SureBook

Privacy

Two separate things are described here: this website, and the SureBook plugin. They are not the same, and the distinction matters if you are working out your own obligations.

This website

This site is static HTML. It sets no cookies, runs no analytics, loads no fonts or scripts from anywhere else, and has no forms. It collects nothing about you. The server keeps ordinary web-server access logs — the address the request came from, the page asked for, the time — which are used to keep the site running and are not combined with anything else or shared.

The SureBook plugin

Bookings made through SureBook are stored in your own WordPress database, on your own hosting. They are not sent to us. We do not receive, hold, or have access to your customers' details. If you install the free plugin and never use the paid service, no data about your site or your customers reaches us at any point.

That means that for the personal data your customers give you, you are the controller and we are not a processor of it. Your obligations to your customers are yours, and this page cannot discharge them.

What the plugin stores in your database

Booking detailsService, resource, start and end time, price, and payment status.
Customer detailsThe name, email address and phone number given when booking.
Payment referencesAn identifier for the Stripe payment, and whether it was made in test or live mode.
A management tokenA random string that lets a customer open their own booking from the link in their confirmation email, without an account.

Card details are never stored, and never reach your server. They are typed into fields hosted by Stripe and sent directly to Stripe. Your site holds a reference to the payment and nothing that could be used to make another one.

Where data goes outside your site

StripeIf you connect Stripe, your site sends the amount, currency, and the booking details you configure to Stripe in order to take payment, and the customer's browser loads Stripe's own payment fields from js.stripe.com. Stripe is the processor for that payment, under your Stripe agreement with them. See Stripe's privacy policy.
Nothing elseThe free plugin contacts no other service. It does not phone home, check licences, report usage, or send us statistics.

The payment-page script check

When you use the payment-page script inventory, your site requests one of its own pages over HTTP and reads the list of scripts in the response. That request goes to your own site and nowhere else. The list is stored in your own database. Inline scripts are recorded by size and by a one-way fingerprint, not by copying their contents.

Email

The plugin sends booking confirmations to your customers using whatever email your WordPress site is already configured to use. It does not route mail through us.

Deleting data

Uninstalling the plugin always removes its settings. Your bookings and customer records are kept unless you switch on the "delete all data on uninstall" option first — deleting a plugin is often an accident or a debugging step, and customer records are not something software should discard on that basis.

The paid service

The paid tier is in development and not yet available. When it exists it will necessarily involve your site communicating with a server we run, and this page will be updated to describe exactly what is sent before that happens.

Contact

Questions about this policy: [contact address to be added before publication].

Please read this properly before relying on it

This page is accurate about what the software does — that part has been checked against the code. It has not been reviewed by a lawyer, and whether it satisfies your obligations in your jurisdiction is not something it can tell you.