Where your client data is stored
If a client has asked you “where is my data, and can you delete it”, this page is what you need to answer them. It covers where the records physically sit, who else handles them, what happens if you leave JustBook, and what you actually click to export or delete one client.
There’s an example reply at the end you can adapt and send today.
The one thing to be clear about first
Section titled “The one thing to be clear about first”The client records in your account are yours. JustBook stores and processes them on your instructions. In data-protection language, your business is the controller and JustBook is the processor.
That’s not a formality — it decides who has to act. When your client asks to see or delete their record, you decide and you answer. We can’t release or erase your client records on our own judgement, because they aren’t ours to decide about. What we do is hold them securely, hand you the tools to answer, and route the request to you if it arrives at our door instead of yours.
The practical steps for handling one are in When a client asks about their data. This page is the “where does it live” half of the same question.
Where the data physically lives
Section titled “Where the data physically lives”Everything runs in the United States. If you or your clients are outside the US, that’s where the data is transferred to and processed.
| Part of JustBook | Where it runs | What sits there |
|---|---|---|
| The application and API | Render, US — Oregon | Everything in transit through the app |
| The database | Render PostgreSQL, US — Oregon | Clients, appointments, invoices, loyalty, packages, notes, activity logs |
| Files and images | Amazon S3, United States | Uploaded documents and photos, invoice PDFs, logos, service and category images |
| Image delivery (CDN) | Amazon CloudFront | Public images only — logos, service photos, package and category images, profile pictures |
| Your booking page, admin portal, and this site | Cloudflare Workers | The pages themselves; no client records are stored here |
| Network edge and DNS | Cloudflare | Traffic passing through — IP addresses and request metadata |
Two details worth knowing, because they’re the ones clients ask about:
- The file storage bucket is private. It isn’t browsable, and nothing in it opens from a link alone.
- Private documents never go through the CDN. Invoice PDFs and files you upload to a client, appointment or team record are fetched by the server behind your sign-in and permission checks, and sent with instructions not to cache. Only decorative images — logos, service photos — are served from the CDN. So a consent form or an ID scan can’t leak through a shareable cached URL. More on those in Files and storage.
Which companies touch it, and what each one sees
Section titled “Which companies touch it, and what each one sees”None of these hold a copy of your whole client list. Each sees only what its job needs:
| Company | What it does for you | What it actually sees |
|---|---|---|
| Render | Runs the application and the database | Everything — this is the primary store |
| Amazon Web Services | File storage, image delivery, encrypted database backups | Uploaded files and images; backup copies of the database |
| Cloudflare | Serves your booking page and admin portal; sits in front of the API; DNS | IP addresses and request metadata in transit |
| Stripe | Card payments — both your subscription and your clients’ deposits | Card details (entered on Stripe’s own pages), payer email, amounts and references |
| Twilio | Sends SMS and WhatsApp | The recipient’s phone number and the message text — so a reminder’s client name and appointment time |
| Zoho ZeptoMail | Sends email | The recipient’s email address and the message text — confirmations, receipts, invoices, sign-in codes |
| Sentry | Tells us when something crashes | Technical error context only. It’s configured not to collect message bodies or personal profiles |
| GitHub | Runs the nightly backup job | Handles the database contents in passing, inside an encrypted pipeline |
| Google Fonts | Supplies a font on booking pages | Your visitor’s IP address and browser details, as a normal web font request. No cookies are set for it |
If you’re on a plan that lets you bring your own sender and you’ve plugged in your own email or SMS provider, that provider is yours, not ours — you chose it and you’re answerable for it. We store the credentials you gave us, encrypted.
Card details are never ours
Section titled “Card details are never ours”Your clients’ card numbers never reach JustBook. When someone pays a deposit, or you pay your own subscription, the browser is sent to Stripe’s own hosted payment page — a full redirect away from JustBook. There is no card field anywhere in this product.
What that means when a client asks:
- We hold the result of a payment — amount, date, status, and Stripe’s reference — not the card.
- Card details aren’t in any export, because there is nothing of theirs for us to export.
- If a client wants their card details removed, that’s a question for their bank or for Stripe. We can’t move or delete something we never held.
Refunds you issue in JustBook act on Stripe’s record of the payment — see Refunds.
What happens if you cancel
Section titled “What happens if you cancel”Cancelling doesn’t delete anything. The ladder runs slowly and on purpose, and you can stop it at any point before the last step:
- You cancel. Your subscription runs to the end of the period you’ve paid for, then your booking page goes offline. Nothing is deleted. Your records are all still there, and you can still sign in to export them.
- 60 days after the page goes offline, the account is closed. You lose access; the data is still held.
