← Nabbee

Privacy Policy

WKL Labs · Version 2026-09-07

Effective date: 2026-09-07

Nabbee is operated by WKL Labs ("we", "us"). This Privacy Policy explains what data we collect, how we use it, and your choices. A full data-collection breakdown is maintained in our DATA_PRIVACY_MAP.

1. Who this applies to

This policy applies to customers, service providers / staff, and business owners who use Nabbee on the web or mobile app.

2. Information we collect

  • Account data: name, email, phone number, password (stored only as a secure hash).
  • Booking data: appointments, services, schedules, notes, and status history.
  • Payment proof: screenshots/files you upload, payment method, reference number, sender name, amount, and payment date for manual payment verification (e.g. GCash, Maya, bank transfer).
  • Business data (owners/providers): business name, address, hours, services, staff, and payout/account details you choose to add.
  • Device & technical data: app version, device type, IP address, and crash/diagnostic logs.
  • Support data: messages and attachments you send to support or disputes.

3. How we use your information

  • To create and manage bookings and appointments.
  • To verify manual payment proofs and prevent fraud (duplicate-reference and duplicate-file detection, amount checks).
  • To send transactional notifications (booking, payment, and account updates).
  • To provide customer support and resolve disputes.
  • To keep the service secure and comply with legal, tax, and accounting obligations.

4. Legal bases

We process data to perform our contract with you, for our legitimate interests in operating and securing the service, and to comply with legal obligations.

5. Sharing and our sub-processors

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We share data only with: the business/shop you book with (or its staff), the sub-processors listed below who operate Nabbee on our behalf under contract, and authorities where required by law.

These are the sub-processors we use today, what each one receives, and where it is processed:

  • Railway (application hosting and database, United States) — all account, booking, business, and payment-verification data, because it hosts the service itself.
  • Stripe, Inc. (payments and subscription billing, United States and Ireland) — for card payments and owner subscriptions: name, email, amount, currency, and card details entered directly into Stripe. We never receive or store your full card number.
  • Resend (transactional and campaign email delivery, United States) — recipient email address, message subject and content, and delivery status.
  • Anthropic, PBC (automated analysis of uploaded payment screenshots, United States) — see section 7. The screenshot and the text it contains (which can include a sender name, an account or reference number, and an amount) are transmitted to Anthropic for automated extraction. If you are in the Philippines or elsewhere outside the United States, this is a cross-border transfer of your personal data to the United States. We rely on the contractual protections in our agreement with Anthropic, which prohibits using your data to train models and requires deletion after processing.
  • PostHog (product analytics, United States) — see section 6 for when it loads and how to refuse it.
  • Sentry (error and crash reporting, United States) — technical error details, app version, device type, and a truncated network address.
  • Expo, Apple Push Notification service (APNs), and Firebase Cloud Messaging (FCM) (mobile push delivery, United States) — a device push token and the notification text, so booking and payment notifications reach your phone.
  • Google LLC (sign-in with Google where you choose it, and calendar synchronisation where you connect it; United States) — your Google account identifier and email, and, for calendar sync, the booking times we write into your calendar.

We publish changes to this list by updating this policy and its effective date. A full field-level data-collection breakdown is maintained in our DATA_PRIVACY_MAP.

6. Analytics, cookies and your choices

We use privacy-preserving product analytics and error-reporting tools to understand how Nabbee is used and to detect and fix problems. These tools collect usage events (such as which pages are viewed and general navigation), approximate device and browser information, and technical error details. We do not enable automatic click/content capture or session recording, and we do not use these tools to build advertising profiles or to sell your data. Web addresses sent to these tools are stripped of query strings and of identifiers such as booking, review, or payment tokens before they leave Nabbee. Analytics events are collected on an anonymous basis and are not linked to your name or contact details. Our current providers are PostHog (product analytics) and Sentry (error reporting), acting as our processors.

