Privacy Policy
Last updated 18/09/2026
Calenti is an online booking and business-management service for appointment-based businesses, operated by Chrysanthos Chrysanthou, a sole trader established in Cyprus, of Strovolos, Nicosia 2021, Cyprus ("we", "us"). This policy explains what personal data we handle, why, and what rights you have. You can reach us at privacy@calenti.cy about anything written here.
1. TWO DIFFERENT ROLES
We handle two kinds of personal data and our responsibilities differ for each.
For the businesses that use Calenti — shop owners, their staff, and our affiliate partners — we are the data controller. We decide what account data is needed to run the service.
For a shop's own clients — the people who book appointments — the shop is the controller and we are its processor. We hold that data on the shop's behalf and act on its instructions. A client who wants their details corrected or deleted should ask the shop they booked with; if you contact us instead, we will pass the request to that shop, or help you through the request form on this page.
2. WHAT WE COLLECT
Client data, when you book: your name, surname and mobile number, and optionally an email address and a note to the shop. You do not need an account to book. The shop can also see your booking history with that shop, and may record visits, loyalty points, reviews you leave and payments you make.
Account data, from shop owners, staff and affiliates: name, email address, mobile number, password (stored only as a hash, never in a readable form), role, and language preference. If you sign in with Google or Apple, we receive your name and email address from that provider. If you use a passkey we store its public key and a name you give the device; your fingerprint, face or device PIN never leave your device.
Business data, entered by the shop: shop name, address and location, photos, services and prices, staff, working hours, client records, bookings, products, invoices and payments.
Technical data, collected automatically: IP address, the country it resolves to, browser and device description, and the time of significant actions such as signing in or changing a booking. We use it to keep accounts secure, detect attempts to break in or abuse booking forms, and diagnose faults. We also count visits to public pages.
We do not use advertising cookies and we do not track you across other websites. Booking forms are protected by Cloudflare Turnstile, which checks that a request comes from a person rather than a bot.
3. GOOGLE USER DATA
Connecting a Google account is entirely optional. Calenti works fully without it, and you can disconnect at any time. This section describes exactly what we access from Google, why, and what happens to it. We ask for the narrowest permission Google offers for each task.
Sign in with Google. If you choose to sign in with Google, we request your basic profile (openid, email, profile). We receive your name, email address and Google account identifier, and use them only to create your account and sign you in. We do not receive your Google password.
Google Calendar. A shop owner can connect Google Calendar for themselves or for a staff member. We request two permissions:
- View and edit events on your calendars (https://www.googleapis.com/auth/calendar.events). We use it to add that person's Calenti appointments to their calendar, keep those events up to date, and notice when one of them is moved, resized or deleted in Google Calendar so the booking can be updated or the event restored.
- View your availability (https://www.googleapis.com/auth/calendar.freebusy). We use it to read the start and end times of busy periods, so a client cannot book a staff member at a time their own calendar already shows them as busy. We do not read the titles, descriptions, locations or attendees of those events.
Events you create yourself are never changed or deleted by Calenti, and their contents are not stored; at most we keep their busy times for up to five minutes to show available slots.
Google Contacts. A shop owner can connect Google Contacts. We request permission to manage contacts (https://www.googleapis.com/auth/contacts). We use it for one purpose: to copy the shop's own client names and phone numbers into a contact group named after the shop (for example "My Barber Clients") in the owner's Google account, so incoming calls show who is calling. The copying is one way. We do not read, change or delete any contact outside that group. Google does not offer a narrower permission that only allows adding contacts, so the permission we must request is broader than what we use.
What we store. For each connection we store a refresh token that lets synchronisation continue while you are not signed in, and the identifiers needed to keep it in step (the calendar notification channel and sync position, or the contact group identifier). We do not store copies of your Google calendar events or contacts beyond the Calenti bookings and clients they correspond to.
Disconnecting. Disconnecting Google Calendar deletes the stored token and stops notifications immediately; appointment events we created are left in your calendar, because removing appointments you may still rely on would be the more harmful surprise. Disconnecting Google Contacts deletes the stored token, the contact group we created and the contacts inside it. When a shop's data is deleted after it closes its account, its stored Google tokens are deleted with it. You can also revoke our access at any time at https://myaccount.google.com/permissions, and you can delete anything we created yourself.
Limited Use. Calenti's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We use Google user data only to provide the features described above. We do not sell it, transfer it to others except as needed to provide those features, comply with the law or as part of a merger or acquisition, use it for advertising, or use it to develop, improve or train any artificial intelligence or machine learning model. No human reads it unless you ask us to for a specific support problem, it is needed for security reasons such as investigating abuse, or the law requires it.
4. WHY WE ARE ALLOWED TO HANDLE THIS DATA
To perform a contract: making and managing your booking; running a shop's account, storing its records and billing its subscription.
