Privacy Policy

Last Updated: August 23, 2026

Effective: August 23, 2026

This is a non-binding convenience translation. The German version is legally binding.

Introduction

Welcome to Appointa. This Privacy Policy explains how the entity that owns and operates Appointa (the "Company," "we," "us," or "our") — a sole proprietorship (Einzelunternehmen) based in Munich, Germany; full provider identification is set out in the Imprint and available on request — collects, uses, discloses, and protects personal information when you use our website, platform, and related services (collectively, the "Services").

Protecting your privacy is a top priority for us. We are committed to being transparent about the data we collect and how we use it. This policy is designed to help you understand your privacy rights and how to exercise them, in accordance with applicable data protection laws, in particular the European Union General Data Protection Regulation (GDPR).

This Privacy Policy is incorporated into our Terms of Service. By using our Services, you agree to the collection and use of information in accordance with this policy.

1. Scope of This Policy & Our Role

This policy applies to all users of our Services, including:

  • Providers (or Subscribers): Businesses or individuals who subscribe to our Services to manage their appointments.
  • End Customers (or Clients): Individuals who book appointments with Providers through our platform.
  • Website Visitors: Individuals who browse our website.

Understanding Our Role in Data Processing

It is crucial to understand our role in processing your data, which depends on how you interact with our Services:

Appointa as Data Controller: When we collect personal information from Providers to create and manage their accounts, process subscription payments, and communicate with them directly, we act as the Data Controller. This means we determine the purposes and means of processing that data.

Appointa as Data Processor: When Providers use our Services to collect and manage information about their End Customers (e.g., names, contact details, appointment information), the Provider is the Data Controller, and Appointa acts as the Data Processor. We process this data on behalf of and in accordance with the instructions of the Provider and the Data Processing Addendum.

Important for End Customers: If you are an End Customer, your data is primarily controlled by the Provider with whom you booked an appointment. Any questions or requests regarding your data should first be directed to that Provider. We will assist Providers in responding to such requests as required.

2. Information We Collect

We collect different types of information depending on your interaction with our Services.

2.1. Information You Provide to Us

From Providers:

CategoryExamplesPurpose
Account InformationName, email address, password, business name, business address, phone numberAccount creation and management, customer support, communications
Billing InformationPayment card details, billing address (processed by Stripe)Subscription payment processing
Business ProfileService descriptions, pricing, availability schedules, portfolio images, logosCreating public booking pages and providing the Services
Client/Customer DataNames, email addresses, phone numbers, appointment details of your End CustomersEnabling appointment booking and management on your behalf

From End Customers:

CategoryExamplesPurpose
Booking InformationName, email address, phone numberBooking appointments, sending confirmations and reminders, OTP verification
Appointment DetailsSelected service, date, time, any notes providedFacilitating the appointment with the Provider

2.2. Information We Collect Automatically

When you use our Services, we automatically collect certain information:

Usage Data:

  • Features used and actions taken within the Services
  • Pages and screens viewed
  • Clicks and navigation patterns
  • Date, time, and duration of your activities

Device and Technical Information:

  • IP address, browser type and version
  • Operating system, device type
  • Screen resolution, language and timezone settings

2.3. Information from Third Parties

We may receive information from:

  • Third-party integrations: When you connect your Appointa account with third-party services
  • Payment processors: Transaction status and fraud prevention data from Stripe
  • Analytics providers: Aggregated usage insights

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1. To Provide and Operate the Services

  • Creating and managing your account
  • Processing appointments and bookings
  • Sending transactional communications (confirmations, reminders, OTP codes)
  • Providing customer support
  • Processing subscription payments

3.2. To Improve and Develop the Services

  • Analyzing usage patterns to improve functionality
  • Developing new features and services
  • Conducting research and analytics

3.3. For Security and Protection

  • Detecting and preventing fraud, abuse, and security incidents
  • Protecting the rights, property, and safety of our users
  • Enforcing our Terms of Service, including the Provider Content & Acceptable Use Policy
  • Reviewing and acting on reports of illegal or infringing content, handling related complaints, and keeping moderation records
  • Complying with legal obligations

3.4. Legal Basis for Processing (GDPR)

For users in the EEA, UK, and Switzerland, we process personal data based on:

PurposeLegal Basis
Providing the ServicesPerformance of a contract
Processing paymentsPerformance of a contract
Security and fraud preventionLegitimate interests
Content moderation and handling reports of illegal contentLegitimate interests and legal obligation
Analytics and improvementLegitimate interests
Legal complianceLegal obligation
Marketing communicationsConsent

4. How We Share and Disclose Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1. With Service Providers

We share information with third-party vendors who perform services on our behalf. These providers are contractually obligated to protect your data.

