Privacy Policy
How Grafiko handles personal data. This was written by going through what the software actually stores, sends and keeps — not from a template — so it describes this product rather than software in general.
Last updated August 22, 2026
This text is a working draft. It was written by reading what the software actually does, and it has not yet been checked by a lawyer. Treat it as an honest description of how Grafiko behaves, not as a final legal document. If something on this page matters to a decision you are making, write to us first.
Who handles your data
Grafiko is operated by [not yet supplied], identification number [not yet supplied], registered at [not yet supplied]. You can reach us at [not yet supplied].
Two parties are involved in almost every record. The salon you booked with decides what it records about you and why — it is the salon that writes the notes, sets the prices and sends the campaigns. Grafiko provides and operates the software and stores that data on the salon's behalf.
How responsibility is formally divided between the salon and Grafiko under the Georgian Law on Personal Data Protection is one of the things this draft is still waiting on legal review to state precisely.
What we hold about clients
When you book, the salon's page asks for what a salon needs to hold an appointment for you:
- Your name, and your email address and phone number. If a salon books you in over the phone, one of those may be missing, and the booking still works.
- The language you prefer, so we know which language to write to you in.
- A password, if you chose to create an account. It is stored only as a scrypt hash — we cannot read it, and we cannot tell you what it is.
- Your appointments: the salon, the service, the stylist, the date and time, the status, the price recorded at the moment you booked, and who created or cancelled the booking.
- Notes salon staff write about an appointment or about you as a client. These are free text, written by people, and visible only to the salon that wrote them.
- Waitlist entries and recurring series you are part of.
- Whether you agreed to receive marketing from a salon, and when you agreed or withdrew.
One thing to know about email addresses
Grafiko does not verify email addresses. If someone types your address into a salon's booking form, the confirmation email arrives with you. If that happens, write to us or to the salon and it will be removed.
What we hold about salon staff and owners
If you work at a salon that uses Grafiko, we hold:
- Your name, email address, phone number, preferred language, and password hash.
- Your role in the salon (owner, manager, staff) and whether your account is invited, active or disabled.
- Your job title, biography and profile photo, if the salon added them. These are shown publicly on the salon's booking page — that is their purpose. The photo is stored in our database and served from our own address, not a third party's.
- Your working hours, days off and one-off exceptions, and which services you perform.
- The appointments assigned to you, and the reports the salon derives from them, including what was charged and what was recorded as taken, and how many clients you saw.
What we do not collect
This section exists because most privacy policies quietly leave room for these things. Grafiko does none of them. There is one thing it does hold that points at a person, and it is set out here rather than left for you to find.
Every public form — signing in, signing up, registering a salon, asking for a password reset, booking, and changing a booking from the link in your email — is throttled against the network address your request arrives from. So we store that address, exactly as it reaches us, in an hourly counter: the address, which form it was, the hour, and how many attempts it holds. It is not hashed, and that is worth saying plainly, because the email addresses counted in the same table are stored only as a SHA-256 digest so that a copy of the database gives up no address. Nothing you typed and no outcome is kept beside it. These counters are also the one thing Grafiko deletes on a schedule — see How long we keep it.
- No analytics, no tracking pixels, no advertising cookies, no session recording, no A/B testing tools.
- No card numbers or bank details. Grafiko does not process payments at all today.
- No location data, no identity documents, no photographs of clients.
- No social sign-in, so nothing arrives here from Google, Facebook or anyone else.
- No third-party scripts on any page, and fonts are served from our own address rather than loaded from an external service.
Cookies
Grafiko sets only what it needs to function. There is no advertising or analytics cookie anywhere on the site, which is also why you are not being asked to dismiss a cookie banner.
- A session cookie once you sign in, so you stay signed in. It cannot be read by scripts in your browser, and it lapses after about 30 days without use.
- Two supporting cookies from the same sign-in library: one guards against cross-site request forgery, one remembers where to return you after signing in.
- A language cookie (NEXT_LOCALE) remembering whether you chose Georgian or English.
Who else sees your data
A short list, and it is the whole list.
- The salon you booked with sees its own records. Salons cannot see each other's clients, appointments or notes — the separation is enforced on the server for every single action, not merely hidden in the interface.
- Resend, our email delivery provider, receives the recipient's address and the full content of each message we send.
- Our hosting and database provider: UpCloud (Frankfurt, Germany).
- Grafiko's own operators can open a salon's records — read-only — to answer a support request. Every such view is kept in a support access log: which operator, which salon, and what they opened.
- Other platform screens are not scoped to one salon — the email log, which holds every message's recipient and subject, and a salon's record showing its owner's contact details. Unlike the support views above, these are not recorded.
- Nobody else. Grafiko does not sell personal data and does not share it for advertising.
