Privacy Policy
BookClay is software that pottery studios use to run classes, memberships and the kiln. That means we hold records about studios, and we hold records about their members on their behalf. This page explains both.
The short version
- We do not sell personal information, and we never have.
- There are no advertising trackers on this site or in the app. The only cookies we set keep you signed in.
- Card numbers never touch our servers. Stripe handles them.
- Your studio owns its member data. You can export it at any time, and you can ask us to delete it.
- Member text messages are processed by Twilio to deliver them and by Anthropic to draft replies. They are not used to train anyone's models.
1. Who we are
BookClay is operated from Denver, Colorado, United States. When this policy says "we" or "BookClay" it means the company that makes and runs the BookClay software. When it says "studio" it means a business that has a BookClay account. When it says "member" it means one of that studio's students, members or customers.
You can reach us at hello@bookclay.app about anything on this page.
2. Who controls what: studios are the controller, we are the processor
This distinction decides who you should talk to about a particular record, so it is worth being precise about it.
For member data, the studio is the data controller and BookClay is the processor. A studio decides which members to enroll, what to record about them, how long to keep it and who on staff can see it. We store and process that data under the studio's instructions and do not use it for our own purposes. If you are a member and you want your record changed or removed, ask the studio first. They can do it themselves in the app, and they are the ones who decide.
For studio account data, BookClay is the controller. That covers the owner and staff accounts, the subscription and billing records, and the support conversations we have with you. We decide how those are handled, and this policy governs them.
3. What we collect
Studio account data
When you create a studio you give us a name, an email address and a password (or you sign in with Google). Authentication is handled by Clerk, which stores the credential itself; we never see or store your password. We also hold your studio name, address, time zone, phone number, staff roster and role assignments, plan and billing status.
Member data, held for the studio
The studio puts this in, or a member enters it themselves when booking. It typically includes name, email address, phone number, emergency contact if the studio asks for one, booking and class history, attendance and check-ins, kiln pieces and firing fees, membership status and dues history, waivers the studio collects, and any notes staff add to the record.
Payment data
Card numbers, CVCs and bank details are collected directly by Stripe in fields we cannot read, and are never stored on BookClay servers. What we store is what Stripe hands back: a token, the card brand and last four digits, the amount, and whether the charge succeeded. Class fees and membership dues are charged on the studio's own Stripe account through Stripe Connect and settle directly to the studio's bank. We are not a custodian of that money at any point.
Messages
Texts to and from the studio number are carried by Twilio, which processes the phone numbers and message content in order to deliver them. When the AI front desk is switched on, the text of an inbound message and the studio context needed to answer it (class schedule, the member's bookings, kiln status, the studio's policies) are sent to Anthropic's API to draft a reply. That data is not used to train models. Email is sent through Resend and SendGrid.
Technical data
Our servers keep standard request logs: IP address, browser and device type, pages requested and timestamps. Sentry receives a record when something throws an error, which includes a stack trace and the studio and user identifier so we can tell whose problem to fix.
4. Why we process it, and on what legal basis
If a legal basis is required where you are (for example under the UK or EU GDPR), these are the ones we rely on.
- Performance of a contract. Running the studio account, taking bookings, billing memberships, sending the transactional messages the service exists to send.
- Legitimate interests. Keeping the service secure, preventing fraud and abuse, fixing errors, and understanding aggregate usage so we know what to build next. We do not run profiling or ad targeting on this basis.
- Legal obligation. Tax, accounting and responding to lawful requests.
- Consent. Marketing email from us, which you can withdraw at any time. Consent for a studio's own marketing to its members is collected and held by the studio, not by us.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Section 5
Sub-processors
These are the companies that can touch data held in BookClay. Each one is bound by its own data processing terms, and each is here because the service cannot work without it.
| Sub-processor | What it does | What it can reach |
|---|---|---|
| Clerk | Staff sign-in, studio organizations and role membership | Staff names, email addresses, sign-in metadata |
| Supabase | Managed Postgres database hosting (runs on AWS) | All studio and member records stored in BookClay |
| Vercel | Application hosting and content delivery | Request logs, IP addresses, standard server metadata |
| Stripe | Card processing, payouts and BookClay subscription billing | Payment and payout data. BookClay never receives full card numbers |
| Twilio | Sending and receiving SMS on the studio phone number | Phone numbers and the text of messages |
| Resend | Transactional email (receipts, reminders, magic links) | Email addresses and the content of those emails |
| SendGrid | Email delivery for larger sends such as studio broadcasts | Email addresses and the content of those emails |
| Anthropic | The AI front desk that drafts and sends SMS replies | The text of inbound messages plus the studio context needed to answer |
| Sentry | Error and performance monitoring | Stack traces, plus the studio and user identifiers attached to an error |
All of these are United States companies and data is processed in the United States. If we add a sub-processor we will update this table before the change takes effect, and studios on an annual plan can email us to be notified when it changes.
