Security and data handling
Clear information about account access, client payments, email connections, signatures, and supported AI access.
Operator and client access remain separate.
The client portal is designed to give each client access to their own booking experience without exposing the operator dashboard or other client records.
Portal access is validated on the server against a stored session that is scoped to a single business and booking. A client session cannot read another client's booking or reach operator screens.
Client payments go through your Stripe account.
You connect your own Stripe account and remain the merchant of record.
BoothIQ does not add a transaction fee. Stripe’s normal processing fees still apply.
Every payment is recorded once, so a refreshed page or a retried request cannot double-charge a client or double-count your ledger.
Your email connection remains under your control.
BoothIQ supports connecting Gmail, configuring your own SMTP provider, or using BoothIQ’s built-in sending.
Replies return to the business inbox configured by the operator, not to a separate BoothIQ inbox.
Connected access can be removed when it is no longer needed.
AI access can be disconnected.
Supported AI connections are scoped to the operator’s BoothIQ account and can be removed when no longer required.
The connection accepts an OAuth 2.1 access token or a personal access token created inside BoothIQ. Either can be revoked, and personal access tokens record when they were last used.
The current toolset does not expose delete actions, and client email is previewed before a send is confirmed.
Signature records remain attached to the agreement.
Supported signature records and completed agreement files remain connected to the appropriate contract and booking.
A stored signature includes the signer’s name, the time it was signed, and the IP address recorded by the server at signing.
Have a security or data-access question?
Email support@photoboothiq.com or use the contact form.

