Privacy policy
Last updated: 20 September 2026
This policy explains what personal data we process at Reserv (reserv.day), why, for how long, and who we share it with. It is written to be understood: if anything is unclear, email [email protected] and we will explain it.
1. Who we are
Reserv is an online appointment booking service for businesses that work by appointment: hair and barber shops, dental clinics, physiotherapists, psychologists, beauty salons and similar.
Data controller: Reserv, operator of reserv.day. Contact address for any privacy matter: [email protected].
We have not appointed a Data Protection Officer because none of the circumstances in Article 37 GDPR apply. The address above reaches a person who answers.
2. Two different roles, and the difference matters
We handle two very different sets of data, and our responsibility for each is not the same. This is probably the most important section of this policy.
We are the controller of data belonging to the people who sign up for Reserv — the business and whoever administers it: name, email, phone, billing details, account activity. We decide what that data is used for.
We are a processor of data belonging to that business's own clients: the people who book appointments. The business decides what is collected, why, and for how long. We only host and process it on their documented instructions.
In plain terms: if you booked an appointment at a hair salon through Reserv and you want your data deleted, the salon is the controller. Write to them. If you cannot reach them or they do not reply, email [email protected] and we will help you find them and pass your request on.
The data processing agreement required by Article 28 GDPR is built into our Terms of Service, in the "Processing of personal data" article. Every business using Reserv accepts it on sign-up: there is no separate document to sign.
3. What data we process
We do not process special category data under Article 9 GDPR — health, beliefs, sexual orientation — and the service is not designed for it. The notes field is free text: if a business writes clinical information there, it does so under its own responsibility as controller and must have an Article 9 basis for doing so. Our Terms say this to them explicitly.
| Category | What it includes | Our role |
|---|---|---|
| Business account | Name, email, password (hashed, never in plain text), phone, trading name, premises address, logo, brand colour, time zone. | Controller |
| Billing | Plan, amounts, charge dates, last four digits and brand of the card, tax country, tax ID where you provide it. Full card numbers never touch our servers: Stripe captures them directly. | Controller |
| Service usage | Sign-in times, actions taken in the dashboard, IP address, browser and device type, technical error logs. | Controller |
| The business's own clients | Name, email, phone, national ID (DNI/NIE) where the business asks for it, notes written by the client or the business, appointment history, attendance and no-shows. | Processor |
| Appointments | Service, staff member, date, time, duration, price, status and cancellation reason. | Processor |
| Connected calendars | Only if the business connects Google Calendar or Outlook: encrypted access tokens and event identifiers. We do not read the content of events unrelated to Reserv. | Processor |
4. About the Spanish national ID (DNI/NIE)
Reserv includes an optional DNI/NIE field on the booking form. We flag it prominently here because a national identifier is not an ordinary piece of data: it identifies a person uniquely and permanently, and misuse makes identity fraud easier. The GDPR and the Spanish LOPDGDD require a specific justification for collecting it.
The field is optional for the person booking and configurable by the business. In the default configuration it is never required to complete a booking.
We do not ask for it and we do not use it for anything. Reserv does not look it up, validate it, enrich it or share it with anyone. It feeds no profile, no fraud system and no advertising tool. It is stored encrypted and visible only to the business that collected it.
It exists because some sectors genuinely need it. A dental clinic must identify the patient in their clinical record (Spanish Law 41/2002). A business issuing a named invoice needs the recipient's tax ID (Royal Decree 1619/2012). For a hair salon there is no justification at all, and we recommend turning it off.
The responsibility for asking is the business's, not ours. If you are a business using Reserv: only enable it if you can explain why you need it. If you are a client being asked and cannot see the reason, you can leave it blank or ask the business before filling it in.
5. What we use data for, and on what legal basis
Each purpose has its own legal basis. We do not lump them all under "consent", because that would not be true.
