Scope and our role
This Privacy Policy explains how BookMahj collects, uses, discloses, and retains personal information when you use our websites, applications, marketplace, and communications (the “Platform”). “BookMahj,” “we,” “us,” and “our” refer to the operator of the Platform under the BookMahj trade name.
Providers use BookMahj to offer classes, events, leagues, private lessons, and related services. When a Provider receives your booking, attendee, inquiry, or service information to deliver its offering, it may independently determine how to use that information and is responsible for its own privacy practices. This Policy does not govern third-party sites or services you visit separately.
Information we collect
Account and identity information
Name, email address, email-verification status, phone number, profile image, account role, sign-in provider identifiers, authentication tokens, and account and session timestamps. Session records can include IP address and browser or device user-agent information.
Profile, organization, and listing information
Instructor biography, photo, website, experience, teaching formats, city and state, organization name and description, member roles, logos, cover images, locations, time zone, service areas, pricing, availability, event and service details, venue address, Google Place identifier, latitude and longitude, and uploaded media.
Bookings, payments, and participation
Player and guest names, emails, phone numbers, invite or claim tokens, party size, booking and attendance status, waiver acceptance, cancellation choices and reasons, notes, waitlist preferences and auto-charge consent, amounts, taxes, fees, payouts, refunds, failures, disputes, and Stripe customer, payment-method, PaymentIntent, refund, and dispute identifiers. Stripe receives full payment-card details; BookMahj does not store full card numbers or card security codes.
Communications and community content
Inquiries, form responses, proposals, support requests, reviews, ratings, helpfulness votes, moderation records, Provider responses, notification preferences, device push tokens, and email or SMS content, delivery, bounce, complaint, read, and error records.
Calendar and technical information
If an instructor connects Google Calendar, we process OAuth account and token information, calendar identifiers, synchronization status, and free/busy intervals used to block unavailable times. We also collect cookies and local-storage preferences, request and security logs, IP-derived general location, browser and device information, referring pages, and interactions needed to operate and troubleshoot the Platform.
Sources of information
- you, when you create a profile, book, pay, join a waitlist, inquire, review, upload content, or contact us;
- Providers and organization administrators, including listing, attendee, fulfillment, attendance, refund, and inquiry information;
- people who book for or invite you;
- Stripe, identity providers, Google Calendar, communications providers, and other integrations you choose to use;
- your browser or device through cookies, local storage, headers, and server logs; and
- public sources when reasonably necessary to prevent fraud, verify information, or resolve a dispute.
How we use information
- create, authenticate, secure, and support accounts;
- publish profiles, organizations, locations, listings, schedules, images, and reviews selected for public display;
- match players with offerings and process bookings, waitlists, inquiries, invitations, and attendance;
- process payments, platform fees, Provider payouts, subscriptions, taxes, refunds, disputes, and accounting records;
- send confirmations, verification, reminders, proposals, offers, schedule changes, announcements, safety notices, and support responses;
- import calendar availability and prevent scheduling conflicts;
- moderate reviews and content, investigate violations, prevent fraud and abuse, enforce agreements, and protect people and the Platform;
- produce first-party business insights such as booking, revenue, utilization, and waitlist aggregates for authorized organizations;
- debug, maintain, personalize, and improve Platform performance and accessibility; and
- comply with law and establish, exercise, or defend legal claims.
How we disclose information
We disclose personal information to:
- Providers and participants: to fulfill bookings, inquiries, invitations, services, attendance, support, and safety needs;
- the public: when information is part of a public profile, listing, organization page, venue, image, review, rating, or response;
- service providers: for hosting, databases, authentication, storage, payments, email, SMS, queues, caching, security, maps, and calendar integration;
- payment and financial parties: including Stripe, connected accounts, card networks, banks, and tax or accounting providers;
- professional advisers and authorities: when reasonably necessary for legal, audit, insurance, safety, fraud, or compliance purposes;
- business transaction parties: in a financing, merger, acquisition, reorganization, sale, or diligence process, subject to appropriate safeguards; and
- others at your direction or with your consent.
We may use and disclose aggregated or de-identified information that cannot reasonably identify you, and we require recipients not to attempt to re-identify it where required by law.
