Privacy, security & merchant ownership

Control the customer relationship without weakening customer rights

MagiBooking gives each business a protected operating workspace, portable records, consent-aware communication, and merchant-directed payment choices. This center explains what the merchant controls, what MagiBooking protects, and where external-provider boundaries apply.

Business-isolated recordsCustomer, booking, payment, staff, consent, import, and audit records are scoped to the business workspace and checked through role-based access.
Consent and privacy requestsTransactional and marketing permissions stay separate. Access, correction, export, deletion, and withdrawal requests have explicit workflows.
Auditable high-risk actionsImports, staff changes, privacy actions, wallet authorization, payment review, and sensitive account events produce traceable records.

Five merchant-control promises

Customer, data, communication, payment, and workspace controls in one system

These controls work together. No single badge can honestly replace customer consent, staff permissions, payment-provider rules, or the merchant's own legal responsibilities.

Direct customer relationship

Clients book through the merchant's branded link without being routed through a competing-services marketplace.

The merchant keeps the business record; the customer keeps applicable privacy and consent rights.

Portable, reviewed data

Supported CSV and Excel files are quarantined, mapped, previewed, deduplicated, and committed only after merchant confirmation.

Imported fields never become proof of marketing consent by default.

Merchant-selected channels

Merchants choose where phone, SMS, email, WhatsApp, Telegram, and Signal links appear.

Signal is E2EE. Telegram Cloud Chats and Secret Chats differ. MagiBooking does not copy external private conversations.

Merchant-directed payments

Stripe can process cards; merchants may also configure supported cash, Zelle, Venmo, Cash App, and verified USDT/USDC ERC20 instructions.

MagiBooking does not custody or exchange merchant-directed funds. Proof and crypto submissions require verification and merchant review.

Protected merchant workspace

Business isolation, owner/manager/staff permissions, consent records, audit logs, privacy requests, and wallet authorization reduce unauthorized access.

Security controls reduce risk; they are not a promise that any system can be absolutely secure.

Customer rights

Customer rights remain part of merchant ownership

Merchant ownership means control of the business relationship, not ownership of a person. MagiBooking keeps customer rights and merchant responsibilities visible.

Access and correction requests
Portable exports
Deletion requests with lawful retention exceptions
Channel-specific consent and withdrawal
No automatic marketing permission from imported records
External providers remain subject to their own privacy and payment terms

Safe upload

Data import safety

Upload paths use a shared safe-upload gateway, encrypted temporary payloads, expiry, merchant attestation, and an explicit preview-to-commit flow.

CSV / Excel import

.csv and .xlsx only, maximum 4MB, up to 500 rows per import.

Logo and brand images

png, jpg, jpeg, or webp only, maximum 3MB.

Support attachments

png, jpg, jpeg, webp, pdf, or txt only, maximum 8MB each, up to 5 files.

Backend checks

Size, extension, MIME type, file signature, empty file, row count, and file count.

High-risk files are rejected

.exe.js.html.svg.php.zip.docm.xlsm

Audit log fields

Merchant or userOriginal filenameFile sizePolicy nameAllowed or rejectedFailure reasonTimestamp