Privacy Policy

Last updated: October 2026

1. Who we are

Alignext is an online booking platform. References to "we", "us", or "Alignext" refer to the Alignext service operator. When you use Alignext, your data may be processed both by us (as platform operator) and by the business you are booking with (as independent data controller).

2. What data we collect

  • Booking data: name, email, phone number provided when booking an appointment.
  • Reviews: the rating, comment and display name you provide after a visit. The display name and comment are published on the business page.
  • Account data: email and password for business accounts.
  • Subscription billing: our invoices to the business and, when it pays by card, the bank's card token and the masked card number (first and last digits). We never see the full card number.
  • Usage data: timestamps and basic logs necessary for service operation.
  • Mobile app: notification token, installation identifiers, crash diagnostics, photos and support chat (see section 11).
  • Cookies: necessary session cookies to run the service, and — only with your consent — analytics and advertising cookies (see section 8).

3. How we use your data

  • To send booking confirmations and reminders.
  • To allow the business to manage their appointments.
  • To provide and maintain the platform.
  • To provide optional AI-assisted features to the business (see section 7).

We do not sell your personal data to third parties, and we do not use it to train AI models.

4. Legal basis (GDPR)

Processing is based on contractual necessity (Art. 6(1)(b) GDPR) — to fulfill the booking you requested — and legitimate interests (Art. 6(1)(f)) for platform security and abuse prevention.

5. Data retention

A business's bookings, clients and sales are that business's own records: they are kept while its account exists, and the business decides what to delete. A deleted branch's data stays in the account too and is deleted together with it. A client can ask the business to delete their data earlier (see section 6). When a business deletes its account, personal data is erased within 30 days of the request (how exactly - on the Account deletion page). The periods our code keeps:

DataHow long
A business's data (bookings, clients, sales) while its account existsUntil the business deletes it, or deletes the account
Our invoices and credit notes to a business, with the buyer details printed on them (name, e-mail, legal name, address)As long as tax law requires
A deleted business's data without names and contacts: bookings, sales, payments, cash, fiscal receipts3 years from the deletion (for a branch deleted earlier - from the day that branch was deleted), then deleted completely
The activity log in the business dashboard12 months
Server logs30 days in our log system; a small buffer on the server itself has no set period - newer entries push out older ones as it fills up, so it can hold older ones
Error reportsUp to 90 days
Events for integrations (webhooks, API)60 days, once they have been processed
Webhook delivery records30 days after the delivery ends
Stored API replies (for safe retries of a request)24 hours
One-time links for connecting Telegram30 days after they expire
Background jobs with their dataUp to 7.5 days after they run; a job that never runs - up to 21 days
Our Google or Apple token queued for revoking after a deletionUntil it is revoked; if every attempt fails, it stays encrypted until we retry by hand
Database backups30 days (plus the newest copy on the server itself)
Full server backups7 days
Our e-mail block list: addresses that unsubscribed, that mail could not be delivered to, or that reported spam (clients of businesses included)No end date - so we never write to them again
A record that a deleted account existed (internal ids and dates, no personal data)No end date

Deleted data can remain in backups for up to 30 days. If we ever have to restore a backup, we repeat every deletion made after it, and the periods above apply again.

6. Your rights

Under GDPR you have the right to access, correct, or erase your personal data. To exercise these rights, contact the business you booked with directly, or email us at privacy@alignext.io.

A business owner can delete their account themselves in the app or the business dashboard - what is deleted and what is kept is described on the Account deletion page. A team member whose login the owner manages can ask us to delete that login by emailing privacy@alignext.io from the address they sign in with; we answer within 30 days.

7. AI-assisted features

Some optional features use a third-party AI provider to help the business you booked with run its operations:

  • Business insights — we send aggregated statistics (such as the number of bookings per service or per staff member) to generate plain-language summaries for the business owner. Client contact details (name, email, phone) are not sent.
  • Draft messages — when an owner requests it, we send the business name and a short prompt they type to generate a draft marketing email. Client contact details are not sent; any personalisation (e.g. the recipient's first name) is added by our platform afterwards, not by the AI.

These features use a third-party AI provider located in the USA (named in our DPA). Data sent to its API is not used to train AI models and is handled under a data-processing agreement with appropriate transfer safeguards (EU Standard Contractual Clauses). Legal basis: legitimate interests (Art. 6(1)(f) GDPR) of the business to operate and improve its services. We never use one business's data for the benefit of another.

8. Analytics & advertising

On our website (alignext.io) we use Google Analytics 4 and the Meta (Facebook) Pixel and Conversions API to understand how visitors use our marketing pages and to measure our advertising. These run only on our public marketing pages (not inside the booking widget or the business dashboard) and only after you accept cookies — you can decline in the cookie banner, and no analytics or advertising data is collected if you do.

Inside the business dashboard we use Microsoft Clarity for product analytics (session recordings and heatmaps) to see where the interface is confusing and improve it. Recordings are anonymized: all text and input fields are masked, so neither your personal data nor your clients' data appears in them. You can turn this off at any time under Settings → Profile → Features. Data is processed by Microsoft under Standard Contractual Clauses (SCC).

