Privacy Policy
Last updated: 3 August 2026
This Privacy Policy explains how Acme Software LLC (“Klub”, “we”, “us”) collects, uses, shares and protects personal data when you use our appointment-booking platform and websites (the “Service”). We are committed to processing personal data lawfully and transparently, including under the EU/UK General Data Protection Regulation (GDPR).
1. Who we are
The Service is operated by Acme Software LLC, a single-member limited liability company registered in the State of Delaware, United States. For any privacy question or to exercise your rights, contact us at info@klubparrucchieri.it.
2. Controller and processor roles
Klub is a platform that beauty, wellness and service businesses (“Salons”) use to take and manage appointments with their own customers.
- When you book an appointment with a Salon, that Salon is the data controller of your personal data, and Klub acts as a data processor on the Salon’s behalf, processing your data only to provide the booking service.
- For a Salon’s own account (the business’s account, staff and settings) and for our websites, Klub is the data controller.
3. What data we collect
- Account data (Salons & staff): name, email, phone number, business details, role and login credentials.
- Booking data (customers): the name, phone number and email you provide when booking, the services and times you request, notes you add, and your appointment history with the Salon.
- Verification data: a one-time code we send by SMS, WhatsApp or email to confirm your phone number or email during booking.
- Reliability data: attendance information (e.g. completed appointments, cancellations, no-shows) used by the Salon to manage its schedule.
- Payment status: whether an appointment has been marked paid and by what method. We do not store full card numbers; card payments, where offered, are handled by our payment processor.
- Technical data: device, browser and usage information needed to operate and secure the Service.
4. How we use personal data and our legal bases
- To provide the booking service — create, confirm, reschedule and cancel appointments (legal basis: performance of a contract).
- Transactional messages only — appointment confirmations, reminders, reschedule and cancellation notices, and one-time verification codes, sent by SMS, WhatsApp or email to people who booked or entered their details. We do not send marketing or bulk email through these channels (legal basis: performance of a contract / legitimate interests, and consent where required).
- Security, fraud prevention and support (legal basis: legitimate interests).
- Legal compliance (legal basis: legal obligation).
5. Service providers we share data with
We use a small set of trusted providers who process data on our behalf under contract. They may only use the data to provide their service to us:
- Supabase — database, authentication and file storage (hosted in the EU, Frankfurt).
- Twilio — SMS and WhatsApp delivery of transactional messages and verification codes.
- Resend / Amazon SES — delivery of transactional email.
- Google Firebase — application hosting and push-notification delivery.
- Anthropic — AI features (e.g. text suggestions and data-import mapping); only the minimum content needed is processed, and it is not used to train models.
We do not sell personal data, and we do not share it with advertisers.
6. International transfers
Some providers are located outside the European Economic Area (including the United States). Where data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep data
We keep personal data for as long as the Salon’s account is active and as needed to provide the Service, then delete or anonymise it, unless a longer period is required by law (e.g. tax or accounting rules). A Salon can request export or deletion of its data at any time.
8. Your rights
Subject to applicable law, you have the right to access, correct, delete or restrict processing of your personal data, to object to processing, to data portability, and to withdraw consent. To exercise these rights, contact the relevant Salon (as controller of your booking data) or us at info@klubparrucchieri.it, and we will assist. You also have the right to lodge a complaint with your local data-protection authority (in Italy, the Garante per la protezione dei dati personali).
9. Security
We use industry-standard measures to protect personal data, including encryption in transit, access controls and row-level security so each business can only access its own data. No method of transmission or storage is completely secure, but we work to protect your information and to notify affected users of any breach as required by law.
10. Children
The Service is intended for adults. We do not knowingly collect personal data from children under 16 without appropriate consent. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date above.
12. Contact
Acme Software LLC — email info@klubparrucchieri.it.