Legitimate interests: keeping the service secure, preventing fraudulent sign-ins and spam bookings, sending appointment confirmations and reminders, and diagnosing faults.
Consent: marketing emails from us to shop owners, marketing messages from a shop to its clients, optional emails, push notifications, and connecting a Google account. You can withdraw consent at any time without affecting anything else.
Legal obligation: keeping accounting and tax records for the periods Cypriot law requires.
5. WHO ELSE SEES IT
The shop you book with sees your booking and client details. Other shops do not.
We use a small number of service providers, each handling only what its task needs:
- Cloudflare, which hosts the service and stores its data.
- Resend, for booking, account and invoice emails.
- BulkGate, for appointment confirmations and reminders by SMS.
- Stripe, for subscription billing, and Stripe or Revolut for shops that take online payment from clients. Card details go to that provider directly and never pass through Calenti.
- Brevo, for marketing emails to shop owners who have agreed to receive them. Clients are never added.
- Google, for map display, address lookup, translation, sign-in and optional calendar and contacts sync; Geoapify, for address lookup; Apple, for sign-in and optional iCloud contacts sync.
Some providers may process data outside the European Economic Area under safeguards approved by the European Commission.
We do not sell personal data. We do not share it for advertising. We will disclose data if a court or a competent authority lawfully requires it.
6. HOW LONG WE KEEP IT
Shop account and business records stay while the shop's account is open. After a shop closes its account we keep its data for at least 90 days so it can return or export it, then may delete it. Records we must keep by law, such as issued invoices, are kept for the period Cypriot tax law requires.
Some data is deleted automatically on a fixed schedule:
- completed, cancelled and missed bookings: after 18 months
- loyalty point history: after 18 months
- SMS delivery records: after 180 days
- visit logs of public pages: after 90 days
- in-app notifications: after 7 days once seen, 30 days if not
- the security and activity log: after one year
7. SECURITY
Passwords are stored only as hashes and cannot be read back by anyone, including us. Data is encrypted in transit and at rest. A shop's data is visible only to that shop's own accounts, and every request is checked against the account making it. Repeated failed sign-in attempts lock the account. Payment details and Google refresh tokens are never exposed to the browser.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the Office of the Commissioner for Personal Data Protection and affected people as required by law.
8. YOUR RIGHTS
Under the General Data Protection Regulation you may ask for a copy of your data, ask for it to be corrected or deleted, ask us to limit how we use it, object to processing based on legitimate interests, and ask for your data in a portable format. Where we rely on consent you can withdraw it at any time.
Clients can use the request form below this policy, entering the phone number they booked with. Anyone can also write to privacy@calenti.cy. We respond within one month. If you are not satisfied you may complain to the Office of the Commissioner for Personal Data Protection in Cyprus (www.dataprotection.gov.cy).
9. CHILDREN
Shop, staff and affiliate accounts are for adults acting for a business. We do not knowingly collect data from children under 14 without the consent of a parent or guardian; a parent may book on a child's behalf.
10. CHANGES
If we change this policy we will update the date at the top and, where the change is significant, tell account holders directly.
11. INSTAGRAM AND FACEBOOK DATA
Connecting an Instagram or Facebook account is entirely optional. Calenti works fully without it, and you can disconnect at any time.
What we store. For Instagram: your Instagram account identifier and username, and an access token that expires after 60 days and is refreshed automatically while the connection lasts. For Facebook: the connected Page's identifier and name, and a Page access token. We also store the shop's own choice of which options appear in its chat menu.
Posts. If a shop displays its Instagram feed, we fetch that account's own recent posts and their images, refreshed a few times a day rather than read live. Captions are fetched only if the shop owner turns that on.
Messages. A shop can switch on automatic replies to direct messages. When someone taps one of the shop's menu options, we record the sender's platform-scoped identifier, which option was tapped, and the time. We do not store the text of messages people send, and we do not read conversations.
We never post to your account, and we do not use this data for advertising or to train any model.
Disconnecting. Disconnecting deletes the stored tokens and connection details immediately, along with any Instagram posts and images we had cached for the shop's page. Nothing further is needed from you. You can also remove Calenti's access from your Instagram or Facebook settings directly — Meta notifies us and the same deletion runs automatically. When a shop's data is deleted after it closes its account, its Instagram and Facebook tokens are deleted with it.
12. HOW TO DELETE YOUR DATA
To delete data a shop holds about you as a client, use the request form below this policy, entering the phone number you booked with, or write to privacy@calenti.cy.
To delete data linked to an Instagram or Facebook account, disconnect it in Calenti under Settings then Integrations. The stored tokens, the connection details and any cached posts and images are deleted immediately, and nothing further is needed from you. Removing Calenti from your Instagram or Facebook account settings has the same effect: Meta notifies us and the same deletion runs automatically.
To delete a shop, staff or affiliate account entirely, write to privacy@calenti.cy. We respond within one month.