Skip to content

When a client asks about their data

A client may ask to see the information you hold about them, have it corrected, or have it deleted. Most owners will get one of these rarely, if ever — but there’s a deadline attached, so it’s worth knowing the shape of it before the first one arrives.

The client records in your account are yours. You decide what to collect and what to keep; JustBook stores it on your behalf and on your instructions.

In data-protection terms your business is the controller and JustBook is the processor. The practical consequence: when a client asks about their data, your business answers. We can’t decide to release or erase your client records for you, because they aren’t ours to decide about.

Your booking page carries a “Your data” link in its footer. A client who uses it goes straight to you — we register the request, email you with the deadline, and send them a receipt saying you’ll be the one replying. Nothing is released or deleted on your behalf.

If a client contacts JustBook some other way instead, we pass it to you the same way.

Data requests in your admin menu lists every request, with the date each one needs an answer by and a link to that client’s record. Mark one as handled when you’re done, with a note of what you did — that note is only visible to your team, and it’s your record of what was decided.

Data requests are gated by their own permission, under Settings → Roles. Whoever has it sees the page and receives the email when a request comes in — so give it to the people who will actually answer, and to more than one person if you can. Owners and admins have it automatically.

If nobody has the permission, we can’t tell who to notify, so we’ll contact you directly instead.

1. Check they are who they say they are.

Do this first, before you look anything up. An email address alone isn’t proof — anyone can type one. If the request arrives from an address you don’t recognise, or you have any doubt, contact the client through the details already on their record and confirm it was them. Handing someone else’s records to the wrong person is worse than being slow.

2. Find what you hold.

Go to Customers and open the client’s record. You can export everything you hold on one client as a single file — their details, appointment history, notes, payments, loyalty and packages. See Reports and logs for where exports live.

3. Do what they asked.

  • See their data — send them the export.
  • Correct it — edit the record. Worth doing anyway; a wrong phone number costs you a booking.
  • Delete it — delete the client record. Where there’s no appointment history, the record and its files are removed entirely.

4. Reply to them, by the date in our email.

Tell them what you did. If you’re refusing part of it, say which part and why.

You don’t have to delete everything on request. You can keep what you’re required to keep — most commonly transaction records you need for tax and accounting, which typically have their own retention period in your country.

If that applies, delete what you can, keep what you must, and tell the client which is which. Being specific is the point: “we’ve removed your contact details and notes, and kept the invoices for your past appointments because we’re required to hold those for X years” is an answer. “We can’t delete your data” isn’t.

Reply to the email we sent you, or write to privacy@justbookapp.com. We can tell you what’s in the account and how to get it out. We can’t tell you what to decide — that’s the controller’s call, and it’s yours — and for anything with real consequences, your own legal advice beats ours.

Our side of this is in the Privacy Policy.