Effective Date: 01.07.2023 Last Updated: 01.09.2026 Version: 3.2
At bookaLEAP B.V. (“bookaLEAP”, “we”, “us”, or “our”), we value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your information when you use our platform, apps, services, and website.
We comply with the General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (UAVG), and other applicable privacy laws.
bookaLEAP B.V. Jan Pieter Heijestraat 107H, 1053 GN, Amsterdam, Netherlands KvK: 89959973 — VAT: NL86516506B01 info@bookaleap.com
We act as a Data Controller for personal data collected through our platform and services.
If you register as a professional (Partner) or a Business, we additionally collect the data we need to verify you and pay you:
Event organizers may ask registration questions (for example about experience level or information relevant to participating safely). Your free-text answers are stored with your registration and shared with the organizer of that event. If you choose to include health-related information in an answer, see Section 5.
Feed posts, comments to the extent the platform supports them, and images you upload (profile photos, post images) are stored and displayed as you direct.
If you contact us through our public contact or event-hosting forms, we collect the name, email address, and message you submit.
If you connect your Google Calendar for availability sync, we store your Google account email and the access tokens Google issues — encrypted — and use them only for the sync you configured.
To work out when you are unavailable, we read the events in your selected calendar within the window we are checking. From each event we use only whether it is cancelled, whether it is marked “free” or “busy”, whether you declined it, and its start and end times. All we derive from this is a list of busy periods — the start and end times of blocks in which you are unavailable — which is held briefly in memory (up to one minute) and never written to our database. Event titles, descriptions, locations, attachments, and the identities of other attendees are never stored by us.
We also write events into that calendar for the bookings you receive, and update or remove those events when a booking changes or is cancelled. We only ever modify or delete events that bookaLEAP created; events you or anyone else created are never changed.
That is how calendar sync works on the bookaLEAP platform. Our earlier ILU app, which is still running while we migrate people across, syncs calendars differently: it connects through Nylas (section 7), and that integration receives more than busy times — event titles, times, attendees and updates — because it keeps whole events in step across platforms rather than only reading availability. If you connected a calendar in the ILU app, that is the integration you authorised. Disconnecting it there ends it; connecting on the new platform gives you the narrower access described above.
How we handle this data is further restricted by the Limited Use commitments in section 7.
If you allow push notifications in our mobile app, we store the notification token your device’s operating system issues, which platform it is (Android or iOS), and when we last saw it. The token identifies a device rather than you by name, but we keep it against your account so we can reach your devices, so we treat it as your personal data.
We keep at most the ten most recently used devices per account; registering an eleventh removes the least recently used one. If you never allow push notifications, we never hold a token for you and this section does not apply to you.
If you review a Partner who coached you or a Business whose venue hosted you, we store the rating you gave, any text you wrote, which booking earned you the right to write it, and when. The review is published: your first name and profile picture appear next to it on that Partner’s or Business’s public profile, which anyone can read without signing in. Your full name, phone number and email address are not shown.
A review is also personal data of the person it is about. Do not include anyone else’s personal data in the text.
If someone reports your review and we decide to hide it, we keep the report, our decision and the reason for it, and we send that reason to you.
If you send us feedback about the app, we store what you wrote, which account sent it, when, and — so that a bug report carries the build it came from — the platform and app version you sent it from. Feedback is a private channel to our team: unlike a review it is never published and no other user can see it.
Write what you like about the app itself, but please do not include other people’s personal data, and do not use it to raise a complaint about a specific person — that is what the report route on a review, and info@bookaleap.com, are for.
