Privacy Policy
We are committed to protecting your personal data and being transparent about how we use it.
Contents
Agendo is an appointment booking platform that connects clients with studios and professionals. This Privacy Policy describes how we collect, use, and protect your personal information when you use the Agendo mobile app or any related services.
For questions about this policy or your personal data, contact us at agendo.app@outlook.com.
We collect only what is necessary to provide the service.
| Category | Examples | Source |
|---|---|---|
| Account data | First and last name, email address, mobile phone number | Provided by you on registration |
| Profile data | Profile photo (optional) | Uploaded by you |
| Appointment data | Booked services, dates, times, notes, status history | Generated when you or a professional creates a booking |
| Location data | Approximate device location (latitude / longitude) | Collected with your permission to show nearby studios |
| Device & usage data | Push notification token, app crash reports | Collected automatically |
| Subscription data | Subscription status, plan type, purchase dates | Received from RevenueCat / App Store / Google Play |
We do not collect payment card numbers or bank details. All payment transactions are handled directly by Apple or Google billing infrastructure and RevenueCat.
We use the data we collect to:
- Provide the service โ authenticate your account, display your appointments, connect you with studios and professionals.
- Send notifications โ appointment confirmations, reminders, status updates, and join-request approvals.
- Show nearby studios โ your location is used only in-session to sort studios by proximity and is never stored on our servers.
- Manage subscriptions โ verify your professional subscription status to unlock professional features.
- Improve the product โ aggregate, anonymised usage analytics and crash reports to fix bugs and improve performance.
- Comply with legal obligations โ respond to lawful requests from public authorities.
We do not use your data for advertising, sell it to third parties, or use it to build marketing profiles.
Where the GDPR or equivalent legislation applies, we process your personal data on the following legal bases:
- Contract performance โ processing your account and appointment data is necessary to provide the service you signed up for.
- Legitimate interests โ sending service-related notifications, preventing fraud, and improving reliability.
- Consent โ accessing your device location and sending push notifications (you may withdraw consent at any time in your device settings).
- Legal obligation โ retaining records where required by applicable law.
We share personal data only with the following sub-processors, each bound by appropriate data protection agreements:
| Sub-processor | Purpose | Data transferred |
|---|---|---|
| Railway | Cloud infrastructure hosting the Agendo API and database | All data stored in the platform |
| Amazon Web Services (S3) | Storage of user profile photos | Profile images only |
| Twilio | SMS OTP delivery for account registration verification | Mobile phone number |
| SendGrid | Transactional email delivery (login OTP codes) | Email address |
| RevenueCat | Subscription management and receipt validation | Subscription status, purchase identifiers |
| Apple / Google | Push notification delivery | Device push token |
We do not sell, rent, or share your personal data with any other third party for their own commercial purposes.
We retain your personal data for as long as your account is active or as needed to provide the service.
- Account data โ retained until you delete your account.
- Appointment records โ retained for 3 years after the appointment date for studio record-keeping purposes, then deleted.
- Profile photos โ deleted from storage within 30 days of account deletion or photo replacement.
- Device push tokens โ removed when you log out or delete your account.
- Aggregated analytics โ retained indefinitely in anonymised, non-identifiable form.
When you request account deletion through the app (Profile โ Danger Zone โ Delete account), all your personal data is permanently deleted from our systems within 30 days. See our Account Deletion page for full instructions.
Depending on your location, you may have the following rights regarding your personal data:
- Access โ request a copy of the data we hold about you.
- Rectification โ correct inaccurate or incomplete data.
- Erasure โ request deletion of your data ("right to be forgotten"). You can initiate this directly in the app: Profile โ Delete account, or visit our Account Deletion page.
- Restriction โ ask us to limit processing of your data in certain circumstances.
- Data portability โ receive your data in a structured, machine-readable format.
- Objection โ object to processing based on legitimate interests.
- Withdraw consent โ withdraw consent for location access or push notifications at any time via your device settings.
To exercise any of these rights, email us at agendo.app@outlook.com. We will respond within 30 days.
The Agendo mobile app does not use cookies. Authentication tokens are stored securely on your device using the platform's encrypted secure storage (expo-secure-store), not in cookies or unencrypted local storage.
This website (agendo.app) uses no third-party analytics or advertising trackers.
With your permission, Agendo sends push notifications for:
- Appointment confirmations, rejections, cancellations, and completions
- Appointment reminders (24 hours and 2 hours before)
- Rating requests after completed appointments
- Studio join-request approvals
You can disable push notifications at any time in your device settings or in the app. Disabling notifications does not affect your ability to use the service.
Professional subscriptions are processed through Apple App Store or Google Play and managed via RevenueCat. Agendo never receives, processes, or stores your payment card details.
RevenueCat may share anonymised subscription status and purchase event data with us via webhook to unlock or revoke professional features. For RevenueCat's privacy practices, see revenuecat.com/privacy.
Subscription billing, refunds, and cancellations are handled directly by Apple or Google according to their terms of service.
Agendo is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information, please contact us at agendo.app@outlook.com and we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via a push notification or an in-app message before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.
Continued use of Agendo after the effective date of any changes constitutes acceptance of the updated policy.
Questions about your privacy?
We're here to help. Send us an email and we'll respond within 30 days.
โ๏ธ agendo.app@outlook.com