Skip to main content

Documentation

Basic Configuration
Privacy & GDPR
# 47
Last editetd on 06 August 2026

JoomBook is built with privacy compliance from the ground up. This page explains the GDPR-relevant settings.

Privacy Consent

Navigate to JoomBook → Settings → Frontend Settings.

  • Enable Privacy Consent - Required checkbox in the booking form. Customers must accept it before a booking can be completed.
  • Privacy Policy URL - Link to your privacy policy page (required when the checkbox is enabled).

Anonymising old customer data automatically

Personal data may only be kept as long as there is a reason to keep it. JoomBook can take care of that for you: under JoomBook → Settings → General Settings, in the Data protection section, you set a retention period. Once a customer has not had an appointment for that long, their name, email address and phone number are replaced by placeholders.

The appointments themselves stay. Your statistics and turnover figures therefore remain intact - they simply no longer point to a person. The period is counted from the last appointment, not from the day the record was created; anyone with an appointment still ahead of them is never touched.

Before you save, JoomBook shows a preview of how many records a run would affect right now, and from which date onwards.

This cannot be undone. For the records affected, the personal details are gone for good. That is why the feature is off by default - switch it on only once you have decided how long you really need to keep customer data.

The scheduled task needed for it is set up automatically by JoomBook when you save. A running task scheduler is still required, see "Setting Up Web-Cron & Scheduled Tasks".

Double opt-in: preventing bookings under someone else's address

With double opt-in (Settings → General Settings → Booking Settings) an appointment only comes into being once the customer has clicked the link in their confirmation email. That demonstrates the address given really belongs to the person booking - and nobody can place an appointment on somebody else's address. If no one confirms, no record with a valid appointment is created either.

Data Storage

All customer data is stored exclusively in your local Joomla database. No data is transmitted to external services - with the exception of:

  • Google Calendar Sync (Full Plan, optional): Only appointment metadata without personal customer data is transmitted.
  • License Validation: Only the license key and domain are sent to the license server.

Only data that is strictly necessary for operating the system is transmitted. It never contains personal customer data within the meaning of the GDPR - for Google Calendar synchronisation this is purely anonymised appointment data, and for license validation it is only the domain of your installation.

Deleting Customer Data

You can delete individual customers and their booking data at any time under JoomBook → Customers. When the JoomBook package is completely uninstalled, all JoomBook database tables - and therefore all stored customer data - are removed from the database completely and irrevocably.


Joomla! Logo
JoomBook is not affiliated with or endorsed by The Joomla! Project™ or Open Source Matters, Inc. The Joomla!® name and logo are registered trademarks of Open Source Matters, Inc. in the United States and other countries.

Copyright © · JoomBook