1. Controller and contact
Controller: [LEGAL:entity-name-pending], trading as Anthony Stilo. Tax identifier: [LEGAL:tax-identifier-pending]. Registered address: [LEGAL:registered-address-pending].
Legal contact: [LEGAL:legal-contact-pending]. Privacy and rights requests: [LEGAL:privacy-contact-pending]. Customer support: [LEGAL:support-contact-pending]. Whether a Data Protection Officer must be appointed, and any DPO contact, is still under legal review.
2. Scope and sources
We process information you submit, account information returned by your chosen sign-in provider, records created when you use a feature, and limited technical information produced when your device communicates with our infrastructure. Booksy and other sites opened through an external link operate under their own notices.
3. Data categories
Depending on the feature used, data can include email, display name, account ID, language and authentication records; profile and community content; saved items, follows, blocks, reactions and reports; booking-request and service records; Concierge text; game attempts; notification preferences and push identifiers; consent evidence; and security or diagnostic events.
- A private-service request asks for name, email, optional phone, service, party size, approximate area or postal prefix, and preferred time windows.
- A full service address is not requested in the first form. If later needed for an approved booking, the database design separates encrypted address data from the public account area.
- Payment records are designed to hold provider references, amount, currency and status—not full card numbers. Payment processing is not described as live until a provider and checkout have been verified.
4. Purposes and legal bases
We use data to take steps requested before a service contract, perform confirmed services, operate accounts and requested app functions, provide support, secure the service and prevent abuse, meet legal duties, and establish or defend claims. Separate consent is intended for optional marketing, media publication and any non-essential storage. The exact balancing assessments and purpose-to-basis register require final legal approval.
5. Requests, bookings and payments
Sending a request does not create a booking or charge. The system records the request and contact route so availability and a proposal can be prepared. If a booking is accepted, quote, schedule, service, masked location, access and payment-status records may be linked to the customer. Tax, accounting, dispute and fraud records may need a different retention rule from the customer profile; those rules are pending in the retention schedule.
6. Accounts, Circle, games and notifications
Supabase Auth handles email or selected Google/Apple sign-in, session and optional multi-factor authentication. Circle can process profile and social actions when enabled. After Hours stores score and gameplay metrics linked to the account. Push notifications are optional: after permission, an installation nonce, APNs or FCM token, platform and language are registered and can be revoked.
7. Stilo Concierge and AI reports
Concierge sends the signed-in user's free-text question to the first-party API and OpenAI for moderation and generation. The implementation requests no response storage through the API, but provider abuse-monitoring retention, regional processing, contract settings and human-access rules must be verified before launch. Do not include health data, an exact address, payment details or other unnecessary sensitive information.
- Concierge is an AI system and provides guidance, not a confirmed booking, price or professional decision.
- A report feature can submit a reason and optional detail with encrypted evidence for review; the report retention and reviewer access policy are pending.
8. Recipients and providers
Observed integrations include Supabase for identity, database and storage; OpenAI for Concierge; Cloudflare Turnstile for form-abuse checks; Google or Apple when selected for sign-in; and APNs or FCM when push is enabled. Booksy receives data only when the user follows its external booking flow. Hosting, email, payment and any other production suppliers must be added if actually used. The final provider register, contractual roles, processing agreements and transfer assessment are pending approval.
9. International transfers
Supplier location, project region and support access can result in processing outside the user's country or the EEA. No specific transfer mechanism is asserted in this draft. Before launch, each actual route must be documented with the applicable adequacy decision, contractual safeguards and supplementary measures where required.
10. Retention and deletion
The schema currently makes account, booking, consent, game and operational records persistent until a defined deletion or archival process acts on them. Address records contain a retention date, and short-lived access or idempotency records contain expiry fields, but source code alone does not establish the production periods. The numerical retention schedule is pending operational, tax and legal approval; that is a launch blocker, not an unspecified promise.
- A verified account-deletion request is queued and may be paused for a documented legal hold; the worker and live completion flow still require deployment verification.
- Deletion of an account does not mean every record is erased immediately when a legal obligation or live dispute requires limited, separated retention.
- Provider logs, backups, Concierge safety data, push-token cleanup and report evidence need explicit periods in the approved schedule.
11. Your rights
Subject to the applicable conditions, you may request access, correction, erasure, restriction, portability or objection, and withdraw consent without affecting earlier lawful processing. Send a request to [LEGAL:privacy-contact-pending]; identity may be verified proportionately. You may complain to the supervisory authority for your residence, workplace or the alleged infringement. In Spain, the authority is the AEPD (aepd.es).
12. Security
The reviewed design uses row-level access controls, restricted schemas for addresses and push handles, encryption fields for sensitive records, rate limits, origin checks, short-lived evidence and stronger authentication for account deletion. These controls reduce risk but are not a guarantee. Production secrets, logs, backups, supplier consoles, staff access, incident response and recovery must be tested separately.
13. Automated decisions
The reviewed product does not contain a feature intended to make a solely automated decision with legal or similarly significant effects. Concierge generates guidance and anti-abuse systems can reject or rate-limit a request. If materially different profiling or automated decisions are introduced, this notice and the required user controls must be updated first.
14. Children
The repository does not yet prove an approved age and parental-consent policy for accounts or community features. Those features must not be launched to minors until eligibility, age assurance, guardian consent where required, moderation and store-age-rating decisions are approved and implemented.
15. Changes and evidence
We will identify the version and effective date and provide material notice where the law or relationship requires it. The public policy, consent receipts, App Store privacy details and Google Play Data safety answers must all match the deployed code, SDKs, infrastructure and contracts. A policy update does not turn an incompatible processing purpose into a compatible one.