Legal

Data Retention Policy

Last updated: August 7, 2026

Effective Date: November 01, 2025

Last Reviewed: May 01, 2026

1. Purpose

This Data Retention Policy describes how Nuvbook ("Nuvbook," "we," "our," or "us") collects, stores, retains, and deletes personal and business data generated through the use of our Platform. It applies to both business owners ("Providers") and the clients they serve ("End Users").

This policy is designed to comply with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), the Telephone Consumer Protection Act (TCPA), U.S. federal regulations including the FTC Act and the Gramm-Leach-Bliley Act (GLBA), , and New York and New Jersey state-level privacy requirements.

2. Scope

This policy applies to all data processed by Nuvbook, including account and registration data, booking and appointment data, client contact information, AI assistant interaction logs, payment and billing records, website builder content, SMS and messaging records, and analytics and usage data.

3. Data Retention Periods

Data is retained only as long as necessary for operational, legal, or compliance purposes.

Account and Registration Data

Account data is retained for the duration of the active account. Upon cancellation, data remains accessible for 30 days, after which it is permanently deleted. An exception applies where retention is required by law or at the user's written request prior to deletion.

Booking and Appointment Data

Booking and appointment data is retained for the duration of the active account, plus 30 days following account cancellation. Providers are responsible for exporting any client or appointment data they wish to keep before account closure.

AI Assistant Interaction Logs

AI interaction logs, including automated reminders, client replies, and scheduling communications, are retained for no longer than 24 months from the date of the interaction. Logs may be retained beyond 24 months only where required by law or for the purpose of active dispute resolution.

Payment and Billing Records

Payment data is never stored on Nuvbook servers. All payment processing is handled by third-party providers, including Stripe and PayPal, under their respective data retention and security policies. Billing records such as invoices and subscription history are retained for a minimum of 7 years to satisfy financial reporting and tax compliance obligations.

SMS and Messaging Records

SMS consent records and opt-in and opt-out logs are retained for a minimum of 4 years to comply with TCPA record-keeping requirements. Message content logs are retained for up to 24 months. Mobile phone numbers are never sold, shared, or transferred to third parties for marketing purposes.

Analytics and Aggregated Data

Anonymised, aggregated usage data such as booking trends and platform performance metrics may be retained indefinitely, as it does not constitute personal data under applicable law.

Data Subject Access and Deletion Requests

Records of access, correction, deletion, and opt-out requests are retained for a minimum of 3 years for compliance and audit purposes.

4. Data Deletion

Upon expiry of the applicable retention period, personal data is permanently deleted or irreversibly anonymised. Deletion is applied across all systems where the data is held, including backups, within a reasonable operational timeframe.

Users may request early deletion of their personal data by contacting privacy@nuvbook.com, subject to any legal obligations that require Nuvbook to retain certain data for a longer period.

5. Data Security During Retention

For the duration of any retention period, all stored data is protected by SSL/TLS encryption in transit, firewalls and intrusion detection systems, and role-based access controls limiting data access to authorised personnel only. Data shared with third-party processors such as Stripe, Mailgun, and Twilio is handled under applicable data processing agreements.

In the event of a confirmed data breach, Nuvbook will notify the relevant supervisory authority within 72 hours and will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34 and applicable U.S. state-level breach notification laws.

6. Provider Responsibilities

Providers own the client data they collect through the Platform. Nuvbook processes such data only to deliver the agreed services, such as syncing calendars and sending notifications.

Providers are responsible for ensuring their own data retention practices comply with applicable local, state, federal, and international regulations. They must also inform their clients of any recording or logging features, such as appointment summaries or chat transcripts, and obtain any necessary consent. Providers must export any data they require before account closure, as data will be permanently deleted 30 days after cancellation.

7. International Data Transfers

Where personal data is transferred outside of the user's country of residence or the European Economic Area, Nuvbook relies on appropriate safeguards, including Standard Contractual Clauses and encryption, to ensure lawful and secure processing.

8. User Rights

Users have the right to access the personal data Nuvbook holds about them, request correction of inaccurate or incomplete data, request deletion of their personal data subject to legal retention obligations, and restrict or object to certain processing activities. California residents may also opt out of data sharing or targeted advertising under CCPA/CPRA.

To exercise any of these rights, please contact privacy@nuvbook.com. Requests will be acknowledged and actioned within the timeframes required by applicable law.

9. Updates to This Policy

Nuvbook may update this policy from time to time to reflect changes in our services, legal obligations, or business practices. Updates will be communicated via email or in-platform notice. Continued use of the Platform after such updates constitutes acceptance of the revised policy. The effective date will always be displayed at the top of this document.

10. Contact

For questions about this policy or to submit a data request, please reach out to us at privacy@nuvbook.com,

by mail at

418 Broadway STE 8805, Albany, NY 12207, USA

or by phone at +1 (914) 371-8990.

Our response time is 5 to 10 business days.

Questions or Concerns?

If you have any questions about this data retention policy, please don't hesitate to reach out to our support team.

Contact Support