How Spotbookr Inc collects, uses, stores, shares and protects personal information across all of its products and services, including information received from Google when you connect your Google Calendar.
Spotbookr Inc ("Spotbookr", "we", "us") operates spotbookr.com, the Spotbookr Business products at work.spotbookr.com (Project Management, Scheduling, CRM, Invoicing and Document Signing), Spotbookr Ad Intelligence, the Spotbookr Media Network, Spotsavr and Hermes. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the choices you have. Questions: privacy@spotbookr.com.
How Spotbookr Inc collects, uses, stores, shares, and protects personal and usage information across all Services.
Last Updated: October 6, 2026
Spotbookr Inc collects different categories of information depending on which Services you use:
When you create a Spotbookr account: email address, username, password (stored as a cryptographic hash), full name, company name, job title, phone number, and billing address.
When you create a Spotsavr account: email address, username, password (hashed), and optionally your display name and followed brands.
Hermes requires a Spotsavr account. Data collected by Hermes is limited to checkout-page interactions and includes:
Hermes does not collect: browsing history outside of checkout pages, passwords, payment card numbers, or data from non-checkout pages.
Payments are processed by Stripe, Inc. We store your Stripe Customer ID and billing address but never store complete credit card numbers. Stripe handles all payment data under PCI-DSS standards.
Upon login to any Service, we collect: IP address, browser user agent, login timestamp, session duration, and authentication status. Login attempts (successful and failed) are logged for security monitoring.
Activity within the Services including: search queries, feature usage patterns, dashboard interactions, API calls, report generation, and session flow data.
With your consent (managed through our cookie consent system), we use Google Analytics to collect usage statistics. Our consent manager allows granular control over analytics, functional, and marketing cookies. Consent preferences are stored locally and respected across all Services.
When you register as a creator or brand in the Media Network: the contact details you provide, links to your social media profiles or company, and the information needed to track referrals and pay commissions.
When you contact us, including about enterprise services or a public solicitation: your name, organization, contact details and the content of your message.
The demonstrations on our website keep what you enter in your own browser's local storage. That information is not transmitted to or stored on our servers, and you can clear it with the "Reset demo data" control.
When you create a business account: your company name, your name, work email, password (stored as a cryptographic hash), and optionally your phone number, company website and team size. For billing we hold your billing name and address and a reference to your customer record at Stripe. Card details are entered directly with Stripe and are not stored on our servers.
When you use Free Document Signing, we collect the email address you confirm, which tool you used, and when. Each time you sign a document we also record the name you sign with, the time, your time zone, the name of the file, the number of pages, a summary of what you added (for example "1 signature, 1 date"), fingerprints of the original and finished files, and the internet address and browser type used. A fingerprint is a code calculated from a file; it identifies the file without revealing its contents and cannot be turned back into the document. We use this to provide the signing certificate and the Verify a Document check, to prevent misuse, and to tell you about Spotbookr products; every marketing email includes a way to unsubscribe. A confirmation of your email address is remembered in your own browser for up to 30 days so you are not asked for a code each time.
We do not receive the documents you open, your signature, your initials or anything you type into a document: these are handled entirely in your browser and never reach our servers. Anyone who holds a file you signed can use Verify a Document to see your name, your confirmed email address, the time of signing and the reference; these are the same details printed on the certificate page inside the file. Your internet address and browser type are not shown to them. To ask us to delete a signing record, write to support@spotbookr.com; once a record is deleted the document can no longer be verified.
In the business products, each person can choose to connect their own Google account under Account, Calendar. This is optional and can be disconnected at any time. When you connect, we ask Google only for the following, and you can decline any of it:
How we use and keep it. We use this access only to provide the features above to you. The busy periods are kept for a short time and replaced each time they are refreshed. The permission tokens Google gives us are stored encrypted. We do not sell Google user data, do not use it for advertising, do not use it to train artificial intelligence or machine learning models, and do not transfer it to anyone except as needed to provide these features, to comply with the law, or as part of a merger or acquisition with notice to you. Our staff do not read this data unless you ask us to for support, it is necessary for security, or the law requires it.