| Purpose | Legal basis | Explanation |
|---|---|---|
| Providing the service: creating the account, publishing the booking page, running the calendar and appointments | Performance of a contract — Art. 6(1)(b) GDPR | Without this data there is no service to provide. |
| Sending appointment confirmations and reminders to the end client | Processing on behalf of the controller — Art. 28 GDPR | We send these for the business and on its instructions. The legal basis towards the end client comes from the business, usually performance of its own service contract. |
| Charging the subscription and issuing invoices | Contract and legal obligation — Arts. 6(1)(b) and 6(1)(c) GDPR | Accounting and tax obligations under the Spanish Commercial Code and General Tax Act. |
| User support and incident handling | Performance of a contract — Art. 6(1)(b) GDPR | If you write to us, we need to read what you tell us in order to help. |
| Security, abuse prevention and error diagnosis | Legitimate interests — Art. 6(1)(f) GDPR | Our interest in keeping the service running and protected against unauthorised access. We have weighed the impact: technical logs are kept briefly and are never used to profile anyone. |
| Improving the product using aggregated usage data | Legitimate interests — Art. 6(1)(f) GDPR | We work with aggregated metrics, not identified individual behaviour. You can object by writing to [email protected]. |
| Sending you, as a Reserv customer, news about the product | Legitimate interests and Art. 21(2) LSSI | Only about products similar to those you already use, and every email carries an unsubscribe link that works first time. |
| Non-essential cookies and similar technologies, including advertising | Consent — Art. 6(1)(a) GDPR and Art. 22(2) LSSI | Nothing non-essential runs before you accept it, and you can withdraw as easily as you gave it. |
6. Who we share data with
We do not sell personal data to anyone, and we do not pass it to third parties for their own purposes. We do work with the infrastructure providers the service needs to run. Every one of them is bound by a data processing agreement and may only use the data to provide their service to us.
This is the complete, current list. When it changes we will announce it at least 30 days in advance on this page and by email to the businesses affected.
| Provider | What for | Where data is processed | Safeguard |
|---|---|---|---|
| Supabase | Database, authentication, file storage and server functions. This is where the bulk of the data lives. | European Union — AWS eu-west-1, Ireland | Data at rest stays in the EU. Supabase Inc. is a US company and its support staff may occasionally access data from outside the EEA; that access is covered by Standard Contractual Clauses. |
| Stripe | Subscription payments and invoicing. Captures card details directly, without passing through our servers. | Ireland and United States | Standard Contractual Clauses and the EU-US Data Privacy Framework. Stripe is an independent controller for payment data. |
| Resend | Sending transactional email: appointment confirmations and reminders. | United States | Standard Contractual Clauses. Receives only the name, email and appointment details that appear in the message. |
| Google Calendar sync. Only for businesses that explicitly connect it. | United States | Standard Contractual Clauses and the EU-US Data Privacy Framework. Can be disconnected at any time from the dashboard. | |
| Microsoft | Outlook Calendar sync. Only for businesses that explicitly connect it. | United States and European Union | Standard Contractual Clauses and the EU-US Data Privacy Framework. Can be disconnected at any time from the dashboard. |
| Meta | Measuring how well our advertising on Facebook and Instagram works. Only on our public marketing site, never on a business's booking page or dashboard. | United States | Only loads if you accept the marketing category in the cookie notice. If you reject it, it does not load at all. |
| Static hosting provider | Serving the web application's files (HTML, JavaScript, images) from a content delivery network. | Edge nodes in the European Union | Stores no client or appointment data. Records IP addresses in access logs for a maximum of 30 days. |
We may also disclose data to the competent authorities where a law or court order requires it. In that case, unless legally prohibited, we will tell the affected business before doing so.
7. International transfers
Appointment and end-client data is stored in the European Union, in the AWS eu-west-1 region in Ireland, which is where our Supabase project is hosted. That is the short answer to the question a clinic usually asks before signing up.
There are four routes out of the EEA, all narrow and all tied to specific functions: transactional email (Resend), subscription payments (Stripe), calendar sync if you enable it (Google, Microsoft), and advertising measurement on our public site if you accept it (Meta).
All of them rely on the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, supplemented — where the provider is certified — by the EU-US Data Privacy Framework. You can request a copy of the applicable safeguards at [email protected].
If your organisation requires that no data leaves the EEA at all, contact us before signing up: we can disable calendar sync, but transactional email and payment processing are, today, an inseparable part of the service.
