Privacy Policy
We are committed to protecting your personal data and being transparent about how we use it.
Contents
What we collect
We collect only what is necessary to provide the service. Personal data we process includes:
| Category | Examples | Source |
|---|---|---|
| Account data | First and last name, email address, mobile phone number | Provided by you on registration |
| Profile data | Profile photo (optional) | Uploaded by you |
| Appointment data | Booked services, dates, times, notes, status history | Generated when a booking is created |
| Location data | Approximate device location (latitude / longitude) | Collected with your permission to show nearby studios |
| Device & usage data | Push notification token, app crash reports | Collected automatically |
| Subscription data | Subscription status, plan type, purchase dates | Received from RevenueCat / App Store / Google Play |
We do not collect payment card numbers or bank details. All payment transactions are handled directly by Apple or Google billing infrastructure and RevenueCat.
How we use your data
We use the data we collect to:
- Provide the service β authenticate your account, display your appointments, connect you with studios and professionals.
- Send notifications β appointment confirmations, reminders, status updates, and join-request approvals.
- Show nearby studios β your location is used only in-session to sort studios by proximity and is never stored on our servers.
- Manage subscriptions β verify your professional subscription status to unlock professional features.
- Improve the product β aggregate, anonymised usage analytics and crash reports to fix bugs and improve performance.
- Comply with legal obligations β respond to lawful requests from public authorities.
We do not use your data for advertising, sell it to third parties, or use it to build marketing profiles.
Data retention
We retain your personal data for as long as your account is active or as needed to provide the service.
- Account data β retained until you delete your account.
- Appointment records β retained for 3 years after the appointment date for studio record-keeping purposes, then deleted.
- Profile photos β deleted from storage within 30 days of account deletion or photo replacement.
- Device push tokens β removed when you log out or delete your account.
- Aggregated analytics β retained indefinitely in anonymised, non-identifiable form.
When you request account deletion, all your personal data is permanently deleted from our systems within 30 days.
Your rights (GDPR)
Where the GDPR or equivalent legislation applies, you have the following rights:
- Access β request a copy of the personal data we hold about you.
- Rectification β correct inaccurate or incomplete data.
- Erasure β request deletion of your personal data (βright to be forgottenβ).
- Restriction β limit how we process your data in certain circumstances.
- Portability β receive your data in a structured, machine-readable format.
- Objection β object to processing based on legitimate interests.
To exercise any of these rights, contact us at support@agendo.today. We will respond within 30 days.
Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest
- Regular security assessments and penetration testing
- Access controls and audit logging
- Employee training on data protection obligations
- Incident response procedures and breach notification protocols
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
Children’s privacy
Agendo is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
International transfers
Your data is stored on servers located within the European Economic Area (EEA). Some of our sub-processors (such as Twilio and SendGrid) may process data in the United States. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, where the changes are material, notify you via the App or by email.
Your continued use of the App after the effective date of any changes constitutes acceptance of the updated policy.
Contact
If you have questions or concerns about this Privacy Policy or how we handle your personal data, please contact us:
Email: support@agendo.today