Legal

Privacy Policy

Last updated July 30, 2026

This Privacy Policy explains how BACKEND Booking LLC ("BACKEND Booking", "we", "us", "our") collects, uses, shares, and protects personal information when you use our website at https://backendbooking.com, our mobile applications, and related services (together, the "Service"). It applies to everyone who uses the Service: Creators (users who offer services), Customers (users who book services), and visitors.

By using the Service you agree to this Policy and to our Terms of Service.

1. Information we collect

Account information. Email address, password credentials (stored hashed by our authentication provider), display name, handle, account type, sign-in method (including Google sign-in), and account settings.

Profile information. Avatar, cover image, bio, profession and category, skills and attributes, location (city/region, and where you enable it, approximate coordinates used for distance search), languages, rates, availability, external links, and social handles. Public profile fields are visible to anyone unless you set your profile to private in Settings → Privacy.

Messages. The content of messages, attachments, offers, pitches, and booking notes you exchange with other users. Messages are stored so both parties can access their conversation history and so we can investigate reports, disputes, fraud, and policy violations. Automated scanning flags contact details and off-platform payment attempts as described in our Safety & Trust Policy.

Uploaded media. Photos, videos, portfolio work, and other files you upload, together with any metadata contained in those files. Remove EXIF/location metadata before uploading if you do not want to share it.

Booking and transaction information. Services booked, prices, schedules, deliverables, statuses, cancellations, disputes, refunds, payouts, reviews, and ratings.

Payment information. Payments and payouts are processed by Stripe, Inc. and, for Creators, by Stripe Connect. We do not receive or store full card numbers or bank credentials. We store payment metadata such as amount, currency, card brand and last four digits, payment status, Stripe identifiers, payout status, and account onboarding status. Stripe processes your information under its own privacy policy.

Identity verification information. If you request verification, you may submit a government-issued ID and a selfie. These files are stored in a private, access-controlled bucket, are readable only by you and our review team, and are used solely to confirm identity and prevent fraud. Stripe may separately collect identity and business information as required by financial regulation.

Device and usage information. IP address (and the approximate country/region/city derived from it), device type, operating system, browser type, app version, referring pages, pages and profiles viewed, clicks, search queries, session timestamps, and diagnostic/crash logs.

Cookies and local storage. Session tokens, security tokens, preferences, and analytics identifiers. See our Cookie Policy.

Information from others. Content other users create about you (reviews, reports, messages), and information from sign-in providers (name, email, avatar) when you use social login.

2. How we use information

We use personal information to: (a) create and operate your account; (b) display profiles, portfolios, and search results; (c) enable bookings, offers, messaging, opportunities, and reviews; (d) process payments, escrow, refunds, and payouts through Stripe; (e) verify identity and maintain trust badges; (f) detect, investigate, and prevent fraud, scams, spam, abuse, and policy violations; (g) provide customer support and resolve disputes and chargebacks; (h) send transactional messages (booking updates, payment receipts, security alerts) and, with your consent where required, marketing messages; (i) measure and improve the Service; and (j) comply with legal, tax, and accounting obligations.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

3. Legal bases for processing (GDPR / UK GDPR)

Where the EU or UK GDPR applies, we rely on: performance of a contract (operating your account, bookings, payments); legitimate interests (security, fraud prevention, service improvement, direct communications about the Service); consent (non-essential cookies, marketing, optional location precision) — which you may withdraw at any time; and legal obligation (tax, accounting, anti-fraud, lawful requests).

4. How we share information

With other users. Your public profile, portfolio, ratings, and reviews are visible to other users and, if your profile is public, to search engines. When a booking or application is made, we share the information the counterparty needs to complete it (name, avatar, messages, agreed scope, schedule, and any location you provide).

With service providers (subprocessors). Stripe (payments, Connect payouts, fraud tooling), our cloud database, authentication, and storage provider, Cloudflare (edge delivery and security), transactional email providers, analytics providers, and error monitoring providers. Providers may process data only on our instructions.

For legal reasons. To comply with law, subpoenas, or lawful requests; to enforce our Terms and policies; or to protect the rights, property, or safety of users, the public, or BACKEND Booking.

Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

Aggregated or de-identified data. We may publish or share information that cannot reasonably identify you.

5. Security

We use TLS in transit and encryption at rest, row-level access controls that scope data to the account that owns it, private storage buckets for sensitive uploads, scoped API keys, least-privilege service credentials, and logging of sensitive administrative actions. Card data never touches our servers. No system is perfectly secure; you are responsible for keeping your credentials confidential and for using a unique password. If we become aware of a breach affecting your personal information, we will notify you and regulators as required by law.

6. Data retention

We keep account, profile, and content data while your account is active. After you delete your account we remove or de-identify personal data within 30 days, except where longer retention is required: transaction, tax, and payout records (typically 7 years), records needed for fraud prevention and repeat-offender enforcement, dispute and chargeback evidence until the matter is resolved, and any data we must retain by law or legal hold. Messages remain visible to the other participant in a conversation, and reviews may remain published in de-identified form.

7. Your rights

Subject to your location, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to withdraw consent. You can edit your profile in Settings → Profile, control visibility in Settings → Privacy, manage messages in Settings → Notifications, and export or delete your account in Settings → Account. To make a formal request, email contact@backendbooking.com from your account email; we respond within 30 days (extendable to 60 where permitted) and may need to verify your identity. We will not discriminate against you for exercising these rights. EU/UK/Swiss users may lodge a complaint with their supervisory authority.

8. California privacy rights (CCPA / CPRA)

In the past 12 months we have collected the categories of personal information described in Section 1, including identifiers, commercial information, internet activity, geolocation (approximate), audio/visual information (uploaded media), professional information, and, if you submit it, government identifiers for verification. Sources, purposes, and disclosures are described in Sections 1, 2, and 4.

California residents have the right to know, access, correct, and delete personal information; to opt out of the "sale" or "sharing" of personal information; to limit the use of sensitive personal information; and to be free from discrimination. We do not sell or share personal information as those terms are defined by the CPRA, and we do not use sensitive personal information for purposes other than providing the Service, security, and fraud prevention. Submit requests to contact@backendbooking.com. Authorized agents may submit requests with written permission and proof of identity.

9. International transfers

We operate in the United States, and your information may be processed there and in other countries where our providers operate. Where required, we rely on Standard Contractual Clauses, the UK Addendum, or another lawful transfer mechanism.

10. Children's privacy

The Service is intended only for users 18 years or older. We do not knowingly collect personal information from anyone under 18. If we learn that a minor has created an account, we will terminate it and delete the associated data. If you believe a minor is using the Service, contact contact@backendbooking.com.

11. Account deletion

You can delete your account at any time from Settings → Account. Deletion removes your profile, portfolio, media, and personal data from the Service on the schedule in Section 6. Deletion does not cancel obligations for bookings already in progress, and funds held in escrow are resolved under our Refund & Cancellation Policy before closure completes.

12. Third-party services

Profiles may link to third-party sites, and payments run through Stripe. We are not responsible for the privacy practices of third parties; review their policies directly.

13. Changes to this Policy

We may update this Policy. Material changes will be announced in the Service or by email at least 7 days before they take effect. The "Last updated" date above always reflects the current version.

14. Contact us

BACKEND Booking LLC — Privacy team.
Email: contact@backendbooking.com
Support: Contact & Support

This document is provided for transparency and is not legal advice. Have a licensed attorney review it before relying on it.