Privacy Policy

Effective date: 2026-06-15

This Privacy Policy explains what data the Bookeo MCP service at https://bookeo.iotashan.com (the "Service"), operated by iotashan LLC (Shannon Hicks) (the "Operator," "we," "us"), collects and how we handle it. It accompanies our Terms of Service.

The short version: Bookeo MCP is a pass-through connector. Your actual Bookeo business data — bookings, customers, payments, availability — flows through the Service only in memory to fulfill your AI assistant's request, and is not stored, sold, or mined by us. The only things we store at rest are the small set of identifiers and the encrypted credential needed to route your connection.


1. What the Service does (context for this policy)

Bookeo MCP is a hosted, multi-tenant remote MCP (Model Context Protocol) server that connects your Bookeo booking account to an AI assistant you choose. When your assistant makes a request, the Service proxies it to the Bookeo API and returns the result. We are only the connector; we are not Bookeo and not your AI assistant vendor. See the Terms of Service.


2. Data we store at rest

We store, in a managed PostgreSQL database (Neon, hosted in Amazon Web Services region us-east-2), only the minimum needed to operate your connection:


3. Data we do NOT store

We do not store, retain, sell, mine, or otherwise use your Bookeo business data:

When your AI assistant requests this data, the Service fetches it from Bookeo on demand, holds it in memory only for the moment needed to return it to your assistant, and then discards it. It is used solely to fulfill that request — for no other purpose.

We also do not store the content of your conversation with your AI assistant. The Service receives a request, relays it to Bookeo, and relays the reply back; it does not retain the prompts, messages, or responses that pass through.

Your AI assistant provider is a separate third party

The AI assistant you choose — for example ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), or Copilot (Microsoft) — is an independent third party that we do not operate or control. When you talk to your assistant, your messages, prompts, and the requests it makes (and the replies it receives) pass through that provider and are handled under that provider's own privacy policy and terms, not ours. We are only the connector between your assistant and Bookeo: we relay the request to Bookeo and the reply back, and we do not store your conversation content. Choose the assistant provider whose privacy practices you trust, and review that provider's policy for how it handles what you send it.


4. Authentication / identity

Login and identity are handled by WorkOS AuthKit, a third-party identity provider. WorkOS holds your login identity (for example, your email address). We use WorkOS to verify who you are and to associate your connection with your organization. See WorkOS's own privacy practices for how they handle your identity data.


5. Operational data, analytics, and service improvement

To operate, secure, debug, and improve the Service, we collect operational and technical telemetry about how the Service runs — not the content of your Bookeo records. This may include:

This telemetry is about the operation of the Service, not your Bookeo business data. We use Sentry (a third-party error-tracking and performance-monitoring service, US region) to collect and process it; events are scrubbed to avoid carrying your Bookeo data or credentials. We do not sell this data.


6. Sub-processors and infrastructure

We rely on the following third-party providers to deliver the Service:

Provider Role
Amazon Web Services (AWS) Hosting / compute (region us-east-2)
Neon Managed PostgreSQL database
WorkOS Authentication / identity (AuthKit)
Bookeo The upstream booking API you are connecting to
Sentry Error tracking + performance monitoring / operational diagnostics, US region (see Section 5)
Stripe Subscription billing / payment processing (if you subscribe). Stripe handles your payment-card data directly; we do not receive or store full card numbers.

Each provider receives only the data needed for its role. This list may change as the Service evolves.


7. How we protect your data

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.


8. Data retention


9. Your choices and deletion rights

Note that deleting your connection does not delete data held by third parties (for example, your identity data at WorkOS or your records in Bookeo); contact those providers for their data.


10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children.


11. International users

The Service is operated from the United States and stores data in AWS us-east-2. If you access the Service from outside the United States, you understand your data will be processed in the United States.


12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy at the Service with a new effective date. Your continued use after the update takes effect constitutes acceptance.


13. Contact

Questions or deletion requests: reach us via our contact form.

Operator: iotashan LLC (Shannon Hicks)

Mailing address: PO Box 283, Janesville, WI 53547, USA