The idea
I hold little, and I say who sees it.
A diary knows who booked what. That is personal information, and a therapy practice or a support service has members who must not be visible to each other at all. So the rule I keep is simple: I hold as little as the job needs, every field has one owner, and nothing about a member reaches another member unless two people said it could. This page is the whole of it, written so you can hand it to someone who asks “what do you keep on me?”.
What I hold
Every member is a name and an email, because that is what a booking and a statement need, plus the name they choose to be shown as and the colour their bookings take in the diary. Beyond that there is a record an admin or the member may fill in: a formal name for statements, an address, a phone number, an emergency contact, how they pay, who the bill goes to, and notes only admins see. I also keep when they joined, when they were last in, and their bookings and statements, which are the history of your building and never go away. I do not hold a date of birth, medical or accessibility notes, identity documents, or any photograph beyond the picture on your sign-in account, on purpose: a field I do not have is a field I cannot leak.
For example
Jo Patel: display name Jo, a teal booking colour, [email protected]. On her record, a postal address and mobile, her sister as emergency contact, pays by bank transfer, billed to Patel Counselling Ltd, and an admin note that says the invoice goes to the practice manager.
Leave it alone if
You never need to phone or post anything to a member. Then the record stays empty and I hold a name, an email and their bookings.
Who sees which part
Personal details belong to the member: address, phone, emergency contact. An admin can fill them in before the member has ever signed in, so a new member is not stranded, and the moment the member signs in for the first time those fields lock to the admin and open to the member. Payment details belong to the admins: how they pay, who is billed, the notes. A finance admin sees the payment details and nothing personal. Another member sees none of it, ever, and no list, report or connection carries a member’s address or phone. Every change to the record is logged by field name, never by value, so “who changed the payment method” can be answered without the log becoming a second copy of the data.
For example
The practice manager types Jo's address when she adds her. Jo signs in that evening; from then on the address is Jo's to change on her Account page and the manager can only read it. The treasurer, a finance admin, sees that Jo pays by bank transfer and is billed to the company, and nothing more.
Leave it alone if
You have one admin and everyone else books. Then the admin sees the record, each member sees their own, and there is nothing to arrange.
Names on bookings: two keys
Whether one member can see another member’s name on a booking needs two yeses: the organisation allows it, on Settings, Booking rules, and the member chooses it, on their own Account page. An admin cannot switch it on for someone; a choice an admin can make is not consent. With one key or none, the booking says Booked and carries no colour, because a colour alone lets you follow a person across the week without a name. Both keys switch off backwards as well as forwards: turn either off and every past booking is masked again at once. Admins and the owner always see who booked; a team booker sees their own team by name because an admin put them in charge of it.
For example
A community hall turns name sharing on so the yoga teacher can be found on the calendar. She switches hers on and the room view says Clara. The bereavement group's members leave theirs off and their sessions say Booked, and always will.
Leave it alone if
Members never need to know who else is in. Leave the organisation switch off and every other member's booking says Booked, whatever anyone chooses.
What a booking shows, and to whom
Admins see everything on a booking: who, their email, the answers to your booking questions, and who entered it and when. Another member sees the room and the time, and Booked or a shared name, and nothing else: never an email, never a form answer, never a note. The floor map follows the same rule. A guest hire is a person who is not a member; their name, phone and answers are for the admins and the day sheet, and I delete the person 12 months after the booking while the booking itself stays in the diary.
For example
Dr Okafor's Friday session: the practice manager sees his name, email, the form answers and the note that the booking was entered by the secretary. The counsellor next door sees that Room 1 is taken from two until three, and nothing else.
Leave it alone if
You are the only person who looks at the diary. Then you see everything, and nothing here needs deciding.
Leaving, and what is deleted
A member can leave your organisation from their Account page, and an admin can remove one from the member’s page. Either way they lose access at once, their future bookings are flagged for the admins to deal with and cancelled by me after 7 days if nobody does, and their past bookings and statements stay on record, with their name, because your accounts and your diary history have to stay true. 30 days after they leave I delete the record: the address, the phone, the emergency contact, the payment details and the notes. The wait is so that an accidental removal can be undone without asking anyone to type it all again. Their sign-in still works for any other organisation they belong to. When active membership removes someone who stopped booking, which has its own page, the record goes with them at that moment.
For example
A member leaves from her Account page. Her Tuesday bookings for next month are flagged for the admins, who cancel them or reassign the room; anything still standing after 7 days I cancel myself. 30 days after she left, her address, phone and emergency contact are gone. Her name stays on the bookings she made last year.
Leave it alone if
Nobody ever leaves. It happens, though, and there is nothing for you to do when it does.
Where a member's data goes
Statements go to the member by email. A member’s own calendar feed carries their own bookings, and the organisation feed an admin can hold carries every booking with names, into whichever calendar the admin chose. If you connect other software or an assistant, booking events leave Doris with times, rooms and references; a member’s name and email are included only when you switch that on, for that connection, and the switch is off to begin with. Nothing else leaves, except what a member hands over themselves, as when they pay by card and give the card provider their email.
For example
An admin subscribes to the organisation calendar feed on her phone: every booking with the booker's name, in her calendar app. A member's own feed carries only their own bookings. The hall's webhook to its accounts package sends booking times and a reference, and no email address, because nobody switched that on.
Leave it alone if
You use nothing but Doris. Then a member's data goes to their own email inbox, for statements, and nowhere else.
What I never do
- I never show a member another member’s email address, form answers or notes.
- I never let an admin change a member’s address or phone once that member has signed in.
- I never let an admin switch name sharing on for a member. It is theirs to choose, and theirs to undo.
- I never keep an emergency contact after the relationship ends. Someone who never joined Doris should not stay in it.
- I never hold a date of birth, medical notes, identity documents, or a photograph beyond the one on your sign-in account.
- I never send a member’s email address to another system unless you switch it on for that system.
Where it lives
A member’s page, under Contact & payment, is the record as an admin sees it. A member sees and edits their own on their Account page, where the name sharing switch also lives. The organisation’s name sharing switch is on Settings, then Booking rules. Who may see what by role is Roles and what each can do (bookwithdoris.com/guides/roles); the tidying away of members who stopped booking is Active membership (bookwithdoris.com/guides/active-membership). The privacy policy (bookwithdoris.com/privacy) says the same things in the words a regulator expects.