Genie AppsGenie Apps Help Center

Privacy Policy

Genie Appointment Booking — Last updated September 2, 2026

This Privacy Policy explains how Genie Appointment Booking (“the App”, “we”, “us”, or “our”) collects, uses, stores, and shares information when merchants install and use the App on their Shopify store, and when their customers book appointments through the App.

By installing or using the App, you agree to this Privacy Policy. If you do not agree, uninstall the App and stop using it.

1. Who we are

Genie Appointment Booking is a Shopify app that lets merchants turn products into bookable services (time slots, staff, locations, and related settings) and collect bookings through a storefront widget and Shopify checkout.

For privacy questions, contact us at support@genieapps.xyz.

2. Roles and Shopify

When a merchant installs the App, the merchant is typically the data controller for their customers' personal data. We process that data on the merchant's behalf to provide booking features, and we also process certain merchant and shop data as needed to operate the App.

The App runs on Shopify. Shopify's own policies apply to data Shopify processes as the ecommerce platform. This Policy covers data we process in connection with the App.

3. Information we collect

3.1 Merchant and shop information

  • Shopify shop domain and session / authentication data needed to install and run the App
  • Merchant-configured content: staff profiles (name, email, phone, photo, bio, role), locations (address and contact details), services, availability, widget and notification settings, and translation copy
  • Optional delivery credentials the merchant supplies (for example Twilio or Meta WhatsApp API credentials) stored so the App can send notifications the merchant enables
  • Shopify Admin API data within granted scopes, including products, publications/files, and order information related to bookings

3.2 Customer and booking information

When a customer books through the App (or when booking data is created from a related Shopify order), we may process:

  • Name, email address, and phone number
  • Shopify customer ID (when available)
  • Appointment details: service, staff, location, start/end time, timezone, status, capacity/seat information
  • Order identifiers and amounts paid (order ID, order name, currency)
  • Answers to merchant-defined custom booking questions and optional merchant notes
  • Tokens used for customer self-service actions such as cancel or reschedule links

3.3 Technical and usage information

  • Server logs and operational diagnostics (for example request timing, errors, and webhook delivery status)
  • Device or browser information incidentally present in standard HTTP requests when accessing App pages or the storefront widget

We do not intentionally collect payment card numbers. Payments are processed by Shopify Checkout.

4. How we use information

  • Provide, operate, secure, and improve the App
  • Create and manage bookable services, staff, locations, and schedules
  • Create, display, reschedule, cancel, and otherwise manage bookings
  • Send transactional messages the merchant enables (for example confirmation, reminder, cancellation, or reschedule notices) by email, SMS, or WhatsApp using the merchant's configured providers
  • Sync with Shopify orders and products as required for booking flows
  • Respond to Shopify mandatory compliance webhooks (customer data request, customer redact, shop redact)
  • Provide merchant support and investigate abuse or errors
  • Comply with law and enforce our Terms of Service

We do not sell personal information. We do not use customer booking data for unrelated advertising.

5. How we share information

We may share information with:

  • Shopify — to authenticate the App, sync products and orders, and fulfill platform requirements
  • Infrastructure providers — for example hosting (such as Vercel) and database hosting used to run the App
  • Email delivery providers — such as Resend, to send transactional email
  • SMS / WhatsApp providers — such as Twilio or Meta, when the merchant enables those channels and supplies account credentials
  • The merchant — booking and customer details are available to the installing merchant in the App admin
  • Professional advisors or authorities — when required by law or to protect rights and safety

Subprocessors only receive what is needed to perform their services for us or for the merchant.

6. Data retention

  • Booking and related shop-scoped data are retained while the App is installed and as needed to provide the service
  • When a shop uninstalls the App, or when Shopify sends a shop/redact compliance webhook, we delete shop-scoped App data associated with that shop (including bookings, staff, locations, services, settings, and sessions), subject to short-term backups and legal retention needs
  • When Shopify sends a customers/redact webhook, we anonymize matching customer personal fields on bookings for that shop (for example name, email, phone, customer ID, custom answers, and notes)
  • When Shopify sends a customers/data_request webhook, we locate booking records we hold for that customer so the merchant can fulfill the request as required by Shopify's process

7. Security

We use reasonable administrative, technical, and organizational measures appropriate to the nature of the data, including encrypted transport (HTTPS), access controls, and verified Shopify webhook authentication. No method of transmission or storage is completely secure.

8. International transfers

The App and its subprocessors may process data in countries other than where the merchant or customer is located. Where required, we rely on appropriate safeguards offered by those providers and applicable law.

9. Your rights and choices

Merchants can access, update, or delete much of their App configuration in the Shopify admin App UI, and can uninstall the App at any time.

Customers should contact the merchant (the store) for requests about their booking or personal data. Depending on location, individuals may also have rights to access, correct, delete, or restrict processing of personal data, or to object to certain processing. We will assist merchants with Shopify compliance webhooks and reasonable requests related to data we process.

Contact support@genieapps.xyz for privacy requests directed to us as the App provider.

10. Children

The App is intended for merchants operating Shopify stores and is not directed to children under 16. We do not knowingly collect personal information from children through the App.

11. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the App after an update constitutes acceptance of the revised Policy where permitted by law.

12. Contact

Genie Appointment Booking

See also our Terms of Service.