Privacy Policy

Last updated: April 2025

1. Introduction

HoliSpot is committed to protecting your privacy. We comply with GDPR and applicable laws.

2. Data we collect

• Provided by you: name, email, phone, profile, certifications. • Automatic: device, IP, cookies, usage. • Third parties: Stripe, Google Calendar (if linked), Google Analytics.

3. How we use data

• Service operation • Booking & payment processing • Appointment communication • Personalisation • Security • Legal obligations We do not sell your data.

4. Sharing

Shared only with: Stripe (payments), Google (Analytics, Calendar), Cloudinary (images), practitioners (on booking). All processors are GDPR-bound.

5. Google Calendar API

With your consent we may access Google Calendar to sync availability. Data is not stored or shared. You can revoke access anytime.

6. Payments

Stripe processes payments (PCI DSS). We never store card numbers.

7. Security

Encryption, SSL/TLS, Row Level Security, authentication.

8. Your rights (GDPR)

Access, correction, erasure, objection, withdraw consent, portability, complaint to your DPA. Contact: privacy@holispot.com.

9. Cookies

• Essential (login, language) • Analytics (Google Analytics) • Functional (preferences) Essential cookies cannot be disabled.

10. Children

The platform is not for users under 16.

11. Changes

Significant changes will be communicated by email or on the platform.

12. Contact

Questions: privacy@holispot.com