Privacy Policy
Effective date: 2026-06-15
This Privacy Policy explains what data the Bookeo MCP service at https://bookeo.iotashan.com (the "Service"), operated by iotashan LLC (Shannon Hicks) (the "Operator," "we," "us"), collects and how we handle it. It accompanies our Terms of Service.
The short version: Bookeo MCP is a pass-through connector. Your actual Bookeo business data — bookings, customers, payments, availability — flows through the Service only in memory to fulfill your AI assistant's request, and is not stored, sold, or mined by us. The only things we store at rest are the small set of identifiers and the encrypted credential needed to route your connection.
1. What the Service does (context for this policy)
Bookeo MCP is a hosted, multi-tenant remote MCP (Model Context Protocol) server that connects your Bookeo booking account to an AI assistant you choose. When your assistant makes a request, the Service proxies it to the Bookeo API and returns the result. We are only the connector; we are not Bookeo and not your AI assistant vendor. See the Terms of Service.
2. Data we store at rest
We store, in a managed PostgreSQL database (Neon, hosted in Amazon Web Services region us-east-2), only the minimum needed to operate your connection:
- Routing identifiers — your WorkOS organization id (
org_id) and your Bookeo account id. These identify and route your connection. - Your Bookeo API key — encrypted. The key is encrypted at the application layer (libsodium "secretbox") before it is written to the database. We never write a plaintext API key to the database or to our logs.
- Granted permission scopes and connection status — the set of Bookeo permission scopes you granted, and whether the connection is active.
- Short-lived security tokens — CSRF/PKCE state tokens used during the login and authorization round-trips. These are automatically expired and purged (approximately 15 minutes).
3. Data we do NOT store
We do not store, retain, sell, mine, or otherwise use your Bookeo business data:
- bookings, customer records, payment details, and availability are never persisted by the Service.
When your AI assistant requests this data, the Service fetches it from Bookeo on demand, holds it in memory only for the moment needed to return it to your assistant, and then discards it. It is used solely to fulfill that request — for no other purpose.
We also do not store the content of your conversation with your AI assistant. The Service receives a request, relays it to Bookeo, and relays the reply back; it does not retain the prompts, messages, or responses that pass through.
Your AI assistant provider is a separate third party
The AI assistant you choose — for example ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), or Copilot (Microsoft) — is an independent third party that we do not operate or control. When you talk to your assistant, your messages, prompts, and the requests it makes (and the replies it receives) pass through that provider and are handled under that provider's own privacy policy and terms, not ours. We are only the connector between your assistant and Bookeo: we relay the request to Bookeo and the reply back, and we do not store your conversation content. Choose the assistant provider whose privacy practices you trust, and review that provider's policy for how it handles what you send it.
4. Authentication / identity
Login and identity are handled by WorkOS AuthKit, a third-party identity provider. WorkOS holds your login identity (for example, your email address). We use WorkOS to verify who you are and to associate your connection with your organization. See WorkOS's own privacy practices for how they handle your identity data.
5. Operational data, analytics, and service improvement
To operate, secure, debug, and improve the Service, we collect operational and technical telemetry about how the Service runs — not the content of your Bookeo records. This may include:
- server logs and error reports / diagnostics (including error stack traces);
- aggregate usage metrics — for example, which MCP tools are called, request counts, latency, and error rates;
- technical request metadata such as IP address, timestamps, and request paths.
This telemetry is about the operation of the Service, not your Bookeo business data. We use Sentry (a third-party error-tracking and performance-monitoring service, US region) to collect and process it; events are scrubbed to avoid carrying your Bookeo data or credentials. We do not sell this data.
6. Sub-processors and infrastructure
We rely on the following third-party providers to deliver the Service:
| Provider | Role |
|---|---|
| Amazon Web Services (AWS) | Hosting / compute (region us-east-2) |
| Neon | Managed PostgreSQL database |
| WorkOS | Authentication / identity (AuthKit) |
| Bookeo | The upstream booking API you are connecting to |
| Sentry | Error tracking + performance monitoring / operational diagnostics, US region (see Section 5) |
| Stripe | Subscription billing / payment processing (if you subscribe). Stripe handles your payment-card data directly; we do not receive or store full card numbers. |
Each provider receives only the data needed for its role. This list may change as the Service evolves.
7. How we protect your data
- Your Bookeo API key is encrypted at the application layer before storage; plaintext keys are never written to the database or logs.
- We store the minimum data necessary and keep your Bookeo business data out of persistent storage entirely (Section 3).
- We apply per-tenant isolation and authentication controls so one user cannot access another's connection.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
8. Data retention
- Routing identifiers, encrypted API key, scopes, and connection status are retained while your connection exists, and are deleted when you disconnect (see Section 9).
- Short-lived state tokens are auto-expired and purged (~15 minutes).
- Operational telemetry (logs, error reports, metrics) is retained for a limited period for security, debugging, and service-improvement purposes, then aged out.
9. Your choices and deletion rights
- Disconnect. You can disconnect at any time. Disconnecting deletes your stored connection — the encrypted API key and the connection row.
- Request deletion. You can also reach us via our contact form to request deletion of your stored connection data.
- Bookeo side. Disconnecting or uninstalling the app on the Bookeo side rotates/invalidates the API key, so any previously stored key can no longer be used.
Note that deleting your connection does not delete data held by third parties (for example, your identity data at WorkOS or your records in Bookeo); contact those providers for their data.
10. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children.
11. International users
The Service is operated from the United States and stores data in AWS us-east-2. If you access the Service from outside the United States, you understand your data will be processed in the United States.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy at the Service with a new effective date. Your continued use after the update takes effect constitutes acceptance.
13. Contact
Questions or deletion requests: reach us via our contact form.
Operator: iotashan LLC (Shannon Hicks)
Mailing address: PO Box 283, Janesville, WI 53547, USA