Skip to content

How we use your data

This page describes what actually happens on nakobook.com today, not what we intend to do. It changes as the product does.

Who is responsible

Nakoagency, the operator of the Nakobook platform. For anything about your data, write to contact@nakobook.com — we answer within 30 days at most.

Who is responsible for what when you book

There are two of us, with different roles. The salon decides what it needs in order to see you, and what it does with that afterwards — the salon is the controller. Nakobook keeps the schedule, sends the emails and stores the rows in the database on the salon's instructions — we are the processor. In practice: a request to delete or correct appointment data is decided by the salon and carried out by us. If you are not sure who to ask, write to contact@nakobook.com and we will put you in touch with the salon.

The waiting list

When you sign up we keep: your email address, the industry you selected, the language you browsed in, and a fingerprint of your IP address (SHA-256 with a secret key, so it cannot be turned back into the real address). The purpose: to tell you when we launch; the IP fingerprint only limits automated sign-ups. The basis: your consent, given by submitting the form.

When you book at a salon

We keep exactly what you filled in: your name, phone number and/or email address (at least one of them, so the salon can reach you), the service, the location, the staff member and the time. Plus the proof of your consent — when you gave it and which version of this page you agreed to. The reminders-and-offers box is separate and optional; if you leave it unticked you only get messages about your own appointment. The free-text field “Anything the salon should know” reaches the salon exactly as you wrote it: please do NOT put diagnoses, treatments or other health data there — that is sensitive data (art. 9 GDPR), we do not ask for it and we build nothing on it. At the end you get a management link that lets you move or cancel the appointment without an account: that link is a key, so do not pass it on. We do not store the link itself, only a fingerprint of it, and it expires after 60 days. Legal basis: preparing and carrying out the appointment you asked for. On your own device, the browser remembers your form choices for 24 hours so you do not start over; your contact details are kept for 90 days ONLY if you tick that box yourself, and the button on the page deletes them.

How long we keep it

Waiting list: until launch plus at most 12 months, or until you ask us to delete it — whichever comes first. Appointment data is kept by the salon for as long as it needs it, and we delete it at the salon's request or at yours through the salon; the management link expires after 60 days in any case. We send nothing beyond what is described above and we give your address to nobody.

The tools we use

Sentry receives the site's technical errors so we can fix them; that can include the page address and the browser type. The address of the management page contains your key, so we strip it out of the event before it leaves — Sentry gets the path, without the key. PostHog counts usage events (for example, that the form was submitted) without tying the event to your identity. So that nobody can fill a salon's diary with a script, we cap requests: your IP address is held for one minute, purely as a counting key, at our cache provider (Upstash). Resend sends the emails about your appointment and sees their address and content. All of them are suppliers processing on our behalf.

What you can ask for

To see what we hold about you, to correct it, to have it deleted, or to withdraw your consent. One address for all of it: contact@nakobook.com. You may also complain to your data protection authority.

What we process NOW: your account data (email, name and, if you turn it on, two-step authentication), waiting-list sign-ups, and — since online booking opened — the data of your appointments at salons that use Nakobook. This page changes as the product does: if a new capability brings new data, the text is rewritten BEFORE it goes to production, not after.