Data & privacy

IT / Technical

This page explains what Preb stores about your contacts and bookings, how personal data is protected, and how deletion and retention work. For the isolation model (row-level security) and rate limits, see Rate limits & security.

What data is stored

Within a workspace, Preb stores:

  • Contacts — email, phone, and name, plus attribution data (UTM parameters and ad click IDs such as fbclid/gclid), firmographic data, and any custom fields you collect on the booking form. Contacts are unique per workspace by email.
  • Bookings — the meeting details, attendees (name and email), the host, and the booker's consent records: the SMS opt-in, and — when an event type requires a consent checkbox — a consent timestamp and the exact consent text the booker agreed to.
  • Deals & transactions — pipeline deals and the payments recorded against them (including those pushed via the transactions API).
  • Aggregate analytics — funnel and page-view statistics used for reporting. These contain no personal data: form-funnel events record only the field name and time spent (never what was typed, and no visitor identifier), and page views record only the visit and its campaign parameters.

When a contact is created. By default, a visitor becomes a contact when they submit the first step of the booking form. An event type can instead opt into saving details as the visitor types (before submission) — when that setting is on, the booking page shows a visible notice next to the form telling visitors their details are saved as they type. Visitors are never captured silently.

No session recording. Preb does not record screens, sessions, or keystrokes on public booking pages. Error monitoring runs with EU data residency and scrubs personal data from anything it records.

PII & hashing

Ad-platform tracking is double-gated: it runs only if you enable the integration, and only for visitors who accepted marketing tracking in the booking page's consent banner. This applies to the in-browser tags and to the server-side conversion events — a visitor who declines sends nothing to Meta or Google, in any form. The visitor's consent state is passed to Google via Consent Mode v2. Booking pages of workspaces with no ad tracking configured don't show a consent banner at all, because nothing consent-requiring runs there.

For consented visitors, the personal identifiers Preb sends for conversion tracking are hashed with SHA-256 (lowercase hex) before they leave the system:

  • Email — lowercased and trimmed, then hashed.
  • Phone — normalised, then hashed (for Meta the digits only; for Google in E.164 form keeping the leading +).

The raw values are never transmitted to the ad platform. For Google Ads the hashed identifiers normally accompany the ad's click ID; if a workspace opts an event into Enhanced Conversions for Leads, they are also uploaded for consented visitors who arrived without a click ID — the same hashed data, the same consent gate. Internally, the conversion-dispatch log stores no PII at all (only the provider, event name, and result), and the error monitor scrubs a denylist of sensitive keys — emails, phone numbers, click IDs, tokens, secrets, cookies, and API keys — from anything it records.

Data residency

Preb runs on managed database and hosting providers (see Sub-processors). Your workspace data is stored within the EU (Frankfurt region).

Data processing agreement (DPA / AVV)

Our data processing agreement is published at preb.co/dpa. It is incorporated into our Terms and takes effect automatically when you accept them — no signing flow needed. A German version is available on request via support.

Deletion & retention

Deleting a contact. Workspace admins can delete a contact from the Pipeline. A contact that has deals or transactions (i.e. revenue history) can't be deleted until you delete or reassign those first. When a contact is deleted, their notes, deals, and transactions are deleted with them, while past bookings are kept (the contact link is simply cleared) so your booking history and reporting stay intact.

Automatic retention. Some data is pruned automatically:

DataRetained for
Unfinished leads (started the form, never submitted)30 days by default
Page views90 days
Conversion-dispatch log30 days
Form (funnel) events90 days

The unfinished-lead purge only removes true dead ends: a lead that booked, has a deal, note, or assignment, or was synced to your CRM is always kept. Workspace owners can turn the purge off in Settings → Data retention — doing so makes your workspace responsible for storing those leads lawfully. Owners can also enable sending unfinished leads to a connected CRM; leads transferred that way are kept as pipeline data.

Contacts (other than unfinished leads), bookings, deals, and transactions are not auto-deleted — they persist until you remove them.

Sub-processors

Preb relies on the following third-party providers to operate. Personal data is shared with them only as needed to deliver the service:

ProviderPurpose
Supabase (AWS)Database & authentication — EU (Frankfurt)
Vercel (incl. Upstash)Application hosting & rate-limiting store
ResendTransactional email (confirmations, invites)
TwilioSMS notifications (opt-in only)
StripePayments & subscription billing
SentryError monitoring — EU data region, PII-scrubbed
TermlyCookie-consent management
FeaturebaseIn-app support & feedback widget (account holders only)
ToltReferral program (participants only)

Services you connect to your workspace — calendars (Google, Microsoft, Zoho), conferencing (Zoom, Meet, Teams, Zoho Meeting), CRMs (HubSpot, GoHighLevel), Slack, your own Stripe account, and the ad platforms (Meta & Google, hashed identifiers, consented visitors only) — receive data on your instruction and under your own relationship with those providers; they are not Preb sub-processors.

The authoritative list

The legally binding sub-processor list, including locations and transfer mechanisms, lives in our data processing agreement at preb.co/dpa (Annex 3). We announce changes there in advance.