Effective date: August 5, 2026 · Last updated: August 5, 2026
This Privacy Policy explains how Bilo Tech Ltd ("Bilo Tech", "TurnUp", "we", "us", "our") collects, uses, shares, and protects personal data when you use the TurnUp Service, whether as a Business User, a Client, or a visitor to a TurnUp booking page. It should be read together with our Terms of Service and Cookie Policy.
This Policy applies to personal data we process as a result of operating the Service — for example, data about Business Users and their staff, and data about Clients who book, or attempt to book, a service. Where a Business User uses TurnUp to collect and manage their own clients' data, the Business User is generally the party responsible for deciding how that data is used (a "controller" under data-protection law), and we act on their instructions to provide the Service (a "processor"), while also using certain data for our own purposes described below (for example, platform security and improving TurnUp) as an independent controller.
Bilo Tech Ltd is a company incorporated in Ghana under the Companies Act, 2019 (Act 992). For the purposes of this Policy, Bilo Tech Ltd is the data controller for personal data we process for our own purposes (such as account administration, platform security, billing, and direct marketing you opt into), and can be reached at support@turnup.show.
| Who | What we collect |
|---|---|
| Business Users | Name, email address, password (stored as a salted hash, never in plain text), business name, booking-page URL, phone number, business address/location, opening hours, service listings and pricing, deposit settings, and payout/identity information collected on our behalf by Stripe or Paystack (we do not store full card or bank account numbers). |
| Clients | Name, phone number, and (optionally) email address provided at booking or account sign-up; for account holders, booking history within the Service. |
| Everyone | Any information you include in messages sent through the Service, and any information you provide when you contact our support team. |
When you use the Service, we and our infrastructure providers automatically collect limited technical information, including IP address, browser and device type, pages viewed, timestamps, and — where you enable push notifications — a device push-subscription identifier. See our Cookie Policy for details on cookies and similar technologies.
If a Business User sets their location using our map-search feature, we receive place, address, and coordinate data from Google Maps/Places. If a payment is made or a payout account is set up, Stripe or Paystack shares limited information back with us (such as payment status, payout status, and verification status) — not full card, bank, or government-ID numbers.
We do not intentionally collect sensitive categories of personal data (such as health data, racial or ethnic origin, or religious beliefs). Please do not include such information in booking notes, messages, or any other field within the Service unless it is strictly necessary and you have a lawful basis to share it (for example, a Client voluntarily telling a business about a relevant health consideration for a specific appointment).
Where the GDPR or a similar law applies, we rely on the following legal bases: performance of a contract (to provide the Service you or a Business User signed up for, including completing a Booking); legitimate interests (for example, preventing fraud, securing the Service, and improving it — balanced against your rights and interests); consent (for example, optional marketing communications or non-essential cookies, which you can withdraw at any time); and legal obligation (for example, retaining payment records as required by law).
We use your phone number and/or email address to send booking confirmations, reminders, reschedule links, deposit notices, and — for Business Users — account and platform notifications. These are transactional messages tied to an account or a Booking, not unsolicited marketing. Message delivery is provided by Twilio (SMS and WhatsApp) and Twilio SendGrid (email); see Section 8 for more on these providers. You can manage communication preferences as described in our Terms of Service, Section 9.
We use a small number of strictly necessary cookies to keep you signed in and to protect the Service from abuse. We do not currently use advertising or cross-site tracking cookies. Full details, including cookie names and durations, are in our Cookie Policy.
We do not sell personal data. We share personal data only in the following circumstances:
| Recipient | Purpose | What is shared |
|---|---|---|
| The relevant Business User | To fulfil a Booking | A Client's name, phone number, optional email, and Booking details. |
| Stripe / Paystack | Payment processing and payouts | Payment amount, currency, and the minimum identity/account information those processors require by law. |
| Twilio (incl. SendGrid) | Sending SMS, WhatsApp, and email messages | Recipient phone number/email and message content. |
| Supabase | Hosting our database, authentication, and file storage | All data stored in the Service, encrypted in transit and at rest by Supabase's infrastructure. |
| Google Maps/Places | Location search and address autocomplete for Business Users | Search queries you type and the resulting selected address. |
| Law enforcement or regulators | Where required by law, legal process, or to protect rights, safety, or property | Only the information reasonably required to comply. |
| A successor entity | In connection with a merger, acquisition, financing, or sale of assets | Personal data as part of the transferred business, subject to this Policy or a successor policy. |
We and our service providers may process and store personal data in countries other than your own, including Ghana and the countries where our infrastructure and processor partners operate. Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a country that has not been found to provide an adequate level of protection, we rely on appropriate safeguards recognized under applicable law, such as Standard Contractual Clauses, and require our processors to provide an equivalent level of protection to your data wherever it is processed.
We retain personal data for as long as necessary to provide the Service and for legitimate business purposes, such as maintaining Booking history, complying with legal, tax, and accounting obligations, resolving disputes, and enforcing our agreements. Booking and payment records are typically retained for the period required by applicable tax and financial-record-keeping laws (commonly up to 6–7 years). When data is no longer needed, we delete it or anonymize it so it can no longer identify you.
Wherever you are located, you can ask us to: confirm what personal data we hold about you; correct inaccurate data; delete your data, subject to our legal retention obligations; or ask a question about how we handle your data. You can exercise these rights by contacting support@turnup.show. If your data was provided to us by a Business User you booked with, we may direct part of your request to that Business User, since they control the underlying Booking relationship.
If the GDPR or the UK GDPR applies to you, you additionally have the right to:
You also have the right to lodge a complaint with your local data-protection supervisory authority. We encourage you to contact us first at support@turnup.show so we can try to resolve your concern directly.
If you are a California resident, you additionally have the right to:
You may exercise these rights yourself or through an authorized agent by contacting support@turnup.show. We may need to verify your identity before completing certain requests.
As a Ghana-incorporated company, we are subject to Ghana's Data Protection Act, 2012 (Act 843) and registered, or in the process of registering, as a data controller with Ghana's Data Protection Commission. If you are in Ghana, you have the rights described in Section 11 above, and may also lodge a complaint with the Data Protection Commission if you believe we have not handled your personal data lawfully.
Because TurnUp is used across several countries, we aim to honor equivalent rights for users protected by other data-protection frameworks, including Nigeria's Data Protection Act 2023, Kenya's Data Protection Act 2019, and South Africa's Protection of Personal Information Act (POPIA). If a local law grants you rights beyond those described in this Policy, contact us and we will do our best to honor them.
The Service is not directed at, and we do not knowingly collect personal data from, children under the age of 16. If you believe a child has provided us with personal data, contact support@turnup.show and we will delete it.
We use technical and organizational measures designed to protect personal data, including encryption of data in transit (HTTPS/TLS) and at rest, access controls limiting who can view data within our organization, and hashed (never plain-text) storage of passwords. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
If we become aware of a security incident that risks your personal data, we will notify affected users and, where required by law, the relevant supervisory authority (such as Ghana's Data Protection Commission or an EU authority), without undue delay and in line with applicable legal timelines.
The Service may contain links to third-party websites (for example, a payment processor's checkout page or a map provider). We are not responsible for the privacy practices of those third parties; please review their own privacy policies.
We may update this Policy from time to time. We will post the updated Policy with a new "Last updated" date and, for material changes, provide additional notice where required by law.
Bilo Tech Ltd — for any privacy question or to exercise your rights, contact support@turnup.show.