Your choice. Analytics is not essential to running Nabbee, and we keep it to the minimum described above. We are rolling out an explicit consent choice, so what you see depends on where you are in that rollout:

  • Where you see a "Cookie choices" control — in our site footer and at the foot of this document — we ask before any non-essential analytics tool loads, and until you choose we load only what is strictly necessary for the site to work (your session, security, and preference cookies). You can change or withdraw your choice at any time, and withdrawing is as easy as giving it: use that control, or go straight to our "Do Not Sell or Share My Personal Information" page at /do-not-sell. The control is offered wherever you are, not only in the United States.
  • Where that control is not yet available to you, the analytics and error-reporting tools named above may load when the page loads, on the anonymous basis described above, and we do not yet read an automated browser preference signal in that configuration. You can still refuse them: use your browser's tracking-protection or content-blocking settings, or a content blocker, which we do not attempt to work around; or email hello@nabbee.app and we will stop non-essential analytics for you and act on it as an opt-out request.

Where the Cookie choices control is available to you we honour a Global Privacy Control (GPC) signal as a refusal of non-essential analytics without asking you anything, and, in the absence of an explicit choice, we treat a browser "Do Not Track" preference the same way. Web addresses sent to analytics are stripped of query strings, of identifiers such as booking, review, or payment tokens, and of shop names, so a business's public page name is not disclosed to our analytics provider.

7. Automated processing of payment screenshots

Uploaded payment screenshots may be analyzed by an automated system to extract amount, reference, and sender details and to flag possible fraud. A human reviewer makes the final decision where required.

8. Retention

We keep booking, payment, and audit records for as long as needed to provide the service and to meet legal, tax, accounting, fraud-prevention, and dispute-resolution obligations. When you delete your account we soft-delete and anonymize your profile while retaining records we are legally required to keep (see our Refund/Cancellation and account-deletion process).

9. Your rights

Depending on your location you may request access, correction, deletion, or a copy of your data, and you may object to or restrict certain processing. You can request account deletion in-app (Settings → Account → Delete Account) or via the web at /delete-account.

10. Your U.S. state privacy rights

If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the right to know what personal information we collect and why, to request a copy of it, to correct it, to delete it, to limit the use of sensitive personal information, and to appeal a decision we make about your request. We will not discriminate against you for exercising these rights.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Our analytics and error-reporting providers act as our service providers/processors and are contractually barred from using your data for their own purposes. Because there is nothing to opt out of in the statutory sense, our "Do Not Sell or Share My Personal Information" page, where it is available to you, confirms this and records your Global Privacy Control signal as an opt-out of non-essential analytics: see /do-not-sell. Where that page is not yet available to you, you can exercise the same right by emailing hello@nabbee.app, and we will action it.

To make a request, email hello@nabbee.app. We will verify your request against the account details we already hold. An authorised agent may submit a request on your behalf with written permission that we can verify.

State addendum (draft). Categories collected in the last 12 months: identifiers (name, email, phone, account and device identifiers); commercial information (bookings, purchases, deposits); internet or network activity (pages viewed within Nabbee, diagnostics); approximate location inferred from network address; and, for manual payment verification, financial information contained in payment screenshots. Sources: you, the business you book with, and your device. Purposes: those in section 3. Disclosed for a business purpose to the sub-processors named in section 5. Retention: as described in section 8.

11. Philippines: Data Privacy Act rights and complaints

If you are in the Philippines, Republic Act No. 10173 (the Data Privacy Act of 2012) gives you the rights to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability, and the right to lodge a complaint with the National Privacy Commission.

Contact us first at hello@nabbee.app — our data protection contact reads that mailbox and we aim to respond within 15 working days. If you are not satisfied, you may complain to the National Privacy Commission (privacy.gov.ph). We maintain an internal breach-response procedure and will notify affected individuals and the Commission where a personal data breach meets the notification threshold.

12. Security

Passwords are hashed (bcrypt). Access to sensitive endpoints is authenticated and authorized. Uploaded payment proofs are stored in access-controlled storage and served only to authorized users.

13. Children

Nabbee is not directed to children under 13 (or the minimum age in your jurisdiction).

14. Changes

We may update this policy and will revise the effective date. Material changes may require renewed consent.

15. Contact and data protection

Privacy questions: hello@nabbee.app. General support: hello@nabbee.app.

Questions? Email hello@nabbee.app