Privacy policy

Effective from 30 July 2026

Reservme is a booking system used by hair salons, barbershops, beauty salons and similar businesses. In protecting personal data we therefore act in two different roles, and it matters which one applies to you:

If you booked an appointment with one of those businessesthat business is responsible for your data. We only process it technically on the business's behalf and do only what it instructs. Direct any requests (for example erasure) to the business first; we are happy to help it comply.

If you own a business and use Reservme — we are responsible for your data (sign-in, billing).

1. Who we are

The operator of the Reservme service is Frederik Ján Vereš, with registered office at Dolné Rakovce 1908/5, Turčianske Teplice. Contact for data protection matters: [email protected].

We have not appointed a data protection officer (DPO) — the law does not require one of us, as we neither process personal data at a large scale nor systematically monitor individuals.

2. What data we process

Clients of businesses (booking an appointment)

DataWhere fromWhy
Namefrom you at bookingso the business knows who is coming
Phone numberfrom you at bookingcontact and appointment reminder
Emailfrom you at bookingbooking confirmation and reminder
Booking notefrom you at bookingwhat you need done
Visit historycreated by using the servicethe business's overview of your appointments
The business's notes about youentered by the businessservice quality (e.g. “sensitive skin”)

Business owners

Name, email, phone, business details and the data needed to issue an invoice. We store no password — you sign in to your account with a link we send you by email.

Technical data

The server keeps ordinary operational logs, including the IP address and browser type. We also use the IP address to protect the service from abuse (limiting the number of attempts) — for that purpose it is stored only in an unreadable, hashed form.

3. On what legal basis

  • Performance of a contract (Art. 6(1)(b) GDPR) — the booking itself, its confirmation and the appointment reminder; for businesses, providing and invoicing the service.
  • Legitimate interest (Art. 6(1)(f) GDPR) — securing the system against abuse and backing up data.
  • Consent (Art. 6(1)(a) GDPR) — where you explicitly give it; you can withdraw it at any time.
  • Legal obligation (Art. 6(1)(c) GDPR) — retention of accounting records.

4. How long we keep data

  • Data of businesses' clients — for as long as the business uses the service. When our cooperation with a business ends, we delete its data within 30 days.
  • Sooner on request — if you ask for erasure, we delete the data without undue delay (see section 6).
  • An owner deletes the account — when an owner deletes their account in the settings, access and the booking page are switched off immediately and we irreversibly delete the data after 30 days. We keep that period so a deletion can be undone — whether it was a mistake or someone who got into the account without authorisation. Until then the data is inaccessible and we use it for nothing else.
  • Backups — encrypted backups are kept for at most 90 days and are then overwritten automatically.
  • Accounting records — 10 years, as required by the accounting act.

5. Who we share data with

We do not sell personal data and do not use it for profiling or automated decision-making. We share it only with subprocessors who keep the service running and are bound by a data processing agreement:

SubprocessorCountryWhat it provides
DigitalOcean, LLCGermany (EU) — Frankfurtapplication hosting and staff photo storage (App Platform and Spaces)
Supabase, Inc.Germany (EU) — Frankfurtdatabase — bookings, clients and business settings
Cloudflare, Inc.USA — traffic routed through the nearest European nodesDNS and the protective layer in front of the application — the transfer is covered by standard contractual clauses
ActiveCampaign, LLC (Postmark)USAsending system emails (booking confirmations and reminders) — the transfer is covered by standard contractual clauses
Google Ireland LimitedIreland (EU), with transfers to the USAGoogle sign-in — the business owner's name, email address and profile photo; the transfer is covered by standard contractual clauses
Websupport, s.r.o.Slovakia (EU)domain registration and email mailbox

The application, the database and the photo storage run on servers in the European Union (Frankfurt). Two subprocessors process data outside the EU: Postmark (sending emails, servers in the USA) and Cloudflare (DNS and the protective layer in front of the application). Both transfers rest on standard contractual clauses under Art. 46 GDPR. If another subprocessor outside the EU is ever added, we will list it here together with the legal basis of the transfer before we start using it.

6. Your rights

As a data subject you have the right to:

  • know what data we process about you, and receive a copy of it,
  • have inaccurate or incomplete data corrected,
  • request erasure ("the right to be forgotten"),
  • request restriction of processing,
  • receive your data in a portable format,
  • object to processing based on legitimate interest,
  • withdraw consent, if you gave it.

How to: if you are a client of a business, contact it directly — it manages your data and can also delete it in the system. If you do not know how to reach it, or it does not answer, write to us at [email protected] and we will help sort it out. We reply within one month at the latest.

If you believe we handle your data incorrectly, you have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, Slovakia.

7. Cookies

We use only technically necessary cookies — one keeps you signed in and the other protects forms from abuse. The system would not work without them, which is why the law requires no consent for them and we show you no cookie banner.

We use no advertising or analytics cookies and do not track you across other websites.

8. How we protect data

Communication with the system is always encrypted (HTTPS). You sign in with a one-time link from an email, so we store no password. Each business's data is separated so that one business cannot access another's. Backups are encrypted. Server access is protected by a cryptographic key and by protection against repeated sign-in attempts.

9. Changes to this document

If the data processing changes, we will update this page and change the effective date above. We inform businesses using Reservme about substantial changes by email.