The emails we send
Two kinds, and they behave differently.
Transactional email is part of the booking: the confirmation, a reminder before the appointment (by default 24 hours before, though each salon can change that or switch reminders off), a notice when a waitlisted slot opens, a password reset link, and an invitation if a salon adds you as staff. These contain the salon name, the service, your stylist's name and the appointment time.
Transactional email has no unsubscribe link, because it is the thing you asked for by booking. If you do not want it, tell the salon before you book.
Marketing email is separate, is sent by a salon rather than by us, and only ever reaches people who opted in. Every marketing email carries an unsubscribe link that works without signing in, and the standard unsubscribe header — so mail apps that support it can offer their own unsubscribe button.
We also keep a record of every message we send, which is how an operator can answer whether last night's reminders actually went out. Each entry holds the recipient address, the subject, which template produced it, the outcome — accepted by the provider, rejected by it, or logged without being sent because no provider is configured — the provider's own message id where there is one, the error text if it failed, the salon and the account it belongs to where those are known, and the time. The recipient address is stored as written, and nothing in this log is deleted automatically.
Marketing consent
The consent box on a booking form is unticked by default, and consent is never implied by the act of booking.
A salon can also record consent you gave in person at the desk. If you receive marketing you do not remember agreeing to, use the unsubscribe link, or your account page, which lists every salon that may write to you — and tell us: that combination should never happen.
Withdrawing is recorded as a withdrawal, not as an absence of consent. This matters: it means a later booking at the same salon cannot silently subscribe you again. Getting back on the list requires you to agree again, explicitly.
The link in your confirmation email
Your confirmation and reminder emails contain a link with a secret code in it. That code is what lets you open the booking, reschedule it or cancel it without signing in.
It follows that anyone holding that link can do the same. The code does not expire. Forward the email only to someone you would be content to have cancel the appointment.
The link shows that one booking and nothing else. It is not a way into your account or into any other appointment.
How long we keep it
Stated plainly, because this is where policies usually promise a schedule that the software does not keep: Grafiko deletes nothing automatically, with the single exception below. There is no retention period and no scheduled clean-up. Appointments, client records, staff notes and withdrawn consents stay in the database until somebody removes them.
The exception is the abuse counters described under What we do not collect. The same hourly job that sends appointment reminders also clears counters whose hour has already elapsed, so a stored network address disappears within about two hours of the request that recorded it. That is the only automatic deletion in the software, and the only personal data any automatic deletion touches.
Deletion happens on request and is carried out by hand. Setting a real retention period, and building the job that enforces it, is outstanding work and is one of the reasons this page is still marked a draft.
Your rights
The Georgian Law on Personal Data Protection gives you rights over data held about you. In particular you may ask:
- What data is held about you, and receive a copy of it.
- That inaccurate data be corrected.
- That data be deleted or blocked, where the law allows it.
- To withdraw consent you previously gave, at any time.
- To be told who your data has been passed to.
How to exercise them
Write to [not yet supplied]. We will ask you to confirm who you are before acting, because acting on an unverified request is itself a data breach.
Where the record belongs to a salon — your appointments, the notes written about you — we will pass the request to that salon, since it is the salon that decides about that data, and we will tell you that we have.
Two honest limits, and one thing that is no longer one. Withdrawing marketing consent you can now do yourself — from your account page, or the unsubscribe link in any message we send. For everything else there is still no self-service button: no export, no delete-my-account, and every request is handled by a person. And these terms do not promise you a response time — we would rather leave that blank than print a number we have not committed to.
Security
What the software actually does:
- Passwords are stored as scrypt hashes with a random salt per user, never as text.
- Sessions live in a signed cookie that scripts in your browser cannot read.
- Password reset links can be used once and stop working after an hour.
- Every action that requires you to be signed in re-checks who you are and which salon you may touch. The booking actions, which by design have no signed-in user, re-check that the salon, service and stylist you chose belong together and that the time is genuinely free. Access is not merely hidden from the page — it is refused at the point of change.
- The cron endpoint that sends reminders refuses to run at all if its secret is not configured, rather than running unprotected.
What we are not claiming about security
No certification, audit or penetration test has been carried out, and this page does not claim encryption at rest, because nothing in the software configures it. The hosting arrangement is UpCloud (Frankfurt, Germany), and the guarantees that come with it are the hosting provider's, not ours.
Children
Grafiko is meant for adults booking their own appointments and for salons running their business. There is no age verification. If an adult books an appointment for a child, the details supplied are the adult's responsibility.
Changes to this policy
When the text changes the date at the top changes with it. This version is a draft and will change once it has been reviewed.
Questions about this page
We have not published a contact address yet. It will appear here before launch — until then this page cannot give you a working way to reach us.