The short version: Appointer collects only what we need to run the Service. We never sell your data. Client payments run through your own payment provider (plata by mono, LiqPay or Stripe) and settle to your account — we never see card numbers or hold funds. You (and your clients) can have data exported or permanently deleted at any time. We follow GDPR principles for everyone, everywhere.
2. Who is responsible
For our own account holders' data (your name, email, business details), the controller is [FOP/TOV NAME], registered in Ukraine at [ADDRESS]. For the personal data of your clients that you manage in Appointer, you are the controller and Appointer is your processor — we handle that data only on your instructions, as set out in our Data Processing Agreement. This policy explains both roles.
3. What we collect
We collect three categories of information:
- Account information — your name, email, business name, and password (stored hashed, never in plain text). If you sign in with Google, we receive your name and email address from Google. Payment details for card transactions are handled by our payment processors (plata by mono, LiqPay or Stripe); we never see or store card numbers.
- Customer Data — the bookings, client records, messages, and payment metadata you create in Appointer. You control this; we process it on your behalf.
- Usage data — basic logs (IP address, browser, pages visited, errors) and product analytics so we can run the Service, keep it secure, and fix problems.
4. How we use it
We use your information to:
- Provide, maintain, and improve the Service.
- Send transactional email, SMS, and — where you connect a messaging channel (Telegram, Viber, Facebook Messenger, Instagram) — messenger messages on your behalf (booking confirmations, reminders, and the messages you configure). Messenger conversations with your clients are stored in your account so you can answer them from one inbox.
- Support billing and the online payments you take from your clients.
- Communicate with you about your account and the Service.
- Detect and prevent abuse, fraud, and security incidents.
- Comply with legal obligations.
5. Who we share with
We share data only with vendors ("sub-processors") that help us run the Service, each bound to GDPR-grade processing terms:
- plata by mono (Universal Bank), LiqPay (PrivatBank) & Stripe — online card payments. Client payments connect to your own merchant account; Appointer subscription payments are processed by plata by mono.
- Resend — transactional email delivery.
- Twilio — SMS delivery.
- Telegram, Rakuten Viber, and Meta Platforms (Facebook Messenger, Instagram) — message delivery when you connect the corresponding messaging channel. Message content passes through the platform you connected, under its own terms; we store the channel credentials you grant encrypted and use them only to send and receive your messages.
- PostHog — product analytics and session replay (see "Analytics" below).
- Anthropic (Claude) — the AI provider behind our optional AI features (the admin AI Assistant, brand generation, and retention-opportunity ranking). Data is sent to Anthropic only when you use one of these Pro features; see "AI features" below for exactly what each one sends.
- Cloud hosting and infrastructure providers — servers, storage, and backups.
The full, current sub-processor list is set out in our Data Processing Agreement. We never sell your personal data to anyone, ever.
6. AI features
Some optional, Pro-tier features use a third-party AI provider, Anthropic (Claude), to generate suggestions. These features are off by default and only send data to Anthropic when you actively use them. When they are not in use, nothing is sent to any AI provider. What each feature sends:
- AI Assistant (admin copilot) — to answer a question or prepare a change you ask for, it sends the relevant slice of your business data for that request. Depending on what you ask, this can include client names, email, phone, appointment and service details, notes, and reviews. It is used only to produce your answer; your chat history is stored in your account so you can reopen it, and you can delete a conversation at any time.
- Brand generation — when you generate a brand from a website, it sends that website's address, its title and description, the colours and fonts detected on it, your own brand description, and your site logo image. It uses these only to suggest a brand colour, font, and style you can review before applying.
- Retention-opportunity ranking — to help you prioritise which lapsed clients to win back, it ranks opportunities using only anonymous, numeric signals (an internal reference id, days since last visit, recent visit count, average spend, how long they've been a client, and how many service categories they've used). It does not send client names, contact details, or notes.
Automated processing. The retention-opportunity ranking above is a form of automated profiling: it scores and orders your clients by their likely value so the highest-priority win-back opportunities surface first. It only ranks and prioritises — it never sends a message, changes a booking, or makes any decision with a legal or similarly significant effect on a person on its own; you decide what to act on. If you are a client of a business that uses Appointer, you can object to this profiling for direct-marketing purposes by contacting that business.
[AI-PROVIDER TERMS — PENDING LEGAL REVIEW] The AI provider's processing region, data-retention period, and its commitment not to use your data to train its models are governed by our agreement with the provider. The confirmed wording [REGION / RETENTION / NO-TRAINING TERMS TO BE CONFIRMED] will be stated here before these features are enabled for your account.
7. Payments
When you take deposits or payments from your clients, card processing is handled by your connected payment provider — plata by mono, LiqPay or Stripe — under a merchant arrangement tied to your business. Funds settle directly to your account; Appointer never holds or receives your clients' money and never sees full card details. We store only payment metadata (amount, status, and the processor's reference) so the payment can be shown against the right booking. Card details are handled by the processor under its own privacy terms. Your Appointer subscription itself is billed via plata by mono (monobank acquiring): we store only an encrypted card token issued by mono — never your card number.
8. Analytics
We use PostHog (EU-hosted) for product analytics, so we can understand how features are used and fix usability problems. Each surface is treated differently. On the marketing site, analytics is cookieless and anonymous — page counting that stores nothing on your device. In the admin app, analytics (including session replay) runs for signed-in account holders with input masking — text you type into fields (such as client names, notes, and any payment inputs) is masked and not captured. On public booking pages, analytics only runs after the visitor accepts a consent banner, is limited to booking-funnel steps, and session replay is excluded entirely — your clients making a booking are never recorded.
9. Cookies
We use a small set of first-party cookies: session cookies for sign-in, a support cookie used only when you ask us to troubleshoot your account, and a language-preference cookie. Product analytics may set its own cookies where enabled. See our Cookies policy for the full list.
10. Your rights
Under GDPR you have the right to:
- Access — see what we have about you.
- Correct — fix any inaccuracies.
- Delete — have your data permanently removed.
- Port — export your data in a machine-readable format.
- Object — to certain processing.
Account holders can export their data and delete their account from the app. If you are a client of a business that uses Appointer, that business controls your data — they can export or erase your record from within Appointer, and we will help them do so. To exercise any right, contact the business you booked with, or reach us via our contact page and we'll route it correctly. We respond within 30 days.
11. Data retention
We keep account data while your subscription is active and for 30 days after you close your account, then permanently delete it. Backups roll off after 30 additional days. Logs are kept for 90 days.
12. Security
All traffic is encrypted in transit, passwords are stored hashed, access to production data is role-based and audit-logged, and we keep regular encrypted backups. See our Security page for the full picture.
13. International transfers
Some of our sub-processors may process data outside your country. Where personal data leaves the EU/EEA, we rely on GDPR safeguards such as Standard Contractual Clauses. This includes our AI provider (Anthropic) when you use an AI feature; its processing region and transfer safeguards [AI-PROVIDER REGION / TRANSFER TERMS TO BE CONFIRMED — PENDING LEGAL REVIEW] will be confirmed here before those features are enabled. Details about processing locations are available on request.
14. Children
Appointer is not directed to anyone under 18. We don't knowingly collect data from children. If you believe we have, please contact us.
15. Changes
Material updates to this policy are notified by email at least 30 days in advance.
16. Contact
For any privacy question or request, email support@appointer.co or reach us via our contact page — it goes straight to the team.