Privacy Policy
This policy explains how the Slateroom service (slateroom.com) processes personal data. The Czech version governs. This English version is a translation. If the two versions differ, the Czech text prevails.
1. Who we are
The operator of Slateroom and the controller of personal data is:
David Kurka, company ID (IČO) 06266215, with registered address at Mlýnská 376, 696 21 Prušánky, Czech Republic
a sole trader registered in the Czech Trade Register
Email for privacy matters: info@slateroom.com
Slateroom is software for service businesses such as therapists, financial advisors, salons and barbers. Businesses use Slateroom to run their website, online booking, customers, payment records and staff. We operate the service from the Czech Republic.
2. Slateroom's two roles
Depending on whose data is concerned, we act in two roles:
- Controller. For the data of our own users, meaning business owners and their staff who have a Slateroom account, for billing and communication with us, and for visitors to the slateroom.com website. Sections 3, 4 and 6 to 14 cover this data.
- Processor. For the data that businesses collect in Slateroom about their customers (bookings, contact details, inquiries, payment records). The controller of that data is the business concerned. See section 5 for details.
3. Data we process as controller
3.1 User account
- name and email address,
- password (we store only its hash, never the password itself),
- roles and membership in business teams,
- team invitations: the invited person's email, the assigned role and the invitation status (an invitation is valid for 7 days).
3.2 Sign-in and technical data
- Sign-in tokens. After sign-in we issue a short-lived access token (valid for 1 hour) and a refresh token (valid for 30 days). On the server we store only their hashes.
- IP address and browser data. We use the IP address briefly to limit the number of requests to public forms and to invitation acceptance. The web server's access log records the requested path without it, though an IP can still appear in error records when a request fails. We do not store IP addresses in the application database.
- Error reports. If an error occurs in the application, we record technical data about the error, error and warning messages from the browser console, and a recording of the session at the moment of the error (session replay). By default the session recording masks text and entered values. We do not attach the user's identity to the reports ourselves. A server-side error record may exceptionally contain data from the request being processed at that moment.
- Cookies and local storage. See section 10.
3.3 Billing and communication
- identification and billing details of the business and records of payments for the service (we issue invoices in Fakturoid),
- the content of communication with us (for example emails with questions and support requests).
Slateroom does not include a payment gateway and does not process payment card data.
3.4 Google account data
If you connect a Google account, we process the data described in section 8.
3.5 The slateroom.com website
- Contact form. The name, email, phone and message text you enter in the form. Messages from the form arrive by email in our info@slateroom.com mailbox, and we use them to reply to your inquiry.
- Traffic measurement. The website uses Cloudflare Web Analytics, which does not use cookies and does not build visitor profiles. It processes technical data about the visit, for example the page visited, the browser type and the country.
3.6 Where we obtain data
We obtain data directly from you, from the business that invited you to its team (your email and role) and, when you connect a Google account, from Google (the email address of the Google account).
4. Purposes and legal bases
| Purpose | Data | Legal basis (Art. 6(1) GDPR) |
|---|---|---|
| Creating and maintaining the account, sign-in, team management, providing the service | account, sign-in tokens, necessary cookies | (b) performance of a contract; for staff of a business who are not a party to the contract, (f) legitimate interest in providing the service to the business |
| Optional Google connection (Calendar, Business Profile) | data under section 8 | (b) performance of a contract; for staff of a business, (f) legitimate interest in providing a feature the user has turned on themselves |
| Security, abuse prevention, diagnosing and fixing errors | IP address, operational logs, error reports | (f) legitimate interest in the secure and working operation of the service |
| Billing and accounting | billing details | (b) performance of a contract and (c) compliance with a legal obligation |
| Support and communication with users, operational notices (for example a change to this policy) | contact details, content of communication | (b) performance of a contract and (f) legitimate interest |
| Replying to an inquiry from the contact form on slateroom.com | contact details, content of the message | (b) steps taken prior to entering into a contract and (f) legitimate interest in handling the inquiry |
| Traffic measurement on the slateroom.com website | technical data about the visit | (f) legitimate interest in improving the website |
| Establishing, exercising or defending legal claims | data necessary in the specific case | (f) legitimate interest |
| Traffic measurement on business websites (Google Analytics) | see section 10.2 | (a) the visitor's consent; the controller is the business concerned |
Providing a name, email and password is necessary to create an account. The service cannot be used without them. Connecting Google is voluntary.
