Privacy policy

Updated 2026-09-29

The LT version is the legally binding one.

1. Who we are

edapi (edapi.io) is a booking and salon management system provided by Deividas Pacipavičius, Mickūnai, Vilniaus r., Lithuania (we). For any data question write to support@edapi.io — we answer within 30 days, usually sooner.

This policy covers www.edapi.io, salon pages on edapi.io subdomains and the emails the system sends.

2. Two roles: controller and processor

For salon account data (the owner and staff) we are the data controller: we decide what is needed for the account, its security and billing.

For the salon clients data we are a processor: the salon is the controller and we process the data only on the salon instructions and only to make the system work. A client request about their own data is handled first by the salon; our obligations towards the salon are set out in the Data processing agreement.

3. Salon account data

We collect: name, email address, a cryptographic hash of the password (we never store or see the password itself), phone number if you entered one, salon name, address and contacts, sign-in records, an action log (who changed what and when) and technical error records.

Why: to provide the service (GDPR Art. 6(1)(b)), to protect the account against unauthorised access and to meet accounting and subscription obligations (Art. 6(1)(c) and (f)).

Subscription payments are handled by Stripe. Card details never reach us — Stripe receives and stores them; we only see the payment fact, amount and status.

4. Salon client data

On the salon instruction the system may hold: client name, phone number, email address, salon notes about the client, allergy or health notes, no-show count, a blocked flag, how and when the record was created, and the email language.

If the salon merged two records of the same client, the name, phone and email from the merged record are kept too, so it is visible where the data came from.

For visits: service, specialist, time, status, price, visitor name (when booking for someone else), the client note, cancellation reason, number of reschedules, series information and deposit payment facts.

For messages and consent: marketing consent status, its history (when, from where and through which channel), types and statuses of emails sent, the content of personal messages, campaigns received and opt-outs, and reviews the client left along with decisions on reports about them (DSA).

Allergy and health notes are special category data (GDPR Art. 9). The lawful basis for them is the salon responsibility — the system offers the field but never requires it.

Consent records store a protected (peppered hash) value of the IP address, so that we can prove when consent was given without being able to reconstruct the address itself. It is not shown in the export.

5. Where the data comes from

From the owner — at sign-up, in the setup wizard and later in the admin area, including when importing a client list.

At sign-up we record which link brought you here (UTM tags, a referring salon “ref”, whether the link came from Facebook / Instagram, the referring site’s address) and your answer to the wizard question “How did you hear about edapi?” — to measure marketing. No cookies are used for this and individual visitors are not tracked; this data is included in the salon export and cleared on anonymisation.

From the client — when booking a time on the salon page, confirming or changing a visit through the link in an email, or leaving a review.

Automatically — system records: sign-in times, the action log, error records and email delivery statuses.

6. Requests via the website form

The contact form on the edapi.io home page (for IT service requests) collects your name, email address, the selected service and your message. Purpose — to answer your request; legal basis — steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)).

The request reaches us as an email to support@edapi.io via Resend and is kept in the mailbox for up to 24 months after receipt. We do not store your name, email or message in the system database — only the fact that the email was sent, without personal data. We do not send you a confirmation email.

The form is protected from automated submissions by a Cloudflare Turnstile check, which sees technical request data (IP address, browser type). We receive a short internal notification about a new request (Telegram) without your name, email or message text.

7. Publicly listed business contacts

We may use business contacts that salons and beauty professionals publish themselves (for example on an Instagram, Facebook or Google business profile) to offer edapi. The lawful basis is our legitimate interest in presenting the service to businesses (GDPR Art. 6(1)(f)).

You have the right to object: reply to the message or write to support@edapi.io and we will delete the contact and not contact you again. We keep such contacts for no longer than 12 months.

8. Who receives the data

We use these providers (sub-processors), each only for the stated function: Contabo (Germany) — server and database hosting; Cloudflare — domain, traffic protection, the Turnstile check in the booking form and R2 photo storage; Resend — system and campaign emails; Stripe — subscription and deposit payments; Google (Gemini) — text draft generation when the owner asks for it.

Only the text the owner types themselves (hints for a service description) is sent to Gemini — client data is not sent there.

We receive technical error notifications (the error text and the place in the code) through Telegram — an internal tool for us, not a client data channel.

If you contact support via WhatsApp or Telegram (when these channels are enabled), your messages are also processed by those services — Meta (WhatsApp) and Telegram. Do not send client personal data through them — use the support form or email instead.

Fonts are served from our own server — the browser does not contact any third-party server for them.

We do not sell data and do not share it with anyone for marketing purposes. We disclose it only where the law requires it or where the salon itself asks us to.

9. Transfers outside the EEA

The server and database are in the European Union. Some providers (Cloudflare, Resend, Stripe, Google) are US-based and may process data outside the EEA — such transfers rely on the European Commission standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

10. How long we keep it

We keep salon account and client data for as long as the salon uses the system. The owner can delete an individual client personal data at any time — name, phone, email, notes, allergies, message and review texts are then removed irreversibly, while visit times and amounts remain without personal data (the salon needs them for its own accounting).

Action log entries survive the deletion of personal data but without personal data — they show who performed an action and when.

Email delivery records are kept so the same email is not sent twice and so we can resolve undelivered mail.

We keep a suspended (unpaid) account for 90 days. Then we send a warning to the account email address and, after another 30 days, irreversibly anonymise the personal data of the salon, its staff and its clients and delete the photos; visit times and amounts remain without personal data. To close an account earlier, use the admin area (Salon → Data → "Close account", confirmed with the password) or write to support@edapi.io from the account email address — we then anonymise the data within 30 days of the request; until then the closure can be cancelled (we recommend downloading the archive from the admin area first).

Reports about public reviews (the "Report this review" form): we keep the reporter's name, email and explanation for 365 days after the decision, then anonymise them; the report number, reason, decision and its reasoning remain. We use this data only to handle the report and defend the decision; edapi is the controller.

11. How we protect it

All traffic is encrypted (HTTPS). Passwords are stored only as cryptographic hashes. Every database query is mandatorily scoped to a single salon — without a salon context the system refuses to run it.

Nothing is deleted silently: a destructive action is written to the action log together with its author. The booking form is protected against automated requests by Cloudflare Turnstile and rate limits.

Only we have server access, and it is protected by an SSH key, with no password login.

12. Your rights

You have the right to access your data, to have it corrected or erased, to restrict processing, to object to processing and to receive a copy in a portable format.

A salon owner and a staff member can download a copy of their own data in the admin area (Account → My data), and a copy of the whole salon data in the salon settings.

A client whose data is in a salon record should ask the salon for a copy or erasure — the salon is the controller and can do it with one button. If the salon does not respond, write to support@edapi.io and we will remind them.

You can opt out of marketing emails at any time — every such email carries an unsubscribe link that works without signing in.

If you believe your data is processed unlawfully you may complain to the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt).

13. Changes

The version and date of this policy are shown at the top of the page. If processing changes materially we notify salon owners by email before the change takes effect.