Privacy and spam protection for bookings

How booking photos and answers are kept private, how long bookings are kept, how spam is blocked, and what to ask for so you collect only what you need.

Updated 7 Oct 2026

A booking form collects personal details. This page explains how Forms & Bookings protects them, and the choices that are yours.

Private files

Photos and files that visitors attach are kept in your site's own private storage, not in your public media library. They have no public web address. Only a signed-in member of your team can open one, from the booking, with its Open link.

The app checks what the file really is, not just its name. It accepts a JPG, PNG, HEIC or PDF of up to 5 MB, one file per question. Anything else is refused with a message the visitor can read.

A file that someone uploads but never sends with a booking is removed automatically, within about a day.

Sensitive questions

Mark a question as sensitive for anything like a passport number or an ID photo.

  1. Open the form in Forms and click the question.
  2. Switch on Sensitive.

A File upload question is sensitive on its own when its wording mentions a passport, ID, identity or NRIC. You can switch that off.

For a sensitive question:

  • The answer shows as Hidden in the booking, until a team member clicks Show. Each Show or file open is recorded with who did it and when, but not the answer.
  • Search never looks inside it.
  • It is left out of the summary in the customer's confirmation email.
  • In a CSV export it shows as four dots, unless you tick Include sensitive fields.

One thing to know: the booking alert email to you lists every typed answer as it was entered, including sensitive ones. Photos and files are listed by name only. Send alerts to a mailbox that only your team can read.

Ask only for what you need

Singapore's PDPA asks businesses to collect personal data only for a purpose they can explain, and not to keep it longer than needed. This page is not legal advice, and using the app does not make a business compliant on its own. Some practical habits:

  • Passport numbers and passport photos: ask only when you need them, for example for a trip that crosses a border. Leave them off a class, an enquiry or a local course.
  • Show a question only when it applies. Under Show this question, choose Only when an earlier answer matches, so a trip question appears only when the visitor picks the trip.
  • Make optional things optional. Switch Required off, and put extras under a heading with Start collapsed.
  • Tell people why you ask. Use Help text under the question, for example "Only the dive school sees this, and only to book your ferry."
  • Use a consent line. Add a Consent question that links to your privacy page or terms.
  • Delete when asked. If someone asks you to delete their data, open their booking and use Delete for good. See Manage your bookings.

How long bookings are kept

Each form has a Data retention setting, on its Settings tab:

  • 6 months
  • 12 months
  • 24 months
  • 36 months
  • Keep until I delete them

New forms start at 24 months. A form made before this setting existed has no limit until you choose one, so open each older form and pick a period.

When a booking is past that period, it is deleted for good along with its photos and files. The time is counted from the latest date the booking holds a place on, such as the trip date. If it has no date, it is counted from the day it was made. A trip booked a year ahead is therefore kept until the chosen period after the trip. The clean-up runs about every six hours.

Deleting a booking, whether by hand or by this setting, cannot be undone. Export a CSV first if you need a copy.

Spam protection

You do not set anything up. Every form checks each submission in four ways before it counts as a booking:

  • A hidden box that people never see. Robots fill it in. A submission that did is quietly dropped. The robot is told it worked, and nothing is saved.
  • A minimum time. A form sent within about three seconds of opening is refused. A person cannot read and answer that fast. The visitor is asked to check their answers and send again.
  • A limit per visitor. One connection can send about 10 bookings in 10 minutes, and about 10 uploads. After that the visitor sees "Too many bookings from this connection. Please wait a few minutes and try again."
  • An invisible Cloudflare check (Turnstile). It runs for sites on a contentmetric.com address and asks a visitor for nothing in most cases. If it cannot confirm a visitor, they see "We couldn't confirm you're not a robot. Please try again, or contact us on WhatsApp." Sites on their own domain do not use this check, and the other three still apply.

Spam that is dropped never appears in Bookings, never takes a place on a date, and never emails you.

Common questions

A real customer says the form would not send. They may have used autofill and sent in under three seconds, or shared a connection with many people. Ask them to wait a minute and try again, or to message you on WhatsApp.

Where are the files stored? In the private storage of your site. They are deleted with the booking, and with the site if the site is deleted.

Can I switch the spam check off? No. It is part of every form.

More in this topic

Back to Help centre

Still stuck?

Write to us and a person replies.

Email [email protected]