Privacy Policy
MVP summary. Review with legal counsel before launch.
Controller
Timekeepers, contact: /en/contact.
Data collected
- Email (required for authentication).
- Name and avatar (only if provided by the user or via Google).
- For hosts: business details, address, phone, experience years, liability and safety declarations.
- Booking and payment data (handled by Stripe).
- IP address for security and fraud prevention.
Legal basis
Contract execution for bookings; consent for marketing (separate opt-in); legitimate interest for platform security.
Retention
Sign-in data (tokens, sessions) kept up to 12 months. Bookings and invoices retained for applicable tax obligations (10 years in Italy), anonymized upon request.
Your rights
Access, rectification, erasure, portability and objection under GDPR arts. 15-21. Write via the contact page.
Transfers
Data is processed on Cloudflare infrastructure with EU location hint. Stripe is GDPR-certified.