Skip to content

Partner Privacy Policy

Last updated 5 September 2026

Who we are

EasyBook AI shpk is the data controller for the personal information described in this notice.

  • Company: EasyBook AI shpk
  • NUIS: M56506203S
  • Registered office: Vlore, Rruga "Adem Abazi", zona kadastrale 8602, apartamenti me nr. pasurie 12/387-N2, Albania
  • General contact: [email protected]
  • Data Protection Officer: [email protected]

We process personal data in accordance with Albanian Law No. 9887 dated 10.3.2008 "On Personal Data Protection", as amended, and with Regulation (EU) 2016/679 (GDPR).

Introduction

This Privacy Policy explains how we collect, use and protect personal information when you use the EasyBook Partner platform — the web dashboard at partner.easybook.ai, the EasyBook Partner apps for iOS and Android, and any related EasyBook Partner services (together, the "Partner Services").

The Partner Services are for service providers — salons, spas, clinics, studios, trainers and professionals — who use EasyBook to run their business. Throughout this notice we refer to you and your business as the "Partner".

A separate privacy policy covers the consumer discovery and booking platform at easybook.ai/privacy-policy. The two are designed to be read together where relevant.

What we collect and why

For each category we identify the lawful basis under data protection law.

Automatically collected information

Technical information. IP address, sign-in information, browser type and version, device identifiers, time-zone setting, operating system and platform, app version, and on mobile the device model, OS version and network type.

Usage information. The pages you open in the dashboard, the order in which you open them, response times, session length, and the content of any support conversation you start.

Location. Coarse location derived from your IP address (country and region) to localise the service and detect fraud. With your permission, precise coordinates from your device when you use "use my current location" to complete a venue address.

Lawful basis: legitimate interests (operating and securing the platform); consent (precise location).

Account creation and authentication

  • First and last name, username, email address, optional telephone number
  • Password, stored only as a salted BCrypt hash — we never see it in plaintext
  • If you sign in with Google or Apple: an authentication token and basic profile information (name, email, provider user id; Apple users may use Apple's private relay address)
  • The terms and privacy policy versions you accepted, the date and time, and your confirmation that you are at least 18 years old
  • Account preferences (theme, language, time zone, notification preferences)
  • Session and refresh tokens, held in encrypted HTTP-only cookies
  • A unique account code we assign to you

Lawful basis: contract (providing the Partner Services); legal obligation (recording consent); legitimate interests (account security).

Business and organisation data

Business or organisation name, business type, venue addresses and coordinates, business contact email and telephone, opening hours and time zone, the services, prices, durations and descriptions you publish, staff names and roles you create, photographs and marketing material you upload, and public reviews and ratings about your business.

Lawful basis: contract.

Payments

The Partner Services support cash collected at the venue. Your clients pay you directly; no card or bank details flow through EasyBook. You may record amounts and payment status in the dashboard for your own accounting, and that record is ordinary business data under this notice.

EasyBook does not process card payments and stores no card data. There is no payment processor in the Partner Services, and settlement — in cash or under any other arrangement you have agreed with your client — takes place entirely outside the platform. The dashboard holds only the record you create: the amount, the currency, the date and the status of an obligation or a settlement, kept so that you can run your own accounts. No card number, expiry date, card brand or bank detail is ever collected, transmitted or stored by us.

Lawful basis: contract.

Google Calendar integration

If you connect a Google Calendar account we request the scopes https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.readonly so that appointments can synchronise in both directions. We:

  • read calendar events to detect conflicts and block availability;
  • write EasyBook appointments to your Google Calendar;
  • store an encrypted refresh token so the synchronisation keeps working without re-authentication.

We read only the fields we need for an entry: its identifier, start and end time, title, status, visibility and whether it blocks your time. We do not use Calendar data for advertising, do not sell it, and do not share it with anyone else.

You can disconnect at any time in Settings → Calendar. Disconnecting revokes our access at Google, deletes the stored token, and deletes the copies of your Google events we held for conflict detection.

EasyBook AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Lawful basis: consent — the integration is opt-in and revocable.

Google Contacts integration

If you connect Google Contacts we request the scope https://www.googleapis.com/auth/contacts.readonly for one purpose only: to let you choose existing contacts to add to your client list.

  • We read contact name, email address, telephone number and photograph at the moment you open the import screen, and show them to you for selection.
  • Nothing is stored until you select it. Contacts you do not select are discarded when you leave the screen; there is no ongoing synchronisation.
  • Contacts you do select become client records in your organisation and are then retained as client data under your own control, marked with the provenance "imported from Google Contacts". They are kept until you erase them or close the organisation. The first message we send on your behalf to an imported person tells them that you provided their details and links to the consumer privacy policy.
  • You can disconnect at any time in Settings → Connected accounts → Google Contacts. Disconnecting revokes our access at Google and deletes the stored token. Client records you already imported remain yours and are not deleted by disconnecting — erase them individually if that is what you want.

