Booked & Beautiful

Privacy notice

Last updated: 18 August 2026

Your reading life is private. This notice explains what personal data we process, why, and what control you have over it.

Data controller

Alexandre Escudeiro, trading as Booked & Beautiful, is the data controller for the personal data described here.

Trading name:
Booked & Beautiful
Owner:
Alexandre Escudeiro
Legal form:
Sole trader (empresário em nome individual), Portugal
Email:
support@bookedbeautiful.com
Complaints book:
Livro de Reclamações Eletrónico — complaints are answered within 15 working days.

What we collect and why

  • Account data — email address, password hash, display name, and (if you sign in with Google) the basic profile Google returns. Used to create and secure your account. Legal basis: performance of our contract with you.
  • Reading data — books, shelves, progress, ratings, dates, notes, journal entries and uploaded cover images. Used only to provide the service to you. Legal basis: performance of our contract.
  • Subscription data — your plan, status, billing period and the customer and subscription identifiers issued by Paddle. Used to give you the features you paid for. Legal basis: contract and legal obligation (accounting).
  • Technical and security data — IP address, sign-in attempts, error logs and basic request logs kept by our hosting provider. Used to keep the service secure and to diagnose faults. Legal basis: legitimate interest in security and reliability.
  • Support messages — anything you send us by email. Legal basis: legitimate interest in answering you.

We do not sell personal data, we do not profile you for advertising, and we do not use your reading data to train machine learning models.

Payment data

Payments are processed by Paddle, our Merchant of Record. Card details are entered directly into Paddle's checkout and never reach our servers. Paddle acts as an independent controller for payment, tax and invoicing purposes and is also a recipient of the account email you use at checkout.

Who we share data with

  • Cloud hosting and database providers that run the application and store your data.
  • Paddle, for the sale of Premium, subscription management, tax and invoicing.
  • Our transactional email provider, to send account and support emails.
  • Book metadata services (Google Books, Open Library) — searches send the query text only, never your identity or library.
  • Professional advisers and public authorities, where legally required.

International transfers

Our infrastructure is located in the European Union. Where a provider processes data outside the EEA, the transfer is covered by an adequacy decision or the European Commission's Standard Contractual Clauses.

Cookies and local storage

We use Plausible, a privacy-first analytics tool that does not use cookies, does not collect personal data, and cannot identify individual visitors — only aggregated, anonymous statistics like page views and country. There is no Google Analytics, no advertising pixel and no third-party tracker that identifies you — which is why you still see no cookie consent banner.

We use strictly necessary browser storage only: your authenticated session (so you stay signed in) and your theme preference. During checkout, Paddle sets its own cookies necessary to process the payment.

How long we keep data

Account and reading data is kept while your account exists. If you delete your account, your reading data is deleted along with it. Billing records are kept for as long as tax law requires (normally 10 years in Portugal). Security logs are kept for a short period, typically up to 90 days.

Your rights

Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. You can withdraw consent where processing relies on it. You can export your whole library to CSV yourself, at any time, from the tracker.

Email support@bookedbeautiful.com to exercise any of these rights — we respond within one month. You also have the right to complain to the Portuguese supervisory authority, the CNPD (cnpd.pt), or the authority in your country of residence.

Security

Data is encrypted in transit and at rest. Access to your rows is enforced at the database level so one account cannot read another's data. Passwords are stored hashed, and administrative access is restricted and logged.

Children

The service is not directed at children under 16. If you believe a child has created an account, contact us and we will remove it.

Related pages

See also our terms, refund policy and legal notice.