OpenSlot legal
Privacy notice
How OpenSlot handles personal information for business accounts, for people who book appointments, and for visitors to this website.
Last reviewed: 20 August 2026
Who this notice covers
OpenSlot is hosted online appointment-booking software. This notice covers the public website at open-slot.com, the signed-in workspace used by businesses, and the public booking pages those businesses share with their own customers.
Two different relationships exist and they matter for your rights. For business account holders and website visitors, OpenSlot is the data controller and decides how information is used. For the customer records and appointments a business creates inside its own account, OpenSlot acts as a data processor on that business's instructions, and the business is the controller. If you booked an appointment with a business through OpenSlot, that business is the first place to raise a request, and OpenSlot will support them in answering it.
Questions about this notice can be sent to the contact address published on the contact page.
Information collected from business accounts
Creating an account records an email address, a display name and a password. Passwords are stored only as a salted hash and are never readable by OpenSlot.
Setting up a business records the trading name, public booking slug, contact email, time zone, booking currency, booking terms, cancellation notice and reminder preferences. Staff profiles record a display name, an email address and an optional short biography. Services record names, descriptions, durations, prices and booking rules.
Using the workspace generates operational records: audit entries showing which account performed significant actions, background job and notification status, and standard server logs.
Information collected when someone books
A public booking collects the customer's name and email address, an optional telephone number, an optional message to the business, and the service, staff member and time chosen. A booking reference and a private management token are generated so the appointment can be viewed or cancelled without an account.
Where a business collects marketing consent, that consent is recorded separately from the information needed to deliver the appointment, and it is never assumed from the booking itself.
OpenSlot is booking software, not a clinical or case-management system. Businesses must not enter diagnoses, treatment notes, medical histories, safeguarding information or other special category data into service descriptions, booking messages or internal notes.
Payment information
OpenSlot does not receive, process or store card numbers. All card handling is performed by Stripe.
Subscription payments for the Solo and Team plans are taken by OpenSlot through Stripe. OpenSlot stores the resulting Stripe customer and subscription references, the plan, its status and renewal date.
Where a business collects deposits or full payment at the point of booking, the money is taken directly into that business's own connected Stripe account, not into an OpenSlot balance. OpenSlot stores the amount, currency, status and Stripe references so the payment can be reconciled against the appointment and refunded if required.
Why this information is used
Account and business information is used to operate the service, authenticate access, separate one business's data from another's and provide support. The lawful basis is performance of a contract with the account holder, and legitimate interests in running the platform securely.
Booking and customer information is processed to create, confirm, remind about, amend and cancel appointments, and to let a business run its own operation. Where OpenSlot is the processor, the lawful basis is chosen by the business as controller.
A limited amount of processing rests on legal obligation, such as retaining financial records, and on legitimate interests in preventing fraud, abuse and unauthorised access.
Email and notifications
The service sends transactional email connected to appointments, including booking confirmations, notifications to the business, appointment reminders, password resets and team invitations. These are necessary to deliver the requested service and are not marketing.
Reminder timing is set by each business. A customer who wants to stop receiving messages about a specific appointment should contact the business directly, or cancel using the management link in their confirmation.
Who information is shared with
Information is shared with a small number of service providers who act on OpenSlot's instructions. Stripe processes payments and subscriptions. The hosting provider stores the application and database. Google Analytics provides website measurement, described in the cookie notice.
Where a business connects Google Calendar or Microsoft Outlook, appointment details are shared with that provider under the business's own account, and busy times are read back to prevent double booking. This connection is optional and can be removed at any time from the workspace, which deletes the stored tokens.
Information may also be disclosed where required by law, to establish or defend legal claims, or as part of a business transfer. OpenSlot does not sell personal information and does not share it for third-party advertising.
International transfers
OpenSlot serves businesses worldwide, and some providers, including Stripe and Google, process information outside the United Kingdom and European Economic Area. Where that happens, transfers rely on the safeguards those providers offer, such as approved standard contractual clauses and applicable adequacy decisions.
How long information is kept
Account and business records are kept while the account is open. Appointment and customer records are kept while the business needs them to run its operation, and the business controls their deletion from within its own workspace.
Records connected to payments are kept for as long as tax and accounting rules require, which is normally six years. Security and audit records are kept for a shorter operational period. Calendar access tokens are deleted when a connection is removed.
Deleting a business account removes its associated services, staff, customers and bookings through the database relationships that link them to that business.
Security
Access to the workspace requires authentication, and every request is scoped to the signed-in account's own business so one business cannot read another's records. Forms are protected against cross-site request forgery, the site sends a strict content security policy, and traffic is encrypted in transit.
Stored third-party access tokens, such as calendar credentials, are encrypted at rest using AES-256-GCM. Card details are never held by OpenSlot at all.
No online service can promise absolute security. Where an incident affects personal information, it will be assessed and reported in line with the applicable rules and, where OpenSlot acts as processor, notified to the affected business without undue delay.
Your rights
Depending on where you live, you may have rights to access a copy of your personal information, correct it, delete it, restrict or object to its use, withdraw consent, and receive it in a portable format.
Business account holders can exercise these rights by contacting OpenSlot. If your information is held by a business because you booked an appointment with them, contact that business first, as they control those records. OpenSlot will assist them where needed.
If you are in the United Kingdom and are unhappy with how a request was handled, you may complain to the Information Commissioner's Office. People in the European Economic Area may complain to their local supervisory authority.
Changes to this notice
This notice is updated when the service changes in a way that affects personal information. The review date shown at the top of the page reflects the most recent version, and significant changes will be communicated to account holders directly.