Security & privacy
Your bookings and your clients’ details, protected — and stored in Canada.
NextiaBooking runs on the Nextia platform, so it shares the same account, sign-in and protections as every Nextia app.
Data stored in Canada
- Nextia’s databases (Azure Database for PostgreSQL) and file storage (Azure Blob Storage) are in Microsoft Azure’s Canada Central region.
- The sign-in directory (Microsoft Entra External ID) was created in Canada Central.
- Backups are kept in Azure’s paired Canadian region.
- Services you choose to connect — such as Google Calendar, Microsoft 365, Zoom or Stripe — process data under their own terms, and are named in our privacy policy.
Sign-in and multi-factor authentication
- Sign in with an email and password, or with your Google, Microsoft or Apple account.
- Multi-factor authentication is required for every customer account, with a one-time code sent by email.
- Nextia never holds your password: authentication is handled by Microsoft Entra External ID.
- Your account is keyed to your sign-in identity, not your email address — so changing an email never creates a second account.
Each business is walled off
- Every request for business data is checked against the business it belongs to and the person’s role in it.
- Each app has an automated tenant-isolation test suite that fails the build if data could be read across businesses.
- Clients are shared across your own Nextia apps — never across businesses.
Your clients’ information
- People who book with you don’t need a Nextia account. Your business decides which questions the booking form asks, and is accountable for asking only what it needs.
- Waitlists and group sessions never show anything that identifies another client on the public booking page.
- Staff calendar connections request only calendar access, and can be revoked at any time by disconnecting — or from Google’s or Microsoft’s own security settings.
Credentials and payments
- Tokens for connected calendars and meeting providers, and payment-provider credentials, are encrypted at rest.
- Subscriptions are billed through Stripe; Nextia stores subscription status, never card numbers.
- Nextia’s logging rules forbid logging passwords, tokens, payment credentials or client data beyond identifiers.
Accountability you can see
- Consequential actions are recorded in an audit trail.
- If Nextia support ever needs to act inside your account to help you, it requires a stated reason and every session is recorded.
- The business owner controls the business’s data, including removing a team member’s access.
No trackers in the apps
- The Nextia apps set no analytics cookies and run no third-party trackers; the only stored sign-in state is Microsoft Entra’s own.
- The optional weekly summary email is off unless you turn it on.
Privacy questions
For access, correction or deletion requests about your Nextia account, email privacy@nextia-ai.com.
If a business booked you or invoiced you through Nextia, that business is responsible for your information — contact them first.
Let clients book the time that actually works.
Publish a booking page, connect your calendar and let reminders do the follow-up.
14-day free trial · One Nextia account for every Nextia app · Data stored in Canada