Legal
Privacy Policy
What MangoBook stores, why, for how long, and how to have it deleted. Written with the actual columns in front of us, because a policy you cannot check against the software is not worth reading.
- Document
- Privacy Policy
- Version
- 1.0
- Effective
- Retention
- 24 months, then details erased
01 The short version
MangoBook is booking software made by Money Mango Marketing in Toronto, Ontario, Canada. When somebody books with a business that uses it, we store what that business's form asked for — a name, usually an email address or phone number, and the answers to any questions the business added.
We hold that on the business's behalf. We do not sell it, rent it, share it for advertising, or use it to market anything to anybody. There is no analytics, no advertising pixel and no third-party script anywhere on this website or on a booking page — not one.
Personal data in a booking is kept for 24 months from the date of the booking. After that the name, email address, phone number and notes are erased, and what remains is a booking of a certain size, at a certain time, with nobody's name, address or number on it. Answers to the business's own questions are on the same record and are not cleared by that sweep — clause 4 says why, and clause 8 is how to have them removed. A message sent through a business's enquiry form is deleted outright on the same clock, answers and all.
02 Two roles, and which one you are
This one distinction decides who you should be talking to, so it comes before everything else.
If you booked something — you used a booking page or a booking form on a business's website — then that business decides what to ask you and why. In UK and EU terms it is the controller and we are its processor: we hold your details on its instructions and do nothing else with them. Your first stop for a question, a correction or a deletion is that business. We will help, and clause 8 says how.
If you run a business on MangoBook — you hold the account — then for your own account details we are the controller, and for your customers' booking details you are. Your obligations as a controller are set out in clause 4 of the Terms of Service. If you need a signed data processing agreement for your own compliance file, write to us and we will provide one.
03 What is stored
Listed as fields rather than as categories, because a list you can check is the only kind worth publishing.
If you run a business on MangoBook
- Your account
- Your name, your email address, and an Argon2id hash of your password. The password itself is never stored and cannot be recovered from the hash.
- Sign-ins
- For each signed-in device: a hash of the session token (never the token), the browser's user agent, the IP address it signed in from, and when the session expires. Sessions are held on the server rather than being self-contained tokens, which is what lets one be cut off before it expires instead of merely waiting it out.
- Your booking link
- Everything you configure — venue name, slug, tagline, branding, time zone, opening hours and closures, your resources, your booking types, your prices, and the questions your form asks.
If you booked with a business on MangoBook
- The booking
- Your name, and whichever of email address and phone number that business's form asked for. Party size, the date and time, which resource you were given, a booking reference, and whether it is confirmed or cancelled.
- Your answers
- Anything you typed into the message box, plus your answers to the business's own questions — “any allergies”, “which car are you bringing”. The business chooses these; we never see them before you do.
- A message you sent
- Some businesses put an enquiry form beside the booking form on their own website — for asking a question rather than taking a time. If you used one, we hold your name, whichever of email address and phone number that form asked for, the message you wrote, your answers to any questions the business added to it, and a reference. There is no date, no resource and no party size on it, because nothing was booked.
- Anti-abuse
- Not your IP address. A booking — or a message — carries a salted hash of your IP address and browser user agent, enough to answer “were these two made by the same client?” and nothing else. The salt is held outside the database, so a copy of the data cannot be turned back into addresses.
Everyone
- Server logs
- Our hosting provider records ordinary web-server request logs, which include IP addresses. They exist to keep the service running and secure, and are kept for up to 30 days.
- Blocked attempts
- When something is refused as abuse — a booking form filled in faster than anyone reads it, a key used from a site it does not belong to, too many sign-in attempts — we record what was refused, when, and the salted client hash above. A blocked sign-in also records the email address that was tried, because “why can I not get in” is a question we have to be able to answer.
- Email to us
- If you write to us, we keep the message and your address so we can answer and so we have a record of what was asked.
We do not collect special category data — health, biometrics, beliefs, and so on. A business is free to add a question to its own form that invites it (“any allergies” is the common one), and if it does, that is a decision it makes as controller and must have its own basis for. We store the answer and do nothing with it.
