Skip to content

Where your client data is stored

If a client has asked you “where is my data, and can you delete it”, this page is what you need to answer them. It covers where the records physically sit, who else handles them, what happens if you leave JustBook, and what you actually click to export or delete one client.

There’s an example reply at the end you can adapt and send today.

The client records in your account are yours. JustBook stores and processes them on your instructions. In data-protection language, your business is the controller and JustBook is the processor.

That’s not a formality — it decides who has to act. When your client asks to see or delete their record, you decide and you answer. We can’t release or erase your client records on our own judgement, because they aren’t ours to decide about. What we do is hold them securely, hand you the tools to answer, and route the request to you if it arrives at our door instead of yours.

The practical steps for handling one are in When a client asks about their data. This page is the “where does it live” half of the same question.

Everything runs in the United States. If you or your clients are outside the US, that’s where the data is transferred to and processed.

Part of JustBookWhere it runsWhat sits there
The application and APIRender, US — OregonEverything in transit through the app
The databaseRender PostgreSQL, US — OregonClients, appointments, invoices, loyalty, packages, notes, activity logs
Files and imagesAmazon S3, United StatesUploaded documents and photos, invoice PDFs, logos, service and category images
Image delivery (CDN)Amazon CloudFrontPublic images only — logos, service photos, package and category images, profile pictures
Your booking page, admin portal, and this siteCloudflare WorkersThe pages themselves; no client records are stored here
Network edge and DNSCloudflareTraffic passing through — IP addresses and request metadata

Two details worth knowing, because they’re the ones clients ask about:

  • The file storage bucket is private. It isn’t browsable, and nothing in it opens from a link alone.
  • Private documents never go through the CDN. Invoice PDFs and files you upload to a client, appointment or team record are fetched by the server behind your sign-in and permission checks, and sent with instructions not to cache. Only decorative images — logos, service photos — are served from the CDN. So a consent form or an ID scan can’t leak through a shareable cached URL. More on those in Files and storage.

Which companies touch it, and what each one sees

Section titled “Which companies touch it, and what each one sees”

None of these hold a copy of your whole client list. Each sees only what its job needs:

CompanyWhat it does for youWhat it actually sees
RenderRuns the application and the databaseEverything — this is the primary store
Amazon Web ServicesFile storage, image delivery, encrypted database backupsUploaded files and images; backup copies of the database
CloudflareServes your booking page and admin portal; sits in front of the API; DNSIP addresses and request metadata in transit
StripeCard payments — both your subscription and your clients’ depositsCard details (entered on Stripe’s own pages), payer email, amounts and references
TwilioSends SMS and WhatsAppThe recipient’s phone number and the message text — so a reminder’s client name and appointment time
Zoho ZeptoMailSends emailThe recipient’s email address and the message text — confirmations, receipts, invoices, sign-in codes
SentryTells us when something crashesTechnical error context only. It’s configured not to collect message bodies or personal profiles
GitHubRuns the nightly backup jobHandles the database contents in passing, inside an encrypted pipeline
Google FontsSupplies a font on booking pagesYour visitor’s IP address and browser details, as a normal web font request. No cookies are set for it

If you’re on a plan that lets you bring your own sender and you’ve plugged in your own email or SMS provider, that provider is yours, not ours — you chose it and you’re answerable for it. We store the credentials you gave us, encrypted.

Your clients’ card numbers never reach JustBook. When someone pays a deposit, or you pay your own subscription, the browser is sent to Stripe’s own hosted payment page — a full redirect away from JustBook. There is no card field anywhere in this product.

What that means when a client asks:

  • We hold the result of a payment — amount, date, status, and Stripe’s reference — not the card.
  • Card details aren’t in any export, because there is nothing of theirs for us to export.
  • If a client wants their card details removed, that’s a question for their bank or for Stripe. We can’t move or delete something we never held.

Refunds you issue in JustBook act on Stripe’s record of the payment — see Refunds.

Cancelling doesn’t delete anything. The ladder runs slowly and on purpose, and you can stop it at any point before the last step:

  1. You cancel. Your subscription runs to the end of the period you’ve paid for, then your booking page goes offline. Nothing is deleted. Your records are all still there, and you can still sign in to export them.
  2. 60 days after the page goes offline, the account is closed. You lose access; the data is still held.
  3. Six months after closure, everything is permanently deleted.
  4. 30 days before that deletion, we email the account owner to say the exact date it happens. The deletion doesn’t run until that warning has been out for the full 30 days — so nobody is deleted without notice.

