Skip to content

Privacy Policy

Version 1.0 - last updated 03/06/2026

1. Who we are

CayBook ("we", "us") is the data controller for personal data processed through the CayBook platform, operated in the Cayman Islands. This policy is issued in accordance with the Cayman Islands Data Protection Act (2021 Revision) ("DPA").

2. What we collect

3. Legal basis (DPA Schedule 2)

4. Retention

5. Sharing

We share data with: businesses you book with (name, contact, booking details), email delivery (Resend), and cloud hosting (Supabase). All vendors are bound by data-processing agreements. We never sell your data. CayBook does not currently process payments and does not share your data with any payment processor; you pay the business directly at the time of service.

6. Your DPA rights

Under the Cayman DPA you have the right to: access, rectify, erase, restrict, port, or object to processing of your data. Submit requests at your account page. We respond within 30 days.

7. International transfers

Some processors are located outside the Cayman Islands (EU, US). Transfers are protected by Standard Contractual Clauses or adequacy decisions.

8. Security

We use TLS 1.3 in transit, AES-256 at rest, row-level security, rate limiting, and regular audits. See SECURITY.md in our repository.

9. Breaches

We notify the Ombudsman and affected users within 72 hours of confirmed personal-data breaches that pose risk.

10. Complaints

If unsatisfied, contact the Cayman Islands Ombudsman at ombudsman.ky.

11. Contact

Data Protection Officer - privacy@caybook.ky