When enabled, we share limited data with Google and Meta acting as our processors: interaction/usage events, your IP address, device and browser information, and — when you create an account — a hashed (pseudonymised) version of your email address for conversion measurement. Google and Meta are located in the USA; transfers are made under EU Standard Contractual Clauses.

Legal basis: your consent (Art. 6(1)(a) GDPR / ePrivacy). You can withdraw consent at any time by rejecting cookies. For how Google and Meta process this data, see Google's policy and Meta's policy.

9. Categories of service providers

We rely on a small set of vetted processors to run the service. Each is bound by a data-processing agreement, and any transfers outside the EEA are made under EU Standard Contractual Clauses:

  • Hosting — EU/EEA data centres.
  • Email delivery — EU/EEA.
  • Content delivery network — EU/global edge.
  • Error monitoring - data stored in the EU (Germany); the provider is a US company, so any remote access from outside the EEA is covered by SCCs.
  • App push notifications (Google Firebase Cloud Messaging, Apple Push Notification service) - outside the EEA, under SCCs; only the device token and the notification text (see section 11).
  • AI-assisted features — outside the EEA, under SCCs; API data is not used to train AI models.
  • Analytics & advertising (Google, Meta) — outside the EEA, under SCCs; only with your consent (see section 8).
  • Calendar sync (Google Calendar) — only if a business connects it; access limited to the connected calendar (see section 10).

A current, named list of our sub-processors (with locations and transfer mechanisms) is available to our business customers in our Data Processing Agreement.

10. Google Calendar integration

If a business connects a Google Calendar - the owner's, a branch's or a master's - Alignext asks for the Google Calendar (calendar.events) permission and the Google account's address (openid, email) to (a) create, update and delete calendar events that mirror its Alignext bookings, and (b) read event changes to keep bookings in two-way sync. In a master's calendar we also read their own events, so clients are not booked into time they are busy. We access only the connected calendar.

We store: an encrypted refresh token; the address of the connected Google account - to tell connections of the same account apart; the Google event identifiers; and for masters' calendars the time and titles of their own events, which become busy time. The events we create in the calendar carry the booking details: service and price, time, master, the branch and its address, status, the client's name and contacts, notes and booking form answers; course events list the names of everyone booked.

This data is used solely to provide the calendar-sync feature; it is never sold, never used for advertising or to train AI models, and is not shared with other businesses.

You can disconnect the integration at any time from the business dashboard (the "API & Webhooks" page), and a master can disconnect their own calendar in their own account. We then stop the sync and delete the token, the address, the event identifiers and the busy time. We revoke our access at Google only when we are sure that Google account is no longer connected to Alignext anywhere: Google gives one permission per account, and revoking it would cut the other connections too. So the access stays if the same account is connected somewhere else, or if any connection in Alignext has no Google account address - some older connections, made before we started asking for the address, have none. We revoke with a single request: if Google does not answer at that moment, the access stays too. In each of these cases you can remove Alignext's access yourself in your Google Account settings. Events we already created stay in your calendar: neither disconnecting nor deleting your Alignext account removes them.

Alignext's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

11. The Alignext mobile app

The Alignext app for iOS and Android is for business owners and their teams. The bookings, clients, payments and schedules you manage in the app are processed the same way as in the business dashboard. In addition, the app processes:

  • Notification token and installation identifiers. On start, the Android app obtains a device token and an installation identifier from Google (Firebase Cloud Messaging); the iOS app obtains a token from Apple. When you allow notifications, we store the token with the platform, app version and language to send you booking notifications; once you sign out, the token is no longer used. The notification text (booking time, branch, service, client name) is delivered by Google or Apple.
  • Crash diagnostics. When the app crashes or hits an error, our error-monitoring service (data stored in the EU) receives a report: device model, OS and app version, a random installation identifier, an approximate location (country, region, city) derived from the connection's IP address, and the last actions in the app before the error (taps, screen changes, the addresses of requests to our server and their results). We do not add your name or email to these reports. They are used only to find and fix bugs.
  • Barcode scanning. At checkout the camera can read a gift card code; those frames are not stored or sent anywhere. Recognition runs on the device; in the Android version it runs through Google ML Kit, which sends Google technical diagnostics (an installation identifier, app version, performance, error codes).
  • Photos. Photos a business uploads to its work gallery, cover or banner (from the phone's gallery or taken with the camera) are stored in our EU storage and shown on that business's public pages. Photos sent in the support chat are seen only by our support team.
  • Support chat. Your messages and attachments, plus your name, email and account identifier so we know who we are talking to. The chat runs on our own server.

The app shows no ads, does not use the advertising ID and does not track you across other apps or websites. An owner can delete the business account in the app (Settings → Delete account) or in the business dashboard (the "Privacy & Data" page) - see Account deletion; for any other app data, email privacy@alignext.io.

12. Contact

Questions about this policy: privacy@alignext.io

Privacy Policy | Alignext