Skip to content
welko
How it worksPricingSign in

Welko

Privacy notice

This page explains what happens to personal data on this booking service: whose data we hold, why we hold it, who else can see it, and how long it stays.

Last updated 12 September 2026

Who runs this service

Data Pulse Solutions OÜ runs this service. It is a private limited company registered in the Estonian e-Business Register, registry code 16833707, at Järveotsa tee 13-4, 13520 Tallinn, Estonia.

Who decides what happens to your data

For a provider's own account — their name, email address, business details and settings — Data Pulse Solutions OÜ decides what is collected and why.

For the people who book with a provider, the provider decides. They choose what to ask their clients, what notes to keep and when to delete them. We store it for them and act on their instructions. So if you booked an appointment and you want your details changed or removed, start with the business you booked with. You can also write to us and we will pass it on.

A business can be more than one person. The owner can give a sign-in to the people who work with them, and picks what each of them may see. Some see everything the business holds. Others see only their own appointments and the clients they have served. Whichever of them you deal with, it is still the business you booked with that decides what happens to your details.

How to reach us

  • privacy@welko.eu — questions and requests about your data.
  • support@welko.eu — everything else.

What we hold

  • Provider accounts — name, email address, password (stored as a one-way fingerprint that cannot be turned back into your password), business name, the booking page's web address, services, prices and working hours.
  • Contact details for the booking page — a provider can type a street or address line, a phone number, an email address and a website for their booking page, and tick for each one whether it is shown there. We keep all four whether or not they are ticked. One that is not ticked is not put on the booking page, but the street line, the phone number and the email address are still used in the emails we send a client about a booking, ticked or not: the street line and the phone number are written in them, and replies to them go to that email address. The website is put nowhere but the booking page.
  • What kind of business it is, and where it is — a provider can pick what kind of business they run from a list we keep, and can give a country, a town, and if they want an area and a postcode as well. We keep all of it. None of it is shown to anyone booking, and it is not in the emails: today it is only stored, so that we can later group businesses by what they do and where they are.
  • The provider's photo — a provider can upload a picture of themselves. We keep the image file, and it is shown on their booking page and on the page a client uses to manage a booking with them.
  • Calendar imports — a provider can bring busy times in from their own calendar, by giving us its web address or by uploading a file from it. For each entry we keep when it starts, when it ends, its title — the words the provider wrote in their own calendar, such as "Dentist" — and the identifier the calendar gave that entry, which in some calendar programs is built from an email address. The title is kept so the provider can see which entry blocked a time. We take nothing else from the entry: not its description, not its place, not who else was invited. For a calendar we fetch ourselves we also keep its web address. None of this is on the booking page: someone booking sees only that the time is taken.
  • Bookings — the client's name, email address and any phone number they gave, the service, the time and the price at the time of booking. A public booking also keeps short campaign labels from the link that opened the form, or only the hostname of an outside referring page. If neither is available, it says direct or unknown. Nothing is kept merely because somebody visited or abandoned the form. If the provider cancels or turns down a booking, the reason they type is kept with it.
  • Notes the business keeps about a client — a provider can write notes on a client in their own workspace, and can block a client from booking. The client does not write these and never sees them: the box is labelled "Private notes". Inside the business, who can read them depends on what the owner gave that person: someone who sees everything the business holds reads all of them, and someone who sees only their own appointments reads them for the clients they have served.
  • A mark on each client — new, reliable or at risk, which Welko works out from the appointments that client kept and missed. What the mark is, and who sees it, is explained just below this list.
  • The record of who changed what — most changes made in the workspace leave a line saying which signed-in account made it, what it was about and when: a change to a client, a booking, a payment, the booking page's profile or photo, a day off or a changed day, a client or calendar import, the team, the plan, the email switch, the business's web address, publishing the booking page, exporting the account and asking for the business to be deleted. A change to the services, the working hours, the business name or the time zone leaves no line. A booking a client makes or cancels themselves leaves a line too, and so does each email we sent arriving or failing; those lines name nobody. When a provider cancels or turns down a booking, the reason they typed is on that line as well.
  • A client import waiting in a preview — when a provider uploads a file of clients, we keep the name of the file and, for each row in it, the name, email address, phone number and notes and, if the file has a language column, the language the client is written to in, so the provider can look them over before anything is saved. Finishing the import turns the rows into clients and deletes the rows.
  • Payment records — what the provider wrote down about money they received, and the receipt numbers. We never see card numbers: no payment is taken through this service.
  • Email records — which messages we sent, to which address, whether they arrived, and the subject and text of each message.
  • Technical records — error reports, and counts used to stop abuse. We do not keep the network address a request came from: it is turned into a one-way fingerprint first, so requests from the same source can be counted without the address being stored. Cloudflare and Sentry do see the address itself.
  • Plan waitlist — the email address and whether the person asked about Pro or Team. We also keep when they agreed to receive one availability message.

We do not sell personal data, and we do not use it for advertising.

There is one thing Welko works out about a client on its own, and nobody has to ask for it: a mark on their record that reads new, reliable or at risk. It comes from the appointments that client kept and the ones they did not turn up for. The provider can also set that mark by hand. The mark and the block are only for the business the client booked with: neither is shown on the booking page, neither is sent to the client, and neither is shared with another business.

