Legal
Privacy policy
This Privacy Policy is currently in effect and governs information collected through booknox.com.
BookNox is a service-vendor booking platform: vendors (photographers, wedding planners, DJs, officiants, venues, florists) configure their packages once and send their own clients a hosted page where the client picks options, signs the agreement, and pays the deposit. This Policy explains what BookNox collects, how it’s used, who it’s shared with, and what rights you have. We collect the minimum we need to operate the platform and respect rights under US state privacy laws.
Who we are
BookNox is operated by NetNest Design LLC, a Wyoming limited liability company. References to “BookNox,” “we,” “us,” or “our” in this Policy refer to NetNest Design LLC operating under the BookNox brand.
Information we collect
From vendors who sign up to use the platform
- Email address: required for vendor sign-in (we use a one-time link instead of a password).
- Business name and display name: what your clients see on your hosted page and in proposal emails.
- Package and pricing configuration: the data you enter into your BookNox dashboard for the calculator and proposals.
- Stripe Connect Express account identifier: when you onboard with Stripe through BookNox, Stripe creates a connected account on your behalf and shares its identifier with us so we can route payments. Your sensitive KYC information (SSN, date of birth, full bank account number, ID documents) is collected by Stripe directly through a Stripe-hosted form and is never transmitted to or stored by BookNox. Stripe’s own privacy policy governs that data.
- Google account email and Calendar OAuth tokens: when you connect Google Calendar, Google asks you to authorize BookNox to create events on your calendar. We receive a refresh token, which we encrypt at rest (AES-256-GCM) and use to insert new booking events on the calendar you authorized and to read your free/busy availability (only whether a time is busy or free, never event titles, descriptions, or attendees) so your public booking page can show clients which dates are open. We do not read the contents of your existing events.
- Sign-in session metadata: your IP address, user agent, and timestamp at sign-in time, retained for security and audit purposes.
- Subscription consent record: when you start a paid subscription, we record that you affirmatively agreed to the auto-renewing charge, with the date, your IP address, and your browser/device user agent, as the consent audit trail expected by automatic-renewal laws. Billing itself is handled by Lemon Squeezy as merchant of record.
From clients who view, sign, and pay through a vendor’s BookNox page
- Name and email address: required for the vendor to send you a proposal and for you to receive the signed contract and deposit receipt.
- Booking requests you submit on a vendor’s public booking page: when you configure a quote and submit a booking request at booknox.com/book/[vendor], we collect the name, email address, event date, and optional message you enter, the package options you selected with the computed quote, and your IP address (logged to keep the form safe from abuse). This is used to create and email you the vendor’s proposal and to show the vendor your request. Booking requests are deleted after 12 months; if your request became a signed agreement, the agreement itself is retained under the contract-retention rules below.
- Abandoned quotes: if you enter your email address and configure a quote on a vendor’s booking page but leave without submitting your request, we keep your email, name (if entered), the package options you selected with the computed quote, and your IP address and browser user-agent (logged to keep the form safe from abuse). We use this only so the vendor can follow up with you about the quote you started. We do not send you automated marketing for it. These records are deleted after 12 months, or sooner, if you ask us to remove them (see “Your rights” below), or once your quote becomes a signed agreement (then the agreement is retained under the contract-retention rules below).
- Testimonials: if a vendor accepts our invitation to share a testimonial, we collect the quote they write, the name and role they choose to be credited as, and a consent record (the time, IP address, and browser user-agent of their consent). We publish a testimonial only after the vendor explicitly consents AND we approve it. An approved testimonial is retained as consented public content; a requested-but-unsubmitted or declined one is deleted after 12 months. A vendor can ask us to unpublish theirs at any time by emailing support@booknox.com.
- Service date and event details: what the vendor entered when building your proposal (or what you entered on the vendor’s public booking page).
- Signature record: when you sign a proposal, we capture the typed name or drawn signature image; your IP address; your browser/device user agent; the time you consented to sign electronically; and the time you signed. This audit trail is required for the signature to be legally binding under the federal ESIGN Act (15 U.S.C. §7001) and the Uniform Electronic Transactions Act (UETA). We store these elements together with a copy of the signed agreement and a cryptographic hash of the signed PDF as tamper evidence.
- Payment metadata: when you pay a deposit, Stripe collects your card or bank account details directly through a Stripe-hosted page and processes the charge. BookNox receives only payment metadata (amount, currency, payment method type, success or failure) and never receives your full card number, CVV, or bank account number.
From everyone (vendors, clients, and site visitors)
- Technical metadata on form submission: IP address, user agent, and timestamp captured at the moment of submission (waitlist sign-up, contact form, sign-in request, access-code entry, signature submission). Retained for security, abuse prevention, and evidence preservation.
- Hosting platform usage logs (Vercel): including request paths and basic geolocation derived from IP. Standard server logs; not used for advertising or profiling.
How we use the information
- To operate the platform: sign vendors in, render their hosted page to their clients, generate proposals and signed contracts, route payments through Stripe to the vendor’s bank, and create calendar events on the vendor’s connected calendar.
- To deliver transactional notifications: proposal sent, signed-contract delivery (with the signed PDF attached), deposit received, paid receipt (with an .ics calendar invite attached for the client).
