Booksero App Privacy Policy
Last updated: 2026-09-13
_This is a translation of the Polish privacy policy. In case of doubt, the Polish version prevails._
1. Who is responsible for your data
Booksero is a single app used by many independent salons. The controller of your personal data is the salon (business) where you have a client record — its name and details are shown in the app once you enter the salon. If you use several salons that belong to different businesses, each of them is a separate controller of the data in its own client record.
The app and the Booksero booking platform are provided by VIVI ESTETIC SP. Z O.O., ul. Promienna 6–10, 44‑240 Żory, Poland, e‑mail: developer@viviestetic.eu — as the app operator processing data on behalf of the salons (data processor). For matters concerning your data you may contact the salon or the e‑mail address above.
2. What data we process
- Phone number — for signing in with an SMS code and for contact about appointments.
- First and last name — to identify your bookings and client account.
- E‑mail address (if provided) — for confirmations and contact.
- Booking and appointment data — service, time, chosen specialist, appointment history.
- Loyalty programme data — points, level, rewards, discount codes, referrals (if the salon has enabled these features).
- Device token for push notifications — if you agree to notifications (appointment reminders etc.).
- Basic technical data — app language, installation information.
We do not collect location data, phone contacts or payment data in the app.
2a. How the app knows which salon you are entering
You enter a salon with a QR code, with the name given to you by the salon, or with a link from the salon. The app has no salon search or directory.
If a salon offers entry with a phone number: after your number is confirmed with an SMS code, the app shows the list of salons where you have a client record under that number — including salons that belong to different businesses. The app operator then matches your number across salons only to show you your own client records; no salon learns about your records in other businesses. Each salon can switch off its visibility on this list. This feature is available only after verification that the number belongs to you (SMS code).
3. Purposes and legal bases (GDPR)
- Handling bookings and the client account — Art. 6(1)(b) GDPR (performance of a contract/service).
- Signing in with an SMS code and account security — Art. 6(1)(b) and (f).
- Push notifications — Art. 6(1)(a) (consent), which you can withdraw at any time in the app (Profile → Notifications).
- Loyalty programme (points, codes, referrals) — Art. 6(1)(b) and (f).
4. Recipients of data
Data may be passed only to entities necessary to run the service:
- the provider of the Booksero platform (hosting, technical operation),
- the SMS gateway provider (sending sign‑in codes and notifications),
- push notification service providers (browser/system mechanism).
We do not sell personal data and do not pass it on for third‑party marketing.
5. Retention period
We keep data for as long as you use the account and for the period required by law (including accounting rules). The notification token is deleted when you switch notifications off or sign out.
6. Your rights
You have the right to: access your data, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent. You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO). Contact regarding your data: developer@viviestetic.eu.
7. Deleting your account and data
In the app: Profile → Delete account. We then remove your access to the app (sessions on all devices, registered devices, notifications and app markers on your client record). Your visit history and client record are kept by the salon as the data controller — send a request to erase them directly to the salon (Art. 17 GDPR) or write to developer@viviestetic.eu and we will pass it on to the salon. Data will be deleted subject to obligations arising from the law. After deleting your account you can sign in again at any time.
8. Security
The connection to the app is encrypted (HTTPS). Sign‑in uses an SMS code, without passwords. Only authorised people at the salon have access to the data.
9. Changes to this policy
We will inform you about significant changes in the app or on the website. The date of the last update is shown at the top of the document.