看中文版?纽约很多华人店主用的就是这套系统。

看中文版 →

Home / Privacy Policy

Privacy Policy

What passes through us, what we keep, and what we deliberately do not keep. This describes what the software actually does — it is not a template with features we do not have.

Last updated: 13 August 2026

1. The short version

We do not store your appointment details. When someone books with a business that uses Appt247, that booking lives in the business's own scheduling system. Our software reads it, sends the business one notification, and then lets go of it. Nothing about the customer is written to our database.

We are not going to claim we never see the data — that would be untrue, and a privacy policy that overstates is worse than one that admits the awkward part. The customer's name, phone and email do pass through our server for the few seconds it takes to compose that notification, and they appear in the notification email itself. What does not happen is any of it being kept.

2. Two different situations

  • You are visiting appt247.com. You are reading our pages, or you sent us a message. Here we decide what is collected and why, so we answer for it. See sections 4 and 5.
  • You booked an appointment with a business that uses Appt247. That business decides what is collected and why. Their scheduling system holds the record. We only relay a notification on their instruction. In data-protection terms they are the controller and we are the processor. Requests about that booking go to them first — see section 8.

3. What happens to a booking, step by step

Being specific here is the only way this claim is checkable.

  1. A customer books through the business's own scheduling system. The record is created there, not here.
  2. That system tells us an appointment was saved. The message it sends contains identifiers — an appointment number, a service number — not a name or a phone number.
  3. Our software asks that system for the details it needs to write a readable notification: the customer's name, phone, email, the service, the staff member, and the time.
  4. It composes one email and sends it to the address the business nominated.
  5. The request ends. Everything from step 3 was held in memory only and is gone.

What we do write down is two things, neither of which identifies anybody:

  • The business's account name, the appointment number from their system, and whether it was booked or cancelled. This is how we know a repeated message is a retry, so the business does not get the same notification four times.
  • A short diagnostic log of booking traffic, so a failure can be traced. Before anything is written to that log, customer fields are stripped out and replaced with [removed]. The log keeps only the most recent few hundred entries and rolls off automatically.

There is no appointment list, no customer list, and no export in our back office. Those features existed and were removed in August 2026, precisely so that this page could say what it says.

4. What we collect on this website

  • Contact form: your name, email and message; also phone, subject or company if the form shows those fields. Your IP address is used briefly to rate-limit submissions so the form cannot be turned into a spam relay. The message reaches us as email.
  • Merchant accounts: if you run a business on Appt247, we hold your sign-in details, your business name, the notification email you nominate, and the connection settings for your scheduling system. Passwords are stored hashed, never readable.
  • Server logs and our CDN: the site sits behind Cloudflare, which sees the IP address and basic request details of every visit and uses them for security and delivery. Ordinary infrastructure, not profiling.

5. Cookies

A small number of functional cookies and no advertising or analytics trackers at all. No Google Analytics, no Meta Pixel, no ad network. That is why there is no consent banner — there is nothing here that requires one.

  • a247lang — remembers whether you chose English or Chinese so we stop offering to switch. One year.
  • bk_lang — the same thing inside the back office and booking pages. One year.
  • A session cookie and a CSRF token while a merchant is signed in. Both are required for sign-in to work and to block forged requests. They end with the session.

If we ever add analytics, this page will say so before it goes live, and visitors in regions that require consent will be asked first, with a real way to decline.

6. Who else is involved

  • The business's own scheduling system holds the booking. It is theirs, on infrastructure they control.
  • Our mail server sends the notification and contact-form emails. We do not hand addresses to a third-party mailing service, and we never add anyone to a marketing list. Notification emails sit in the outbound mail queue only until delivery.
  • Cloudflare as the network layer in front of the site.

We do not sell personal information and we do not share it for cross-context behavioural advertising. No one pays us for access to anything.

7. How long things are kept

  • Booking details: not kept. See section 3.
  • Appointment numbers and status: for as long as the business's account is active. Removed when the account closes.
  • Diagnostic log: most recent few hundred entries, personal fields already stripped.
  • Contact-form messages: arrive as email and live in our mailbox. Enquiries that no longer need answering get cleared out.
  • Merchant account records: for as long as the account exists.

8. Your rights, and who to ask

You can ask to see the personal information held about you, have it corrected, or have it deleted. Depending on where you live you may also have the right to object to certain processing, to receive a copy in a portable form, or to opt out of any sale or sharing — of which, as stated, we do none.

About an appointment: ask the business you booked with. They hold the record; we do not have one to show you or delete. If they cannot help, or you cannot reach them, write to us at [email protected] and we will do what we can.

About this website or a message you sent us: write to [email protected]. We reply within five business days. Requests are free, and we will not treat you differently for making one.

9. Children

This service is for businesses and their adult customers. We do not knowingly collect information from children under 13. If you believe a child has given us information, write to us and we will remove it.

10. Security, stated plainly

Traffic is encrypted in transit. Our database sits outside the public web directory and cannot be reached by URL. Merchant passwords are hashed. Server access is key-based only. The strongest safeguard here is structural rather than technical: data we never wrote down cannot leak from us.

What we will not tell you is that a breach is impossible, because nobody can honestly say that. If one affects information we hold, we will notify the affected businesses and, where the law requires, individuals and the relevant authority.

11. Changes to this policy

If we change what we keep or who is involved, we update this page and the date at the top. Material changes go to merchant account holders by email rather than being published quietly.

12. Who we are

Appt247 is operated by Star Web Media 星辰网络传媒.

Email: [email protected]
Phone: 845-837-9314