5. Slateroom as processor (data of businesses' customers)
Businesses use Slateroom to process data about their customers and other persons, in particular:
- bookings (name, phone, email, customer's note, date and time, service, price),
- customer records (name, phone, email, internal notes),
- inquiries from the contact form (name, email, phone, message text),
- payment records (payment method, amount, date; no payment card data),
- staff profiles published on the business's website (for example name, photo, bio).
The controller of this data is the business with which you booked a service or to which you sent an inquiry. Slateroom processes it only on the business's instructions under a data processing agreement we conclude with the business. For this we use the further processors listed in section 6, for example to send a booking confirmation by email or a booking reminder by SMS.
If you are a customer of a business, you will find information about the processing of your data in that business's own privacy notice. Please address requests to exercise your rights directly to the business. If you contact us with a request, we will refer you to the business concerned and inform the business.
6. Recipients and processors
We do not sell personal data. We pass it only to the providers we need to operate the service:
| Provider | What it is used for | What data it receives |
|---|---|---|
| Hetzner Online GmbH (Nuremberg data centre, Germany) | running the servers and the database, storage of uploaded files, database backups, server error records | all data stored in the service, including uploaded images (also photos of people), backups and error records |
| Resend | sending email | the recipient's email and the message content: team invitations, booking confirmations and reminders to customers, notifications to the business about a new booking or inquiry (the customer's name, email, phone and message), and messages from the contact form on slateroom.com (name, email, phone and message text) |
| SMSAPI | sending SMS booking reminders | the customer's phone number, the business name and the booking time |
| Fakturoid | issuing invoices for the service | identification and billing details of the business, invoice data |
| Sentry (data stored in the EU, Frankfurt) | error tracking in the application and on business websites | technical data about the error, browser console messages, a masked session recording on error |
| Anthropic | artificial intelligence features: generating and translating website content | see below |
| Cloudflare | hosting of the slateroom.com website and measurement of its traffic, delivery and protection of traffic to the admin and to business websites, including those on their own domains, forwarding of email sent to @slateroom.com addresses, DNS | traffic passing through Cloudflare: IP addresses and technical data of visitors and users, and the content of requests (for example data submitted in the booking form); email sent to @slateroom.com addresses |
| Google (Gmail) | email communication | email sent to info@slateroom.com, including messages from the contact form |
| optional connection to Google Calendar and Google Business Profile (section 8); Google Analytics and YouTube videos on business websites (section 10.2) | see sections 8 and 10.2 |
Artificial intelligence features. If a business uses website content generation or translation, we send the AI provider the business name and description, the texts of pages, services and testimonials and, for staff profiles, their names, bios, job roles and gender (for a grammatically correct translation). We do not send data about customers, bookings, inquiries, payments or user accounts to AI providers.
We may also pass data to public authorities where the law requires us to, and to our legal, tax and accounting advisers to the extent necessary.
7. Transfers outside the EU and EEA
Some providers are based in the United States or may process data there: Resend, Sentry, Anthropic, Cloudflare and Google. The service's servers and storage are in Germany.
The transfer relies on the European Commission's adequacy decision (the EU-U.S. Data Privacy Framework) for providers certified under that framework, and otherwise on the standard contractual clauses approved by the European Commission. We will give you details of the safeguards used on request.
8. Google API data
Slateroom uses a single Google OAuth app for two optional integrations. The user connects each of them separately and can disconnect it at any time.
8.1 What we obtain on connection (openid and email scopes)
On connection we read from Google only the email address of the connected Google account. We use it to show you in the settings which account is connected and to prevent the connected account from being unintentionally swapped for a different one. We do not obtain or store the name, the profile photo or the Google account identifier.
8.2 Google Calendar (scope https://www.googleapis.com/auth/calendar.events.owned)
Any staff member of a business can connect their own Google account. The connection applies to that user.