| Purpose | Legal Basis |
|---|---|
| To provide and manage user accounts (including phone/email verification and SSO sign-in) | Contractual necessity |
| To publish the reviews you write, and to show ratings on Partner and Business profiles | Contractual necessity |
| To read, triage and act on feedback you send us about the app | Legitimate interest |
| To assess reports about a review and record the decision and its reason | Legal obligation (Digital Services Act) |
| To book, schedule, and deliver sessions, class packs, and events | Contractual necessity |
| To process payments via Stripe and issue invoices | Contractual necessity / Legal obligation |
| To verify Partners and Businesses before they can offer services or receive payouts | Contractual necessity / Legal obligation |
| To pay out Partners and Businesses and issue self-billing invoices | Contractual necessity / Legal obligation |
| To share your registration answers with the organizer of an event you registered for | Contractual necessity |
| To personalize services where you volunteer health-related information | Explicit consent |
| To notify you about your own bookings, events, purchases, invoices, payouts, and account — in the app, by email, and, where you have enabled them, by push notification | Contractual necessity / Legitimate interest |
| To text you when a session or event you are booked on is cancelled shortly before it starts | Legitimate interest |
| To send marketing communications | Consent (opt-in) |
| To secure the platform (rate limiting, abuse and fraud prevention, audit logging) | Legitimate interest |
| To detect and diagnose faults — server errors, web-page failures and mobile app crashes — so we can fix them | Legitimate interest |
| To show professionals and events near a location you search for | Legitimate interest |
| To comply with legal obligations (tax, accounting, platform reporting) | Legal obligation |
We do not require health information and do not systematically collect it. Event registration questions or your communication with a professional may invite information relevant to safe participation (for example injuries or conditions); providing it is optional and constitutes your explicit consent to process it for that booking. You can decline to share it, and you may ask us or the organizer to delete it at any time via info@bookaleap.com.
We only send marketing communications if you opt in — via the checkbox during registration or your profile settings. You can withdraw at any time via your profile settings or by contacting info@bookaleap.com.
Push notifications and SMS are not marketing. We use them only to tell you about your own bookings, events, purchases, invoices, payouts, and account — the same notices you already see in the app. You control push notifications through your device’s notification settings, and turning them off there stops them without affecting your in-app or email notifications.
We only share your data with third parties where necessary to operate the platform:
Stripe — payment processing (payment amounts, currency, and transaction references; your card/bank details go to Stripe directly).
Supabase — our database, authentication (SMS and email verification codes, Google/Apple sign-in), and file storage (uploaded images, invoice documents) provider.
Google — if you sign in with Google or connect Google Calendar sync.
Nylas — calendar synchronisation for our earlier ILU app only, which is still running while we migrate people onto the bookaLEAP platform. Nylas receives Google Calendar data for users who connected a calendar in that app — event titles, times, attendees and updates — and uses it only to keep those calendars in step. It is not used by the bookaLEAP platform, whose calendar sync talks to Google directly and reads only busy periods (section 3H). This entry goes when the ILU app is retired.
Google (Firebase Cloud Messaging) — delivery of push notifications to your mobile devices. Firebase receives your device notification token and the content of the notification, which can include your name, the title of a service or event, and when it starts.
Apple — if you sign in with Apple. On iPhones and iPads, push notifications also pass through Apple’s Push Notification service on their way to your device, carrying the same content described above.
Twilio — sending SMS, used only to tell you that a session or event you are booked on starting within the next 24 hours has been cancelled.
Resend — delivery of transactional emails (for example contact-form notifications).
Photon (komoot) — geocoding: the address text you type into our location search, and the coordinates of a map pin you place, so we can return the matching addresses. Nothing else about you is sent with either lookup.
Cloudflare — network security and content delivery in front of our services.
Render and Vercel — hosting of our backend and web applications.
Sentry — error and crash monitoring. When something goes wrong — our servers fail to complete a request, a page in our web app breaks, or one of our mobile apps crashes — Sentry receives a technical report of the failure. That report contains the error message, the technical stack trace showing where in our code it happened, and context about the environment: the app or browser version, the operating system, the device model on mobile, the address of the page you were on, and our server’s hostname. In every app that reports to Sentry we have switched off the setting that would attach your identity, your IP address, or the contents of your request, and we have asked Sentry not to store the IP address its servers see when your browser or phone sends a report. Our admin panel, which only our own staff use, reports nothing to Sentry at all.
What can still reach Sentry is whatever our own error messages happen to say. Those messages are written for engineers, and some of them name the record that failed — usually an internal reference number for an account or a booking, which means nothing outside our systems. Two cases used to go further, and we would rather say so than quietly drop them: a failed SMS or email carried the number or address we were trying to reach, and a failure from our authentication provider could carry that provider’s own response. Both have since been removed — the recipient is masked before it is written down, and the provider’s response is kept at a level of detail that is never sent on to Sentry.
Professionals and event organizers — when you book with them, they receive your name, the booking details, and your registration answers. For a one-to-one session you book with a professional, they also receive your email address and phone number, so they can reach you about that session. Event organizers do not receive your contact details.
