Privacy Policy
Effective July 22, 2026
Who we are
Dibsy provides booking, reminder-texting, and waitlist software to small appointment businesses. This policy covers both the business owners who use Dibsy and their clients whose information businesses store in it.
What we collect
- Account data — your name, email, business name, phone number, timezone, and password (stored hashed).
- Client data your business adds — client names, mobile numbers, notes, appointments, and waitlist preferences. The business is responsible for having permission to store and text this information.
- Messages — the texts sent and received through Dibsy, so your message history works.
- Calendar data — if you connect a calendar, the events needed to sync your schedule. Stored access tokens are encrypted at rest.
- Payment data — handled by Stripe; we never see card numbers.
How we use it
Only to run the service: sending booking confirmations, reminders, and waitlist offers; syncing calendars; processing payments; showing you your own dashboard; and keeping the service secure. We don't sell personal information, and we don't use your client list for our own marketing.
We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties.
Text messages and opting out
Clients receive texts only about their own appointments and waitlist requests. Anyone can stop receiving texts by replying STOP at any time; the first message a client receives says so. Message and data rates may apply.
Who we share data with
Only the processors needed to operate: Twilio (text delivery), Stripe (payments), Google (only if you connect Google Calendar or sign in with Google), and our hosting provider. Each receives only what it needs to do its job.
Retention & deletion
We keep data while the account is active. Business owners can delete clients, appointments, or their whole account; clients of a business can ask that business (or us) to remove their information. Email us and we'll delete your data within 30 days.
Security
Passwords are hashed, calendar tokens are encrypted at rest, connections use HTTPS, and login attempts are rate-limited. No system is perfectly secure — if a breach affects your data, we'll notify you promptly.
Children
Dibsy is for businesses and isn't directed at children under 13. A business may store appointment info for minors (e.g. a tutoring student) under the direction of a parent or guardian.
Changes & contact
We'll post any changes here and note the new effective date, and we'll tell you about material changes. Questions or requests: drink.more.water.1994@gmail.com.
Terms of Service · Powered by dibsy.