This Privacy Policy describes how Smooth Solutions Oy processes personal data at smoothbooking.fiand in our iOS and Android applications (together, the "Service"). The Service is a booking and queue management system where customers can book appointments or join queues at our partner businesses, and where service businesses can manage bookings, customers and campaigns for their own business.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018).
1. Data controller
Smooth Solutions Oy
Business ID: Y-tunnus rekisteröidään pian
Topeliuksenkatu 18 C 33 00250 HELSINKI
2. Contact for privacy matters
For privacy matters, please contact us by email: smoothbooking.app@gmail.com. General contact: smoothbooking.app@gmail.com.
We have not appointed a dedicated Data Protection Officer because our operations do not meet the thresholds set by GDPR Article 37. We will reassess this if the scale of our operations changes materially.
3. Register name
SmoothBooking user and booking register.
4. What data we collect
We only collect data that is necessary for providing the Service.
From customers (end users)
- Name, email address and phone number
- Password in hashed form (we never store passwords in readable form)
- Profile picture, if you upload one
- Language and notification settings, including marketing consent
- Bookings, queue entries and any free-text notes you add
- Redeemed coupons and discounts
From service businesses (Pro users)
- In addition to the above, the business name, Finnish Business ID and business details
- Branch addresses, opening hours and service descriptions
- Employee names and contact details
- Your own customer data and customer history (visit frequency, recent services)
Automatically
- IP address and basic browser information, used briefly to prevent abuse
- Session cookies required for the Service to function (see our Cookie Policy)
- In the mobile app, a device-specific identifier for push notifications (optional)
- Error and security logs with user identifiers masked
- Crash, error and performance data from the mobile app and the web service (see "Crash reporting in the mobile app" below)
Crash reporting in the mobile app and web service
We use Sentry (Functional Software, Inc.) to detect crashes, errors and performance problems. When the app crashes or hits an error, a technical error report is sent to Sentry: the error message and code stack trace, device model, operating system and app version, and a trail of the actions that preceded the error (for example, which screen was open). On iOS devices the report may include a replay of the moments before the error in which all text, images and graphics are automatically masked: no content can be read from the recording.
In automatic error reports we do not send your name, email address, phone number or IP address to Sentry. (Exception: if you use the "Report a problem" form, the name, email address and description you provide are transmitted as entered so that we can reply to you.) For signed-in users we attach only a one-way SHA-256 hash of the user ID so that errors from the same user can be grouped. The hash cannot be reversed to identify you. Identifiers appearing in URLs (booking, customer and user IDs, one-time tokens, email) are automatically redacted before sending, and the contents of sign-in and password requests are never sent at all. The legal basis is legitimate interest (fixing service errors and security), and the retention period is stated in section 6.
The map view in the mobile app fetches map imagery from Mapbox, which means Mapbox sees the request's IP address and the map area being viewed. Location data is used to show nearby businesses and calculate distances; sharing your location is optional and can be turned off in your device settings.
Sensitive data
We do not request health-related or other special-category data under GDPR Article 9. We recommend keeping free-text notes at a general level.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and maintaining user accounts, sign-in | Performance of a contract |
| Managing bookings, queues and coupons | Performance of a contract |
| Direct marketing via email or push notification | User consent |
| Invoicing and accounting | Legal obligation (Finnish Accounting Act 1336/1997) |
| Service security and prevention of abuse | Legitimate interest |
| Improving the service and fixing bugs | Legitimate interest |
6. Retention periods
- User account data: until the user deletes the account. After deletion, identifiers (name, email, phone) are erased without undue delay.
- Accounting records: if the user has made paid transactions, we retain only the receipt fields required by Finnish accounting law (transaction date, amount, invoice reference, counterparty name) in restricted form for 6 years from the end of the fiscal year.
- Marketing delivery logs: up to 90 days, then deleted automatically.
- Review request opt-out: if you have asked us to stop sending you review requests, we keep a record of that request indefinitely, including after you delete your account. The record contains only your user ID or a one-way hash of your email address, together with the date. It does not contain your name or your email address as such. We keep it because without it we could not recognise your request and review requests would start again. The legal basis is Article 17(3) of the GDPR: we retain the minimum information required to give effect to your objection. The record does not affect any other communication, such as booking confirmations or reminders.
- Session cookies: up to 14 days or until you sign out.
- IP addresses for security use: up to 15 minutes.
- Error and security logs: up to 30 days.
- Crash and error reports in the error reporting service (Sentry): up to 90 days, after which they are deleted automatically.
7. Recipients of data
We do not sell personal data. Data may be disclosed to the following parties:
- To the service business a customer books with or joins a queue at. The Pro user receives the customer's name, contact details and booking information, as needed to provide the service. The Pro user acts as an independent controller for their own customer data. The customer may direct privacy requests to the Pro user directly.
- To subcontractors providing technical services. These include cloud infrastructure providers and email and push notification delivery services. Subcontractors process data on our behalf under written agreements.
- To public authorities when required by mandatory law, or if we are a party in legal proceedings or similar processes.
