Privacy Policy
Last updated: 29 Sep 2026
1. Who we are
Rezervo (“we”, “the platform”) is a booking and scheduling service for salons, studios, clinics and other service companies. Companies sign up to Rezervo and pay a subscription fee, and their customers book appointments through the company’s own booking link.
For any data-protection matter, contact us at support@getrezervo.com.
2. Who is responsible for which data
For account holders — the people who register with Rezervo (company owners, staff and customers with an account) — we are the controller of the account data described below.
For a company’s client records — the clients, bookings and notes a company keeps in its workspace — the company is the controller, and we act on its instructions as a processor. If you are a client of a company and want your data corrected or deleted, ask that company first; you can also write to us and we will pass the request on.
3. What data we process
- Account data — name, email, phone number, a hashed version of the password, preferred language and the account role (company owner, staff member or customer).
- Company data — company name, branches, staff, services, prices and working hours that a company enters into the platform.
- Client records — the details a company keeps about its clients: first and last name, phone number, optional email, preferred language, optional date of birth, the notes the company writes about the visit, and the client’s booking history. A guest can book with just a name and a phone number, without an account.
- Booking data — appointments that are booked, including their date, time, branch, chosen service and specialist and the price of that service.
- Visit payment records — after a visit, the company records what was paid and how (cash or card). The client pays the company directly, in person; Rezervo neither processes that payment nor receives any card data from it. What we store is the amount the company typed in — a bookkeeping entry, not a transaction.
- Messaging data — for every notification sent on a company’s behalf, we store the recipient’s phone number or email address, the message content, the time it was sent and its delivery status, so the company can see what reached its client and so message usage can be counted against its allowance.
- Notification preferences — what each client allows each individual company to send them and through which channel, including a withdrawal, and whether marketing consent was given, when, and by what route.
- Reviews — the rating (1 to 5) and optional comment you leave after a visit, published on the company’s booking page together with your first name and profile picture. The company may reply to it publicly and may flag it for Rezervo to review; only Rezervo decides whether a flagged review stays visible — the company cannot remove it itself.
- Waiting-list and slot-queue requests — if you ask to be told when a slot frees up, or to be put on a company’s waiting list, we keep your name, phone number, the branch, service, specialist and time you asked for and any note you add; if you joined the slot queue, we text you when a matching slot becomes free.
- Images — the logo, photos and profile pictures a company or a user uploads, stored with Cloudflare.
- Acceptance record — which version of the Terms of Service and of this policy you accepted, in which language and when, so we can show what you agreed to.
- Subscription payment data — a company’s subscription and message-pack payments are processed by Flitt (TBC Group). Rezervo does not store and has no access to full card details — card processing and security (PCI compliance) are entirely on the payment provider’s side. For an automatically renewing subscription the card is saved by Flitt, with the consent you give when you pay. We receive only the transaction status and identifier, the identifier of the recurring order and, for your receipts, the card brand and its last four digits, and we store the resulting invoice.
- Usage data — technical logs such as IP address, browser and device type, and records of how you interact with the platform, which help us keep the service secure and working.
- Cookies, browser and device storage — the web app sets one cookie, NEXT_LOCALE, which remembers your language for a year; on your first visit the language is chosen from the country our network provider (Cloudflare) reports for your connection and from your browser’s language settings — we do not store your location. In the browser’s local storage the app keeps your sign-in tokens and a copy of your profile (to keep you signed in), your language and theme (light/dark) choices, your dashboard layout preferences (selected branch, active view, collapsed sidebar) and a draft of what you were entering during sign-up (the chosen plan and company details); for the duration of a browser session it also remembers the day you picked on a booking page and which notices you have dismissed. The mobile app keeps the same sign-in tokens in the device’s secure storage and your language, theme, active view, selected branch and last-opened company in app storage; if you allow push notifications, we store the push token of that device. None of this is used for advertising or shared with third parties for that purpose.
4. Lawful bases for processing
Under the Law of Georgia on Personal Data Protection, we process your data on the following bases:
- Performance of a contract — providing the service, managing your account, processing bookings and sending the notifications a booking requires (confirmation, reminder, change or cancellation).
- Legal obligation — keeping accounting and tax records.
- Legitimate interest — platform security, fraud prevention and improving the service. For operating and improving the service we may use aggregated, anonymised statistics; they never identify a company or a person.
- Consent — where the law requires it, in particular for marketing messages. Consent is given per company and may be withdrawn at any time, from Settings → Notifications in your Rezervo account or by writing to us at support@getrezervo.com.
5. Processors and sub-processors
To deliver the service we work with selected providers who process data on our behalf:
- Hetzner (Germany) — server and data hosting.