EasyBook AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Lawful basis: consent.

Inviting and managing staff

When you invite staff to your organisation we collect their first and last name, email, role and the permissions you assign. Staff accounts are accounts in their own right; their personal data is processed as described in this notice, and what they can see inside your organisation is decided by the role you give them.

Communications with us

When you contact support by email, in-app, or through social media we keep the subject, content and timestamps so we can answer, reproduce problems and improve the service.

Lawful basis: legitimate interests (providing support); contract.

Marketing communications

If you have opted in, we send product updates, tips, surveys and offers about the Partner Services. Every marketing email carries an unsubscribe link, and you can change your choice at any time in your notification preferences.

Lawful basis: consent; legitimate interests (existing-customer marketing, where the law allows).

Your clients' personal data

The Partner Services let you record and manage personal data about your own clients — their name, contact details, booking history, notes and consents.

For that client data you are the data controller and EasyBook is your data processor, acting only on your instructions. The terms of that relationship are published in full as our Data Processing Agreement, which forms part of the Partner Terms of Service and which you accept when you create an organisation.

This means that when one of your clients asks to exercise their rights in relation to data you hold in EasyBook, the request goes to you. The dashboard gives you the tools to answer it: export a client's record, correct it, or erase it from the client's profile. We publish a separate consumer privacy policy covering the data we collect directly from consumers who book through the discovery platform.

You are responsible for giving your clients appropriate privacy information and for obtaining any consent the law requires — in particular before you record health or other special-category data, and before you mark a client as having consented to marketing.

Lawful bases

Consent. Marketing, the optional Google integrations, precise location, and non-essential cookies. You can withdraw consent at any time; the relevant section above and the Cookie Policy explain how.

Contract. Most of what we process is necessary to provide the Partner Services under the Terms of Service — the dashboard, transactional email, the booking calendar.

Legal obligation. Tax and accounting records, records of consent, and responses to lawful requests from competent authorities.

Legitimate interests. Operating, securing and improving the platform; existing-customer marketing where the law allows; enforcing our agreements and recovering amounts owed; defending legal claims. Write to [email protected] if you would like to know how we balanced a particular interest against your rights.

Who we share information with

We share personal data only as described here, and we do not sell personal data.

  • Sub-processors — the providers listed in the table below, who process data on our behalf under contract.
  • Your invited staff — staff you invite see the organisation data their role allows.
  • The discovery platform (easybook.ai) — where you list your business, your public profile, venue, services, prices and reviews are shown there, and bookings made there arrive in your dashboard.
  • Auditors and professional advisers — where required.
  • Law enforcement, regulators and courts — where required by law or valid legal process, or to protect rights, safety or property.
  • A successor — if EasyBook is acquired or transfers assets, subject to this notice.

Sub-processors

These are the providers we currently engage. The same table is Annex 1 to the Data Processing Agreement and changes to it are notified 30 days in advance.

Sub-processorRolePersonal data processedLocation
Google Cloud (Google Ireland Limited, with Google LLC as onward processor)Managed PostgreSQL database and Cloud Storage bucket holding all platform data and uploaded imagesAll categories described aboveFrankfurt, Germany (europe-west3) — database and object storage
Hostinger International LtdHosting of the application servers and of the session and permission cache that runs alongside themAll categories described above, processed in memory while a request is served; session and permission cache entriesMeppel, Netherlands, with a standby cluster in Frankfurt, Germany — both in the European Union, no transfer outside the EEA
Resend Inc.Delivery of transactional email — booking confirmations, reminders, one-time codes, calendar invitationsRecipient name, email address, message contentUnited States (EU-U.S. Data Privacy Framework)
Google Ireland Limited / Google LLC — Firebase Cloud MessagingDelivery of push notifications to Partner devicesDevice push token, notification title and bodyEuropean Union and United States
Google Ireland Limited / Google LLC — Calendar API and People APITwo-way calendar synchronisation and one-off contact import, only where you have connected the integrationAppointment time, title and participants; contact name, email and telephone at the moment of importEuropean Union and United States
Google Ireland Limited / Google LLC — Maps PlatformVenue address autocomplete and map display, only where functional consent is givenApproximate location and the address being searchedEuropean Union and United States
Google Ireland Limited / Google LLC — Analytics 4Aggregate platform usage measurement, only where analytics consent is given; IP anonymisation enabledTruncated IP address, device and usage eventsEuropean Union and United States
Apple Inc. / Apple Distribution International LimitedSign in with Apple and the Apple Push Notification serviceApple account identifier, name and email or Apple private relay address; device push tokenIreland and United States
Cloudflare, Inc.DNS resolution, content delivery, TLS termination and denial-of-service protection in front of every public domain of the platformIP address and request metadata processed at the edgeGlobal edge network (EU-U.S. Data Privacy Framework; Standard Contractual Clauses)

International transfers

The platform is operated from Albania and its data is stored in the European Economic Area. Some of the providers above are, or have parent companies, in the United States. Where personal data leaves the EEA we rely on the EU-U.S. Data Privacy Framework where the recipient is certified, and otherwise on the Standard Contractual Clauses adopted by the European Commission, together with the technical measures described below.

