Data Retention Policy
Last updated: August 7, 2026
Effective Date: November 01, 2025
Last Reviewed: May 01, 2026
1. Purpose
This Data Retention Policy describes how Nuvbook ("Nuvbook," "we," "our," or "us") collects, stores, retains, and deletes personal and business data generated through the use of our Platform. It applies to both business owners ("Providers") and the clients they serve ("End Users").
This policy is designed to comply with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), the Telephone Consumer Protection Act (TCPA), U.S. federal regulations including the FTC Act and the Gramm-Leach-Bliley Act (GLBA), , and New York and New Jersey state-level privacy requirements.
2. Scope
This policy applies to all data processed by Nuvbook, including account and registration data, booking and appointment data, client contact information, AI assistant interaction logs, payment and billing records, website builder content, SMS and messaging records, and analytics and usage data.
3. Data Retention Periods
Data is retained only as long as necessary for operational, legal, or compliance purposes.
Account and Registration Data
Account data is retained for the duration of the active account. Upon cancellation, data remains accessible for 30 days, after which it is permanently deleted. An exception applies where retention is required by law or at the user's written request prior to deletion.
Booking and Appointment Data
Booking and appointment data is retained for the duration of the active account, plus 30 days following account cancellation. Providers are responsible for exporting any client or appointment data they wish to keep before account closure.
AI Assistant Interaction Logs
AI interaction logs, including automated reminders, client replies, and scheduling communications, are retained for no longer than 24 months from the date of the interaction. Logs may be retained beyond 24 months only where required by law or for the purpose of active dispute resolution.
Payment and Billing Records
Payment data is never stored on Nuvbook servers. All payment processing is handled by third-party providers, including Stripe and PayPal, under their respective data retention and security policies. Billing records such as invoices and subscription history are retained for a minimum of 7 years to satisfy financial reporting and tax compliance obligations.
SMS and Messaging Records
SMS consent records and opt-in and opt-out logs are retained for a minimum of 4 years to comply with TCPA record-keeping requirements. Message content logs are retained for up to 24 months. Mobile phone numbers are never sold, shared, or transferred to third parties for marketing purposes.
Analytics and Aggregated Data
Anonymised, aggregated usage data such as booking trends and platform performance metrics may be retained indefinitely, as it does not constitute personal data under applicable law.
Data Subject Access and Deletion Requests
Records of access, correction, deletion, and opt-out requests are retained for a minimum of 3 years for compliance and audit purposes.
4. Data Deletion
Upon expiry of the applicable retention period, personal data is permanently deleted or irreversibly anonymised. Deletion is applied across all systems where the data is held, including backups, within a reasonable operational timeframe.
Users may request early deletion of their personal data by contacting privacy@nuvbook.com, subject to any legal obligations that require Nuvbook to retain certain data for a longer period.
5. Data Security During Retention
For the duration of any retention period, all stored data is protected by SSL/TLS encryption in transit, firewalls and intrusion detection systems, and role-based access controls limiting data access to authorised personnel only. Data shared with third-party processors such as Stripe, Mailgun, and Twilio is handled under applicable data processing agreements.
In the event of a confirmed data breach, Nuvbook will notify the relevant supervisory authority within 72 hours and will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34 and applicable U.S. state-level breach notification laws.
6. Provider Responsibilities
Providers own the client data they collect through the Platform. Nuvbook processes such data only to deliver the agreed services, such as syncing calendars and sending notifications.
Providers are responsible for ensuring their own data retention practices comply with applicable local, state, federal, and international regulations. They must also inform their clients of any recording or logging features, such as appointment summaries or chat transcripts, and obtain any necessary consent. Providers must export any data they require before account closure, as data will be permanently deleted 30 days after cancellation.
7. International Data Transfers
Where personal data is transferred outside of the user's country of residence or the European Economic Area, Nuvbook relies on appropriate safeguards, including Standard Contractual Clauses and encryption, to ensure lawful and secure processing.
8. User Rights
Users have the right to access the personal data Nuvbook holds about them, request correction of inaccurate or incomplete data, request deletion of their personal data subject to legal retention obligations, and restrict or object to certain processing activities. California residents may also opt out of data sharing or targeted advertising under CCPA/CPRA.
To exercise any of these rights, please contact privacy@nuvbook.com. Requests will be acknowledged and actioned within the timeframes required by applicable law.
9. Updates to This Policy
Nuvbook may update this policy from time to time to reflect changes in our services, legal obligations, or business practices. Updates will be communicated via email or in-platform notice. Continued use of the Platform after such updates constitutes acceptance of the revised policy. The effective date will always be displayed at the top of this document.
10. Contact
For questions about this policy or to submit a data request, please reach out to us at privacy@nuvbook.com,
by mail at
418 Broadway STE 8805, Albany, NY 12207, USA
or by phone at +1 (914) 371-8990.
Our response time is 5 to 10 business days.
Questions or Concerns?
If you have any questions about this data retention policy, please don't hesitate to reach out to our support team.
Contact Support
