1. INTRODUCTION
Planoora ("we", "us", "our") is a smart appointment booking platform operated by Planoora ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε., located at Ekavis 66, Thermi, Thessaloniki, Greece. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our platform at www.planoora.com ("Platform").
We act as:
- Data Controller for the personal data of business partners (salons, studios, and wellness businesses) who register on Planoora.
- Data Processor on behalf of business partners for the personal data of their end-customers (clients who book appointments).
For any privacy-related questions or requests, contact us at: info@planoora.com
2. LEGAL BASIS (GDPR Article 13)
We process personal data on the following legal bases:
- Contract performance (Article 6(1)(b)): to provide the booking and platform services you signed up for.
- Legal obligation (Article 6(1)(c)): to comply with applicable EU and Greek law.
- Legitimate interests (Article 6(1)(f)): to operate, maintain, and improve the Platform, and to prevent fraud.
- Consent (Article 6(1)(a)): for cookies and marketing communications, where applicable.
3. DATA WE COLLECT
3.1 Business Partners (Salons, Studios, Wellness Businesses)
- Full name, business name, business address
- Email address and phone number
- Profile photo and business photos
- Staff names, emails, and phone numbers
- Working hours, services offered, and pricing
- Payment information (processed by Stripe — we do not store card details)
3.2 End-Customers (Appointment Bookers)
- Full name, email address, phone number
- Appointment history and booking preferences
- Payment information for in-app payments (processed by Stripe)
3.3 Technical Data (All Users)
- IP address, browser type, and device information
- Usage data collected via Google Analytics (see Section 6)
- Session data and authentication tokens (managed via Supabase)
- Push notification tokens (managed via Firebase)
4. HOW WE USE YOUR DATA
We use your data to:
- Create and manage your account on the Platform
- Process and confirm appointment bookings
- Send booking confirmations, reminders, and cancellation notifications via email and push notification
- Process payments and issue refunds through Stripe
- Provide customer support
- Improve Platform performance and user experience via analytics
- Comply with our legal obligations under Greek and EU law
5. DATA SHARING AND THIRD-PARTY PROCESSORS
We share data only with trusted third-party processors under Data Processing Agreements (DPAs):
| Processor | Purpose | Location |
|---|
| Stripe | Payment processing | USA (EU DPA) |
| Supabase | Database hosting and authentication | USA (EU DPA) |
| Google Analytics | Usage analytics | USA (EU DPA) |
| Firebase (Google) | Push notifications | USA (EU DPA) |
| Microsoft (Outlook/SMTP) | Transactional email | USA (EU DPA) |
We do not sell your personal data to third parties.
6. COOKIES
We use cookies to:
- Maintain your session and authentication state (essential cookies)
- Analyse platform usage via Google Analytics (analytics cookies)
You can manage your cookie preferences via the cookie consent banner on our Platform. Refusing analytics cookies will not affect your ability to use the Platform.
7. DATA RETENTION
We retain your personal data for the following periods:
- Account data (business partners): for the duration of the account, plus 3 years after account closure for legal compliance purposes.
- Booking records: 3 years from the date of the appointment.
- Payment records: 7 years, as required by Greek tax law.
- Analytics data: as per Google Analytics retention settings (default: 14 months).
After these periods, data is securely deleted or anonymised.
8. YOUR RIGHTS UNDER GDPR
As a data subject, you have the following rights:
- Right of Access (Article 15): request a copy of the data we hold about you.
- Right to Rectification (Article 16): request correction of inaccurate data.
- Right to Erasure (Article 17): request deletion of your data ("right to be forgotten").
- Right to Restriction (Article 18): request that we limit how we use your data.
- Right to Data Portability (Article 20): receive your data in a machine-readable format.
- Right to Object (Article 21): object to processing based on legitimate interests.
- Right to Withdraw Consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at info@planoora.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.
9. DATA SECURITY
We implement appropriate technical and organisational measures to protect your data, including:
- Row Level Security (RLS) on all database tables via Supabase
- Encrypted data transmission (HTTPS/TLS)
- Access controls and authentication for all staff with system access
- Secure payment processing via Stripe (PCI DSS compliant)
10. INTERNATIONAL TRANSFERS
Some of our processors (Stripe, Supabase, Google, Microsoft) are based outside the EU/EEA. All transfers are made under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of data protection.
11. CHILDREN'S DATA
Our Platform is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us at info@planoora.com and we will delete it promptly.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice on the Platform. The "Last updated" date at the top of this page reflects the most recent revision.
13. CONTACT
For any questions about this Privacy Policy or to exercise your rights:
Planoora
Planoora ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε. G.C.R.
Ekavis 66, Thermi, Thessaloniki, Greece
VAT / ΑΦΜ: 803318818
GEMI / ΓΕΜΗ: 194490904000
Email: info@planoora.com
Phone: +30 6971710422