- To run the site securely: rate-limiting, abuse detection, signature audit trail preservation, fraud monitoring at the Stripe layer.
- To answer your messages: when you submit a contact form, send a sign-in request, or reply to a transactional email.
We do not use your information for advertising or behavioral profiling. The only analytics we run is Vercel Web Analytics, cookieless and privacy-first: it records anonymous, aggregate page views with no cookies, no cross-site tracking, and no individual profiling. We run no third-party advertising trackers, pixels, or behavioral-profiling scripts.
We do not sell your personal information
BookNox does not sell or share your personal information for cross-context behavioral advertising. We do not lease, trade, or otherwise provide your information to data brokers or marketing list vendors.
Service providers
We rely on the following providers to operate the platform. Each acts as a processor of data on our behalf or, in Stripe’s case for vendor onboarding and customer payments, as an independent controller for the data they collect directly from you.
- Stripe, Inc.: payment processing and Stripe Connect Express vendor onboarding. Stripe collects KYC information from vendors and payment information from clients directly through Stripe-hosted forms. Governed by stripe.com/privacy.
- Lemon Squeezy (a Stripe Inc. company): merchant of record for vendor subscriptions to the BookNox platform. Lemon Squeezy collects vendor billing details (card or payment method, billing address, tax-residency information) directly through their hosted checkout and customer portal, issues the invoice or receipt for each subscription charge, and collects and remits any applicable sales tax, VAT, or GST. BookNox receives only subscription-state metadata (customer identifier, status, plan, renewal or cancellation dates) via webhook. Governed by lemonsqueezy.com/privacy.
- Neon, Inc.: Postgres database hosting (via the Vercel Marketplace). Stores vendor accounts, proposal records, signature audit trails, and booking records. US-region.
- Vercel, Inc.: site hosting, server function runtime, domain registration, DNS, and private Blob storage for signed PDFs and signature images.
- Resend, Inc.: transactional email delivery (proposal links, signed-contract attachments, deposit receipts, ICS calendar invites, sign-in links).
- Google LLC (Google Calendar API): only when a vendor explicitly authorizes BookNox to write events to their Google Calendar and read free/busy availability (busy/free time ranges only, never event titles, descriptions, or attendees) to show open dates on their public booking page. We do not read the contents of existing events. The authorization is revocable at any time.
- Geoapify GmbH (mapping & distance): when you type an event address on a vendor’s booking page to get an exact travel quote, we send that address to Geoapify to find its location, measure the driving distance from the vendor’s studio, and render a route map. Optional: leaving the address blank skips Geoapify entirely (the vendor sets travel manually).
For a structured, always-current version of this list, including what each provider handles and where it operates, see our Subprocessors page. We update it whenever our subprocessors change and notify active vendors before any material change takes effect.
How long we keep your information
- Vendor account data: retained for as long as your account is active and for a reasonable period afterward to satisfy tax, audit, and dispute-resolution obligations.
- Signed contracts and signature audit trails: retained as part of the immutable record of a legally-binding agreement, per ESIGN Act and UETA retention principles. Even after an account is closed, signed agreements remain available so both parties can produce them if needed.
- Payment records: retained as required by Stripe and applicable tax law (typically 7 years for IRS recordkeeping).
- Booking requests from public booking pages: deleted 12 months after submission. The proposal generated from a request (and any signed agreement) is retained under the contract-retention rules above.
- Server logs and rate-limit metadata: roll off on a short rotation (typically 30 days).
- Waitlist contacts: kept until you ask us to delete them or until we shut down the product.
Your rights under US state privacy laws
Depending on where you live, you have rights under state privacy laws including the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, and similar laws in other states. These rights generally include:
- The right to know what we have about you.
- The right to a copy of your information.
- The right to delete your information.
- The right to correct inaccurate information.
- The right to opt out of any sale or sharing of your data (we do not do either; this opt-out is automatic).
- The right to be free from retaliation for exercising your rights.
To exercise any of these rights, email privacy@booknox.com or use our contact form. We’ll confirm receipt within 10 days and respond within 45 days of a verifiable request; where reasonably necessary we may extend once by an additional 45 days and will notify you of the extension and the reason. We may need to verify your identity before acting, and may decline requests we cannot verify. We will not retaliate against you for asking.
One important note on deletion: signed contracts cannot be deleted on request because they document a legally-binding agreement between you and a counterparty (the vendor or the client), and federal ESIGN Act retention principles require both parties to have access to the executed record. We will, however, delete the rest of your account data on request.
Security incidents
We maintain administrative, technical, and physical safeguards designed to protect your information. In the event of a data breach affecting your personal information, we will notify affected users and, where applicable, regulators, without undue delay and within the timeframes required by applicable law.
Children
BookNox is built for professional service vendors and their clients. We do not knowingly collect information from anyone under 18. If you believe a minor has submitted information to us, please contact privacy@booknox.com so we can delete it.
Changes
We’ll update this page if our practices change. The “Last updated” date at the top reflects the most recent revision. Material changes will be sent to active vendors via the email on file.
Contact
For any privacy question or to exercise your rights, email privacy@booknox.com or use our contact form.