tax, and legal obligations.
7. Uninstall and billing cancellation
The in-app disconnect action stops operational processing when the disconnect completes. After BookableCheck confirms a disconnect, HubSpot uninstall, or OAuth revocation, it records the event and submits a request to cancel any active Stripe subscription at the end of the current paid billing period. If Stripe cannot confirm the request immediately, BookableCheck retries automatically; once confirmed, the subscription will not renew. HubSpot operational data is deleted from active systems within 24 hours of the confirmed lifecycle event. Uninstalling removes access to BookableCheck. A reinstall starts with a clean operational dataset and may restore Pro only for the remaining active paid term; it does not restore deleted data or restart renewal. The separate Free-scan entitlement record remains only to prevent a previously used Free scan from being issued again.
8. Security
Safeguards include authenticated encryption for OAuth credentials, signed-request verification, one-time OAuth state, least-privilege scopes, tenant-scoped queries, restricted secrets, redacted logs, idempotent background work, retention jobs, and monitoring. No method of storage or transmission is completely secure.
9. International transfers
Service providers may process information in countries other than the customer’s. BookableCheck’s production D1 database was created with Cloudflare’s western North America placement hint.
10. Your choices and rights
Authorized admins may manage alert subscriptions, disconnect the app, and request assistance with access, correction, or deletion. Billing contacts may also manage the subscription through Stripe. Depending on location, individuals may have additional rights to access, correct, delete, restrict, object, or receive a copy of personal information.
11. Children
BookableCheck is a business service not directed to children, and we do not knowingly collect children’s personal information.
12. Changes and contact
We may update this notice as the service changes. We will post the updated notice and effective date and provide additional notice of material changes when required by applicable law. Questions or privacy requests may be sent to support@bookablecheck.com or mailed to Bigbee Solutions LLC, 3202 N 27th St., Phoenix, AZ 85016, United States.