What Slateroom does in Google Calendar:
- when a booking is confirmed, it creates an event in the user's primary calendar,
- when a booking is rescheduled, it updates the event,
- when a booking is reassigned to another staff member, it removes the event from the original staff member's calendar and creates it in the new staff member's calendar, if they have a calendar connected,
- when a booking is cancelled or deleted, it removes the event,
- on first connection (and on reconnection) it adds the user's existing upcoming confirmed bookings to the calendar.
We leave the events of completed bookings and of bookings the customer did not show up for in the calendar.
What the event contains: an event title made up of the service name and the customer's name, the start and end of the booking, and the business's time zone. The event does not contain a description, a location, attendees, the customer's phone or email, a note or the price.
What Slateroom reads from Google Calendar: nothing. Slateroom currently does not read any of the user's events or calendars. It works only with the events it created itself.
For the customer's name in the event title, the controller is the business (section 5). The name is written to the staff member's calendar so that the staff member can see their bookings.
8.3 Google Business Profile (scope https://www.googleapis.com/auth/business.manage)
The connection is made by a user with permission to manage the business and applies to that business.
Current state: on connection Slateroom stores only the email address of the connected Google account and an encrypted refresh token. It does not yet read any data from Google Business Profile (accounts, locations, reviews) and writes nothing to it.
Planned use: once the feature is live, Slateroom will only read from Google Business Profile:
- the list of accounts and locations, so that the user can select their business's location,
- the reviews of the selected location: the author's display name, a link to their profile photo, the rating, the review text and the date.
The reviews will be displayed as testimonials on that business's website. We will not edit the review text. If the business's website has several language versions, the review text may be machine translated through our AI provider (section 6), solely to display a labelled translation on the business's website. Slateroom will not write anything to Google Business Profile (for example replies to reviews).
8.4 Storage and security
- We store OAuth refresh tokens encrypted (authenticated encryption using the libsodium library). The encryption key is stored separately from the database.
- We do not store access tokens. We obtain them as needed and hold them only in memory for the duration of a single operation.
- Besides the encrypted refresh token we store the email address of the connected account, the connection status and, for Google Calendar, a record of which bookings have been written to the calendar.
8.5 What we do not use Google data for
Data obtained from Google APIs:
- is not sold,
- is not used for advertising or for personalising advertising,
- is not used to develop or train artificial intelligence models,
- is not passed to third parties, except where that is necessary to provide the feature you have turned on, to comply with a legal obligation or to keep the service secure.
We currently do not pass any data obtained from Google APIs to AI providers.
Slateroom's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
8.6 Disconnection and deletion
- Disconnecting in Slateroom (Calendar in the user settings, Business Profile in the business settings) deletes the stored connection, including the Google account email address and the encrypted refresh token. This stops synchronisation.
- Events that Slateroom has already created in Google Calendar do not disappear on disconnection. You can delete them directly in Google Calendar.
- Disconnecting in Slateroom does not by itself revoke the permission granted on Google's side. You can fully remove Slateroom's access to your Google account at https://myaccount.google.com/permissions.
- If Google reports that the permission is no longer valid (for example because you removed it in your Google account), synchronisation stops and we mark the connection as invalid. The stored encrypted token is unusable at that point. We delete it on disconnection; on reconnection a new one replaces it.
- You can also request deletion of data related to the Google connection at the email address given in section 1.
9. Retention
- Account data: for as long as the account exists. On a request sent to the email address given in section 1 we anonymize the account within 30 days: we replace the name and email address, make signing in impossible, and remove sessions, team memberships and connected services. Records we have to keep for accounting, such as payments, then refer to an anonymous account.
- Sign-in tokens: the access token is valid for 1 hour, the refresh token for 30 days. We invalidate them when you sign out.
- Team invitations: valid for 7 days. We delete the invitation record 30 days after it expires, whether or not it was accepted.
- Google connection: until disconnection (section 8.6).
- Billing and accounting documents: for the period required by tax and accounting laws (10 years for tax documents).