Limited Use. Spotbookr's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. You can disconnect in Account, Calendar, and choose to have the events Spotbookr created removed from your calendar. Disconnecting deletes the stored permission tokens and busy periods and asks Google to revoke the access. You can also remove Spotbookr's access at any time from your Google Account's security settings.
When a customer signs an estimate, or someone on a business account signs a document, we store the signed file in that company's account together with a signing record: the signer's name and email address, the time, the internet address and browser type used, the name of the document and its fingerprints. For a customer signing an estimate, or a person signing a document sent to them, we also store the picture of the signature they draw or type, as part of the signed file, and the email address the document was sent to. The company whose account it is controls these documents, and requests about them should go to that company. Anyone who holds a signed file can use Verify a Document to see the signer's name and email address, the time, the reference and the company's name.
The business products store what you and your team enter, which can include information about your own customers and contacts, such as names, email addresses, appointments and invoices. We hold this information on your behalf, to provide the service to you. Your company decides what is collected and is responsible for it; requests from those individuals about their information should be directed to your company, and we will assist you in responding.
We share data with: Stripe (payment processing and subscription billing), Google Analytics (with consent, usage analytics), our own email infrastructure together with Brevo (delivery of transactional emails), affiliate and partnership networks such as Awin and PartnerStack (tracking of referrals and commissions for the Media Network and Spotsavr), and the cloud infrastructure providers that host our systems. We do not sell personal information to any third party.
SBKr Index data is published publicly as part of our research mission. Index data is fully aggregated and derived from advertising platform data, not individual consumer behavior.
We may disclose information in response to subpoenas, court orders, or legal processes; to comply with applicable laws; to protect our rights, property, and safety; or to investigate security issues.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity with advance notice.
In the event of a data breach affecting your personal information, we will notify affected users via email within 72 hours of confirmed discovery, providing details about: the nature and scope of the breach, categories of data affected, remedial steps taken, and recommended user actions.
You can access your account data through your dashboard. For a complete data export in machine-readable format, contact privacy@spotbookr.com. We will respond within 30 days.
Update profile information through your account settings. For changes to email or critical account data, contact support for verification.
Request deletion by contacting support@spotbookr.com. Upon verification we will: cancel active subscriptions, terminate sessions, delete account data within 90 days, remove Stripe payment methods, anonymize activity records, and retain only legally required records (billing for tax purposes).
You can opt out of contributing anonymized data to Spotbookr through your Spotsavr account settings. Opting out does not affect your ability to use Spotsavr for finding and applying discount codes.
Uninstalling the Hermes extension immediately stops all checkout signal collection. You can also disable specific data collection features through the extension's settings popup without uninstalling.
Manage cookie and analytics preferences through our consent manager (accessible on first visit and via "Cookie Settings" in the footer). Settings are stored locally and must be configured per device/browser.
Opt out of marketing emails via the unsubscribe link in any message. Transactional emails (account confirmation, security alerts, password resets) cannot be disabled as they are essential to service operation.
California residents have the right to: know what personal information is collected, request deletion, and opt out of sale of personal information. We do not sell personal information. To exercise CCPA rights, contact privacy@spotbookr.com.
EU/EEA residents have additional rights including: right of access, rectification, erasure, restriction of processing, data portability, and objection. Our lawful bases for processing include: consent (analytics), contract performance (account services), and legitimate interests (security, product improvement). Contact our privacy team to exercise these rights.
Spotbookr Inc is based in the United States. Data is primarily stored and processed on U.S.-based servers. For users outside the United States:
We may update this Privacy Policy to reflect changes in our practices, products, or legal requirements. For material changes, we will: post the updated policy with a new "Last Updated" date, send email notification to registered users, display a notice within the Services, and provide at least 30 days notice before changes take effect. Continued use after the effective date constitutes acceptance.
This Privacy Policy is part of Spotbookr's legal terms. The Terms of Service, Data Policy and Information Disclaimer are published together in the Legal and Policy Center.