- Six months after closure, everything is permanently deleted.
- 30 days before that deletion, we email the account owner to say the exact date it happens. The deletion doesn’t run until that warning has been out for the full 30 days — so nobody is deleted without notice.
That’s about eight months end to end, and reactivating the account at any point cancels the countdown outright.
Step 3 is an automated job that runs every night, not a request you have to chase. When it runs on your account it removes the records — clients, appointments, invoices, loyalty, packages, activity history — along with your stored invoice PDFs and every file you’d uploaded. It can’t be undone and we can’t recover it afterwards, which is what the warning email at step 4 is for: it’s the last moment to download anything you want to keep.
If you’d rather not wait out the ladder and want the account deleted sooner, write to privacy@justbookapp.com and ask.
What backups hold, and for how long
Section titled “What backups hold, and for how long”The database is backed up once a day to separate, private, encrypted storage — a different location from your files, run by a different system from the one it’s insuring.
- Copies expire on their own after 30 days. That’s enforced by the storage service’s own expiry rule, not by our code remembering to tidy up.
- The backup job can write but not delete. Even if its credentials were stolen, history couldn’t be erased with them.
- Our hosting provider additionally keeps a rolling 3-day point-in-time recovery window.
The consequence, and the honest thing to tell a client who asks: when a record is deleted it goes from the live system immediately, and from backup copies within 30 days, as those copies reach their expiry date and are dropped. Nobody goes digging through a backup to remove a single row — the copies simply age out.
Answering a client who asks about their own record
Section titled “Answering a client who asks about their own record”Where the request gets logged
Section titled “Where the request gets logged”Your booking page footer carries a Your data link. A client who uses it goes to a form, and when they submit it we register the request, email everyone on your team who holds the privacy permission — with the date it’s due — and send the client a receipt telling them plainly that you will be the one replying. Nothing is released or deleted on your behalf.
Every request lands on the Data requests page in your admin menu, soonest deadline first, with a link to the matching client record. When you’ve dealt with one, mark it handled and add a note of what you decided. That note is private to your team, and it’s your record of the decision.
If a client contacts JustBook some other way instead, we pass it to you the same way.
Exporting one client’s data
Section titled “Exporting one client’s data”Go to Customers, open the client’s record, and use the export there. You get a single ZIP containing:
- profile.csv — their details, tags and loyalty balance
- notifications.csv — every message sent to them
- appointments.csv — their booking history (needs the appointments permission)
- invoices.csv, loyalty-transactions.csv, packages.csv, package-usage.csv (need the financials permission, and the plan features they belong to)
- their actual uploaded files, bytes and all — the signed consent form itself, not just a line saying one exists
Sections you don’t have permission for are simply left out, so what you send is bounded by what you can see. If you need everything for the whole business rather than one person, that’s Settings → Data Export.
Deleting one client
Section titled “Deleting one client”Open the client’s record and use Delete. The record and its uploaded files are removed together.
If that client has any appointments, deletion is blocked and you’ll be offered deactivation instead. That isn’t a bug — appointment history is a financial record, and removing the client would tear a hole in it. Deactivate the client, and tell them which parts you removed and which you kept and why. When a client asks about their data covers how to word that.
An answer you can adapt
Section titled “An answer you can adapt”Something like this, edited to fit what you actually did:
Hi [name],
Your details are held in our booking system, JustBook, which stores them on our behalf — we decide what’s kept, they hold it for us. The records are stored on servers in the United States.
We hold your name and contact details, your appointment history with us, any notes and files on your record, and your invoices. Card details are not held by us or by JustBook — payments are handled by Stripe on their own systems, so there’s no card number of yours in our records to give you or delete.
I’ve attached everything we hold about you.
[If you’re deleting:] I’ve now deleted your record. It’s gone from the live system immediately, and backup copies expire within 30 days.
[If appointment history has to stay:] I’ve deleted your contact details, notes and files. I’ve kept the invoices for your past appointments, because we’re required to hold those for [X] years for tax purposes. Once that period is up they go too.
[name of your business]
Two things to do before you send it, both from When a client asks about their data: check they are who they say they are first — an email address alone proves nothing — and reply by the date in the email we sent you.
If you need more detail
Section titled “If you need more detail”- When a client asks about their data — the steps, the deadline, and when you can lawfully say no
- Files and storage — who on your team can open a file, and what’s allowed to be uploaded
- Privacy Policy — JustBook’s own commitments, in full, including the complete list of providers
- privacy@justbookapp.com — we can tell you what’s in your account and how to get it out. We can’t tell you what to decide, and for anything with real consequences, your own legal advice beats ours.