SmartBook

Privacy policy

1. Data controller

SmartBook AS, org. no. 937 622 252, is the data controller for data we process for our own purposes: user accounts for businesses on the platform, technical logs and security, our customer relationship with the business, and data we must process to meet legal obligations such as accounting, anti-money-laundering and payments. Contact: hello@smartbook.now.

For data about guests who book a service, the business you book with is the data controller. SmartBook is a data processor and processes the data on the business’s behalf under a data processing agreement that meets GDPR Article 28. Requests about your rights as a guest should be directed to the business you booked with. If you contact us, we will refer you and notify the business.

2. What data do we collect?

For customers booking services: name, email address, phone number.

For businesses: email, password (encrypted), business information, bank details (via Stripe).

For businesses connecting Google Calendar: Google account email, calendar ID and name, OAuth refresh token, and calendar events (times and titles) synchronised between SmartBook and Google Calendar.

Technical data: IP address, browser type, time zone (for troubleshooting and security).

3. Purpose and legal basis

Performance of a contract (GDPR Art. 6(1)(b)): Process bookings, send confirmations and reminders.

Legitimate interest (GDPR Art. 6(1)(f)): Prevent fraud and improve the service.

Consent (GDPR Art. 6(1)(a)): Marketing (only with explicit consent).

4. Sharing of data

We share personal data with the business you book with, and with these processors: Supabase, Inc. (database, authentication and file storage, EU), Vercel Inc. (website and application hosting, EU), Stripe (payment processing and payouts), Twilio Inc. (SMS), Resend, Inc. (email), Functional Software, Inc. / Sentry (error tracking and monitoring, EU) and OpenRouter, Inc. with Google LLC as model provider (AI features).

When booking pages are shown in a language other than Norwegian or English, the business’s texts (service descriptions, website content and interface labels) are machine-translated by Google Cloud Translation (Google Ireland Ltd., EU endpoint). Only the business’s published content is sent for translation – never your name, contact details or booking details. Translations are cached in our database for reuse. Your language choice is stored in a cookie (GUEST_LANG) for 12 months.

Google LLC additionally receives calendar data when a business voluntarily connects Google Calendar, and an accounting system such as Tripletex receives accounting data when the business enables that integration.

All have data processing agreements or equivalent processor obligations. Where processing takes place outside the EEA, transfers rely on the European Commission’s Standard Contractual Clauses (SCC), supplemented by the EU–US Data Privacy Framework where the provider is certified. An up-to-date list of processors is available on request.

5. Google Calendar integration

Business owners can voluntarily connect SmartBook to Google Calendar for two-way synchronisation. The purpose is to create calendar events for confirmed bookings in Google Calendar, and to read busy times in Google Calendar so those slots are blocked in SmartBook availability.

Legal basis: consent when you approve the connection via Google (GDPR Art. 6(1)(a)), and contract performance to deliver the booking service (GDPR Art. 6(1)(b)).

We request a single OAuth scope: read/write access to calendar events (calendar.events) on your primary calendar. From existing events we read only start and end times — never titles, descriptions, attendees or locations.

The refresh token and sync status are stored in the organisation settings in our database (Supabase), protected by row-level security (RLS). This data is deleted when you disconnect Google Calendar under Settings → Disconnect Google.

Synchronised calendar events may contain customer names and booking details related to the business. Retention of booking data follows section 8 below.

Google API Services User Data Policy (Limited Use)

The use and transfer of raw or derived user data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. See: https://developers.google.com/terms/api-services-user-data-policy

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

SmartBook uses Google Calendar data solely to provide two-way calendar sync for the business owner who connects: creating and updating events for confirmed bookings, and reading busy times to block availability. We do not use Google data for advertising, profiling outside the service, or sale to third parties. Data is not shared with anyone other than necessary subprocessors (hosting/database) under a data processing agreement, and only to operate the integration you have enabled.

Google Calendar content is never sent to AI models. The booking assistant only sees which time slots are open for booking, which may reflect that a day is blocked. Google user data — raw, aggregated, anonymised or derived — is not used to develop, improve or train generalised AI or machine-learning models, and the AI provider we use does not train on API data.

Human access to Google Calendar data occurs only for technical troubleshooting, security incidents, or when required by law — not for marketing or independent analysis.

You can revoke access at any time via Settings → Disconnect Google; the OAuth token is then deleted and we stop synchronisation.

6. AI processing

SmartBook uses AI models to generate text suggestions, power guest chat and provide insights. AI calls are routed via OpenRouter, Inc. to the model provider, currently Google (Gemini). Conversations are logged for quality assurance and troubleshooting. Neither content nor personal data is used to train AI models.

The AI features provide suggestions and decision support. They do not make automated decisions producing legal effects or similarly significant effects for you, cf. GDPR Article 22.

7. Your rights

You have the right to: access, rectification, erasure, data portability, restriction of processing, and to withdraw consent. Contact hello@smartbook.now.

8. Retention

Booking data is stored for 3 years after last activity (as required by Norwegian accounting law). Google Calendar OAuth tokens are deleted on disconnect. You may request deletion of non-accounting data at any time.

9. Right to complain

You may lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no) if you believe your rights have not been respected.