BOIntake
Privacy Policy
Last updated: 30 August 2026
Introduction
This Privacy Policy explains how BOIntake (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you use our booking and order intake platform (the “Service”).
BOIntake is the trading name of the Service at bointake.com. Contact us at support@bointake.com or +959 4000 833 16. Guests should also contact the enterprise whose form they used.
1. Who this policy covers
BOIntake is a multi-tenant platform. We process data for three groups:
| Who | Role |
|---|---|
| Enterprise customers | Organizations that register a workspace, design public forms, and manage bookings and orders. |
| Workspace users | Root admins and sub-admins who sign in to a workspace. |
| Guests | People who submit a public form or look up a request with a reference code and track token. Guests do not create a BOIntake account. |
For account, billing, and platform data, BOIntake is the data controller. For guest form submissions, the enterprise is the controller of that guest data. BOIntake processes it on the enterprise’s behalf so the workspace can receive, store, update status, and look up requests.
2. Data we collect
2.1 Enterprise and account data
When someone registers or is invited to a workspace, we store:
- Enterprise name, public URL slug, optional subdomain, contact email, phone number, and address
- Subscription plan, wallet credits, usage against plan limits, and subscription expiry
- Workspace settings (date format, cancel-reason presets, remark presets, success and fully-booked copy, logo)
- User name, username, email, role (admin or super-admin), root-admin flag, and account status
- A password hash (we do not store plaintext passwords)
- Email verification status and timestamps
- If you use Continue with Google: Google account identifier, email, name, and whether Google reports the email as verified
2.2 Guest booking and order data
Public forms always collect a full name. Phone number is collected only when the enterprise includes a phone field; that field may be required, optional, hidden, or omitted. Enterprises may add extra fields (for example email, dates, times, numbers, free text, and choice fields). We store answers as submitted, form title and field labels at submission time, a public reference code (for example BO-7K2M9Q), an unguessable track token used to view the request, a hashed edit key (the plaintext key is shown once after submit), status (pending, confirmed, completed, cancelled), optional remark updates (admin label, guest-facing message, and time for each update), cancel reason and optional note, and submission time. For invite-only forms we also store which invite token was used.
Anyone who has the enterprise’s public track page, a valid reference code, and a valid track token (including the track link shown after submit) can view that request’s details. Treat the reference code like a username and the track token like a password. Either one alone is not enough to open the request. Changing a pending request also requires the edit key shown at submit; treat that key like a password. After the enterprise confirms, completes, or cancels the request, guests cannot edit it. An enterprise can turn guest tracking off on a designed form (for example a contact form). In that case guests are not shown a reference code or track token, that form has no track panel, and guest edit is not available. Staff still receive the submission.
Designed forms can be open (anyone with the public URL may submit) or invite-only. Invite-only forms require a unique invite link. We store invite tokens, optional labels, revoke time, and a link from each invite-only submission to its invite. One pending request is allowed per invite at a time. The same invite can be used again only after that request is cancelled. After a request on that invite is confirmed or completed, the invite link cannot be used again. Treat invite links as secrets — anyone with a valid invite link can submit.
2.3 Billing data
Plan upgrades and credit purchases are manual. We do not process card numbers in the app. When you submit a billing request we may store the target plan or credit amount, payment region (Myanmar or international), currency (MMK or USD), quoted amount, contact channel (Viber, Telegram, WhatsApp, or email), contact number, message, and a payment screenshot you upload. Platform operators review these requests and approve or reject them.
2.4 Support tickets
Workspace admins can browse in-app help articles and, if those do not answer the question, open a support ticket. We store the ticket subject, category, message thread, optional screenshot, enterprise, and the account that opened it. Platform operators (super-admins) read and reply in the app to provide support.
2.5 Files you upload
We store enterprise logos, images used on public forms, billing payment screenshots, and optional support-ticket screenshots in object storage. Logos and form images are served at a public URL so they can appear on shared forms. On paid plans, guests may attach images or PDFs to a form. Those guest files are stored in private object storage and are not published at a public URL. Workspace admins can download them. We keep file name, type, size, and a storage key so we can serve and delete the file with the submission.
