Privacy policy
Last updated 2 October 2026
This policy explains what personal data daybag.io collects, why, and what happens to it. Two kinds of people use daybag: outfitters, who sign up and run their bookings here, and guests, who book with an outfitter.
Who decides what
For an outfitter's own account, like your sign-in email, daybag decides how the data is used, as this policy describes.
Guests' data belongs to the outfitter they book with. We process it on the outfitter's behalf, only to run their bookings, and the outfitter's own privacy notice applies to it. If you're a guest, the quickest way to your data is through the outfitter. If you write to us, we'll pass your request on and help them answer it.
What we collect
From outfitters:
- your email address, to sign you in;
- your business details: name, booking page address, time zone and currency;
- what you set up: offerings, hours, sessions, prices, webhook URLs and API keys (we store only a hash of each key);
- Pro billing details, handled by Stripe (we never see your card number);
- technical data such as IP address, browser and logs, to keep daybag secure and working.
From guests, on the outfitter's behalf:
- name, email and, if given, phone number;
- what they booked: offering, time, quantity, price and any notes they write;
- payment status, when the outfitter takes payments. Card details go straight to Stripe; daybag never sees or stores them.
How we use it
- to run daybag: bookings, availability, sign-in and booking emails, and the events and webhooks sent to the outfitter's own systems;
- to keep daybag secure, prevent abuse and fix problems;
- to bill Pro subscriptions;
- to tell outfitters about their account and about important changes.
We don't sell personal data, we don't share it for advertising, and we don't use guests' data for our own purposes.
Who else handles it
A few services run parts of daybag for us, under contracts that protect the data:
- Supabase: database and sign-in (United States);
- Vercel: hosting (United States);
- Stripe: Pro billing, and guest payments on the outfitter's own Stripe account;
- Resend: sending emails.
Outfitters can also send data onward themselves, through the API keys, AI agents and webhooks they connect. Where that data goes is up to them.
We'll disclose data when the law requires it. If daybag is ever sold, this policy stays with the data.
Where it's stored
daybag runs in the United States, on servers in California. If you use it from elsewhere, your data is transferred to and processed in the US.
How long we keep it
We keep an outfitter's data while their account exists.
An outfitter can erase a guest's name, email, phone and notes at any time. The bookings stay as anonymous records, so the outfitter's history and numbers stay right. Entries already in the outfitter's event log are kept until the organization is deleted.
Deleting an organization removes its offerings, bookings, customers, API keys, webhooks and events from our database straight away. Backups may keep a copy for up to 30 days until they roll over.
Your choices and rights
Outfitters can export everything as JSON (Settings → Download your data), correct it in the dashboard and delete their organization in Settings. Email us for anything else.
Guests can ask the outfitter they booked with to show, correct, export or erase their data. The outfitter can do all of that in daybag.
Depending on where you live, for example California, the EU or the UK, you may have the right to access, correct, delete or port your data and to object to how it's used. We honor those rights as the law requires and won't treat you differently for using them. If you need a data processing agreement, ask us.
Security
Data is encrypted in transit and at rest. Browsers can't read the database directly; only our server can, and every query is limited to one organization. API keys are stored only as hashes, and webhooks are signed.
No system is perfect. If a breach affects your data, we'll tell you promptly, as the law requires.
Children
daybag is made for businesses. Guests under 16 should have a parent or guardian book for them.
Changes
If we change this policy, we'll update the date at the top. For material changes, we'll email outfitters before they take effect.
Contact
Questions or requests about privacy: hello@daybag.io.