revoo.me
ENLT

Legal

Privacy notice

What happens to personal data on revoo.me — for the people who book appointments, and for the businesses that take them.

Version 1 · draft, not yet in force

This document is not yet in forceOur registration details and the mailbox for data protection requests are not published yet, so this text is a draft. It describes how the product actually works, but it is not the notice you can rely on until those details appear below.

This notice explains what happens to personal data on revoo.me — an online booking service for local businesses such as salons, barbershops, clinics and studios.

Two very different sets of people use revoo.me, and the answers are different for each. If you booked an appointment with a business, read Part A. If you run a business on revoo.me, read Part B. Parts C to F apply to everyone.

We have kept the language plain. Where a legal term matters we use it and say what it means.

Part A — When you book an appointment with a business

Who is responsible for your data

The business you booked with — the salon, barbershop, clinic or studio — decides what to collect about you and why. In the words of the GDPR, that business is the controller.

We are the processor. We supply the software the business runs on, we hold the data on their behalf, and we act on their instructions. We do not decide what happens to your booking data, we do not use it for our own purposes, and we do not combine what one business knows about you with what another one does.

Concretely, this means three things, and we have written them into our own architecture as conditions rather than promises:

  • we never match clients across businesses — there is no shared profile, no "this phone number is also known at another salon", no cross-business deduplication;
  • we never use your booking data for marketing, machine learning, benchmarking or product analytics;
  • we never message you on our own behalf. Every message you receive about a booking is sent on the instruction of the business you booked with, about your booking with them.

If you want your data changed or erased, ask the business. They hold the record and they are the only ones who can confirm that you are you. Section E explains what happens if you write to us instead.

What the business collects, and why

Through the booking form, and through their own records inside revoo.me, a business may hold:

  • your name, telephone number and email address;
  • the appointments you booked — date, time, service, price at the time of booking, which member of staff, and the status of the booking;
  • a note you wrote yourself when booking;
  • notes a member of staff wrote about you, and any labels they applied to your record;
  • the language you chose, so that messages reach you in it.

The legal basis for all of this is performance of a contract — Article 6(1)(b) of the GDPR. You asked for an appointment; the business needs these details to give you one and to tell you about it.

Notes may be health information

The note fields are free text, and in a beauty, wellness or clinical setting they will sometimes contain health information — an allergy, a pregnancy, a course of treatment. Article 9 of the GDPR calls this special category data and protects it more strictly.

We treat both note fields as special category data by default. They are excluded from every administrative view we have, they are never written into our logs, they are kept for a shorter period than the rest of the record, and they are the first thing deleted when a record is erased.

The lawful basis for holding health information is the business's to establish — usually your explicit consent, or the provision of care. Ask them if you want to know which one they rely on.

Who else sees it

Your data is visible to the staff of the business you booked with, according to what each of them does there. Notes written about you are visible only to their author.

Beyond that, it is handled by the companies we use to run the service — hosting, messaging, payment and security providers. They act only on our instructions and never for their own purposes. The current list names each one, what it does and where it is.

Messages you receive

Confirmations, reminders and cancellation notices are part of the booking itself, not marketing. We send no promotional messages of any kind, and neither the business nor we may use revoo.me to send you any.

If you would rather not be contacted at all, tell the business: they can switch off email or SMS for your record, and the block applies to everything the system would otherwise send you.

How long it is kept

The business chooses how long it keeps client records, within a limit we set. Our default is 36 months after your last appointment, and the longest any business may choose is 60 months. Staff notes default to 18 months and are never kept longer than the record they belong to. Delivery records for individual messages are kept for 90 days.

When a record expires, or when the business erases it at your request, we do not delete the appointment itself — the business needs its own history of what was done and what was charged. Instead every part of the record that points at you is destroyed: your name, contact details, your note and the staff notes about you. What is left is an appointment with no person attached to it, which is no longer personal data.

This is irreversible. There is no archive copy, no recycle bin and no restore.

One honest limit, because a promise with a hidden exception is not a promise. Erasure is applied to our live database immediately, but we also keep backups of it against a disaster. Backups are retained for 30 days, are never edited selectively, are restored only whole and only after an incident, and erasures are re-applied after any restore. So for up to 30 days a backup we hope never to open may still hold a record that has already been erased in the live system.

What we collect for ourselves on a booking page

Two things on the public booking page are ours rather than the business's, and we are the controller for them:

  • Cloudflare Turnstile, the check that runs when you submit a booking. It exists to keep automated abuse off the form. Legal basis: our legitimate interest in the security of the service — Article 6(1)(f).
  • Vercel Web Analytics and Speed Insights, which count page views and measure loading performance. They set no cookies and build no profile. Legal basis: our legitimate interest in understanding and improving the service — Article 6(1)(f).