Why we are allowed to hold it

  • To do what was agreed — running the account, showing the booking page, making and changing bookings, sending the confirmation and the reminder.
  • Because we have a fair reason — keeping the service secure, stopping abuse, and fixing faults.
  • Because the law says so — where a law requires us to keep or hand over something.
  • Because you said yes — where we ask for permission first, and you can take it back at any time.

How long we keep it

A provider's account and business data stays while the business exists.

You can delete your business at any time. First export what you need to keep. Your booking page goes offline at once, and after 14 days everything is deleted for good, including receipts. Within those 14 days you can change your mind in Welko, or by writing to us.

Two of those things happen the same day, not after the 14 days. The export comes first: the screen will not let you confirm a deletion until you have downloaded one. And every booking still to come is cancelled, with an email to the guest telling them so. That second one is not undone by changing your mind: those guests have already been told, and their times have been given away.

The provider is the one who has to keep their own books. That is why the export comes first: after those 14 days it is gone, and neither the bookings, the receipts nor the record of who changed what can be brought back.

A single client can also be erased, by the owner or by somebody the owner has given the run of the business. The client's name, email address, phone number and notes are removed straight away and cannot be recovered; the mark on their record goes back to new, and any block is lifted. The bookings and receipts themselves stay, without the personal details, because they are the business's own records.

  • The provider's photo — uploading a new picture deletes the old file at once, and removing the picture deletes the file at once. Otherwise it stays while the business exists and is deleted with it.
  • The record of who changed what — stays while the business exists and is deleted with it. Erasing a client removes nothing from it.
  • A client import waiting in a preview — the rows are deleted the moment the provider finishes the import. A preview the provider never finishes is deleted on its own a day after the file was uploaded, and its rows go with it. While a preview is still waiting, erasing a client does not touch its rows.
  • Calendar imports — a calendar we fetch is read again every hour for as long as its web address keeps working, and each read that works replaces everything we hold from it, so an entry the provider changes or deletes in their own calendar goes with the next read. If a read fails we stop reading that calendar, and we keep the entries from the last read that worked until the provider fixes the address or removes the calendar. Removing that calendar in Welko deletes its busy times and its web address at once. A busy time that came from an uploaded file is deleted on its own 3 days after it has ended; the ones still to come stay until the provider undoes that upload, or the business is deleted. Undoing an upload still removes all of its busy times at once.
  • Email records — we keep the message itself: the address it went to, its subject and its text. There is no time limit. The record stays while the business exists, so a booking confirmation we sent long ago can still be read. It is deleted with everything else when the business is deleted.
  • The copy used to send an email — the part of the service that sends the mail keeps its own copy of the message. That copy is deleted 7 days after the message is finished with, and at the latest 28 days after we tried to send it.
  • Verification codes — the short code a guest types to confirm their email address is deleted about a day after it expires.
  • Abuse counters — the counts used to slow down repeated requests are deleted as soon as they expire, within the hour.
  • Old booking page addresses — when a provider changes their web address, the old one keeps pointing at the new one for 90 days, then it is deleted.
  • Error reports — kept by Sentry for 90 days and then deleted.
  • Plan waitlist — kept for 12 months after the person most recently joins that plan's waitlist, or deleted sooner if they ask us.

Companies that help us run the service

These companies handle data on our behalf. Each one sees only what it needs for its job.

  • Cloudflare — serves the website. Sees the requests to the site, including network addresses. A United States company with servers worldwide, Europe included.
  • Convex — the database and the part of the service that does the work: accounts, bookings, clients, payments. A United States company, and the data is held in a United States region.
  • Resend — sends the confirmation, reminder and verification emails to guests, team invitations, and the emails that tell a provider a guest has booked or cancelled. Sees the recipient's address and the message. A United States company.
  • Sentry — receives error reports so faults can be fixed. Addresses are cleaned before they are sent: booking management links, email addresses and anything after a question mark in a web address are stripped out. A United States company.

Some of these companies process data outside the European Union. Contact us if you want to know what safeguards apply to a particular transfer.

Cookies

There are no tracking cookies on this site, and no advertising cookies. That is why you are not asked to accept any.

A provider who signs in gets a session stored in their own browser. It is what keeps them signed in; without it there is no way to stay signed in. There is no visitor-tracking script on the site at all.

The booking form keeps campaign labels in its memory only while that page is open and stores them only with a completed, verified booking. It does not use a cookie, browser storage or a visitor identifier for this, and it does not record visits or abandoned forms.

Your rights

Under the European Union's data protection rules you can ask to see the data we hold about you, to correct it, to have it deleted, to get a copy you can take elsewhere, to limit what we do with it, or to object to what we do with it.

Write to privacy@welko.eu. We answer within one month. If your request is about a booking you made with a provider, ask the provider first: they decide what happens to their own client records.

If you are not happy with our answer, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), the authority that supervises us. Its website is www.aki.ee.

Changes to this page

When this notice changes we update the date at the top.

welko

Simple booking for independent providers.

PricingAdd to your sitePrivacyTerms
© 2026 Welko