- Database backups: 30 days.
- Server operational logs and error reports: operational logs are kept until the next deployment and at most 30 MB per service. Error reports are deleted after 30 days, both in our own storage and in Sentry.
- Communication with us: for as long as we need it to handle your request, and then for the period in which a related claim could be raised — at most 3 years after the last message.
- Staff profiles: when a business deletes a staff member, we remove their contact details, photo, biography, credentials, schedule and vacations. We keep the name, because bookings, payments and inquiries reference it as a record of who provided the service.
- Data of businesses' customers (section 5): the retention period is decided by the business as controller. A booking, inquiry or payment record that the business deletes is removed from the database permanently. It remains in backups until the backup retention period expires. After the contract with the business ends, we permanently delete its data from active systems once 30 days have passed. It disappears from backups in the regular backup rotation.
10. Cookies and local storage
The slateroom.com website does not use analytics or advertising cookies. Traffic measurement (section 3.5) works without cookies.
10.1 Slateroom admin
The admin uses only necessary cookies and browser local storage items. We do not use analytics or advertising tools in the admin.
| Name | Type | Purpose | Duration |
|---|---|---|---|
refresh_token | cookie (HttpOnly) | keeping you signed in | 30 days |
admin-locale | cookie | admin language | 1 year |
google_oauth_nonce, google_business_oauth_nonce | cookie (HttpOnly) | protecting the Google connection process | 3 minutes |
accessToken, tokenExpiresAt | local storage | the signed-in user's access token and its expiry time | until sign-out or expiry |
Browser local storage is also used to remember the state of the interface, for example the last opened website or a website creation wizard in progress. This data stays in your browser.
10.2 Public business websites
Business websites run on Slateroom do not by themselves store any cookies or local storage items, with these exceptions:
| Name | Origin | Purpose | Duration |
|---|---|---|---|
cookieConsent | business website | remembering your choice about analytics cookies | 180 days |
_ga, _ga_… | Google Analytics | traffic measurement | set by Google |
- Google Analytics. It is used only on websites where the business has set it up, and it loads only after you give consent in the cookie banner. If you refuse consent or withdraw it later (the "Cookie settings" link in the website footer), we delete the Google Analytics cookies. The controller of the measurement data is the business concerned.
- YouTube videos. If a page contains a YouTube video, the thumbnail image is loaded from YouTube (Google) servers as soon as the page is displayed. Google thereby receives your IP address and browser data. The YouTube player, which may store its own cookies, loads only after you click the video.
- Error reports. We also record errors on business websites in the way described in section 3.2.
You can also delete or block cookies in your browser settings. Without the necessary cookies, signing in to the admin will not work.
11. Security
- We store passwords only as a hash (the Argon2id algorithm).
- We store sign-in tokens only as a hash. If misuse of a refresh token is suspected, we invalidate the whole session.
- We store Google refresh tokens encrypted (section 8.4).
- The data of individual businesses is separated in the database at row level (PostgreSQL Row-Level Security).
- Communication takes place over an encrypted HTTPS connection.
- Users' access to a business's data is governed by roles and permissions.
- Public forms are protected by request rate limiting.
12. Your rights
Under the GDPR you have the right:
- of access to your personal data,
- to rectification of inaccurate data,
- to erasure of data where the reason for processing it no longer applies,
- to restriction of processing,
- to portability of data that you provided to us and that we process by automated means on the basis of a contract or consent,
- to object to processing based on legitimate interest,
- to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before the withdrawal.
You can exercise your rights by email at the address given in section 1. We will reply without undue delay and within one month at the latest.
You also have the right to lodge a complaint with the supervisory authority: Úřad pro ochranu osobních údajů (the Czech Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, https://www.uoou.cz.
13. Automated decision-making
We do not carry out automated decision-making or profiling that would have legal or similarly significant effects on you.
14. Changes to this policy
We may update this policy, for example when we introduce a new feature or change a provider. You will always find the current version with its effective date on this page. We will inform users of material changes by email or in the admin.
If we wanted to materially change the way we use users' Google data, we will inform you in advance and ask for your consent before the new use begins.