Privacy Notice
What Beurto stores about the people who use it, why, and for how long. It covers the platform (booking pages, the dashboard and the staff app) and this site.
Who holds what
There are three parties, and they are deliberately not the same one.
- A Business
- Each salon, barber or studio that uses Beurto is the controller of its own Customers' data. Every Business's records are kept apart from every other's: the same person booking at two Businesses is two separate Customer records, and neither Business can see the other's.
- The platform
- Beurto processes that data on each Business's behalf. It is the controller of the accounts of the people who sign in to the dashboard and the staff app, and of this site's analytics.
- Sub-processors
- The services listed below, which handle data for the platform.
Beurto is run by [COMPANY NAME, ADDRESS AND KVK NUMBER]. Questions about this notice go to [PRIVACY EMAIL].
Sub-processors
These services handle personal data for the platform.
- Postmark
- Sends email, from its EU region.
- Bird
- Sends the SMS reminder.
- Firebase Cloud Messaging (Google)
- Delivers push notifications to the staff app. A notification carries a Customer's name and appointment time through Google's infrastructure to a team member's phone: that is what makes it useful without opening the app.
- Stripe
- Takes payment for a Business's subscription, and is the one sub-processor outside the EU. Stripe holds what an Owner enters on Stripe's own pages: the Business's name, address and tax number, the Owner's email address and the payment method. Beurto sends it the Business's id and the Owner's email address and language. It never receives a Customer's data, and Beurto never holds a card or bank account number.
- Cloudflare Turnstile
- Only when a Business switches it on: a check on its booking page that the visitor is a person. The visitor's browser contacts Cloudflare, and Beurto sends Cloudflare the check's token and the visitor's IP address to verify it.
- Google Analytics
- On this site only, and only after you accept. See Analytics on this site.
Apart from Turnstile where a Business switches it on, no page the platform serves loads anything from another company's servers. How long Postmark and Bird keep the messages they send is set in their own accounts; Beurto logs no message's text.
If you book at a Business
The Business you book with decides what happens to your data. Beurto keeps it for that Business and for nobody else.
- Your name, email address, phone number and language
- Until you ask the Business to erase them, or after three years without an appointment (below).
- A note the team wrote about you, and your notes for the Business on a booking
- The same.
- Your bookings, their services and their prices
- Kept: they are the Business's record of its own day. Once you are erased, they hold nothing that identifies you.
- What happened to a booking, and when
- Kept, as references and statuses only: never a name, an address or a number.
- The links in your emails to manage your bookings
- Only a one-way hash of each link is stored, and it is overwritten when you are erased.
- Whether an email to you bounced, and whether you asked for an SMS reminder
- Cleared when you are erased.
Erasing you blanks your record, and the database refuses a record that is only half erased. A log of the erasure is kept, holding an id, a time and a reason and nothing about you, so that restoring a backup erases you again.
Three years without an appointment: a Customer who has had no appointment, past or upcoming, at a Business for three years is anonymised automatically. Cancelled appointments and no-shows count, and nobody with a future booking is ever anonymised. The record is marked thirty days before, and any new booking in that time withdraws the mark. This is built, but not yet switched on: for now it runs every night as a check that only reports what it would do.
Keeping booking pages safe
Anyone can book on a booking page without paying, without an account and without approval. To stop abuse the platform keeps a little data, and no more than each check needs.
- Counters that limit how often something can be tried
- Keyed on a one-way hash, never on an address or an IP address. A counter is replaced by the next request on the same key, and erasing you deletes the counters keyed on your address.
- A salted hash of your IP address and browser identification (User-Agent) for each online booking
- 30 days, deleted every night after that, and at once if you are erased. It can tell that many bookings came from the same device, not which device. The salt is the Business's own, so the same device at two Businesses cannot be linked.
- A Business's block list
- Until the Business removes the entry, or the Customer it names is erased.
The SMS reminder
A text message the day before an appointment, sent only if you ticked the box when you booked. Whether or not you get one, you still get the email reminder.
- How many texts were sent today, per Business and per number
- Keyed on a one-way hash of the number, never the number itself. Replaced by the next day's count.
- A phone number that asked to stop
- Kept indefinitely, on purpose: the number, when it stopped and how, and nothing else.
Deleting a stop would undo it: the next booking with that number would start the reminders again. A stop applies at every Business on Beurto. You stop through the link in every text, not by replying.
If you work at a Business
- Your name, email address, password (as a hash) and two-step sign-in secret
- Until your account is deleted, or the Business is.
- Your sessions
- Until they expire.
- Password-reset and invitation links
- Only as a one-way hash; each works once, for a short time.
- What an Owner changed about the Business
- Kept, as an account id and the kind of change: never a name or an address.
- Your phone: its push token, its language and your notification settings
- Until you sign out or lose access, the Business is deleted, or the token stops working.
The push token is stored as it was issued, because it is needed to deliver a notification. It is never shown in a response or written to a log.
Backups
Backups are kept for 30 days. So for up to 30 days after you are erased, a copy of your data still exists in a backup. Before a restored database serves anyone, every erasure is applied to it again.
When a Business is deleted
An Owner can delete their Business. After 30 days' grace, with an export offered during it, every record of the Business is deleted, its Customers and its team's accounts included.
A Business whose Free Period has ended and that has had no paid subscription for twelve months enters the same 30 days' grace, and is deleted at the end of it unless it subscribes. An abandoned Business and its Customers' data are gone within thirteen months.
Analytics on this site
This site sets no cookie and loads nothing from Google until you choose. Its font comes from this site itself.
If you accept, Google Analytics counts visits and which buttons are clicked. Google receives the page you are on, the button you click, and what every browser sends with a request: your IP address and details of your browser and device. These are stored in your browser:
- _ga
- A Google Analytics cookie that recognises your browser on a later visit. Up to two years.
- _ga_<id>
- A Google Analytics cookie that keeps track of your current visit. Up to two years.
- beurto-consent
- Not a cookie but this site's own storage in your browser: your choice and when you made it. After 12 months the site asks again.
If you reject, nothing is measured. If you accept and later reject, measuring stops and the Google Analytics cookies are deleted. You can change your choice at any time, with Cookie settings at the bottom of every page.
Your rights
You may ask to see the data held about you, to have it corrected or erased, to receive it in a form you can take elsewhere, and to object to how it is used.
If you booked at a Business, ask that Business: it decides about your data, and exports or erases it from its dashboard. For your own account, for this site, or if you cannot reach the Business, write to [PRIVACY EMAIL].
You may also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.