Authorities — where we are legally required to report (for example tax reporting on platform sellers under DAC7, which applies to Partners and Businesses, not Clients).
All processors act under data processing agreements and only process your data per our instructions. We never sell or rent your personal data.
Parts of your profile are visible to other people on the platform, so that everyone can recognise who they are training, booking, or attending an event with:
Because the “about” description is free text that other users can read, write only what you are comfortable sharing — in particular, you do not need to put health information there (see section 5). You can edit or clear it at any time in your profile settings, and the same applies to your social-media links: adding them is optional, and clearing a field removes that link from your profile.
bookaLEAP’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely, that means:
You can disconnect your Google Calendar at any time from your partner settings, or revoke bookaLEAP’s access from your Google Account permissions page. Disconnecting stops all further reading and writing; see section 10 for what happens to the data we already hold.
Some of our processors may process data outside the EU/EEA. In such cases we ensure adequate safeguards, such as Standard Contractual Clauses (SCCs) or transfers to countries with an EU adequacy decision.
Our Sentry organization is hosted in Sentry’s European region, so the error and crash reports described in section 7 stay in the EU and no transfer mechanism is required for them.
You have the right to access, correct, delete, restrict, and port your data, to object to processing (including marketing), and to withdraw consent at any time.
To delete your account, use Delete my account on your profile in the app or on the web. You confirm by typing a short word, after which your account closes immediately and we erase your personal data within one month. We email you a confirmation when the request is received and again once the erasure is complete. Before you confirm, the app tells you if you still have upcoming bookings or a pending payout — we will not refuse the request because of them, but deleting does not cancel or settle them.
To get a copy of your data, use Download my data on your profile in the app or on the web. We prepare a file containing your personal data and notify you when it is ready; the download link stays available for seven days, after which the file is deleted and you can request another. The file includes a machine-readable copy you can take to another service, and a readable summary explaining why we hold each kind of data and how long we keep it. Where a booking involves someone else, it shows their display name and the booking details, never their contact details. You can request an export twice a day.
To exercise any other right — correction, restriction, objection, or withdrawing consent — contact us at info@bookaleap.com. You can also use that address for deletion or access if you prefer. We respond to any request within one month. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Some data must survive an erasure request, either because the law requires us to keep it or because another legal obligation applies to it:
If you are a Partner or Business, please read this before you delete: the retention above is not something we can waive, and it is the one part of your data that a deletion request will not remove.
We use essential storage only. Our web apps keep you signed in using browser local storage (session tokens), not tracking cookies. Stripe may set cookies strictly for payment security and fraud prevention. Our error-monitoring provider (Sentry, section 7) sets no cookies and is not used to profile you: it only reports technical failures, and only when one happens. We use no analytics, advertising, or marketing cookies or SDKs, and we do not track your activity across our website or apps for any other purpose.
| Category | Purpose | Consent required? |
|---|---|---|
| Essential | Keeping you signed in, enabling core booking functionality, processing payments securely (including Stripe fraud-prevention cookies), remembering interface preferences | No — required for the platform to function |
If this changes — for example if we introduce analytics — we will update this section, request consent where required by law, and give you a way to accept or reject non-essential cookies.
bookaLEAP B.V. operated a booking platform under the name ILU, and that app is still running while we move everyone across. bookaLEAP is the same company, with the same registration (KvK 89959973) and the same responsibility as Data Controller for that data. It has not been sold, shared with, or transferred to anyone else.
While both are live, the two apps handle calendars differently — see section 3H and the Nylas entry in section 7. Everything else in this policy applies to both.
If you had an ILU account, we have moved your records onto the bookaLEAP platform so that your history stays with you. What we carried over:
What we deliberately did not carry over:
Your data is now held on the infrastructure and by the processors described in section 7, which are not the same as ILU’s. The purposes we use it for, described in section 4, have not changed.
Everything else in this policy applies to your migrated data exactly as it does to data you give us directly — including your rights in section 11 and the retention periods in section 10. If you would rather we did not keep your ILU history at all, use Delete my account, or contact us at info@bookaleap.com.
We may update this Privacy Policy periodically. Material changes will be notified via email or app alert. Continued use of the platform implies acceptance of the updated policy.
bookaLEAP B.V. Jan Pieter Heijestraat 107H, 1053 GN, Amsterdam, Netherlands info@bookaleap.com