- Cloudflare — CDN, DNS, network security and file storage.
- Flitt (TBC Group) — processing of subscription and message-pack payments.
- uBill.ge — delivery of SMS messages.
- the mail provider configured for the platform — delivery of email, over SMTP.
- Expo — delivery of push notifications to the mobile app.
Each provider is bound to protect the data under an appropriate agreement and security standards.
If we add or replace a provider that processes a company’s client records, we update this list at least 14 days before the change takes effect. The terms on which Rezervo processes client records on a company’s behalf are set out in section 9 of the Terms of Service.
A public booking page may also embed a Google map of the branch address. Loading that map sends your IP address to Google, as with any content embedded from another website.
6. International transfer of data
Because some providers (e.g. Hetzner) are located outside Georgia — within the European Union / European Economic Area — your data may be transferred and processed abroad. Any such transfer is carried out with the appropriate safeguards permitted under Georgian law.
Specifically: account data, company data, client records and bookings are stored on Hetzner servers in Germany, a member of the European Union, which is on the list of states with adequate data-protection guarantees approved by the Personal Data Protection Service of Georgia. Traffic to the platform passes through Cloudflare, which also stores the files a company uploads; push notifications go through Expo; and an embedded map is loaded from Google. These providers are headquartered in the United States and operate global networks. Only the data the function needs reaches them — respectively: your IP address and request metadata together with the uploaded files; a device push token and the text of the notification; the branch’s map coordinates and your IP address. Each of these transfers rests on the provider’s data-processing terms, which bind it to protect the data, and on a ground provided by the Law of Georgia on Personal Data Protection for transfer to another state. Data is not transferred abroad for any other purpose, and card data never passes through Rezervo at all.
7. Data retention
We keep data for as long as the account or company it belongs to exists; we do not delete it earlier on a fixed schedule. Client records, bookings and the log of messages sent stay in a company’s workspace until that company deletes them or deletes its own account — or, if its subscription has lapsed, until we delete the workspace after giving notice to the account owner, as section 15 of the Terms of Service allows; the message log is kept as evidence of what was sent and counted. A personal account’s data stays until the account is deleted (section 9), and records of security-relevant actions are deleted together with the account they belong to.
A company may export its data as CSV from the dashboard at any time. Deleting a company account is immediate and permanent: its whole workspace — bookings, client records, notes, messages, images and settings — is purged at once and cannot be recovered, so export your data first. The only records we keep afterwards are the invoices and payment records for the subscription fees and message packs the company paid to Rezervo: they are our own accounting documents, which the Tax Code of Georgia obliges us to keep for six years, after which we delete them.
8. Personal data breaches
If a security incident leads to the accidental or unlawful destruction, loss, alteration or disclosure of personal data, or to unauthorised access to it, we record the incident and its consequences in our incident register and, where it is likely to put the rights and freedoms of the people concerned at risk, notify the Personal Data Protection Service of Georgia within 72 hours of learning of it. Where the risk is high, we also inform the affected people directly, without undue delay, describing what happened, its likely consequences and the measures we have taken. For data held in a company’s workspace, where the company is the controller, we notify that company without undue delay so that it can meet its own obligations.
9. Your rights
As a data subject you have the following rights in relation to your personal data:
- Access — to know what data we process about you;
- Rectification of inaccurate data;
- Erasure (“the right to be forgotten”);
- Restriction of processing;
- Objection to processing;
- Withdrawal of consent at any time;
- Lodging a complaint with the Personal Data Protection Service of Georgia.
To exercise a right, contact us at support@getrezervo.com. We answer within 10 working days of receiving the request, as the Law of Georgia on Personal Data Protection requires. If the data is held in a company’s workspace, we forward your request to that company, which decides on it as the controller. If you are not satisfied with our answer, you may lodge a complaint with the Personal Data Protection Service of Georgia or apply to a court.
You can delete your own account yourself: in the web app under Settings, or in the mobile app under More. The deletion is carried out 14 days after the request — until then you can cancel it from the same place — and it cannot be requested while you have upcoming bookings or while your account owns or belongs to a company (a company owner deletes the company first, as described in section 7). When it runs, your account, your reviews, your notifications, your notification preferences, your push tokens and your activity records are deleted; the bookings a company keeps about you stay in its workspace with your name, phone number, email, date of birth, picture and the notes on your client card removed, because they are that company’s records; a note you yourself typed into a booking stays on that booking.
10. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you through the platform or by email. The “Last updated” date at the top of the page always reflects the version in force. This policy is published in Georgian and in English; if the two versions ever differ, the Georgian text prevails.
11. Contact
For any data-protection questions, write to us at support@getrezervo.com.