Ugrás a tartalomhoz

Privacy Policy

Effective date: April 21, 2026
Last updated: May 14, 2026

This Privacy Policy explains how Foglaljszepseget Kft. collects, uses, stores, shares and protects personal data when users access the FoglaljSzepseget.hu website, web application and related services. This English version includes Google OAuth and Google Calendar disclosures and is provided to make our data practices clear to international users and reviewers. The Hungarian version is available at /adatvedelmi-szabalyzat.

In Plain Language

  • We process your data to manage bookings, accounts, payments, notifications and the operation of the service.
  • We do not store bank card details.
  • We process Google Calendar data only if you connect your calendar as a service provider.
  • We do not sell Google Calendar data, use it for advertising, or share it with other providers or clients.
  • You may request deletion of your account at any time, but some billing or legal records may have to be retained.

1. Data Controller

Controller: Foglaljszepseget Kft.
Registered office: 2461 Tarnok, Szolohegyi ut 10., Hungary
Company registration number: 13-09-246845
Tax number: 33038935-1-13
Email: info@foglaljszepseget.hu
Phone: +36 30 422 2018
Website: https://www.foglaljszepseget.hu

2. Scope

This Policy applies to visitors, registered clients, service providers, provider staff, newsletter subscribers, purchasers of vouchers or passes, and users who contact our support team.

Service providers listed on the platform may also act as independent data controllers for their own services, customer communication, accounting, legal obligations and marketing activities.

3. Data We Collect

  • Account and login data, such as name, email address, phone number, account identifiers and authentication data.
  • Provider profile data, such as business details, contact details, service descriptions, opening hours, prices, images and billing details.
  • Booking data, such as client name, email address, phone number, appointment time, selected service, price, booking status and notes.
  • Payment and transaction data, such as payment status, amount, transaction identifiers and billing data. We do not store full card details.
  • Voucher and pass data, such as purchaser details, recipient details, value, validity and redemption status.
  • Reviews, support messages, technical logs, device data, cookie identifiers and consent records.

4. How We Use Data

  • To provide accounts, bookings, provider profiles, payments, vouchers, passes and customer support.
  • To send transactional emails, reminders, booking confirmations and service-related notifications.
  • To operate, secure, maintain and improve the platform.
  • To comply with legal, accounting, tax, consumer protection and dispute-resolution obligations.
  • To send marketing communications only where we have a valid legal basis, such as consent.

5. Google OAuth and Google Calendar Data

Providers may choose to connect their own Google Account and Google Calendar to FoglaljSzepseget.hu. This integration is optional and is used only to synchronize provider appointments and to help calculate bookable availability.

When a provider connects Google Calendar, we may collect and process the Google Account identifier or email address, OAuth access and refresh tokens, the selected calendar identifier, Google Calendar event identifiers, event times, event titles and statuses, and free/busy availability intervals needed for appointment scheduling.

We use this Google user data only to create, update or delete appointment events in the connected Google Calendar, refresh the Google Calendar connection, display synchronization status to the connected provider, and prevent bookings from conflicting with existing busy times.

Sharing, transfer and making Google user data accessible

We do not sell, rent, disclose or transfer Google user data for advertising, retargeting, profiling, credit-worthiness, data broker, information resale, unrelated commercial, or AI model training purposes.

We may share, transfer or disclose Google user data only with the following recipients and only to the extent necessary for the stated purposes:

  • Google Ireland Limited / Google LLC: to perform OAuth authorization, token refresh and Google Calendar API operations requested by the connected provider.
  • Infrastructure and backend providers: such as Supabase and Vercel, which provide database, authentication, hosting and server-side infrastructure for the platform. They may process data only to operate the platform and under contractual data protection obligations.
  • The connected provider admin interface: to show calendar connection and synchronization status related to bookings of that provider. Other providers and clients do not receive access to the connected Google Calendar contents.
  • Authorities, courts or legal advisers: only where required by law, binding request, legal proceedings, security incident handling or legal claims.

We do not make the connected Google Calendar public. Free/busy information is used only as time intervals needed to calculate availability and is not shared with advertising partners.

Access tokens and refresh tokens are stored with restricted access and used only to operate the Google Calendar integration. Providers can disconnect the integration at any time from the platform or from their Google Account security settings. After disconnection, we stop performing Google Calendar operations and delete or invalidate the tokens needed for the connection, unless temporary retention is required for security, debugging or legal purposes.

Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

6. Service Providers and Recipients

We may use external service providers or disclose personal data to recipients where necessary to operate the platform, provide requested services or comply with law.

ProviderRoleActivityNature of data transfer
Supabaseprocessordatabase, authentication, backend infrastructureaccount, booking and technical data
Vercelprocessorhosting, application infrastructuretechnical and log data
Stripe Payments Europe, Ltd.independent controller / payment service provider with processor-like functionsonline payments, transaction processing, refundstransaction and payment status data; the platform does not store card details
Resendprocessortransactional email deliveryemail address, notification data
Brevoprocessornewsletter delivery and marketing communication where usedname, email address, marketing preferences
Sentryprocessorerror monitoring, performance monitoring, incident handlingtechnical logs, error messages, device and browser data
Billingo Technologies Zrt.processor / independent controller depending on the functioninvoicing and invoice management where usedbilling data
Google Ireland Limited / Google LLCindependent controller or processor depending on the serviceOAuth, Calendar, Maps/Places, Analytics, Ads, Firebase Cloud MessagingGoogle integration, location, analytics, marketing measurement, push notification and technical data
Meta Platforms Ireland Limitedindependent controller / marketing and analytics provider with processor-like functionsMeta Pixel and Conversions API analytics and marketing measurementtechnical, analytics and marketing measurement data according to cookie consent and provider settings
TikTok Technology Limited / TikTok Information Technologies UK Limitedindependent controller / marketing and analytics provider with processor-like functionsTikTok Pixel and Events API analytics and marketing measurementtechnical, analytics and marketing measurement data according to cookie consent and provider settings

Where required for platform operation, we may also use additional hosting, backup, security, error monitoring, analytics, push notification, support or other technical providers. We disclose data to authorities, courts, accountants and legal advisers only where required by law, an authority request or legal claims.

Detailed rules on sharing, transferring and making Google user data received from Google APIs accessible are set out in Section 5 of this Privacy Policy.

7. International Transfers

Some providers may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards such as European Commission adequacy decisions, standard contractual clauses and additional technical or organizational measures where required.

8. Retention

  • Account data is kept while the account exists, unless legal obligations or legitimate interests require longer retention.
  • Booking data is generally kept for 5 years from the appointment date for legal claim management.
  • Accounting and invoice data is generally kept for 8 years under Hungarian accounting rules.
  • Support and complaint data is generally kept for 2 to 5 years, depending on the nature of the case.
  • Technical logs are generally kept for up to 12 months unless a security incident or dispute requires longer retention.
  • Google Calendar tokens are kept only while the integration is active and are deleted or invalidated after disconnection.

9. Security

We use technical and organizational measures designed to protect personal data, including encrypted transmission, access controls, authentication, logging, backups, provider access restrictions, incident handling procedures and contractual safeguards with processors.

10. Your Rights

Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction, portability, objection to processing and withdrawal of consent. You can submit requests at info@foglaljszepseget.hu. We may need to verify your identity before fulfilling a request.

11. Complaints

You may contact us first at info@foglaljszepseget.hu. You also have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), website: https://www.naih.hu.

12. Changes

We may update this Privacy Policy if our services, legal obligations, providers or data practices change. The updated version becomes effective when published on the platform, unless a different date is stated.