Last updated: 28 July 2026
1. Who we are
BarberHQ is operated by Henrik Rantala, a sole proprietor based in Norway.
Contact: info@trybarberhq.com
We are the data controller for the personal data described in this policy.
2. Who this policy covers
BarberHQ provides booking pages for independent barbers. This policy covers two groups:
- Barbers who subscribe to BarberHQ and use it to run their bookings.
- Clients who book an appointment through a barber’s BarberHQ page.
If you booked an appointment, your barber decides what happens with your booking. We process it on their behalf and on our own account as the operator of the service.
3. Data we collect from barbers
- Name, email address, phone number
- Business name, address, opening hours, services and prices
- Photos you upload during onboarding
- Payment details, handled by Stripe — we never see or store your card number
- Login credentials (password stored hashed) and session data
- Google account email address, if you connect Google Calendar
When you sign up, your name, business name, email address, location and market are sent to our internal notification channel on Telegram so we can prepare your page.
4. Data we collect from clients
- Name and phone number
- Email address, if provided
- Appointment date, time, service and any notes you add
- Whether you have consented to marketing messages, and whether you have opted out
We do not use tracking cookies, advertising pixels or third-party analytics.
5. Google Calendar integration
Connecting Google Calendar is optional. Barbers can use BarberHQ without it, and can disconnect at any time.
Scopes we request and why
| Scope | What we use it for |
|---|---|
.../auth/calendar.events |
Create, update and delete the calendar event for each booking, so appointments appear in the barber’s own calendar |
.../auth/calendar.freebusy |
Read which time slots are already busy, so clients are not offered a time the barber is unavailable |
openid, email |
Show which Google account is connected, in the dashboard |
What we do not access
We never read the content of your calendar events. The availability check returns only whether a time period is busy or free — not event titles, descriptions, attendees, locations or attachments. We do not access any calendar other than your primary calendar, and we do not access Gmail, Drive, Contacts or any other Google service.
How the data is stored
Google access and refresh tokens are encrypted at rest using AES-256-GCM. Busy periods retrieved from your calendar are used to calculate available appointment times and are not stored.
Deletion
When you disconnect Google Calendar in your dashboard, we revoke the token with Google and delete it from our database immediately. You can also revoke access directly at https://myaccount.google.com/permissions.
Limited Use
BarberHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Why we process your data
- To provide the booking service — creating, changing and cancelling appointments
- To send appointment confirmations and reminders
- To take subscription payments from barbers
- To send marketing messages, where the recipient has given consent
- To meet legal obligations, including bookkeeping
7. Who we share data with
We do not sell personal data. We use the following service providers:
| Provider | Purpose | Location |
|---|---|---|
| Railway | Application hosting and database | EU |
| Netlify | Website hosting | Global CDN |
| Cloudflare R2 | Image storage | EU |
| Resend | Transactional email | EU |
| GatewayAPI | SMS delivery | EU (Denmark) |
| Stripe | Subscription payments | EU/US |
| Calendar integration, where enabled | EU/US | |
| Telegram | Internal notification when a barber signs up | Outside EU/EEA |
Transfers outside the EU/EEA are covered by the European Commission’s Standard Contractual Clauses where available. Client booking data is never sent to Telegram.
8. How long we keep data
- Booking data: retained while the barber’s account is active, so they keep their appointment history
- Barber accounts: deleted within 90 days of a subscription ending, unless bookkeeping law requires longer
- Google tokens: deleted immediately on disconnection
- Accounting records: retained for five years, as required by Norwegian law
9. SMS messages
Appointment confirmations and reminders are sent as part of the service you booked. Marketing messages — such as rebooking suggestions — are only sent to clients who have actively consented. Every marketing message contains an opt-out link, and opting out takes effect immediately.
10. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, receive a copy in a portable format, restrict or object to processing, and withdraw consent at any time.
To exercise any of these, email info@trybarberhq.com. We respond within 30 days.
If you booked an appointment and want your data removed, contact your barber or email us directly — either route works.
You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), postkasse@datatilsynet.no.
11. Cookies
We use a single session cookie to keep barbers logged in. It is strictly necessary for the service and is not used for tracking or advertising.
12. Security
Data is transmitted over HTTPS. Passwords are hashed. Google tokens are encrypted at rest. Access to production systems is restricted to the operator.
13. Changes
We will update this page if our processing changes, and update the date at the top. Material changes will be communicated to barbers by email.