Skip to content

Privacy Policy

Effective Date: July 24, 2026 · Last updated: July 24, 2026

This Privacy Policy explains how Lumooly ("Lumooly", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use our appointment scheduling platform at lumooly.com and related applications, public booking pages, and integrations (together, the "Service").

By using the Service, you acknowledge that you have read and understood this Privacy Policy. Our Terms & Conditions also apply to your use of the Service.


1. Who we are

The Service is operated under the brand Lumooly. We do not yet have a registered company office published on this page; legal entity details will be updated here when available.

2. Definitions

  • Operator (User) — a person or business that creates an account to run schedules, team, services, and appointments (for example, a salon, clinic, or studio owner or staff member).
  • Client — an end customer who books an appointment with an Operator through a public booking page or related tools. Clients do not need a Lumooly account.
  • Product / Location — a business location or workspace configured by an Operator inside the Service.
  • Personal data — information that identifies or can reasonably identify a natural person.

3. Roles: controller and processor

Lumooly is a multi-tenant platform. How we treat personal data depends on whose data it is:

  • Operator account data — We act as data controller for data about Operators (for example, account registration, authentication, support, security, and optional marketing to Operators who opt in).
  • Client data — When Operators use the Service to collect and manage Client information (bookings, names, phone numbers, emails, appointment history), the Operator is the data controller and Lumooly acts as a data processor on the Operator's behalf to provide the Service.

Operators are responsible for having a lawful basis to process Client data, for informing Clients about how their data is used, and for handling Client requests that relate to the Operator's own business relationship with those Clients. We process Client data only to operate the platform features Operators enable (scheduling, notifications, calendar sync, and related functionality).

4. Data we collect

4.1 Operator (account) data

When you register or use the Service as an Operator, we may collect:

  • Full name — to identify you in the account, team, and appointment contexts.
  • Email address — for authentication, verification, support, and service communications.
  • Password — stored only in a securely hashed form when you sign up with email (not used when you sign in only with Google).
  • Business and operational data — such as location settings, services, working hours, team members, appointments, and related configuration you create in the Service.
  • Invitation data — email addresses of people you invite to join your team.

If you sign in with Google OAuth, we receive your name and email (and related basic profile identifiers) from Google. We do not receive or store your Google password. Optional Google Calendar data is described in Section 8.

4.2 Client data (processed for Operators)

When a Client books through an Operator's public booking page, or when an Operator adds a customer in the dashboard, we process on the Operator's behalf:

  • Name
  • Phone number — used as the primary identifier for a Client within a Location (to find and group appointments)
  • Email address — when provided, for booking confirmations and related notices
  • Appointment details — service, time, staff, status, and related booking history

Clients do not create a Lumooly account. Their relationship for the underlying service (haircut, consultation, class, etc.) is with the Operator, not with Lumooly.

4.3 Technical and usage data

  • Log and security data such as IP address, device/browser type, timestamps, and request metadata needed to operate and secure the Service.
  • Diagnostic information from error monitoring (see Section 9).
  • Cookies and similar technologies as described in Section 13.

5. How we use your data

We use personal data to:

  • Create and manage Operator accounts and team access.
  • Provide scheduling, booking, modification, cancellation, and related calendar features.
  • Send transactional emails (account verification, password reset, appointment confirmations, booking notices, invitations).
  • Sync appointments to Google Calendar when an Operator connects that integration (Section 8).
  • Provide customer support and respond to inquiries.
  • Maintain security, prevent abuse, and troubleshoot issues.
  • Send product tips or newsletters to Operators who opt in to marketing communications.
  • Improve the Service using aggregated or diagnostic information where appropriate.

We do not sell, rent, or share personal data with third parties for their own marketing, advertising, or data brokerage purposes.

7. Emails, notifications, and SMS

7.1 Transactional emails

We send emails that are necessary to operate the Service, including:

  • Account verification and security messages for Operators who signed up with email.
  • Password reset and invitation emails.
  • Appointment confirmations, updates, and related notices to Clients (when an email is available) and to Operators/staff about new or changed bookings.

These are not marketing messages. You cannot opt out of essential transactional emails while using the related features.

7.2 Marketing emails

We may send product tips, feature updates, or newsletters to Operators who opt in. You can unsubscribe at any time using the link in those emails or by contacting us. We do not send marketing emails to Clients on our own behalf.

