1. Controller and contact
The service is operated by the owner of the site and of the Anthony Stilo brand (Barcelona), who is the controller for the processing described in this policy.
Privacy and rights requests can be made through the site assistant (/en/assistant) or through the official Instagram account @anthonystilo. Whether a Data Protection Officer must be appointed is still pending legal review.
2. Scope and sources
We process information you submit, account information returned by your chosen sign-in provider, records created when you use a feature, and limited technical information produced when your device communicates with our infrastructure. Booksy and other sites opened through an external link operate under their own notices.
3. Data categories
Depending on the feature used, data can include email, display name, account ID, language and authentication records; profile and community content; saved items, follows, blocks, reactions and reports; booking-request and service records; Concierge text; game attempts; notification preferences and push identifiers; consent evidence; and security or diagnostic events.
- A private-service request asks for name, email, optional phone, service, party size, approximate area or postal prefix, and preferred time windows.
- A full service address is not requested in the first form. If later needed for an approved booking, the database design separates encrypted address data from the public account area.
- Payment records are designed to hold provider references, amount, currency and status—not full card numbers. Online payment does not operate until a payment provider and checkout have been confirmed.
4. Purposes and legal bases
We use data to take steps requested before a service contract, perform confirmed services, operate accounts and requested app functions, provide support, secure the service and prevent abuse, meet legal duties, and establish or defend claims. Separate consent is intended for optional marketing, media publication and any non-essential storage. The detailed mapping of each purpose to its legal basis is still pending final legal approval.
5. Requests, bookings and payments
Sending a request does not create a booking or charge. The system records the request and contact route so availability and a proposal can be prepared. If a booking is accepted, quote, schedule, service, masked location, access and payment-status records may be linked to the customer. Tax, accounting, dispute and fraud records may need a different retention rule from the customer profile; those rules are still pending in the retention schedule.
6. Accounts, Circle, games and notifications
Supabase Auth handles email or selected Google/Apple sign-in, session and optional multi-factor authentication. Circle can process profile and social actions when enabled. After Hours stores score and gameplay metrics linked to the account. Push notifications are optional: after permission, an installation nonce, APNs or FCM token, platform and language are registered and can be revoked.
7. Stilo Concierge and AI reports
Concierge sends the signed-in user's free-text question to the first-party API and OpenAI for moderation and generation. The implementation requests no response storage through the API, but provider abuse-monitoring retention, regional processing, contract settings and human-access rules are still being verified. Do not include health data, an exact address, payment details or other unnecessary sensitive information.
- Concierge is an AI system and provides guidance, not a confirmed booking, price or professional decision.
- A report feature can submit a reason and optional detail with encrypted evidence for review; the report retention and reviewer-access policy are still pending.
8. Recipients and providers
Current integrations include Supabase for identity, database and storage; OpenAI for Concierge; Cloudflare Turnstile for form-abuse checks; Google or Apple when selected for sign-in; and APNs or FCM when push is enabled. Booksy receives data only when the user follows its external booking flow. Hosting, email, payment and any other suppliers will be added here if and when they are used. The final provider register, contractual roles, processing agreements and transfer assessment are still pending approval.
9. International transfers
Supplier location, project region and support access can result in processing outside the user's country or the EEA. This policy does not yet assert a specific transfer mechanism. Each actual route will be documented with the applicable adequacy decision, contractual safeguards and supplementary measures where required.
10. Retention and deletion
Account, booking, consent, game and operational records are kept until a defined deletion or archival process acts on them. Address records carry a retention date, and short-lived access records carry expiry fields, but the final retention periods have not been fixed yet. The detailed retention periods are still pending operational, tax and legal approval; until they are approved, no specific periods are stated here.
- A verified account-deletion request is queued and may be paused for a documented legal hold; the end-to-end completion of that process is still being verified.
- Deleting an account does not mean every record is erased at once when a legal obligation or live dispute requires limited, separated retention.
- Provider logs, backups, Concierge safety data, push-token cleanup and report evidence still need explicit periods in the approved schedule.
11. Your rights
Subject to the applicable conditions, you may request access, correction, erasure, restriction, portability or objection, and withdraw consent without affecting earlier lawful processing. Send a request through the site assistant (/en/assistant) or through the official Instagram account @anthonystilo; identity may be verified proportionately. You may complain to the supervisory authority for your residence, workplace or the alleged infringement. In Spain, the authority is the AEPD (aepd.es).
12. Security
The service uses row-level access controls, restricted schemas for addresses and push handles, encryption fields for sensitive records, rate limits, origin checks, short-lived evidence and stronger authentication for account deletion. These controls reduce risk but are not a guarantee. Secrets, logs, backups, supplier consoles, staff access, incident response and recovery must be verified separately.
13. Automated decisions
The service does not include a feature intended to make a solely automated decision with legal or similarly significant effects. Concierge generates guidance and anti-abuse systems can reject or rate-limit a request. If materially different profiling or automated decisions are introduced, this notice and the required user controls will be updated first.
14. Children
The final age and parental-consent policy for accounts and community features is still pending. Those features will not be offered to minors until eligibility, age assurance, guardian consent where required, moderation and store-age-rating decisions are approved and implemented.
15. Changes and evidence
Each version of this policy is identified by its update date, and material changes will be notified where the law or the relationship requires it. The public policy, consent receipts, App Store privacy details and Google Play Data safety answers must remain consistent with how the service actually works. A policy update does not turn an incompatible processing purpose into a compatible one.