Last updated: October 2026
Alignext is an online booking platform. References to "we", "us", or "Alignext" refer to the Alignext service operator. When you use Alignext, your data may be processed both by us (as platform operator) and by the business you are booking with (as independent data controller).
We do not sell your personal data to third parties, and we do not use it to train AI models.
Processing is based on contractual necessity (Art. 6(1)(b) GDPR) — to fulfill the booking you requested — and legitimate interests (Art. 6(1)(f)) for platform security and abuse prevention.
A business's bookings, clients and sales are that business's own records: they are kept while its account exists, and the business decides what to delete. A deleted branch's data stays in the account too and is deleted together with it. A client can ask the business to delete their data earlier (see section 6). When a business deletes its account, personal data is erased within 30 days of the request (how exactly - on the Account deletion page). The periods our code keeps:
| Data | How long |
|---|---|
| A business's data (bookings, clients, sales) while its account exists | Until the business deletes it, or deletes the account |
| Our invoices and credit notes to a business, with the buyer details printed on them (name, e-mail, legal name, address) | As long as tax law requires |
| A deleted business's data without names and contacts: bookings, sales, payments, cash, fiscal receipts | 3 years from the deletion (for a branch deleted earlier - from the day that branch was deleted), then deleted completely |
| The activity log in the business dashboard | 12 months |
| Server logs | 30 days in our log system; a small buffer on the server itself has no set period - newer entries push out older ones as it fills up, so it can hold older ones |
| Error reports | Up to 90 days |
| Events for integrations (webhooks, API) | 60 days, once they have been processed |
| Webhook delivery records | 30 days after the delivery ends |
| Stored API replies (for safe retries of a request) | 24 hours |
| One-time links for connecting Telegram | 30 days after they expire |
| Background jobs with their data | Up to 7.5 days after they run; a job that never runs - up to 21 days |
| Our Google or Apple token queued for revoking after a deletion | Until it is revoked; if every attempt fails, it stays encrypted until we retry by hand |
| Database backups | 30 days (plus the newest copy on the server itself) |
| Full server backups | 7 days |
| Our e-mail block list: addresses that unsubscribed, that mail could not be delivered to, or that reported spam (clients of businesses included) | No end date - so we never write to them again |
| A record that a deleted account existed (internal ids and dates, no personal data) | No end date |
Deleted data can remain in backups for up to 30 days. If we ever have to restore a backup, we repeat every deletion made after it, and the periods above apply again.
Under GDPR you have the right to access, correct, or erase your personal data. To exercise these rights, contact the business you booked with directly, or email us at privacy@alignext.io.
A business owner can delete their account themselves in the app or the business dashboard - what is deleted and what is kept is described on the Account deletion page. A team member whose login the owner manages can ask us to delete that login by emailing privacy@alignext.io from the address they sign in with; we answer within 30 days.
Some optional features use a third-party AI provider to help the business you booked with run its operations:
These features use a third-party AI provider located in the USA (named in our DPA). Data sent to its API is not used to train AI models and is handled under a data-processing agreement with appropriate transfer safeguards (EU Standard Contractual Clauses). Legal basis: legitimate interests (Art. 6(1)(f) GDPR) of the business to operate and improve its services. We never use one business's data for the benefit of another.
On our website (alignext.io) we use Google Analytics 4 and the Meta (Facebook) Pixel and Conversions API to understand how visitors use our marketing pages and to measure our advertising. These run only on our public marketing pages (not inside the booking widget or the business dashboard) and only after you accept cookies — you can decline in the cookie banner, and no analytics or advertising data is collected if you do.
Inside the business dashboard we use Microsoft Clarity for product analytics (session recordings and heatmaps) to see where the interface is confusing and improve it. Recordings are anonymized: all text and input fields are masked, so neither your personal data nor your clients' data appears in them. You can turn this off at any time under Settings → Profile → Features. Data is processed by Microsoft under Standard Contractual Clauses (SCC).
When enabled, we share limited data with Google and Meta acting as our processors: interaction/usage events, your IP address, device and browser information, and — when you create an account — a hashed (pseudonymised) version of your email address for conversion measurement. Google and Meta are located in the USA; transfers are made under EU Standard Contractual Clauses.
Legal basis: your consent (Art. 6(1)(a) GDPR / ePrivacy). You can withdraw consent at any time by rejecting cookies. For how Google and Meta process this data, see Google's policy and Meta's policy.
We rely on a small set of vetted processors to run the service. Each is bound by a data-processing agreement, and any transfers outside the EEA are made under EU Standard Contractual Clauses:
A current, named list of our sub-processors (with locations and transfer mechanisms) is available to our business customers in our Data Processing Agreement.
If a business connects a Google Calendar - the owner's, a branch's or a master's - Alignext asks for the Google Calendar (calendar.events) permission and the Google account's address (openid, email) to (a) create, update and delete calendar events that mirror its Alignext bookings, and (b) read event changes to keep bookings in two-way sync. In a master's calendar we also read their own events, so clients are not booked into time they are busy. We access only the connected calendar.
We store: an encrypted refresh token; the address of the connected Google account - to tell connections of the same account apart; the Google event identifiers; and for masters' calendars the time and titles of their own events, which become busy time. The events we create in the calendar carry the booking details: service and price, time, master, the branch and its address, status, the client's name and contacts, notes and booking form answers; course events list the names of everyone booked.
This data is used solely to provide the calendar-sync feature; it is never sold, never used for advertising or to train AI models, and is not shared with other businesses.
You can disconnect the integration at any time from the business dashboard (the "API & Webhooks" page), and a master can disconnect their own calendar in their own account. We then stop the sync and delete the token, the address, the event identifiers and the busy time. We revoke our access at Google only when we are sure that Google account is no longer connected to Alignext anywhere: Google gives one permission per account, and revoking it would cut the other connections too. So the access stays if the same account is connected somewhere else, or if any connection in Alignext has no Google account address - some older connections, made before we started asking for the address, have none. We revoke with a single request: if Google does not answer at that moment, the access stays too. In each of these cases you can remove Alignext's access yourself in your Google Account settings. Events we already created stay in your calendar: neither disconnecting nor deleting your Alignext account removes them.
Alignext's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The Alignext app for iOS and Android is for business owners and their teams. The bookings, clients, payments and schedules you manage in the app are processed the same way as in the business dashboard. In addition, the app processes:
The app shows no ads, does not use the advertising ID and does not track you across other apps or websites. An owner can delete the business account in the app (Settings → Delete account) or in the business dashboard (the "Privacy & Data" page) - see Account deletion; for any other app data, email privacy@alignext.io.
Questions about this policy: privacy@alignext.io