πŸ”’ Legal

Privacy Policy

We are committed to protecting your personal data and being transparent about how we use it.

Effective: 13 April 2026Applies to: All Agendo products
πŸ“‹
Section 01

What we collect

We collect only what is necessary to provide the service. Personal data we process includes:

CategoryExamplesSource
Account dataFirst and last name, email address, mobile phone numberProvided by you on registration
Profile dataProfile photo (optional)Uploaded by you
Appointment dataBooked services, dates, times, notes, status historyGenerated when a booking is created
Location dataApproximate device location (latitude / longitude)Collected with your permission to show nearby studios
Device & usage dataPush notification token, app crash reportsCollected automatically
Subscription dataSubscription status, plan type, purchase datesReceived from RevenueCat / App Store / Google Play
πŸ”’

We do not collect payment card numbers or bank details. All payment transactions are handled directly by Apple or Google billing infrastructure and RevenueCat.

βš™οΈ
Section 02

How we use your data

We use the data we collect to:

  • Provide the service β€” authenticate your account, display your appointments, connect you with studios and professionals.
  • Send notifications β€” appointment confirmations, reminders, status updates, and join-request approvals.
  • Show nearby studios β€” your location is used only in-session to sort studios by proximity and is never stored on our servers.
  • Manage subscriptions β€” verify your professional subscription status to unlock professional features.
  • Improve the product β€” aggregate, anonymised usage analytics and crash reports to fix bugs and improve performance.
  • Comply with legal obligations β€” respond to lawful requests from public authorities.

We do not use your data for advertising, sell it to third parties, or use it to build marketing profiles.

🀝
Section 03

Sharing & third parties

We share personal data only with the following sub-processors, each bound by appropriate data protection agreements:

Sub-processorPurposeData transferred
RailwayCloud infrastructure hosting the Agendo API and databaseAll data stored in the platform
Amazon Web Services (S3)Storage of user profile photosProfile images only
TwilioSMS OTP delivery for account registration verificationMobile phone number
SendGridTransactional email delivery (login OTP codes)Email address
RevenueCatSubscription management and receipt validationSubscription status, purchase identifiers
Apple / GooglePush notification deliveryDevice push token

We do not sell, rent, or share your personal data with any other third party for their own commercial purposes.

πŸ—„οΈ
Section 04

Data retention

We retain your personal data for as long as your account is active or as needed to provide the service.

  • Account data β€” retained until you delete your account.
  • Appointment records β€” retained for 3 years after the appointment date for studio record-keeping purposes, then deleted.
  • Profile photos β€” deleted from storage within 30 days of account deletion or photo replacement.
  • Device push tokens β€” removed when you log out or delete your account.
  • Aggregated analytics β€” retained indefinitely in anonymised, non-identifiable form.

When you request account deletion, all your personal data is permanently deleted from our systems within 30 days.

πŸ›‘οΈ
Section 05

Your rights (GDPR)

Where the GDPR or equivalent legislation applies, you have the following rights:

  • Access β€” request a copy of the personal data we hold about you.
  • Rectification β€” correct inaccurate or incomplete data.
  • Erasure β€” request deletion of your personal data (β€œright to be forgotten”).
  • Restriction β€” limit how we process your data in certain circumstances.
  • Portability β€” receive your data in a structured, machine-readable format.
  • Objection β€” object to processing based on legitimate interests.

To exercise any of these rights, contact us at support@agendo.today. We will respond within 30 days.

πŸ”
Section 06

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS) and at rest
  • Regular security assessments and penetration testing
  • Access controls and audit logging
  • Employee training on data protection obligations
  • Incident response procedures and breach notification protocols

While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

πŸ§’
Section 07

Children’s privacy

Agendo is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

🌍
Section 08

International transfers

Your data is stored on servers located within the European Economic Area (EEA). Some of our sub-processors (such as Twilio and SendGrid) may process data in the United States. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

πŸ“
Section 09

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, where the changes are material, notify you via the App or by email.

Your continued use of the App after the effective date of any changes constitutes acceptance of the updated policy.

πŸ“§
Section 10

Contact

If you have questions or concerns about this Privacy Policy or how we handle your personal data, please contact us:

Email: support@agendo.today