Technology and payment providers
Platform infrastructure includes Vercel for application hosting, Neon for the PostgreSQL database, Cloudflare R2 for uploaded images, Resend for email, Upstash services for workflow delivery, caching, rate limiting, and delayed jobs, Stripe and Stripe Connect for payments, payouts, subscriptions, refunds, and disputes, and Twilio for optional SMS. We also use sign-in services from Google, Apple, or Facebook when you select them.
These providers process information in the United States and may process it in other countries where they or their subprocessors operate. Their independent account and service data is also governed by their privacy notices. Provider availability and configuration may vary by feature and environment.
Google Calendar
Instructors can authorize an import-only Google Calendar integration. BookMahj requests free/busy access to the selected calendar, stores busy time intervals for the configured look-ahead period, and uses those intervals to prevent conflicting availability. BookMahj does not write events to Google Calendar through this integration.
Calendar synchronization can continue in the background using an authorized refresh token. Disconnecting removes the BookMahj calendar integration and imported busy-time cache and attempts to revoke the integration token; it does not necessarily unlink Google as an account sign-in method. BookMahj’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Email, SMS, and push choices
Transactional messages include account verification, security, bookings, proposals, payments, waitlists, reminders, changes, cancellations, refunds, and support. They are part of providing the service and may continue while your account or transaction remains active. Optional marketing preferences default off in the Platform.
You can unsubscribe from marketing email using its link and change available notification preferences in settings. You may opt out of SMS using the instructions in the message. Message and data rates may apply. We retain suppression records to honor bounce, complaint, and opt-out choices. Providers are responsible for having an appropriate basis for communications they send using customer information.
Retention and deletion
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including maintaining an account; providing and documenting bookings and services; processing payments, refunds, disputes, and taxes; honoring communication choices; preventing fraud; enforcing agreements; and meeting legal, accounting, insurance, and safety obligations.
Retention varies by record. Sessions generally expire after seven days, verification links after 24 hours, and calendar availability uses a limited forward-looking synchronization window. Transaction, attendance, refund, dispute, tax, message-delivery, consent, and organization audit records can remain after account closure. When information is no longer needed, we delete or de-identify it, subject to backup cycles and technical or legal constraints. Closing an account does not automatically delete records belonging to an independent Provider.
Security
We use administrative, technical, and organizational measures designed to protect personal information, including access controls, signed and expiring links or tokens, encrypted network transport, scoped provider credentials, webhook verification, authorization checks, and payment processing through Stripe. No system is completely secure. Protect your credentials and notify support@bookmahj.comof suspected unauthorized access.
Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to know or access personal information, obtain a portable copy, correct inaccuracies, delete information, restrict or object to processing, withdraw consent, or appeal a denied request. You may also have a right to opt out of sale, targeted advertising, sharing for cross-context behavioral advertising, or certain profiling.
BookMahj does not currently sell personal information for money or use it for targeted advertising. To submit a request, email support@bookmahj.com with “Privacy Request” in the subject. Describe the request and the email associated with your account. We will verify identity and authority in a manner proportionate to the request and respond within the period required by applicable law. An authorized agent may submit a request where law permits, but we may require proof of authorization and direct identity confirmation. You will not receive discriminatory treatment for exercising a privacy right.
You can edit certain profile and preference information through the Platform and disconnect calendar access in instructor settings. For Provider-held information, you may also need to contact the relevant Provider directly.
Children
The Platform is for adults and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action. A parent or guardian may provide attendee information for a minor only when the Provider permits minors and the adult has authority to do so; the adult remains responsible for the booking and supervision.
International use and transfers
BookMahj operates from the United States. If you access the Platform elsewhere, your information may be transferred to, stored in, and processed in the United States and other countries where our providers operate. Those countries may have different data-protection laws. Where required, we and our providers use recognized transfer mechanisms or other safeguards.
Policy changes
We may update this Policy to reflect changes in the Platform, providers, or law. We will post the updated Policy with a new effective date and provide additional notice when required or when changes materially affect your privacy rights. Prior versions may be retained for compliance and audit purposes.
Contact us
For privacy questions or requests, contact BookMahj at support@bookmahj.com.