Data controller
CutOnTime acts as controller for personal data collected and processed through the platform.
For privacy questions or data-right requests, contact us through the email listed on this page.
Data we process
We only process data needed to operate the service, including:
- Barbershop and staff account data (name, email, login credentials).
- Customer booking data (name, email, phone, appointment details).
- Foreground location selected by you (approximate or precise) when you choose “Use my location” to find nearby barbers. CutOnTime does not request background location or use location for advertising.
- Content you provide, such as profile and business images, review text, support messages, and webshop messages.
- Purchase and subscription data, such as the product, status, and transaction or provider references. CutOnTime does not receive full payment-card details from Google Play or the App Store.
- Technical security and app-usage data (sessions, IP address, user agent, mobile installation ID, app screens visited, timestamps, and abuse-prevention logs).
- Notification and communication records for confirmations, reminders, and service updates.
Purposes and legal bases
We process personal data only under valid GDPR legal bases:
- Performance of a contract (bookings, account access, service communication).
- Legal obligations (administration, anti-fraud duties where required).
- Legitimate interests (security, reliability, quality assurance, and operational usage measurement).
- Consent (optional marketing or web analytics and similar technologies).
Retention periods
Data is retained no longer than necessary for the purpose it was collected for.
Where possible, data is deleted or anonymized after retention periods expire.
Third-party processors
We share data only with processors necessary to provide the platform, such as hosting, email, mapping, push-notification, app-store, and payment providers.
Google Maps may process technical request, device, crash, and map-interaction data when a map is displayed. Expo and platform push services process push tokens and notification content for delivery. Google Play, the App Store, and RevenueCat process purchase and subscription data for in-app subscriptions.
Processor agreements and appropriate safeguards are in place with relevant vendors.
International transfers
If personal data is processed outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
Your rights
Under GDPR, data subjects have rights including:
- Right of access, rectification, and erasure.
- Right to restrict processing and to object.
- Right to data portability for data provided by you.
- Right to withdraw consent at any time where processing relies on consent.
Security
CutOnTime applies technical and organizational measures to protect data against loss, misuse, and unauthorized access.
In case of a data breach, we act under applicable incident response and legal notification obligations.
Complaints
If you believe we handle personal data incorrectly, please contact us first so we can address it promptly.
You also have the right to lodge a complaint with the Dutch Data Protection Authority.