LEGAL

Privacy Policy

How we collect, use and protect personal data — for barbers and for the clients who book with them.

1. Who we are

BarberHQ is operated by Henrik Rantala, a sole proprietor based in Norway.

Contact: info@trybarberhq.com

We are the data controller for the personal data described in this policy.

2. Who this policy covers

BarberHQ provides booking pages for independent barbers. This policy covers two groups:

If you booked an appointment, your barber decides what happens with your booking. We process it on their behalf and on our own account as the operator of the service.

3. Data we collect from barbers

When you sign up, your name, business name, email address, location and market are sent to our internal notification channel on Telegram so we can prepare your page.

4. Data we collect from clients

We do not use tracking cookies, advertising pixels or third-party analytics.

5. Google Calendar integration

Connecting Google Calendar is optional. Barbers can use BarberHQ without it, and can disconnect at any time.

Scopes we request and why

ScopeWhat we use it for
.../auth/calendar.events Create, update and delete the calendar event for each booking, so appointments appear in the barber’s own calendar
.../auth/calendar.freebusy Read which time slots are already busy, so clients are not offered a time the barber is unavailable
openid, email Show which Google account is connected, in the dashboard

What we do not access

We never read the content of your calendar events. The availability check returns only whether a time period is busy or free — not event titles, descriptions, attendees, locations or attachments. We do not access any calendar other than your primary calendar, and we do not access Gmail, Drive, Contacts or any other Google service.

How the data is stored

Google access and refresh tokens are encrypted at rest using AES-256-GCM. Busy periods retrieved from your calendar are used to calculate available appointment times and are not stored.

Deletion

When you disconnect Google Calendar in your dashboard, we revoke the token with Google and delete it from our database immediately. You can also revoke access directly at https://myaccount.google.com/permissions.

Limited Use

BarberHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Why we process your data

7. Who we share data with

We do not sell personal data. We use the following service providers:

ProviderPurposeLocation
RailwayApplication hosting and databaseEU
NetlifyWebsite hostingGlobal CDN
Cloudflare R2Image storageEU
ResendTransactional emailEU
GatewayAPISMS deliveryEU (Denmark)
StripeSubscription paymentsEU/US
GoogleCalendar integration, where enabledEU/US
TelegramInternal notification when a barber signs upOutside EU/EEA

Transfers outside the EU/EEA are covered by the European Commission’s Standard Contractual Clauses where available. Client booking data is never sent to Telegram.

8. How long we keep data

9. SMS messages

Appointment confirmations and reminders are sent as part of the service you booked. Marketing messages — such as rebooking suggestions — are only sent to clients who have actively consented. Every marketing message contains an opt-out link, and opting out takes effect immediately.

10. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, receive a copy in a portable format, restrict or object to processing, and withdraw consent at any time.

To exercise any of these, email info@trybarberhq.com. We respond within 30 days.

If you booked an appointment and want your data removed, contact your barber or email us directly — either route works.

You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), postkasse@datatilsynet.no.

11. Cookies

We use a single session cookie to keep barbers logged in. It is strictly necessary for the service and is not used for tracking or advertising.

12. Security

Data is transmitted over HTTPS. Passwords are hashed. Google tokens are encrypted at rest. Access to production systems is restricted to the operator.

13. Changes

We will update this page if our processing changes, and update the date at the top. Material changes will be communicated to barbers by email.

14. Contact

info@trybarberhq.com