Information we collect
- Account information, including your email address, display or artist name, account role, and authentication identifiers. Firebase handles passwords and sign-in security; BookingPilot does not receive your plaintext password.
- Profile and business information you choose to add, such as genres, biography, city, service ZIP codes, venue details, contact details, rates, links, and branding images.
- App content and activity, including venues, pitches, pitch text, bookings, gigs, earnings or expenses you enter, templates, reviews, community posts, venue requests, email replies captured for booking conversations, and feature settings.
- Purchase and entitlement information from Apple, Google Play, RevenueCat, or Stripe, such as product, subscription status, renewal, and transaction identifiers. We do not store complete payment-card numbers.
- Device and service information needed for authentication, security, notifications, and reliable operation, such as push tokens, IP address, browser or device type, and diagnostic request logs.
- Location only when you choose a nearby-venue feature and grant permission. Coordinates may be sent to Google Places to return nearby results. BookingPilot does not continuously track your location.
- Communications you send to us and transactional email you ask BookingPilot to deliver to a venue or artist. When a pitch uses a BookingPilot reply address, replies are processed, stored with the booking, and forwarded to the intended participant.
How we use information
We use information to:
- create and secure accounts and sync your data across devices;
- run venue discovery, booking, pitch, gig, review, and community features;
- send requested pitch emails, relay replies, booking alerts, and local or push reminders;
- process purchases, restore access, and prevent billing fraud;
- provide support, enforce limits, investigate abuse, and improve reliability;
- meet legal, tax, security, and platform obligations.
We do not sell personal information or use it for cross-context behavioral advertising. BookingPilot does not currently display third-party ads.
Services that process data
We disclose only the information needed for vendors to provide their services. Depending on the features you use, those providers include:
- Google Firebase for authentication, Firestore database, file storage, and cloud messaging; Google Places for venue results; and Google Calendar when you explicitly connect it.
- SendGrid for transactional pitch email, inbound reply parsing, and reply forwarding.
- RevenueCat, Apple, and Google Play for mobile subscriptions.
- Stripe for web checkout, subscription management, and billing.
- Vercel for web hosting, server execution, and operational request logs.
We may also disclose information when required by law, to protect users or the service, during a corporate transaction, or with your direction. Venue-facing profile information and community content are visible to other signed-in BookingPilot users as the feature indicates.
Google Calendar and device permissions
Google Calendar connection is optional. BookingPilot requests only the permissions shown during Google authorization to read calendar choices and create or manage gig events. OAuth tokens are stored in the device's encrypted secure storage, not in your BookingPilot cloud profile. You can disconnect Calendar in Settings, which revokes the token and removes its local copy.
Location, photos, and notifications are also optional. You can change those permissions in your device settings. Denying a permission limits only the feature that needs it.
Retention and deletion
We keep account and app data while your account is active and as needed to provide the service. Shorter-lived security logs, email-delivery records, backups, and processor records may remain for a limited period. We may retain information when required for fraud prevention, disputes, tax, accounting, legal compliance, or enforcement.
You can permanently delete your account in the mobile app under Settings or on the web from either Profile page. The deletion process removes your Firebase account, owned BookingPilot records, and files. Stripe subscriptions are canceled by the web deletion service. Apple App Store and Google Play subscriptions must be canceled in the corresponding store settings; deleting BookingPilot cannot cancel them for you.
Processor backups and records are removed according to each provider's retention schedule. Email already delivered to another person and content they independently retained cannot be recalled. See the public account deletion page for the available paths.
Your choices
- Edit profile and booking information in BookingPilot.
- Export supported mobile data from Settings.
- Disable notifications or location access in device settings.
- Disconnect Google Calendar in BookingPilot Settings.
- Delete your account and associated data using the controls above.
- Contact us to ask about access, correction, deletion, or other rights available where you live.
Security and international processing
We use access controls, encrypted transport, provider security features, and server-only credentials designed to protect information. No system is perfectly secure. Our providers may process information in the United States and other countries where they operate.
Children
BookingPilot is not directed to children under 13, and we do not knowingly collect personal information from them. Contact us if you believe a child has provided personal information so we can investigate and remove it.
Changes and contact
We may update this policy as BookingPilot changes. We will update the date above and provide additional notice when appropriate.
Questions or privacy requests: flightcrew@pilotsuite.design. BookingPilot is operated by PilotSuite LLC.