How we protect information

  • TLS for all data in transit
  • AES-256-GCM encryption at rest for OAuth tokens, multi-factor authentication secrets, recovery codes and push tokens; database and object storage encrypted at rest by the cloud provider
  • Passwords stored only as BCrypt hashes
  • Encrypted, HTTP-only session cookies
  • Optional multi-factor authentication: time-based one-time passwords, passkeys and hardware security keys, and recovery codes
  • Role-based access control with organisation-scoped permissions on every read and write
  • Append-only audit logging of security and data-protection events
  • Dependency and vulnerability scanning on every build

No transmission over the internet is ever completely secure. If you believe your account has been compromised, write to [email protected] immediately.

Multi-factor authentication and security keys

If you enable multi-factor authentication we additionally process an encrypted shared secret for time-based one-time passwords, a public-key credential and limited device metadata for a passkey or hardware key (your private key never leaves your device), and encrypted recovery codes. You can remove any method from your security settings.

Push notifications

We use Firebase Cloud Messaging to deliver push notifications — new bookings, cancellations, daily summaries. When you enable them we store a device push token that identifies your device for delivery. You can turn them off in your account settings or in your device's settings, and the token is deleted when you sign out or revoke the permission. See Google's privacy policy.

Automated decisions

We do not make decisions about you that produce legal effects or similarly significantly affect you by automated means alone. The platform derives suggestions — recommended rebooking dates, client reliability indicators, ranking of businesses in discovery search — from your own data and your clients' activity. These are suggestions shown to a person, and a person decides.

Account closure

You can close your Partner account yourself, from Settings → Close account. There are two outcomes:

  • Deactivate — your account is disabled and your profile disappears from the platform. Nothing is deleted, and signing back in restores it.
  • Delete — after a 30-day grace period, during which signing in cancels the deletion, your personal data is permanently erased: profile, addresses, devices, notifications, connected accounts, calendar data and stored tokens. Your Google grants are revoked at Google and the tokens are deleted at the moment you request deletion, not at the end of the grace period.

Some records survive deletion because the law requires it: financial records (amounts, dates and references, with your notes and IP addresses removed) for the period required by Albanian tax and accounting law, and the record that you consented to a policy version, kept as proof of consent with your email address replaced by an irreversible hash. Reviews you wrote are attributed to a deleted user.

Closing an account is not the same as closing an organisation. If you are the sole owner of an organisation, you must close or transfer the organisation first; the dashboard tells you what is blocking the closure.

Your data export

You can ask for a copy of everything we hold about you from Settings → Privacy → Download your data. We prepare an archive containing your profile, addresses, bookings, holdings, transactions, reviews, devices, consents, connected accounts and notifications, and give you a private download link valid for 24 hours. The archive is deleted when the link expires; you can request a new one.

How long we keep information

  • For as long as it is needed for the purpose it was collected — in general, while your Partner account is open.
  • Records required for tax and accounting are kept for the period Albanian law requires after the account closes.
  • Security records — sign-in attempts, one-time codes, device records — are kept for short, defined periods and then deleted automatically.
  • Consent and data-protection audit records are kept for three years so we can prove what was consented to and when.
  • Aggregated data that can no longer identify anyone is not personal data and may be kept indefinitely.

Your rights

You have the right to obtain a copy of your personal data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time. You also have the right to complain to a supervisory authority.

To exercise a right, write to [email protected]. We answer within the period the law sets — normally one month, extendable to three for complex requests. Access, portability and erasure of your own account data are also available directly in your settings.

If your request concerns data your own clients gave you through the Partner Services, it should be directed to you as the controller of that data. See "Your clients' personal data" above.

Albanian Information and Data Protection Commissioner

  • Website: www.idp.al
  • Email: [email protected]
  • Address: Commissioner for the Right to Information and Protection of Personal Data, Rr. "Abdi Toptani", Nd. 5, Tiranë, Albania

Children

The Partner Services are not directed at children. To create a Partner account you must be at least 18 years old and legally entitled to operate a business; we do not knowingly permit anyone below that age to hold a Partner account.

Cookies

The Partner Services use cookies and equivalent storage on mobile to operate the platform, remember your preferences, secure your account and — with your consent — measure how the platform is used. The Cookie Policy lists every cookie we set and explains how to change your choices.

Changes to this policy

We may update this notice. The "last updated" date at the top changes with it, and the current text is always published here. Where a change is substantive we ask you to accept the updated notice when you next sign in, and record what you accepted and when.