Privacy Policy
Last updated:
This policy explains what personal data CiaoBarber processes, for what purposes, on what legal bases, and what rights you can exercise. It is written under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and, for the processing carried out in Morocco, under Moroccan law 09-08.
CiaoBarber is barbershop management software. That creates two separate relationships: the one with you, the shop owner using the platform, and the one with your own clients, whose data you enter into the system. The privacy roles differ between the two, and section 2 explains how.
CiaoBarber is run from Morocco and deliberately targets the Italian market. The GDPR therefore applies under Article 3(2)(a), because we offer a service to people located in the European Union, even though we have no establishment in the Union.
1. Data controller
The controller for the data relating to your CiaoBarber account is:
- Controller: Youssef Bitar, sole trader (auto-entrepreneur) under Moroccan law, trading as CiaoBarber.
- Address: Résidence Al Kawtar, Sidi Moumen, 20630 Casablanca, Morocco.
- Moroccan national register of auto-entrepreneurs (RNAE): no. 002112908000094.
- Moroccan tax identifier (IF): 26051294.
- Email for privacy requests: privacy@ciaobarber.com.
- Email for general support: support@ciaobarber.com.
CiaoBarber is not an Italian company: it has no Italian VAT number, no Companies Register entry and no REA number. This matters to you, because it determines how invoicing is taxed, which the Terms of Service explain, and which transfer rules apply, which section 6 explains.
Representative in the European Union, designated in writing under Article 27 GDPR:
- Representative: Ibtissam Bitar.
- Address: Via Silvio Pellico 6, 31044 Montebelluna (TV), Italy.
- Email: ibtissambitar25@gmail.com.
The representative is the point of contact in the Union for data subjects and supervisory authorities under Article 27(4) GDPR. They are additional to the contacts above and do not replace them: you may approach either the controller or the representative, and the designation is without prejudice to legal action that may be brought against the controller itself.
No Data Protection Officer has been appointed. Appointment is not required under Article 37 GDPR: CiaoBarber is not a public authority, its core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and it does not process special categories of data under Article 9 on a large scale. For any question about personal data, write to privacy@ciaobarber.com.
2. The two roles CiaoBarber plays
For your account data (name, email, billing details, access logs) CiaoBarber acts as the controller.
For the data of your own clients that you enter or collect through the platform, meaning client records, appointments, notes and payment history, you are the controller and CiaoBarber acts as processor under Article 28 GDPR. It is on you to give your clients a privacy notice and to collect their consent where it is needed.
Article 28 GDPR requires that relationship to be governed by a written contract. That contract is the Data Processing Agreement published at /dpa, which you accept together with the Terms of Service when you open an account. It also contains the Standard Contractual Clauses covering the transfer of data to Morocco, where the provider is established.
3. What data we process
Account holder data:
- Identity and contact details: name, email address, phone number.
- Credentials: password stored as a hash, session tokens, email verification status.
- Shop data: name, address, contact details, opening hours, logo and uploaded images, social profiles, custom domain.
- Subscription and billing data: active plan, subscription status, PayPal subscription identifier, invoice history. We never process or store card numbers: payment happens entirely on PayPal.
- Technical data: IP address, browser and device type, application logs generated for security and diagnostics.
Data about your own clients, which you enter into the platform:
- Name, email address, phone number, and date of birth if you record it.
- Service and barber preferences, and the free-text notes you write on the client record.
- Appointment history, cancellations and no-shows, including a no-show risk score the platform calculates from that history.
- Consents and contact preferences: subscription or unsubscription from communications, SMS opt-in.
- Transactions recorded at the till (POS) and invoices issued.
The no-show risk score is a statistical reading of data you already hold in the platform. It produces no legal effects and does not similarly significantly affect anyone under Article 22 GDPR: it is an indication shown to you, which you remain free to ignore, and no booking is refused automatically on the strength of it.
The free-text notes on a client record are an open field. Please do not use them for special categories of data under Article 9 GDPR, such as health information, allergies or skin conditions. The platform is neither designed nor held out as suitable for that kind of data, and processing sensitive data in Morocco would require prior authorisation from the CNDP.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the platform, managing your account and access | Performance of the contract (Art. 6(1)(b) GDPR) |
| Managing subscriptions, payments and invoicing | Performance of the contract and legal obligation (Art. 6(1)(b) and (c)) |
| Sending service emails: address verification, password reset, subscription notices | Performance of the contract (Art. 6(1)(b)) |
| Sending appointment reminders and notifications | Performance of the contract between you and your client; CiaoBarber acts as processor |
| Keeping the service secure, preventing abuse and diagnosing faults | Legitimate interests (Art. 6(1)(f)) |
| Meeting Moroccan accounting and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Sending marketing about our own products | Consent, withdrawable at any time (Art. 6(1)(a)) |
5. Providers and sub-processors
We rely on the providers listed below, which process data on our behalf as processors or sub-processors. The list reflects the infrastructure actually in use and is current as at the date at the top of this page.
