PrivacyMinimal data, by designExport or delete anytime

Privacy Policy

What we collect, and why.

This policy explains what Book247 gathers when a business runs its front desk through us, and when that business's own customers call, text or chat in.

Last updated August 17, 2026

1. Who this policy covers

This policy applies to book247.app and to every channel Book247 answers on behalf of a business that runs its front desk on us: phone, SMS, WhatsApp, web chat and the booking widget. It covers three groups of people: visitors to this site, the appointment businesses that subscribe to Book247 ("Customers"), and the Customers' own patients, clients and callers ("End Users") who book, reschedule or ask a question through a Customer's Book247 number or widget.

Where an End User's data is involved, the Customer is the one who decides what gets collected and why; Book247 processes it on the Customer's instructions. If you are an End User with a question about a specific booking, the fastest answer is usually the business you booked with directly.

2. Book247 and The AI Leap

Book247 is a product and a brand. It is operated by The AI Leap, the registered company behind it. Wherever this policy says "we," "us" or "Book247," it means The AI Leap acting under the Book247 name.

3. What we collect

The rule we hold ourselves to: name, phone, email, and what was booked, nothing else without an explicit opt-in. In practice that means:

  • Name, phone number and email address, when given during a call, text, chat or web form.
  • Appointment details: service, provider, time, location and any note attached to the booking.
  • Call and message content, as text: what was said or written, to the extent needed to route the conversation and complete the booking.
  • Call recordings and audio, only where a Customer has explicitly turned recording on for a location. See Call recording and transcription below.
  • Standard technical data from anyone browsing book247.app: IP address, browser type, and pages viewed, collected the way most websites do.

We do not collect payment card numbers, government ID numbers, or diagnosis-level health record detail. Card payments run through Stripe or Razorpay directly; Book247 never sees the card number.

4. How we collect it

Directly from a call answered by the Book247 agent, a text or WhatsApp conversation, a web chat or booking-widget session, a form on book247.app (demo request, contact, pricing questions), or from a Customer's own staff when they set up an account, add providers, or import existing customer records.

5. How we use it

  • To answer the call, text or chat, identify a returning customer, and check real availability.
  • To hold, book, reschedule or cancel an appointment according to the Customer's own rules.
  • To write the appointment, note and any relevant detail into the Customer's practice software, so nothing has to be re-entered by hand.
  • To send transactional confirmations and reminders for that appointment.
  • To provide support, secure the service, and meet legal and regulatory obligations.

6. Call recording and transcription

Recording is off by default. A Customer has to switch it on, per location, before any call is recorded. Turning it on runs a jurisdiction check for two-party consent requirements and turns on a mandatory notice at the start of the call, before recording begins.

Transcripts are kept for 90 days and recordings for 30 days by default, removed automatically by a nightly job rather than a manual process.

7. AI processing and model training

Calls and messages are handled by an AI agent restricted to a fixed set of tools: it can look up availability, match a customer, hold a slot and write a booking, and nothing outside that list. The agent never writes to the database directly; every action goes through a tool that enforces the Customer's own rules.

Conversations are never used to train the underlying AI models. Before anything reaches application logs, error tracking, or the model provider's own logs, a redaction layer strips phone numbers, email addresses, names, addresses and transcript text.

9. Sharing and sub-processors

We do not sell personal data. We share it only with the vendors that keep the service running:

  • Twilio, for voice and messaging in the US, Canada, UK and Australia.
  • MSG91 and Gupshup, for SMS and WhatsApp in India.
  • Vapi, for the voice AI infrastructure behind phone calls.
  • Stripe Connect and Razorpay Route, for payments; Book247 never sees a card number.
  • Our hosting and database providers, who store the data the service runs on.
  • The Customer's own practice-management or EHR software, where a booking is written back at the Customer's instruction.

A current sub-processor list and a signable Data Processing Agreement are available on request at security@book247.com.

10. International transfers

Where a Customer is based determines where its data lives: EU and UK data is stored in an EU or UK region, US and Canadian data in a US region, and Indian data in India once volume justifies a local region. This is a deployment setting, chosen per Customer, not a rewrite per request.

11. Retention

  • Call transcripts: 90 days.
  • Call recordings, where enabled: 30 days.
  • Cancelled appointments: 24 months.
  • Active account and booking data: for as long as the Customer's account stays active.

These windows are enforced automatically, every night, not by manual cleanup.

12. Your rights

Export or delete your data any time from account Settings, at no charge and with no exit fee. End Users can also ask the business they booked with directly. Depending on where you are, you may have additional rights, access, correction, restriction or portability, under GDPR, UK GDPR, India's DPDP Act, or applicable US state privacy law; we honor requests within the window each regime requires.

13. Security

Data is encrypted in transit and at rest, every business's data is isolated from every other business's at the database layer, and access is controlled by role. For the commitments specific to protected health information, including our Business Associate Agreement, see the HIPAA & BAA page.

14. Children's privacy

Book247 is not directed at children. Where a booking is for a minor, for example a pediatric appointment, the information involved is provided by a parent or guardian on the minor's behalf.

15. Changes to this policy

When this policy changes, we update the date at the top. For changes that materially affect how we handle your data, we'll also notify Customers directly by email.

16. Contact

Questions about this policy or a specific request: reach us at support@book247.com for account and data requests, or security@book247.com for security and compliance questions.