Privacy Policy

Last Updated: July 16, 2026

1. Introduction

Reelin Booking, operated by Reelin Solutions Inc., a British Columbia corporation ("Reelin", "we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, use our apps, or use our booking platform (the "Services").

Two roles, stated plainly: for the business owners and staff who hold Reelin accounts ("Business Users") and for website visitors, Reelin decides how account data is handled and is responsible for it. For the customers of those businesses ("Clients") who book appointments, Reelin processes booking information on behalf of the Business User — your service provider controls that data, and Reelin acts as their service provider (data processor).

2. Information We Collect

  • Information You Provide to Us:
    • Account Data: Name, email address, phone number, business name, and password when you register.
    • Financial & KYC Data: To accept payments through Stripe Connect, Business Users provide identity verification (KYC) data — such as date of birth, business/tax identifiers, address, and government ID — directly to our payment processor (Stripe). This information is governed by Stripe's privacy policy; Reelin does not store it.
    • Billing Data: Payment card details for subscriptions are collected and vaulted by Stripe. Reelin never stores full card numbers on our servers.
    • Booking & Client Data: Information Clients or Business Users enter to manage appointments — names, contact details, appointment history, notes, and answers to a business's booking questions. Reelin processes this on the Business User's behalf.
    • Service Addresses (mobile services): When booking a business that travels to its customers (e.g., mobile detailing), the Client's service address and access details (such as parking or gate notes, and whether water/power are available) are collected so the provider can perform the service. This is shared only with that business.
    • Photos & Media: Images uploaded to the platform (e.g., business logos, staff photos, service photos).
    • Communications: Content of messages you send to us or through the platform (e.g., support messages, feedback reports, SMS/email content).
  • Information We Collect Automatically:
    • Usage Data: Pages visited, features used, and interaction data.
    • Device Data: IP address, browser type, operating system, and device identifiers.
    • Error & Diagnostic Data: When something goes wrong (and for a small sample of sessions), our monitoring service (Sentry) collects error details and a limited session replay to help us fix problems. Replays mask all text you type and block media — they capture interface interactions, not your readable content.
    • Push Notification Tokens: If you enable notifications, we store the subscription token needed to deliver them to your device.
    • Cookies & Local Storage: We use essential cookies (e.g., to keep you signed in) and local storage for device preferences. We do not use advertising trackers, ad networks, or third-party marketing cookies.

3. How We Use Your Information

  • To provide, operate, and maintain the Services — including delivering booking confirmations, reminders, and notifications on behalf of your service provider.
  • To process subscription payments and manage accounts.
  • To send transactional messages (e.g., booking confirmations, password resets, billing receipts).
  • To send marketing communications only where you have opted in — with an unsubscribe option in every message (see Section 10).
  • To power AI-assisted features (e.g., drafting marketing content for Business Users).
  • To monitor performance and fix errors, and to detect, prevent, and address abuse or fraud (including IP-based rate limiting).
  • To comply with legal obligations.

4. Sharing Your Information

SMS Consent & Mobile Data Sharing

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We do not sell your personal data. We share information only as follows:

  • With your service provider: When a Client books an appointment, the booking details (including any service address) are shared with that Business User — that is the purpose of the platform.
  • Service Providers (subprocessors): Vendors who perform services on our behalf, under their own contractual and legal obligations:
    • Stripe — payment processing, identity (KYC) verification, and fraud prevention.
    • Telnyx — SMS delivery; Resend — email delivery.
    • Supabase — database and authentication; Vercel — application hosting; Upstash — abuse-prevention rate limiting.
    • Sentry — error monitoring and masked session replay diagnostics.
    • AI providers (e.g., Google) — powering AI-assisted features.
  • Business Transfers: If we are involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to this policy.
  • Legal Requirements: We may disclose information where required by law or in response to valid requests by public authorities.

5. Where Your Data Is Stored

Our infrastructure providers store and process data in Canada and/or the United States. When your information is processed outside Canada, it may be subject to the laws of those jurisdictions (including lawful access by their authorities). By using the Services, you acknowledge this cross-border processing. We choose reputable providers with strong security practices regardless of region.

6. Data Retention & Deletion

  • We retain personal information for as long as your account is active or as needed to provide the Services.
  • Self-serve deletion: Business Users can delete their account and business data from Settings, or by emailing us. Clients should direct deletion requests to their service provider (who controls the booking data); we will assist the Business User in honouring such requests.
  • Limited data may be retained after deletion where necessary to comply with legal, tax, or accounting obligations, resolve disputes, enforce agreements, or maintain security logs — then deleted.
  • Residual copies in encrypted backups are purged on the backup rotation schedule.

7. Security & Breach Notification

We protect data using encryption in transit (TLS/SSL), encryption at rest with our database provider, row-level tenant isolation (each business's data is segregated), and least-privilege access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

If a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and keep records of the breach as the law requires.

8. Your Data Rights

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate information.
  • Deletion — request erasure of your personal data, subject to legal retention requirements.
  • Portability — receive your data in a usable format (Business Users can self-serve export from Settings).
  • Withdraw consent — at any time, subject to legal or contractual restrictions.

Clients: because your booking data is controlled by your service provider, the fastest path is to contact them directly; you can also email us and we will assist. To exercise any right, contact info@reelinbooking.ca. We may need to verify your identity before acting on a request.

9. Children's Privacy

Reelin accounts are for adults: you must be at least 18 (or the age of majority in your province) to register as a Business User. Appointments for minors should be booked by a parent or guardian, who provides any information on the minor's behalf. We do not knowingly collect personal information directly from children; if you believe a child has provided us personal data, contact us and we will delete it.

10. Marketing Communications (CASL)

We — and Business Users using the platform — send commercial electronic messages only with consent as required by Canada's Anti-Spam Legislation (CASL) and comparable laws. Every marketing email includes the sender's identity and a working unsubscribe link, honoured promptly. You can also opt out by contacting us. Transactional messages (booking confirmations, reminders, password resets, billing receipts) are not marketing and will still be sent as part of the service.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last Updated" date above; for material changes we will provide additional notice through the Services or by email.

12. Canadian Privacy Rights (PIPEDA) & Privacy Officer

Reelin collects, uses, and discloses personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including British Columbia's Personal Information Protection Act (PIPA). You may access or correct your personal information, or withdraw consent, as described in Section 8. Our designated Privacy Officer can be reached at info@reelinbooking.ca. If you are not satisfied with our response to a privacy concern, you may contact the Office of the Privacy Commissioner of Canada (oipc.bc.ca for British Columbia matters).

13. Contact Us

Questions about this Privacy Policy:

Privacy Policy | Reelin Booking | Reelin Booking