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Neon (managed PostgreSQL) | Main application database | All application data | United States |
| Vercel | Application hosting and delivery | Technical data, request logs | Global network, headquartered in the United States |
| PayPal | Subscription payments and POS collection by QR | Billing and transaction data | European Union and United States |
| Resend | Sending transactional email and campaigns | Recipient name and email address | United States |
| Twilio | Sending SMS, where enabled | Phone number and message text | United States |
| UploadThing | Storage of uploaded images | Logo, shop photos, avatars | United States |
| Google Calendar API | Calendar synchronisation, where you enable it | Appointment data | European Union and United States |
| Cloudinary | Delivery of the intro video on the public site | IP address and technical data of whoever plays the video | Global network |
Push notifications are sent directly from our own servers using the Web Push protocol and VAPID keys, through the push service of whichever browser you are using. We no longer use Firebase Cloud Messaging.
The site's typeface is served from our own servers rather than from Google Fonts, so visiting the site makes no request to Google servers. The public site carries no analytics, audience measurement or advertising tools.
If we change a provider or add a new one, we update this table and, where the provider processes your own clients' data, we notify you as set out in the Data Processing Agreement.
6. International transfers
There are two movements of data to explain, and they are worth keeping apart because different rules govern them.
The first is the data we collect directly from you when you use the site and the platform. The controller is established in Morocco, a country which, as at the date of this policy, is not covered by a European Commission adequacy decision. Under EDPB guidelines 05/2021, collection of data directly from the data subject by a controller established outside the Union is not a transfer within the meaning of Chapter V GDPR, though the processing remains subject to the GDPR under Article 3(2). In practice: your data is processed in Morocco and the United States with the protection the GDPR requires, and with the rights set out in section 9.
The second is your own clients' data. Here you are the controller, established in Italy, and we are your processor, established in Morocco. That is a transfer within the meaning of Chapter V. It is covered by the Standard Contractual Clauses adopted by the European Commission in implementing decision (EU) 2021/914, module 2 (controller to processor), which form part of the Data Processing Agreement you accept when you open an account.
Several of the providers listed in section 5 are based in the United States. Transfers to them rely on the Standard Contractual Clauses in their own data processing agreements or, for certified providers, on the EU-U.S. Data Privacy Framework.
Transferring personal data out of Morocco is separately governed by Articles 43 and 44 of law 09-08 and requires CNDP authorisation.
You can request a copy of the safeguards in place by writing to privacy@ciaobarber.com.
7. The processing carried out in Morocco
Because the controller is established in Morocco, Moroccan law 09-08 on the protection of individuals with regard to the processing of personal data also applies, supervised by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).
That law requires processing to be declared to the CNDP in advance and, for certain categories of data, to be authorised in advance. Where the GDPR and law 09-08 diverge, we apply whichever is more protective of the data subject.
If you are in Italy or another EU country, the application of Moroccan law does not reduce the rights the GDPR gives you, nor your ability to complain to the Italian Garante.
8. How long we keep data
- Account data: for the duration of the contract. When you close the account from your profile settings, the account, shop, staff, client, appointment and inventory data is deleted immediately and irreversibly.
- Your clients' data: you decide how long it is kept; it is deleted when you remove it from the platform or when you close your account.
- Accounting and tax documents: kept for the period required by the Moroccan tax rules that apply to the controller, regardless of account closure, under Article 17(3)(b) GDPR.
- Technical and security logs: up to 12 months.
- Backups: deleted data can persist in encrypted database backups for up to 30 days, after which the normal rotation overwrites it.
Account deletion is final and has no grace period. Export your data before you proceed: the export function sits on the same screen.
9. Your rights
You can exercise the rights in Articles 15 to 22 GDPR at any time:
- Access to your personal data and a copy of it.
- Rectification of inaccurate or incomplete data.
- Erasure, in the cases the law provides for.
- Restriction of processing.
- Portability in a structured, machine-readable format.
- Objection to processing based on legitimate interests.
- Withdrawal of consent, without affecting the lawfulness of processing already carried out.
Articles 7, 8 and 9 of Moroccan law 09-08 grant corresponding rights of access, rectification and objection, which you can exercise at the same contact points.
You can exercise access and portability yourself from inside the platform: your profile settings contain a data export function that produces a downloadable file with your account and client data. The same section lets you delete the account.
For anything else, write to privacy@ciaobarber.com. We answer within one month of receipt, extendable by two months for particularly complex requests.
If you believe the processing breaches the law you can complain to the Italian Garante per la protezione dei dati personali (www.garanteprivacy.it), to the supervisory authority of the EU country where you live, or to the Moroccan CNDP (www.cndp.ma). You can also contact our representative in the Union, named in section 1.
10. Security
- Traffic between your browser and the platform runs over an encrypted connection (HTTPS/TLS).
- Passwords are stored only as hashes and are not readable, including by us.
- Access to data is governed by role-based permissions: a barber sees only their own appointments and clients, not billing or staff management.
- Third-party integration tokens are encrypted before being written to the database.
- The database is run by a specialist provider, with encryption at rest and automated backups.
If a personal data breach occurs that poses a risk to the rights and freedoms of data subjects, we notify the competent supervisory authority within 72 hours and inform the data subjects in the cases set out in Article 34 GDPR. Where the breach concerns your own clients' data, we notify you without undue delay, because in that case it is you, as controller, who must notify the authority.
11. Minors
The platform is for professional operators and is not aimed at anyone under 18. If you record the details of a client who is a minor, it is on you to obtain the consent of whoever holds parental responsibility, where that is required.
12. Changes to this policy
We may update this policy to reflect changes to the platform or to the law. The date at the top of the page shows the last update. Where a change is material we will tell you by email or with a message inside the platform.
13. Contact
For any question about this policy or about how your data is processed, write to privacy@ciaobarber.com.