Legal document

Privacy Policy (GDPR)

This policy explains how CutOnTime processes personal data for bookings, platform administration, and customer communication.

Last updated: 15 July 2026
1

Data controller

CutOnTime acts as controller for personal data collected and processed through the platform.

For privacy questions or data-right requests, contact us through the email listed on this page.

2

Data we process

We only process data needed to operate the service, including:

  • Barbershop and staff account data (name, email, login credentials).
  • Customer booking data (name, email, phone, appointment details).
  • Foreground location selected by you (approximate or precise) when you choose “Use my location” to find nearby barbers. CutOnTime does not request background location or use location for advertising.
  • Content you provide, such as profile and business images, review text, support messages, and webshop messages.
  • Purchase and subscription data, such as the product, status, and transaction or provider references. CutOnTime does not receive full payment-card details from Google Play or the App Store.
  • Technical security and app-usage data (sessions, IP address, user agent, mobile installation ID, app screens visited, timestamps, and abuse-prevention logs).
  • Notification and communication records for confirmations, reminders, and service updates.
3

Purposes and legal bases

We process personal data only under valid GDPR legal bases:

  • Performance of a contract (bookings, account access, service communication).
  • Legal obligations (administration, anti-fraud duties where required).
  • Legitimate interests (security, reliability, quality assurance, and operational usage measurement).
  • Consent (optional marketing or web analytics and similar technologies).
4

Retention periods

Data is retained no longer than necessary for the purpose it was collected for.

Where possible, data is deleted or anonymized after retention periods expire.

5

Third-party processors

We share data only with processors necessary to provide the platform, such as hosting, email, mapping, push-notification, app-store, and payment providers.

Google Maps may process technical request, device, crash, and map-interaction data when a map is displayed. Expo and platform push services process push tokens and notification content for delivery. Google Play, the App Store, and RevenueCat process purchase and subscription data for in-app subscriptions.

Processor agreements and appropriate safeguards are in place with relevant vendors.

6

International transfers

If personal data is processed outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.

7

Your rights

Under GDPR, data subjects have rights including:

  • Right of access, rectification, and erasure.
  • Right to restrict processing and to object.
  • Right to data portability for data provided by you.
  • Right to withdraw consent at any time where processing relies on consent.
8

Security

CutOnTime applies technical and organizational measures to protect data against loss, misuse, and unauthorized access.

In case of a data breach, we act under applicable incident response and legal notification obligations.

9

Complaints

If you believe we handle personal data incorrectly, please contact us first so we can address it promptly.

You also have the right to lodge a complaint with the Dutch Data Protection Authority.

Privacy contact

support@cutontime.nl