6. How long we keep things
We keep data for as long as the studio needs it to operate, then for as long as the law requires, then no longer.
| Studio account and billing records | Kept while the account is open, then 7 years for tax and accounting |
| Member profiles, bookings and attendance | Kept while the studio account is open, or until the studio deletes them |
| SMS and email message history | 24 months, then deleted |
| AI front desk conversation logs | 12 months, then deleted |
| Application and error logs | 90 days |
| Database backups | 30 days of rolling point-in-time backups |
| Everything else after you close the account | Deleted within 30 days, backups age out within 30 days after that |
A studio can delete an individual member record at any time without waiting for any of these windows.
7. If you are a studio member
You have the right to know what a studio holds about you, to get a copy of it, to correct it, and to ask for it to be deleted.
Start with the studio. They control your record and can pull, correct or delete it themselves, usually in a couple of minutes. If the studio does not respond, write to us at hello@bookclay.app and we will help them act on it. We will not unilaterally hand over or delete a studio's records on a third party's say-so, because we cannot verify from here that the request is really yours, but we will make sure it reaches someone who can.
We will never charge you for a request or make you sign up for anything to make one, and we will not treat you differently for having made one.
8. Colorado, California and other US state privacy rights
If you live in Colorado, the Colorado Privacy Act gives you the right to confirm whether your personal data is being processed and to access it, to correct inaccuracies, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data and certain profiling.
If you live in California, the CCPA as amended gives you comparable rights: to know what is collected and why, to access and delete it, to obtain a portable copy, to correct it, to limit the use of sensitive personal information, and to opt out of sale or sharing. Several other states now provide similar rights, and we handle those requests the same way.
Three things are true across all of them and worth stating plainly. We do not sell personal information. We do not share it for cross-context behavioral advertising or targeted advertising, so there is no opt-out to offer because there is nothing to opt out of. And we do not use it for automated decisions that produce legal or similarly significant effects.
To exercise a right, email hello@bookclay.app. We will confirm receipt and respond within 45 days, and will tell you if we need the extension the law allows. If we deny a request you can appeal by replying to that decision, and we will answer the appeal within 45 days. Colorado residents can escalate an appeal to the Colorado Attorney General.
9. GDPR
If you are in the United Kingdom, the European Economic Area or Switzerland, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time without affecting what we did before you withdrew it.
Where a studio is the controller, direct these requests to the studio and we will support them as their processor. Where BookClay is the controller, email hello@bookclay.app.
Data is processed in the United States. Where a transfer out of the EEA or UK requires a safeguard, we and our sub-processors rely on the European Commission's Standard Contractual Clauses and the UK Addendum. You also have the right to complain to your local supervisory authority.
Studios that need a signed data processing agreement can request one at hello@bookclay.app. We will send it the same week.
11. Children
BookClay is a tool for businesses. Nobody under 13 may create a BookClay account, and we do not knowingly collect personal information directly from children under 13.
Studios do teach kids, and a studio may enroll a minor in a class by entering the record itself, with the parent or guardian's involvement and using the parent's contact details for anything we send. In that case the studio is responsible for obtaining whatever consent the law requires of it, and the minor does not get their own login.
If you believe a child under 13 has created an account or given us information directly, email hello@bookclay.app and we will delete it.
12. Security
Data is encrypted in transit and at rest, every table is scoped to a studio and enforced at the database layer, and card data never reaches our servers. The security page describes how, in detail, including the parts we have not built yet.
If a breach affects your data we will notify you and, where required, the relevant regulator, without undue delay.
13. Changes to this policy
When this policy changes we update the date at the top. If a change materially affects how we handle your data we will email the account owner of every active studio before it takes effect, rather than quietly reposting the page.
14. Contact
Privacy questions, requests and complaints all go to hello@bookclay.app. Security reports go to security@bookclay.app. BookClay is based in Denver, Colorado, United States.
A real person reads that inbox, usually the same day on a weekday.
Still have a question about any of this?