7.3 SMS (planned)

We plan to offer appointment-related SMS notifications (for example, confirmations or reminders). Client phone numbers are already stored to identify appointments. When SMS is enabled for a Location:

  • Messages will be limited to appointment and service lifecycle communications unless you clearly enable something else.
  • Operators remain responsible for any Client consent required under local law for SMS.
  • Message and data rates may apply; delivery depends on carriers and third-party SMS providers we engage as subprocessors.

This Policy will be updated with provider details when SMS goes live if material new processing is introduced.

8. Google user data

This section describes how we access, use, store, share, and protect data received from Google APIs. It applies when you use Google Sign-In and/or the optional Google Calendar integration.

8.1 Data access (what we access)

Depending on the features you enable, we may access:

  • Google Sign-In (basic profile) — your Google account identifier, name, and email address. Used only to create or authenticate your Lumooly account. Scopes: openid, userinfo.email, userinfo.profile.
  • Google Calendar (optional integration) — after you explicitly connect the integration in Settings → Integrations, we request permission to create, read, update, and delete events on your primary Google Calendar via the calendar.events scope. We use this access to write appointment and class events that you manage in Lumooly, including event title, description, start/end time, time zone, recurrence rules (for series), and attendee email addresses of Clients associated with those bookings when applicable. We do not use Calendar access to read your full personal calendar history for unrelated purposes.
  • OAuth tokens — access and refresh tokens needed to perform the authorized Calendar actions on your behalf until you disconnect the integration or delete your account.

8.2 Data use (how we use it)

Google user data is used only to provide or improve user-facing features of the Service:

  • Authenticate you with Google Sign-In.
  • Sync Lumooly appointments and classes to the Google Calendar you connected (one-way sync from Lumooly to Google Calendar).
  • Keep those calendar events accurate when bookings are created, updated, or cancelled in Lumooly.
  • Troubleshoot and maintain the reliability of the integration.

We do not use Google user data for targeted advertising, personalized ads, credit decisioning, or lending. We do not use Google Workspace or Calendar user data to develop, improve, or train generalized AI/ML models.

8.3 Data transfer and sharing

We share Google user data only as needed to operate the features you request:

  • Google — receives OAuth requests and Calendar API calls you authorize (including event content and attendee emails written to your calendar).
  • Infrastructure providers — host encrypted application data, including stored OAuth tokens and Google event identifiers, under our instructions.
  • Email delivery provider — may process email addresses for transactional messages related to the Service (not for marketing of Google data).

We do not sell or transfer Google user data to data brokers, advertising platforms, or other third parties for purposes unrelated to providing or improving the Service. We do not transfer Google Calendar or Workspace user data to third-party AI/ML services for model training.

8.4 Data protection

We protect Google user data with technical and organizational measures appropriate to the sensitivity of the data, including:

  • HTTPS/TLS for data in transit.
  • Access controls limiting production data access to authorized personnel who need it to operate the Service.
  • Storage of OAuth tokens in our application database, accessible only through authenticated server-side processes.
  • Least-privilege OAuth scopes: sign-in requests only basic profile scopes; Calendar scopes are requested only when you connect the integration.

8.5 Retention and deletion

  • While connected — we retain Google OAuth tokens and Google event identifiers as long as the Calendar integration remains connected and your account is active, so we can continue syncing.
  • Disconnect — when you disconnect Google Calendar in Settings → Integrations, we delete the stored Google OAuth tokens for that connection from our systems. Events already created in your Google Calendar remain in Google Calendar unless you delete them there or cancel the related bookings in Lumooly before disconnecting (while still connected, cancellations remove the corresponding Google events).
  • Account deletion — if you delete your Lumooly account, we delete or anonymize personal data associated with the account, including Google OAuth tokens and stored Google event identifiers, within 30 days, unless a longer retention period is required by law.
  • Your Google account controls — you may also revoke Lumooly's access at any time from your Google Account permissions page. After revocation, sync stops; you should also disconnect the integration in Lumooly so local tokens are removed.

8.6 Limited Use compliance

Lumooly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve user-facing features of the Service, is not sold, and is not used for serving advertisements.

