BOIntake

Privacy Policy

Last updated: 30 August 2026

This Privacy Policy explains how BOIntake (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you use our booking and order intake platform (the “Service”).

BOIntake is the trading name of the Service at bointake.com. Contact us at support@bointake.com or +959 4000 833 16. Guests should also contact the enterprise whose form they used.

BOIntake is a multi-tenant platform. We process data for three groups:

WhoRole
Enterprise customersOrganizations that register a workspace, design public forms, and manage bookings and orders.
Workspace usersRoot admins and sub-admins who sign in to a workspace.
GuestsPeople who submit a public form or look up a request with a reference code and track token. Guests do not create a BOIntake account.

For account, billing, and platform data, BOIntake is the data controller. For guest form submissions, the enterprise is the controller of that guest data. BOIntake processes it on the enterprise’s behalf so the workspace can receive, store, update status, and look up requests.

2.1 Enterprise and account data

When someone registers or is invited to a workspace, we store:

  • Enterprise name, public URL slug, optional subdomain, contact email, phone number, and address
  • Subscription plan, wallet credits, usage against plan limits, and subscription expiry
  • Workspace settings (date format, cancel-reason presets, remark presets, success and fully-booked copy, logo)
  • User name, username, email, role (admin or super-admin), root-admin flag, and account status
  • A password hash (we do not store plaintext passwords)
  • Email verification status and timestamps
  • If you use Continue with Google: Google account identifier, email, name, and whether Google reports the email as verified

2.2 Guest booking and order data

Public forms always collect a full name. Phone number is collected only when the enterprise includes a phone field; that field may be required, optional, hidden, or omitted. Enterprises may add extra fields (for example email, dates, times, numbers, free text, and choice fields). We store answers as submitted, form title and field labels at submission time, a public reference code (for example BO-7K2M9Q), an unguessable track token used to view the request, a hashed edit key (the plaintext key is shown once after submit), status (pending, confirmed, completed, cancelled), optional remark updates (admin label, guest-facing message, and time for each update), cancel reason and optional note, and submission time. For invite-only forms we also store which invite token was used.

Anyone who has the enterprise’s public track page, a valid reference code, and a valid track token (including the track link shown after submit) can view that request’s details. Treat the reference code like a username and the track token like a password. Either one alone is not enough to open the request. Changing a pending request also requires the edit key shown at submit; treat that key like a password. After the enterprise confirms, completes, or cancels the request, guests cannot edit it. An enterprise can turn guest tracking off on a designed form (for example a contact form). In that case guests are not shown a reference code or track token, that form has no track panel, and guest edit is not available. Staff still receive the submission.

Designed forms can be open (anyone with the public URL may submit) or invite-only. Invite-only forms require a unique invite link. We store invite tokens, optional labels, revoke time, and a link from each invite-only submission to its invite. One pending request is allowed per invite at a time. The same invite can be used again only after that request is cancelled. After a request on that invite is confirmed or completed, the invite link cannot be used again. Treat invite links as secrets — anyone with a valid invite link can submit.

2.3 Billing data

Plan upgrades and credit purchases are manual. We do not process card numbers in the app. When you submit a billing request we may store the target plan or credit amount, payment region (Myanmar or international), currency (MMK or USD), quoted amount, contact channel (Viber, Telegram, WhatsApp, or email), contact number, message, and a payment screenshot you upload. Platform operators review these requests and approve or reject them.

2.4 Support tickets

Workspace admins can browse in-app help articles and, if those do not answer the question, open a support ticket. We store the ticket subject, category, message thread, optional screenshot, enterprise, and the account that opened it. Platform operators (super-admins) read and reply in the app to provide support.

2.5 Files you upload

We store enterprise logos, images used on public forms, billing payment screenshots, and optional support-ticket screenshots in object storage. Logos and form images are served at a public URL so they can appear on shared forms. On paid plans, guests may attach images or PDFs to a form. Those guest files are stored in private object storage and are not published at a public URL. Workspace admins can download them. We keep file name, type, size, and a storage key so we can serve and delete the file with the submission.

2.6 Notifications

We create in-app notifications for workspace events such as new submissions, plan limits, a form closing, billing updates, and support ticket replies. Outbound notification email is designed but not currently sent; those records stay in the product.

2.7 Technical data

We automatically process session and security cookies (see Cookies below), standard server logs (such as IP address, browser, request time, and pages requested) as needed to run and secure the Service, and language preference via the locale in the URL (/en/ or /my-MM/). For abuse control we store a short-lived hash of the visitor IP (not the raw address) for about 48 hours. Admin theme preference is stored in localStorage on your device (bom-theme) and is not sent to us as a cookie. The submissions table datetime display preference is a first-party cookie (bom-show-full-datetime).

We do not use third-party advertising pixels, Google Analytics, or similar marketing trackers in the current product. Cloudflare Turnstile (bot check) runs on enterprise registration and public forms.

