Appointo Appointo
Features How it works Pricing FAQ
UA EN PL DE IT FR
Start free

Privacy Policy

Effective: May 2026  ·  Version 1.0

1. Data Controller

Appointo ("Appointo", "we", "us") operates the online booking platform available at appointo.xyz. Appointo acts as data controller with respect to business admin accounts, and as data processor with respect to booking client data processed on behalf of businesses using the platform.

Privacy contact: v.fedorov@appointo.xyz

2. Data We Collect

Business Admins (company accounts)

  • Full name, email address, hashed password
  • Company information: name, type, city, address, description, logo
  • Schedule and service configuration
  • Google Calendar credentials (encrypted token — only when the integration is enabled)

Booking Clients

  • Name, phone number, email address (when provided)
  • Appointment date, time, selected services, and notes

Technical Data

  • IP address, browser type — collected in server logs solely for security and diagnostics

3. Purpose and Legal Basis

  • Providing the platform service — performance of contract (Art. 6(1)(b) GDPR)
  • Booking confirmations and reminders — performance of contract (Art. 6(1)(b) GDPR)
  • Google Calendar sync — explicit consent (Art. 6(1)(a) GDPR); revocable at any time by disconnecting the integration
  • Security and fraud prevention — legitimate interests (Art. 6(1)(f) GDPR)
  • Service improvement — legitimate interests (Art. 6(1)(f) GDPR)

4. Retention Periods

  • Account data — for the lifetime of the account; 30 days in backups after deletion
  • Booking records — up to 3 years for the business's visit history (or a shorter period at the business's instruction or the client's request)
  • Technical logs — 90 days

5. Recipients of Data

We do not sell or share your data with advertising partners. Data is only accessible to:

  • Hosting infrastructure (EU) — processing and storage
  • Technical providers acting as processors under our instructions: Mailtrap (email delivery), Telegram (client notifications), Sentry (error monitoring), cloud hosting (EU). Some of them may process data outside the EEA under appropriate safeguards (EU Standard Contractual Clauses)
  • Google LLC — solely for Google Calendar functionality when enabled
  • Company admin — has access to their own clients' data within the scope of the service agreement

6. Your Rights (GDPR)

Under the GDPR you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — restrict processing under certain conditions
  • Data portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdrawal of consent — at any time (does not affect the lawfulness of prior processing)

To exercise your rights, contact us at v.fedorov@appointo.xyz. We will respond within 30 days.

Security and breach notification. If a data breach is likely to pose a risk to your rights, we will notify the competent supervisory authority and, where required, you — within the timeframes set by the GDPR (Art. 33-34).

Age. The Service is not intended for persons under 16, and we do not knowingly collect their data.

7. Supervisory Authority

If you believe our processing of your data violates the GDPR, you have the right to lodge a complaint with your national data protection authority. For UK residents: the Information Commissioner's Office (ico.org.uk).

8. Changes to This Policy

For material changes we will notify business admins by email at least 14 days before the new version takes effect. The effective date at the top of this page reflects the current version.

9. Google Calendar Integration and Use of Google API Data

Connecting Google Calendar is optional. It is enabled only with your explicit consent and can be disconnected at any time in Appointo settings, after which we immediately delete the stored access tokens.

Which permissions we request and why

We request the https://www.googleapis.com/auth/calendar scope. It is needed to keep your working schedule and your client bookings in sync, in both directions:

  • Creating events — when a client books a service, we create an event in your calendar with the service name, client name, time and duration.
  • Updating and deleting events — if a booking is changed or cancelled, we update or delete the event we created accordingly.
  • Reading free/busy availability — we read the busy intervals of your calendar so we don't offer clients a time when you are already occupied, and to avoid double-booking.

We use this data solely for the schedule-synchronization features described above. We do not use Google data for advertising, we do not transfer it to third parties, and we do not use it to train artificial-intelligence models.

Token storage

Google access and refresh tokens are stored encrypted and used only to perform the operations described above. You can revoke access at any time — in Appointo settings or on your Google Account permissions page.

Limited Use

Appointo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Changelog Roadmap Status Legal notice Terms of service Privacy policy Cookie policy
Ми у соцмережах

© 2026 Appointo

Appointo

Features How it works Pricing FAQ Start free

We use essential cookies to run the service and functional cookies to remember your settings. No analytics or advertising cookies. Learn more