2.6 Notifications
We create in-app notifications for workspace events such as new submissions, plan limits, a form closing, billing updates, and support ticket replies. Outbound notification email is designed but not currently sent; those records stay in the product.
2.7 Technical data
We automatically process session and security cookies (see Cookies below), standard server logs (such as IP address, browser, request time, and pages requested) as needed to run and secure the Service, and language preference via the locale in the URL (/en/ or /my-MM/). For abuse control we store a short-lived hash of the visitor IP (not the raw address) for about 48 hours. Admin theme preference is stored in localStorage on your device (bom-theme) and is not sent to us as a cookie. The submissions table datetime display preference is a first-party cookie (bom-show-full-datetime).
We do not use third-party advertising pixels, Google Analytics, or similar marketing trackers in the current product. Cloudflare Turnstile (bot check) runs on enterprise registration and public forms.
3. How we use data
We use personal data to:
- Create and operate enterprise workspaces and public forms
- Authenticate users (email or username and password, or Google)
- Verify email addresses and reset passwords
- Accept guest submissions, apply capacity and plan limits, and let guests track status
- Show dashboards and in-app notifications to workspace users
- Process billing requests and apply plan or credit changes after review
- Provide in-app help articles and support tickets between workspace admins and platform operators
- Isolate each enterprise’s data from other enterprises
- Maintain security, prevent abuse, and comply with law
- Improve and support the Service
We do not sell personal data.
4. Legal bases
Depending on your location, we rely on contract (to provide the Service you or your organization signed up for), legitimate interests (security, fraud prevention, product operation, and support), consent where required (for example optional Google sign-in), and legal obligation when we must retain or disclose data.
Enterprises are responsible for having a lawful basis to collect guest data on their forms, including any extra fields they add.
7. Retention
We keep data while the account or workspace is active and as needed afterward for billing, security, and legal requirements.
- Passwords are stored as bcrypt hashes.
- Guest edit keys are stored as bcrypt hashes. The plaintext key is shown once after submit.
- Guest track tokens are stored so the track page can look up a request. Treat them like secrets.
- Email-verification tokens expire after 24 hours (stored as SHA-256 hashes).
- Password-reset tokens expire after 60 minutes (stored as SHA-256 hashes).
- Hashed visitor IPs used for rate limits are removed after about 48 hours.
- Workspaces can deactivate user accounts so those users cannot sign in. Users and forms are not deleted in the product; contact us for permanent erasure.
- Soft-deleted submissions stay in a recycle bin for 30 days, then are permanently deleted.
- Super-admins can suspend or archive enterprises.
Soft-deleted submissions are permanently removed after 30 days. For other permanent deletion, contact us (or, for guest data, contact the enterprise that collected it). Some records may remain in backups for a limited period.
8. Security
We use measures appropriate to a web app of this type, including hashed passwords, hashed guest edit keys, hashed email tokens, HTTP-only session cookies, HTTPS in production, per-enterprise data scoping, Cloudflare Turnstile on public registration and guest forms, IP-based rate limits, unguessable track tokens for viewing submissions, and unguessable invite tokens for invite-only forms. No method of transmission or storage is completely secure. Keep track tokens, edit keys, invite links, and login credentials confidential.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection.
- Workspace users: use Settings and account tools where available, or email support@bointake.com.
- Guests: contact the enterprise whose form you submitted. We will assist that enterprise where we reasonably can.
- Google sign-in: you can also manage Google’s sharing of your account in your Google account settings.
We may need to verify your identity before acting on a request.
10. Children
The Service is built for enterprise operations, not for children. We do not knowingly collect account data from children under 13 (or a higher age required in your country). Enterprises must not design forms to target children unless they comply with applicable children’s privacy laws.
11. International transfers
We may process data in countries other than yours (for example where our host, Resend, or Cloudflare Turnstile operates). If you are in Myanmar, the EEA, UK, or another region with transfer rules, we take steps required by those rules when we transfer data.
12. Changes
We may update this policy. The “Last updated” date will change. Material changes may also be announced in the product or by email to workspace contacts.
13. Contact
Contact BOIntake using the details below. Guests should also contact the enterprise that collected their data.
| support@bointake.com | |
| Phone | +959 4000 833 16 |
| Website | bointake.com |
Related: Terms of Service