8. How long we keep each thing
Specific periods, not "as long as necessary". When a period expires, the data is deleted from the live database; any backups still holding it rotate out within a further 30 days at most.
| Data | Period | Why |
|---|---|---|
| Business account and its contents, while the account is active | Until you close it | It is your working tool. |
| Closed account: recovery and export window | 30 days | Time to recover the account or download your data if the closure was a mistake. |
| Closed account: permanent deletion | 60 days from closure | After the recovery window, everything goes: account, clients, appointments and files. |
| Free trial that did not convert to a subscription | 90 days after the trial ends | In case you come back. Deleted after that without further notice. |
| Invoices and accounting and tax records | 6 years | Article 30 of the Spanish Commercial Code. Also covers the 4-year tax limitation period. |
| Technical and access logs (IP, errors, security audit trail) | 90 days | Long enough to investigate an incident without hoarding data indefinitely. |
| Delivery metadata for transactional email | 90 days | So we can show a reminder was sent if there is a dispute. |
| Support conversations | 2 years from case closure | Context for recurring issues and a record of what was agreed. |
| Cookie consent record | 3 years | So we can demonstrate to the Spanish DPA what you chose and when, under Article 7(1) GDPR. |
| The cookie preference stored in your browser | 12 months | After that we ask again — below the 24-month maximum the Spanish DPA allows. |
| Database backups | 30-day rotation | Disaster recovery. A deletion takes at most 30 days to propagate. |
9. How we protect data
No system is invulnerable, and be suspicious of anyone who tells you otherwise. Here is what we actually do:
TLS encryption in transit on every connection, and encryption at rest for the database and file storage.
Row-level isolation in the database (Row Level Security): each business can only read and write its own records, and the rule is enforced by the database engine, not by application code. A bug in the interface does not expose another business's data.
Passwords stored as one-way hashes. Not even we can read them.
Calendar tokens encrypted and scoped to the minimum needed.
Staff access limited to what is strictly necessary, subject to confidentiality obligations, and logged.
Automated daily backups with a 30-day retention.
If a personal data breach occurs, we will notify the Spanish DPA within 72 hours where required, and the affected business without undue delay and in any case within 48 hours of becoming aware, so that it can meet its own obligations.
10. Your rights
You can exercise the following rights at any time, free of charge:
- Access
- Find out what data of yours we process and get a copy.
- Rectification
- Correct anything that is wrong or incomplete.
- Erasure
- Ask us to delete it, where no legal obligation requires us to keep it.
- Restriction
- Ask us to keep it but stop using it while a disagreement is resolved.
- Portability
- Receive your data in a structured, commonly used format, or have us send it directly to another provider.
- Objection
- Object to processing based on legitimate interests, including direct marketing.
- Automated decisions
- Not be subject to decisions based solely on automated processing with legal effects. We make no such decisions today.
- Withdrawal of consent
- Withdraw consent you have given at any time, without affecting the lawfulness of processing before withdrawal.
How to exercise them: write to [email protected] saying which right you want to exercise. We reply within one month, extendable by two further months if the request is complex, in which case we will tell you within the first month. We will only ask for extra identification if we have reasonable doubts about who you are.
If you are a client of a business that uses Reserv: that business is the controller of your data and is who you should ask. Even so, write to us if you cannot reach them: we will pass your request on and confirm that we have.
If you are a business using Reserv: you can export all your data from the dashboard at any time, without asking us and at no cost.
11. Complaining to the supervisory authority
If you think we have handled your request badly, or that we are processing your data improperly, you can lodge a complaint with the Spanish supervisory authority. It is free and you do not need a lawyer.
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6 — 28001 Madrid, Spain
Phone: +34 901 100 099 / +34 91 266 35 17
Online portal: sedeagpd.gob.es
We would appreciate it if you wrote to [email protected] first — not to put you off, but because almost everything gets resolved in one email. Your right to complain directly does not depend on that.
12. Minors
Reserv is a professional tool: to open an account you must be an adult acting on behalf of a business.
End clients booking an appointment may be minors. Article 7 of the Spanish LOPDGDD sets 14 as the age from which a minor can consent on their own behalf; below that, authorisation from a parent or guardian is needed. Because the controller in that relationship is the business and not us, it is the business that must obtain and keep that authorisation.
If we find we have processed data belonging to a child under 14 without proper authorisation, we will delete it as soon as we know. Tell us at [email protected].
13. Changes to this policy
We will update this policy when what we do changes. The last updated date always appears at the top.
If a change is material — a new purpose, a new sub-processor, a longer retention period — we will announce it at least 30 days in advance by email to every business with an active account and with a visible in-app notice. We will not change anything retroactively and quietly.
We keep previous versions and will send them to you on request.
14. Contact
For anything about privacy, data protection or this policy: [email protected]. A person writes and a person answers.