That’s about eight months end to end, and reactivating the account at any point cancels the countdown outright.

Step 3 is an automated job that runs every night, not a request you have to chase. When it runs on your account it removes the records — clients, appointments, invoices, loyalty, packages, activity history — along with your stored invoice PDFs and every file you’d uploaded. It can’t be undone and we can’t recover it afterwards, which is what the warning email at step 4 is for: it’s the last moment to download anything you want to keep.

If you’d rather not wait out the ladder and want the account deleted sooner, write to privacy@justbookapp.com and ask.

The database is backed up once a day to separate, private, encrypted storage — a different location from your files, run by a different system from the one it’s insuring.

  • Copies expire on their own after 30 days. That’s enforced by the storage service’s own expiry rule, not by our code remembering to tidy up.
  • The backup job can write but not delete. Even if its credentials were stolen, history couldn’t be erased with them.
  • Our hosting provider additionally keeps a rolling 3-day point-in-time recovery window.

The consequence, and the honest thing to tell a client who asks: when a record is deleted it goes from the live system immediately, and from backup copies within 30 days, as those copies reach their expiry date and are dropped. Nobody goes digging through a backup to remove a single row — the copies simply age out.

Answering a client who asks about their own record

Section titled “Answering a client who asks about their own record”

Your booking page footer carries a Your data link. A client who uses it goes to a form, and when they submit it we register the request, email everyone on your team who holds the privacy permission — with the date it’s due — and send the client a receipt telling them plainly that you will be the one replying. Nothing is released or deleted on your behalf.

Every request lands on the Data requests page in your admin menu, soonest deadline first, with a link to the matching client record. When you’ve dealt with one, mark it handled and add a note of what you decided. That note is private to your team, and it’s your record of the decision.

If a client contacts JustBook some other way instead, we pass it to you the same way.

Go to Customers, open the client’s record, and use the export there. You get a single ZIP containing:

  • profile.csv — their details, tags and loyalty balance
  • notifications.csv — every message sent to them
  • appointments.csv — their booking history (needs the appointments permission)
  • invoices.csv, loyalty-transactions.csv, packages.csv, package-usage.csv (need the financials permission, and the plan features they belong to)
  • their actual uploaded files, bytes and all — the signed consent form itself, not just a line saying one exists

Sections you don’t have permission for are simply left out, so what you send is bounded by what you can see. If you need everything for the whole business rather than one person, that’s Settings → Data Export.

Open the client’s record and use Delete. The record and its uploaded files are removed together.

If that client has any appointments, deletion is blocked and you’ll be offered deactivation instead. That isn’t a bug — appointment history is a financial record, and removing the client would tear a hole in it. Deactivate the client, and tell them which parts you removed and which you kept and why. When a client asks about their data covers how to word that.

Something like this, edited to fit what you actually did:

Hi [name],

Your details are held in our booking system, JustBook, which stores them on our behalf — we decide what’s kept, they hold it for us. The records are stored on servers in the United States.

We hold your name and contact details, your appointment history with us, any notes and files on your record, and your invoices. Card details are not held by us or by JustBook — payments are handled by Stripe on their own systems, so there’s no card number of yours in our records to give you or delete.

I’ve attached everything we hold about you.

[If you’re deleting:] I’ve now deleted your record. It’s gone from the live system immediately, and backup copies expire within 30 days.

[If appointment history has to stay:] I’ve deleted your contact details, notes and files. I’ve kept the invoices for your past appointments, because we’re required to hold those for [X] years for tax purposes. Once that period is up they go too.

[name of your business]

Two things to do before you send it, both from When a client asks about their data: check they are who they say they are first — an email address alone proves nothing — and reply by the date in the email we sent you.

  • When a client asks about their data — the steps, the deadline, and when you can lawfully say no
  • Files and storage — who on your team can open a file, and what’s allowed to be uploaded
  • Privacy Policy — JustBook’s own commitments, in full, including the complete list of providers
  • privacy@justbookapp.com — we can tell you what’s in your account and how to get it out. We can’t tell you what to decide, and for anything with real consequences, your own legal advice beats ours.