You may object to either at any time, on the grounds of your particular situation, by writing to us.

Part B — When you run a business on revoo.me

For your own account, your workspace and everything to do with paying for it, we are the controller. This part is about you, not about your clients.

What we hold about you

  • Your account: name, email address, telephone number if you gave one, profile photo, language and interface preferences, and — if you sign in with Google — the identifier Google gives us. We hold a hash of your password, never the password.
  • Your membership of one or more workspaces, and your role in each.
  • Your workspace's subscription: plan, status, trial and billing period, and the identifiers that connect it to our payment provider. Invoices and payment records are held by Stripe; card details never reach us.
  • Security and operational records: sign-in attempts, our administrators' actions on workspace records, and the aggregate statistics we compute about how the product is used.

Why, and on what basis

What Why Basis
your account and workspace to provide the service you signed up for contract — Art. 6(1)(b)
subscription and invoicing to charge for it, and to keep our books contract, and legal obligation
sign-in protection, rate limiting, our administrative log to keep the service and your workspace secure legitimate interest — Art. 6(1)(f)
aggregate product statistics to understand and improve the product legitimate interest — Art. 6(1)(f)

How long

Your account lives as long as you have one. Our administrative log is kept for up to 24 months. Accounting and invoicing records are kept for the period Lithuanian law requires, and that period survives a deletion request — Article 17(3)(b) of the GDPR expressly allows this.

If a workspace goes twelve months with no member signing in and no booking arriving, we treat it as dormant. We write to the owner and every administrator, offering an export and giving sixty days' notice, and then we anonymise every client record in it and unpublish its public page. Bookings survive as anonymous history. Member accounts are not touched — a person may work at more than one place.

Deleting your account

You can delete your own account from your profile. We do not remove the row — that would take a business's records about its own clients with it — we destroy what identifies you: your name, contact details, photo, sign-in credentials and any linked Google account. Your memberships are switched off, your sessions end immediately, and appointments where you were the member of staff remain in the schedule with your name replaced by a placeholder.

Your email address is replaced rather than emptied, so that you are free to register again on the same address later.

This is irreversible, and billing records are not part of it — see above.

If you are the only owner of a workspace that is still in use, we will refuse: transfer ownership or close the workspace first, so that one person cannot erase the working records of everyone else.

Part C — Where your data is

We are established in Lithuania and the service is hosted for the European market. Some of the companies we rely on are established outside the European Economic Area — the subprocessor list says which, and states the safeguard we rely on for each. Where a transfer happens it is covered by the European Commission's standard contractual clauses under Article 46(2)(c).

Part D — Cookies and similar technologies

We do not ask for cookie consent, and that is a considered position rather than an omission.

The public pages store two things in your browser: the language you are reading in, and whether you chose the light or the dark appearance. Both are strictly necessary to show you the page you asked for. Our analytics are cookieless and build no profile. Turnstile is a security measure. None of this engages Article 5(3) of the ePrivacy Directive, so there is nothing to consent to.

Signed-in users' browsers additionally hold what is needed to keep them signed in.

If we ever add a technology that does require consent, we will ask for it before switching it on.

Part E — Your rights

You have the right to ask for access to your data, its correction, its erasure, a restriction on its use, a copy in a portable form, and — where we rely on legitimate interest — to object.

Ask the right party. If your data is a booking record, the business you booked with is the controller and only they can act on it; we have given them the tools to do so. If your data is your own revoo.me account, ask us.

If you write to us about a booking record, we will tell you which business holds it and pass your request to them. We will not act on it ourselves: we cannot verify that you are who you say you are, and "delete this person's data", accepted from anyone, would be a weapon rather than a right.

We answer within one month, as Article 12(3) requires. If we need longer we will tell you why.

You may also complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) or to the supervisory authority where you live.

Part F — Security, changes and contact

We protect your data with encryption in transit and at rest, strict separation between businesses, a narrow role model inside each one, no administrative access to client records at all, and a written assessment of the risks that we review at least annually.

Changes. Every version of this notice carries a number and the date it took effect, and earlier versions stay published at their own addresses. If a change matters to you, we will say so rather than expecting you to compare two texts.

Our details

Our registration details and the mailbox for data protection requests are not published yet. Until they are, this document is a draft.

Supervisory authority: Valstybinė duomenų apsaugos inspekcija

The other documents

  • Terms of service
  • Data processing agreement
  • Subprocessors

Permanent address of this exact text: /en/legal/privacy/v1

revoo.me
© 2026 revoo.me — direct bookings, zero commissions
PrivacyTermsSubprocessors