- To parties in a corporate transaction, if we are involved in a business sale, merger or reorganisation. We will ensure that the recipient commits to comply with this Privacy Policy.
Key subcontractors
| Processor | Purpose | Location |
|---|---|---|
| Google Ireland Ltd. (Firebase / Google Cloud) | Authentication, database, file storage, backend services and push notification delivery (FCM) | EU and the United States |
| Vercel Inc. | Technical hosting of the service — all requests and their IP addresses pass through the platform. Also cookieless visitor analytics. | United States |
| Resend Inc. | Delivery of all email (SMTP): booking confirmations and cancellations, appointment reminders, review requests, password resets, and pilot and administrative messages. Processes the recipient email address and message content. | United States |
| Upstash Inc. | Rate limiting to prevent abuse (short-term processing of IP addresses) | EU (Frankfurt) |
| Functional Software, Inc. (Sentry) | Monitoring of errors, crashes and outages in the web service and in the iOS and Android apps: personal data is filtered automatically before transmission (names, email addresses, phone numbers, cookies and free text are removed). A signed-in user is identified only by a one-way SHA-256 hash of the user ID, never an IP address. Additionally the “Report a problem” form, in which the user voluntarily provides a name, email address and description of the issue — these are transmitted as entered so that we can reply. | EU (Frankfurt) |
| Mapbox, Inc. | Displaying maps and converting address searches into coordinates. The browser and the mobile app load map imagery directly from the provider, which therefore sees the user’s IP address and the map area being viewed. The service is also used as a fallback for converting your location into a city name: if the primary service does not respond, your device’s coordinates are relayed via our server to this provider. The coordinates are not stored on our server and are not linked to your account. | United States |
| OpenStreetMap Foundation (Nominatim) | Address geocoding and converting your location into a city name. If you grant the app location permission, your device’s coordinates are relayed via our server to this service to resolve the city name. The coordinates are not stored on our server and are not linked to your account. | United Kingdom (adequacy decision) |
| 650 Industries, Inc. (Expo) | Delivery of push notifications to the mobile apps (device token and notification content) | United States |
| Apple Inc. (Apple Push Notification service) | Delivery of push notifications and the queue live view to Apple devices (device token and notification content) | United States |
| Selainvalmistajien push-palvelut (Google, Mozilla, Apple) | Delivery of browser notifications. The receiving service is determined by the user’s own browser, and the message content is end-to-end encrypted. | EU and the United States |
| Cal.com, Inc. | Booking of introductory meetings for pilot entrepreneurs — name, email address, company details, booked time and video meeting link | United States |
| Slack Technologies, LLC (Salesforce, Inc.) | Internal notifications to the founders’ team channel about new enquiries and introductory bookings: company name, industry, time, language and a technical identifier. The contact person’s name, email address or written message are NOT transmitted — those are sent by email only. | United States |
8. Transfers outside the EU and EEA
Some of our subcontractors are located in the United States. We transfer data outside the EU and EEA only when a transfer mechanism required by data protection law is in place: the EU–US Data Privacy Framework approved by the European Commission, or standard contractual clauses approved by the Commission. Additional information is available from the contact listed in section 2.
9. Cookies
We only use cookies that are strictly necessary for the Service to function: a sign-in session cookie, a security cookie, and a language-preference cookie. We do not use advertising or tracking cookies, and we do not share data with analytics or ad networks. For details, see our Cookie Policy.
10. Your rights
You have the right to:
- Know what data we process about you and receive a copy.
- Request the correction of inaccurate or incomplete data.
- Request the deletion of your data, or restriction of processing, within the limits set by law.
- Receive the data you have provided in a portable format.
- Object to processing based on legitimate interest.
- Withdraw marketing consent at any time, every marketing message contains a one-click unsubscribe link.
You can exercise your rights by emailing smoothbooking.app@gmail.com, or by downloading your data and deleting your account from the profile page. We respond without undue delay and within one month at the latest.
11. Right to lodge a complaint
If you believe we process your data contrary to data protection law, you may lodge a complaint with the Finnish Data Protection Ombudsman:
Office of the Data Protection Ombudsman
PO Box 800, FI-00521 Helsinki, Finland
Phone: +358 29 566 6700
tietosuoja@om.fi · tietosuoja.fi/en
12. Data security
We protect personal data with appropriate technical and organisational measures. Connections are encrypted, passwords are stored as hashes, and access to data is restricted by role. We process data using only as many personnel as is necessary for the tasks, and all our personnel are bound by confidentiality.
If we detect a personal data breach likely to create a risk to data subjects, we notify the Data Protection Ombudsman within 72 hours and the affected users as the situation requires.
13. Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning the user or similarly significantly affects the user. Automatic limitations relating to service security (such as temporary blocks on abusive use) can always be reviewed by a human by contacting our support.
14. Minors
The Service is intended for users aged at least 18. We do not knowingly collect data from anyone younger. If you become aware that a minor has created an account, please notify us so we can remove it.
15. Changes to this policy
We may update this Privacy Policy as the Service evolves or the law changes. We will notify you of material changes via the Service or by email at least 30 days before they take effect.