We use personal data to:

  • Create and operate enterprise workspaces and public forms
  • Authenticate users (email or username and password, or Google)
  • Verify email addresses and reset passwords
  • Accept guest submissions, apply capacity and plan limits, and let guests track status
  • Show dashboards and in-app notifications to workspace users
  • Process billing requests and apply plan or credit changes after review
  • Provide in-app help articles and support tickets between workspace admins and platform operators
  • Isolate each enterprise’s data from other enterprises
  • Maintain security, prevent abuse, and comply with law
  • Improve and support the Service

We do not sell personal data.

Depending on your location, we rely on contract (to provide the Service you or your organization signed up for), legitimate interests (security, fraud prevention, product operation, and support), consent where required (for example optional Google sign-in), and legal obligation when we must retain or disclose data.

Enterprises are responsible for having a lawful basis to collect guest data on their forms, including any extra fields they add.

We share data only as needed to run the Service:

RecipientWhy
GoogleOptional Continue with Google (OpenID email and profile). Google’s own policies also apply.
CloudflareTurnstile bot check on enterprise registration and public guest forms. Cloudflare’s own policies also apply.
ResendTransactional email: email verification and password-reset links.
Hosting and databaseApplication and PostgreSQL hosting for the Service.
Platform operators (super-admins)Operate the platform: enterprises, users, billing requests, and aggregated usage. They can access workspace data as needed for support and billing.
Your enterprise teammatesAdmins in the same workspace can see that workspace’s forms, submissions, users, and settings.
AuthoritiesIf required by law or to protect rights and safety.

Guest submissions are not shared with other enterprises. Fonts used in the app are bundled at build time; the browser does not need to call Google Fonts at runtime for those typefaces.

CookiePurpose and life
sessionSigned-in session (HTTP-only JWT). Secure in production; SameSite=Lax. Typically 7 days.
google_oauth_stateCSRF protection during Google sign-in. About 10 minutes.
google_signup_pendingCompleting enterprise setup after Google signup. About 30 minutes.
google_signup_credentialsOne-time generated username and password after Google signup. About 5 minutes.
Locale cookieThe language middleware may remember /en or /my-MM.
bom-show-full-datetimeAdmin submissions table: full submitted datetime vs date only. About 1 year. Not HTTP-only; set in the browser so the next page load matches.
Cloudflare TurnstileChallenge cookies may be set on challenges.cloudflare.com when a bot check runs. They are not first-party BOIntake cookies.

The session cookie is essential. If you block it, you cannot stay signed in.

We keep data while the account or workspace is active and as needed afterward for billing, security, and legal requirements.

  • Passwords are stored as bcrypt hashes.
  • Guest edit keys are stored as bcrypt hashes. The plaintext key is shown once after submit.
  • Guest track tokens are stored so the track page can look up a request. Treat them like secrets.
  • Email-verification tokens expire after 24 hours (stored as SHA-256 hashes).
  • Password-reset tokens expire after 60 minutes (stored as SHA-256 hashes).
  • Hashed visitor IPs used for rate limits are removed after about 48 hours.
  • Workspaces can deactivate user accounts so those users cannot sign in. Users and forms are not deleted in the product; contact us for permanent erasure.
  • Soft-deleted submissions stay in a recycle bin for 30 days, then are permanently deleted.
  • Super-admins can suspend or archive enterprises.

Soft-deleted submissions are permanently removed after 30 days. For other permanent deletion, contact us (or, for guest data, contact the enterprise that collected it). Some records may remain in backups for a limited period.

We use measures appropriate to a web app of this type, including hashed passwords, hashed guest edit keys, hashed email tokens, HTTP-only session cookies, HTTPS in production, per-enterprise data scoping, Cloudflare Turnstile on public registration and guest forms, IP-based rate limits, unguessable track tokens for viewing submissions, and unguessable invite tokens for invite-only forms. No method of transmission or storage is completely secure. Keep track tokens, edit keys, invite links, and login credentials confidential.

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection.

  • Workspace users: use Settings and account tools where available, or email support@bointake.com.
  • Guests: contact the enterprise whose form you submitted. We will assist that enterprise where we reasonably can.
  • Google sign-in: you can also manage Google’s sharing of your account in your Google account settings.

We may need to verify your identity before acting on a request.

The Service is built for enterprise operations, not for children. We do not knowingly collect account data from children under 13 (or a higher age required in your country). Enterprises must not design forms to target children unless they comply with applicable children’s privacy laws.

We may process data in countries other than yours (for example where our host, Resend, or Cloudflare Turnstile operates). If you are in Myanmar, the EEA, UK, or another region with transfer rules, we take steps required by those rules when we transfer data.

We may update this policy. The “Last updated” date will change. Material changes may also be announced in the product or by email to workspace contacts.

Contact BOIntake using the details below. Guests should also contact the enterprise that collected their data.

Related: Terms of Service