04 How long it is kept
Bookings are anonymised 24 months after the date of the booking. Name, email address, phone number and notes are erased from the record. What is left — a party of four, at that table, on that evening — stays, so a venue's own history and counts do not retroactively change.
Answers to a business's own questions are not cleared by that sweep, and we would rather say so than let you find out. They sit on the same record as the name, and they can carry as much about a person as the message box does — but the questions are the business's, not ours, and deciding that “any allergies” should survive its own booking by two years is a decision for the business that asked it, not one for us to take quietly on its behalf. Neither the 24-month sweep nor the erasure a business runs from the console clears them today. If you want your answers removed, say so when you write to us under clause 8 and we will remove them directly.
A message sent through an enquiry form is deleted, not anonymised — 24 months after it arrived, rather than after a date it does not have. The difference from a booking is the point: emptying a booking leaves a real record behind, a party of four at that table on that evening, which the business has a genuine reason to keep. Emptying a message leaves nothing at all, because you and what you wrote is the whole of it. So the record goes, and the paragraph above about answers surviving does not apply to one — its answers are on the row that is deleted.
Everything else:
- Your account — for as long as the account exists.
- Your booking link and its configuration — for as long as the account exists. There is no way to delete a booking link from the console today; write to us and we will remove it.
- Sign-in sessions — a session stops working the moment it expires or you sign out, and cannot be used again. The expired row itself is removed when we next clear them out, which is not yet on a timer.
- Anti-abuse records — the salted client hash on a booking stays with the booking. A record of a blocked sign-in attempt keeps the email address that was tried, so that a locked-out account can be explained to the person it belongs to; these are not currently swept on a schedule.
- Server logs — up to 30 days.
05 Why we are allowed to hold it
For UK and EU readers, the lawful bases we rely on, in the language the regulation uses:
- Contract — holding your account details so you can sign in and run a booking link, and holding a booking so the business can honour it.
- Legitimate interests — keeping the service secure and available, and preventing abuse of a public booking form. This is the basis for the salted client hash, the anti-abuse records and the server logs. None of them keeps a raw IP address, and the one contact detail any of them does keep is the email address on a blocked sign-in attempt, which clause 4 sets out.
- Legal obligation — where we are required to keep or disclose something. We will tell you when that happens unless we are prohibited from doing so.
Where the business you booked with relies on a different basis for asking you something, that is its determination to make and to explain in its own privacy notice.
06 Cookies and tracking
This website and every booking page set no cookies at all. No analytics, no advertising pixels, no session storage, no third-party scripts, no fonts loaded from someone else's server. A booking page talks to our own API and to nothing else, which is why you are not being asked to accept anything.
The staff console at dashboard.mangobook.net sets
exactly one cookie: a session cookie, created when you
sign in, so that the next page knows it is still you. It is
HttpOnly — script cannot read it — and
SameSite=Lax, so another website cannot cause your
browser to send it. It is strictly necessary, it carries no
identifier of any other kind, and it is cleared when you sign
out.
The embeddable widget runs inside its own shadow root on the host site. It sets no cookie and reads no storage, and it cannot see the host site's.
07 Where it lives, and who else touches it
MangoBook runs on Google Cloud Platform in the
us-east1 region — South Carolina, in the United
States. That is where the application and the database are.
This website is served by Netlify.
Those two are our only sub-processors. There is no analytics provider, no advertising network, no CRM, no email provider — MangoBook sends no email at all — and no payment processor, because nothing in the product takes payment.
For UK and EU venues, this is a transfer outside the UK and the EEA. Both providers offer Standard Contractual Clauses and the UK Addendum as part of their terms, and we rely on them. If your own compliance requires data to stay in the UK or the EU, MangoBook cannot meet that today — please tell us rather than assume, because it is on the list of things worth changing.
We will disclose data to somebody else only where the law requires it, or to protect the service or someone's safety. If MangoBook is ever sold or merged, the data moves with it and this policy continues to apply until you are told otherwise.
08 Having data deleted
If you booked with a business
Ask the business. It is the controller, it has a screen in the console for exactly this, and it will usually be quicker than going through us. Give it the email address or phone number you booked with: that is what the erasure is matched on, and it clears your name, email address, phone number and message from every booking you have made with that business — past and future alike — and deletes every message you sent it through an enquiry form. It is matched on an identifier and never on a name, because two people share a name and only one of them asked.
