Home / Privacy policy

Privacy policy

How BookAndWaive handles your data

A plain reading of what this website collects, why it is collected, how long it is kept and how to get it deleted. Last updated March 2, 2026.

Who is responsible

The controller of the personal data described here is MLJ, SASU, publisher of bookandwaive.com, represented by Jimenez Julien. You can reach the controller at any time at jimenezjulien42@gmail.com. This policy covers the marketing website you are reading now. Data your venue stores inside a BookAndWaive account, including guest records and signed waivers, is covered by the data processing terms in your subscription agreement, where your venue is the controller and MLJ, SASU acts as processor on your written instructions.

What the contact form collects

The only place this website collects personal data is the demo request form on the home page. When you submit it, these fields are transmitted and stored:

  • name, your full name, so a reply can be addressed to a person.
  • email, your work email address, which is the address we reply to.
  • company, your venue name, so we can look at your public booking page before the call.
  • role, your role at the venue, chosen from a short list such as owner or general manager.
  • request, what you are asking for, such as a demo or a quote.
  • size, how many rooms, lanes or courts you run, which shapes the pricing conversation.
  • message, the free text you write about what jams up your busiest hour.
  • consent, a record that you ticked the consent box before sending.

Three hidden fields travel with the submission and contain no personal data about you: form-name, which routes the submission, subject, a fixed line naming the site, and recipient, the mailbox that receives it. A honeypot field named bot-field is present and invisible to people; only automated scripts complete it, and any submission that fills it is discarded. Netlify also records the submission timestamp and the originating IP address as part of its own spam screening.

Why we may process it, the legal basis

Under the GDPR, processing rests on your consent, given by ticking the consent box, and on our legitimate interest in answering a business enquiry sent to us on purpose. Under United States state privacy laws, the processing is what those statutes describe as a request initiated by you. We do not sell personal information, we do not share it for cross context behavioral advertising, and we do not use it for automated decision making or profiling of any kind.

How long submissions are kept

Form submissions are kept for 24 months from the date you send them, then deleted from both the Netlify Forms store and the receiving mailbox. If you become a customer, the enquiry is retained for the life of the account and for 24 months after it closes, because it forms part of the commercial record. If you ask for deletion earlier, we delete it within 30 days and confirm by email, unless a specific legal obligation requires us to keep an invoice or accounting record.

Who processes the data

Submissions are processed and stored by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, United States, which hosts this site and operates the form service. Replies are handled in a Google Workspace mailbox. These are the only two processors involved on the marketing side of the site. No data broker, no advertising network and no lead enrichment service receives anything you send here.

Cookies and measurement

This website sets no advertising cookies, no analytics cookies and no third party tracking pixels. There is no Google Analytics tag, no Meta pixel, no session recorder and no fingerprinting script. Nothing on the site follows you to another website. The only technical storage used is what your own browser does to cache the stylesheet, the script file and the web fonts, which are requested from Google Fonts when the page loads.

International transfers

MLJ, SASU is established in France, and the hosting and form processing are performed in the United States. When personal data moves from the European Economic Area to the United States, that transfer relies on the European Commission standard contractual clauses signed with the processors, along with the technical measures those providers apply, including encryption in transit and at rest. If you would like a copy of the transfer documentation, ask by email and we will send it.

Your rights in the United States

Residents of California, Colorado, Connecticut, Utah and Virginia have the right to know what personal information is held about them, to request a copy of it in a portable form, to correct it, and to have it deleted. California residents may also exercise rights under the CCPA as amended by the CPRA, including the right not to receive discriminatory treatment for exercising them. Because we do not sell personal information or use it for targeted advertising, there is nothing to opt out of on those grounds, but you can still ask us to confirm that in writing. Requests are answered within 45 days, and an authorized agent may act on your behalf if you tell us so in writing.

Your rights in the European Union and the United Kingdom

If the GDPR or the UK GDPR applies to you, you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest. Where processing rests on consent, you can withdraw that consent at any time, which does not affect processing carried out before the withdrawal. You also have the right to lodge a complaint with a supervisory authority, which in France is the CNIL.

How to exercise your rights

Write to jimenezjulien42@gmail.com from the address you used on the form, and say plainly what you want: a copy, a correction or a deletion. No form and no account is needed. You will get a human reply, normally within five business days, and the action itself is completed within 30 days. If we cannot identify you from the request, we will ask one clarifying question rather than demanding identity documents.

Children

This website is a business to business site for venue operators and is not directed at children. We do not knowingly collect personal data from anyone under 16 through this site. If you believe a child has sent us information through the contact form, write to us and it will be deleted the same week. Guest waivers signed by or for minors inside a customer account are a separate matter, governed by that venue's own privacy notice and by the data processing terms of its subscription, with the venue acting as controller.

Security

The site is served over HTTPS with HTTP Strict Transport Security, a content security posture that blocks framing by third parties, and a referrer policy that limits what leaves the page. Access to the receiving mailbox is protected by two factor authentication. If a breach ever affects data collected through this site, affected people are notified by email without undue delay, and the CNIL is notified within 72 hours where the GDPR requires it.

Changes to this policy

When this policy changes in a way that affects your rights, the date at the top of the page changes and the previous version is archived. Minor wording corrections do not trigger a new date. This version is dated March 2, 2026, and it replaces every earlier version.