9. Third-party services and sharing

We use trusted service providers (subprocessors) to run the Service. They process data only under our instructions and for the purposes described here:

  • Google OAuth and Google Calendar API — authentication and optional calendar sync. Also governed by Google's Privacy Policy.
  • Email delivery provider — to send transactional (and, if you opt in, marketing) emails. Providers process email addresses and message content solely to deliver mail on our behalf (for example, services such as Brevo or comparable SMTP providers).
  • Cloud hosting (EU/EEA) — servers and related infrastructure that store and process Service data under contractual confidentiality and security obligations.
  • Error monitoring (Sentry) — may receive diagnostic data such as IP address, browser information, and error context (which can occasionally include user identifiers) to help us detect and fix failures. We configure this tooling to minimize personal data where practical.
  • SMS provider (when enabled) — will process phone numbers and message content only to deliver appointment-related SMS.

We may also disclose data if required by law, court order, or to protect the rights, safety, or security of Lumooly, our users, or others. We do not use advertising networks or sell data to brokers.

10. International transfers

We aim to store primary application data in the European Union / EEA. Some subprocessors (for example, global cloud, email, or monitoring vendors) may process data in other countries. Where personal data is transferred outside the EEA (or your country of residence), we rely on appropriate safeguards available under applicable law, such as the provider's standard contractual clauses or other lawful transfer mechanisms.

11. Storage and security

We implement technical and organizational measures appropriate to the risk, including:

  • Password hashing using industry-standard algorithms.
  • Encrypted connections (HTTPS/TLS) for data in transit.
  • Access controls limiting production data access to authorized personnel who need it to operate the Service.
  • Least-privilege OAuth scopes for Google integrations (Section 8).

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect your data against unauthorized access, alteration, disclosure, or destruction.

12. Data retention

  • Active accounts — we retain Operator and operational data for as long as the account is active and as needed to provide the Service.
  • Account deletion — if you delete your account, we delete or anonymize personal data associated with it within 30 days, unless a longer period is required by law (for example, limited security or dispute records).
  • Client data — retained while the Operator's Product/Location and related records exist, because we process that data as a processor for the Operator. Operators control Client records in their workspace.
  • Google-related retention — see Section 8.5.
  • Anonymized data — appointment or usage records may be retained in anonymized form for operational or statistical purposes after deletion of personal identifiers.

13. Cookies

We use strictly necessary cookies and similar technologies to maintain your session and authentication state so the Service can function. We do not use advertising cookies or third-party advertising trackers.

Error-monitoring tools (Sentry) may process technical data associated with your session for diagnostics. If we introduce analytics or marketing cookies in the future, we will update this Policy and, where required, request consent.

14. Children

The Service is intended for business Operators who are at least 18 years of age. We do not knowingly collect personal data from children for Operator accounts. If you believe we have collected data from a minor in error, contact us and we will take appropriate steps to delete it.

15. Your rights

Subject to applicable data protection law, you may have the right to:

  • Access — request a copy of personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data, subject to legal exceptions.
  • Restriction — request that we limit processing in certain circumstances.
  • Portability — receive data you provided in a structured, commonly used, machine-readable format.
  • Object — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent (for example, Google Calendar or marketing), without affecting the lawfulness of prior processing.

Operators can update much of their account information in the Service, disconnect Google Calendar, and delete their account in Settings.

Clients should first contact the Operator (business) with whom they booked, because that Operator is the controller of Client booking data. Clients may also contact us at the address below if they need help identifying the Operator or have a platform-related concern.

You may also have the right to lodge a complaint with a supervisory authority, including in the Republic of Moldova or in your place of residence or work where applicable.

16. Account deletion

Operators may delete their account from Settings in the Service (password confirmation may be required). Upon deletion:

  • We stop providing the Service for that account and begin deleting or anonymizing associated personal data within 30 days (Section 12).
  • Google OAuth tokens and stored Google event identifiers for that account are removed as described in Section 8.5.
  • Data we process solely as a processor for surviving Operator workspaces (if any) follows the controller Operator's instructions and product lifecycle.

17. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and/or a notice in the Service, and update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy, except where applicable law requires a different form of consent.

18. Contact

If you have questions about this Privacy Policy, Google user data practices, or wish to exercise your data protection rights, contact us at [email protected].