One limit worth knowing, because it is the only way a request can quietly miss something: an enquiry is matched on the address or number you typed into those boxes, not on anything inside the message. If you gave a different address in the message itself, say so when you write, or the message stays. Searching the text instead would mean deleting a stranger's message that happens to quote your number.
An erasure does not cancel anything. If you are still holding a table next Friday you still have it — the venue keeps the booking and loses the name on it. Cancel it with the venue first if you do not intend to come.
If you cannot reach the business, or you would rather not, write to mango@moneymango.net with the venue's name and the email address or phone number you booked with. We will pass the request on, act on it where we are permitted to act directly, and tell you what happened. Say so in your message if you also want the answers you gave to the business's own questions removed — those are the one thing the console's erasure does not reach.
If you run a business on MangoBook
Erase one person's details from the console, from the booking link's own screen. It clears them from every booking that person has with you, deletes any message they sent your enquiry form, and records that you did it — the log keeps a hashed form of the address and never the address itself, so it is evidence you actioned the request rather than a second copy of the thing you just removed.
Deleting a single message from the inbox is the same kind of action and has the same consequence: it is gone, with no anonymised copy left behind. That is why it asks for the same permission as an erasure rather than the permission to mark something answered.
Cancelling a booking is not the same thing and does not erase anybody: the record stays, with the name on it, until the erasure above or the 24 months in clause 4. There is no way to delete a whole booking link from the console today — write to us and we will remove it and everything under it, and the same goes for closing your account entirely.
Either way
We answer within 30 days, and usually much sooner. We will not charge you for it and we will not ask you why. The only thing we may ask for is enough detail to be sure we are deleting the right person's record, and we will not use what you send us for anything else.
09 Your rights
Depending on where you live, you have some or all of the following, and we honour them for everybody regardless of which law happens to apply:
- Access — a copy of what we hold about you.
- Rectification — have something wrong corrected.
- Erasure — have it deleted, as in clause 8.
- Restriction and objection — tell us to stop a particular use, including anything we do on the basis of legitimate interests.
- Portability — get it in a form you can take elsewhere.
- Withdraw consent, where consent was what we relied on.
There is no automated decision-making and no profiling in MangoBook. Nothing here scores you, ranks you or decides anything about you on its own.
If we get something wrong, tell us first — but you do not have to. In the UK you may complain to the Information Commissioner's Office; in the EU, to your national supervisory authority; in Canada, to the Office of the Privacy Commissioner.
10 How it is protected
- Everything travels over HTTPS. There is no unencrypted route in.
- Passwords are stored as Argon2id hashes — memory-hard, so a stolen hash is expensive to attack and the password itself is never written down.
- Session tokens are stored as hashes, so a copy of the session table contains nothing that can be presented as a cookie.
- The salt that protects the anti-abuse hash is held in a secret manager, outside the database, so a copy of the database cannot be turned back into IP addresses.
- The database is not reachable from a booking page. The public booking API is separately keyed, rate limited per venue and per client, and carries no session cookie.
- Access to production data is limited to the people who run the service, and used for running it.
No system is perfectly secure and we are not going to claim otherwise. If a breach affects your data, we will tell you and the relevant regulator, within the time the law requires and without waiting to have a tidy story first. If you have found something, please write to us — we would much rather hear it from you.
11 Children
MangoBook is business software and is not directed at children. We do not knowingly hold account data for anyone under 16.
A booking form is a different matter: a parent may perfectly reasonably book a child's haircut or a swimming lesson and type in a child's name. That is the venue's decision as controller. If you believe a child's details are held and should not be, write to us and we will remove them.
12 Changes, and how to reach us
If this policy changes, the version and effective date in the block at the top of the page change with it. For anything that materially affects you — a new sub-processor, a new purpose, a longer retention period — we will give notice at the address on your account before it takes effect.
Money Mango Marketing, Toronto, Ontario, Canada.
mango@moneymango.net
We have not appointed a data protection officer; we are not required to. Privacy questions go to the address above and are read by a person.
Want something deleted?
One email is enough. Tell us the venue and the address or phone number you booked with, and we will deal with it and write back.