Booking Hub · Interim · v2026-08-11-eu
Privacy notice
How the Booking Hub Romania/EU pilot handles Operator and Fan personal data under GDPR and Romanian Law 190/2018, plus cookies under Law 506/2004. Transparency for a small invite-only pilot — not counsel-signed. A formal policy naming the registered SRL will replace this when ready. English controls.
RO: Document interimar pentru pilot. Până la o traducere oficială, versiunea în limba engleză prevalează. Legea aplicabilă: România.
← Home · Terms · Privacy · Report abuse
Who this notice covers
This interim privacy notice explains how Booking Hub handles personal data during the invite-only pilot operated by the natural person operating Booking Hub pending Romanian SRL incorporation. It applies to (1) invited Operators who sign in with Google, and (2) Fans who submit a public booking form. It aims to meet the transparency requirements of GDPR Articles 12–14 and Romanian Law no. 190/2018 for a small pilot; it is not yet counsel-signed.
When the SRL is registered, this notice will be replaced or amended with the company as named controller (and processor where applicable), including CUI and registered office.
Roles (GDPR framing)
Fan booking data collected on an Operator’s public /book page: the Operator is typically the controller of that Fan relationship (they decide what fields to require and how to fulfil the session). Booking Hub acts as a processor / service provider hosting and transmitting booking data on the Operator’s instructions implemented in the product.
Operator account data (Google sign-in identifiers, memberships, hub settings, sealed calendar tokens): the pilot operator is the controller, processing that data to provide access and run the Platform.
A written Data Processing Agreement (DPA) and full Records of Processing will be published when the SRL exists and the product leaves pure pilot status. Until then, this notice + product behaviour are the instructions Operators rely on.
Fan data on /book
Depending on hub settings, a booking may include name, email, phone, locale, chosen service and slot, custom form answers, technical metadata used for abuse protection (the IP address behind rate limits, which we store only as a salted hash), and CAPTCHA verification outcomes. Purposes: create and manage the booking, send confirmation/reconfirm messages when enabled, create calendar events when the Operator connected Google Calendar, prevent spam/abuse, and display the booking to the Operator.
Legal bases (typical): performance of a contract or steps prior to contract between Operator and Fan (Art. 6(1)(b) GDPR) as reflected in the booking request; legitimate interests in securing the service (Art. 6(1)(f)); Operator responsibility for any consent they choose to collect beyond that.
Operator account data
Sign-in uses Google OAuth (Auth.js). We store account identifiers needed for access (such as email, name, image URL if provided, and membership/role). Calendar connections store sealed tokens so the hub can create events. Hub configuration (services, availability, flags, gallery URLs you paste) is stored to run your workspace.
Legal bases: performance of the pilot service agreement (Art. 6(1)(b)); legitimate interests in security, invite control, and abuse prevention (Art. 6(1)(f)); legal obligations when applicable (Art. 6(1)(c)).
Analytics, feature flags, and security logging
Product analytics. We use Vercel Web Analytics. It is cookieless: it does not store an identifier on your device (so it does not trigger the cookie-storage consent rule in Romanian Law no. 506/2004 / ePrivacy Art. 5(3) for device storage). The provider derives a short-lived anonymous visitor hash from request metadata and keeps aggregate traffic metrics. We use it for product quality — not advertising, profiling, or cross-site tracking — and we do not sell it or share it with ad networks. Lawful basis under GDPR: legitimate interests (Art. 6(1)(f)) in understanding aggregate use of an invite-only pilot, balanced against minimal data and no advertising use.
Custom events. Alongside page views we record a small set of product events (for example booking_created, booking_create_failed, booking_ui_blocked, booking_denied, slots_denied). They carry compact outcome or reason codes such as “rate_limit_ip” or “captcha_failed” — never Fan names, emails, phones, or form answers. A sanitizer runs before every event is sent: values under contact-like field names, and values that look like an email address, phone number, or URL, are replaced with “redacted”.
Feature flags. Evaluated feature-flag values (for example whether email confirmation or the gallery is on for a hub) are attached to page views and events so we can tell which product configuration produced a result. Flags are product switches rather than personal data, and flags that would reveal weakened abuse controls are excluded from public pages.
Security logging. Our hosting platform and its firewall record request metadata — including IP address, user agent, path, and timestamp — to detect and block scanning, scraping, and abuse (Art. 6(1)(f) GDPR). Abuse counters we keep ourselves (rate limits, per-contact booking limits) store a salted hash of the IP address or contact detail rather than the plaintext value. Cloudflare Turnstile receives the visitor IP and a CAPTCHA token to score bot traffic. Error monitoring (Sentry, where configured) runs with personal-data collection switched off, and we do not log booking form contents, access tokens, or refresh tokens.
Consent banner. We do not show a marketing-cookie consent banner today because we do not run advertising, remarketing, or other non-essential tracking cookies. If we add tools that require prior consent under Law no. 506/2004 (for example advertising pixels or analytics cookies), we will add a consent mechanism before switching them on.
Processors and international transfers
Infrastructure may include Vercel (hosting/edge and Web Analytics), Neon (Postgres), Google (sign-in / Calendar), Resend (transactional email when configured), Cloudflare Turnstile (bot protection), and Sentry (errors, if configured). Data may be processed in the EU and in third countries (for example the United States) where providers operate.
Where GDPR Chapter V applies, we rely on the providers’ appropriate safeguards (such as Standard Contractual Clauses and supplementary measures they document). Ask us if you need the current subprocessors list for a specific hub.
Retention
Bookings and form answers are kept while the hub needs them for scheduling history and dispute context, and for a reasonable period after cancellation/expiry of holds, unless you delete data earlier via product tools or a verified request.
Operator accounts are kept while the invite/hub remains active. Security and rate-limit records are kept for short operational windows: rate-limit rows (already pseudonymized) are pruned as the limit window rolls forward, and platform/firewall request logs follow the hosting provider’s own retention. Backup copies may persist for a limited time after deletion.
When the SRL is formed, pilot data may continue under the SRL as successor. If the pilot shuts down without a successor, we will notify Operators at the account email and delete or return data within a reasonable wind-down period unless law requires retention.
Your rights (GDPR)
Where GDPR applies, data subjects may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing was based on consent. Contact bookinhub@zohomail.eu. Fans should usually contact the Operator first for booking-specific requests; we will assist Operators or act on verified requests that only we can fulfil (for example account deletion).
Analytics and abuse-control records are aggregated or pseudonymized on purpose, so we usually cannot tie them back to one person and cannot use them to answer an access request (Art. 11 GDPR). We will not collect extra identifying data just to make that possible.
You may lodge a complaint with the Romanian supervisory authority — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro — or another EU authority of your habitual residence or workplace. We encourage contacting us first so we can fix issues quickly during the pilot.
Children
Booking Hub is not directed at anyone under 18. We do not knowingly collect children’s data. If you believe a minor used the service, report it immediately via /report.
Version and contact
Privacy notice version 2026-08-11-eu. Material changes bump this version and may require Operator re-acceptance of Terms that reference it.
Privacy / data requests: bookinhub@zohomail.eu. This notice is for transparency during a Romania/EU pilot. It reflects current product behaviour and common GDPR / Law 506/2004 expectations, but it is not a substitute for lawyer-approved policies before scale-up.