4.2. Between Providers and End Customers

  • End Customer booking details are shared with the relevant Provider
  • Provider public business information is displayed to End Customers

4.3. For Legal Reasons

  • To comply with applicable laws, regulations, or legal processes
  • In response to valid requests by public authorities
  • To protect our rights, property, or safety

4.4. In Case of a Business Transfer

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your personal information becomes subject to a different privacy policy.

5. Our Third-Party Service Providers

We use the following third-party service providers:

CategoryProviderPurpose
Cloud InfrastructureSupabase (AWS)Database hosting, authentication, file storage
Payment ProcessingStripeSubscription billing, payment processing
SMS CommunicationsBirdOTP verification, appointment notifications
Application HostingVercelWeb application hosting
Email DeliveryResendTransactional email delivery
AnalyticsPostHogUsage analytics
Error MonitoringSentryError tracking and debugging
MapsGoogle MapsLocation display on booking pages
AuthenticationGoogleSign in with Google (name, email address, profile ID)
AuthenticationAppleSign in with Apple (name, email address or Apple private relay address)
Push NotificationsOneSignalAppointment alerts to the provider mobile app
Support & FeedbackAirtableContact form and feedback submissions

6. International Data Transfers

Appointa is operated from Germany. Some of our service providers process personal data in countries other than your own, including the United States. When you use our Services, your personal information may therefore be transferred to, stored, and processed in such countries.

6.1. Transfers from the EEA, UK, and Switzerland

We ensure transfers are subject to appropriate safeguards:

  • Standard Contractual Clauses (SCCs): We rely on SCCs as a legal mechanism for transfers to countries without an adequacy decision.
  • Adequacy Decisions: Where applicable, we transfer data to countries deemed adequate by the European Commission.
  • Supplementary Measures: We implement additional technical and organizational measures where necessary.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected.

Data CategoryRetention Period
Provider Account DataDuration of account + 3 years
End Customer DataAs instructed by Provider, or until account termination + 30 days
Billing Records7 years (tax/accounting requirements)
Security Logs1 year

8. Data Security

We implement technical and organizational security measures to protect your personal information.

8.1. Technical Measures

  • Encryption in Transit: All data is encrypted using TLS 1.2 or higher
  • Encryption at Rest: Data stored in our databases is encrypted
  • Access Controls: Role-based access on a need-to-know basis
  • Data Isolation: Row Level Security (RLS) ensures Providers only access their own data

8.2. Organizational Measures

  • Comprehensive security policies and procedures
  • Regular training on data protection
  • Vendor security assessments
  • Incident response procedures

9. Your Data Protection Rights

Regardless of your location, you may:

  • Access your data: Request information about what personal data we hold
  • Correct your data: Update or correct inaccurate information
  • Delete your data: Request deletion of your personal information
  • Export your data: Receive a copy in a portable format

How to Exercise Your Rights

For Providers: Access and update most information directly through your account settings, or contact us at contact@appointa.eu.

For End Customers: Contact the Provider with whom you booked your appointment, as they are the Data Controller for your information.

Response Time: We respond within one month, as required by the GDPR.

10. Additional Information for EEA, UK, and Swiss Users (GDPR)

Under the GDPR, you have these additional rights:

  • Right to Restrict Processing: Request restriction under certain conditions
  • Right to Object: Object to processing based on legitimate interests
  • Right to Data Portability: Receive data in a structured, machine-readable format
  • Right to Withdraw Consent: Withdraw consent at any time

Supervisory Authority: You have the right to lodge a complaint with a supervisory authority in your country of residence.

Contact our privacy team at contact@appointa.eu for any data protection inquiries.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Services.

TypePurpose
Strictly NecessaryEssential for authentication and security
FunctionalRemember your preferences and settings
AnalyticsUnderstand how users interact with our Services

You can control cookies through your browser settings. See our Cookie Policy for more details.

12. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe your child has provided us with personal information, please contact us at contact@appointa.eu.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will:

  • Post the updated policy with a new "Last Updated" date
  • Provide notice through email or in the Services for material changes
  • Seek renewed consent where processing is based on consent and the law requires it

14. Contact Us

If you have any questions about this Privacy Policy, please contact us:


Document Version: 1.2