1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can personally identify you.
2. Hosting and Technical Service Providers
We host the content of our website with the following providers:
Vercel (Website Hosting)
Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA
When you visit our website, Vercel collects various log files including your IP addresses.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in reliable website display)
Privacy Policy: https://vercel.com/legal/privacy-policy
Supabase (Database Hosting)
Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992
Our application data is securely hosted with Supabase in Europe (Frankfurt, Germany).
Legal basis: Art. 6 para. 1 lit. f GDPR and Art. 6 para. 1 lit. b GDPR (contract performance)
Privacy Policy: https://supabase.com/privacy
3. Payment Processing
We use the following payment service provider to process payments:
Stripe (Payment Service Provider)
Provider: Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA. For EU customers: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
When paying via Stripe, your payment data (e.g., credit card number, expiration date, CVC) is transmitted directly to Stripe and processed there. We do not store any complete payment data ourselves.
Data processed: Name, email address, billing address, payment information (stored only at Stripe), IP address, transaction data.
Purpose of processing: Processing payments for subscriptions and paid services.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure payment processing).
Retention period: Transaction data is stored in accordance with statutory retention periods (typically 10 years).
Third country transfer: Stripe is certified under the EU-US Data Privacy Framework and provides adequate safeguards pursuant to Art. 46 GDPR.
Privacy policy: https://stripe.com/privacy
4. Calendar Integration
We offer the option to synchronize bookings with external calendar services:
Google Calendar
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When using Google Calendar integration, your booking data is synchronized with your Google Calendar. This only occurs after your explicit consent through the OAuth authentication process.
Data processed: Calendar entries (title, date, time, description), email address of Google account, calendar access token.
Purpose of processing: Synchronization of booking appointments with your personal calendar for automatic appointment management.
Legal basis: Art. 6(1)(a) GDPR (consent). You can revoke your consent at any time in your account settings.
Data Protection Mechanisms: We protect your Google Calendar data through multiple security layers: end-to-end encryption during transmission (TLS 1.3), encrypted storage of access tokens in our database, strict access control (only authorized requests), regular security audits, and OAuth 2.0 authentication. We use the permissions 'calendar.readonly' (read calendars) and 'calendar.events' (create, edit, and delete events) for full calendar integration.
Booking Data Processed: When bookings are synchronized via the calendar integration, we store: appointment details (title, date, time, duration), customer data (name, email, phone), service information, and booking status. This data is required to provide booking management and notifications.
Retention period: The connection is stored until you actively disconnect it. Calendar entries remain in your Google Calendar.
Data Deletion: You have the right to delete your Google Calendar data at any time. When you disconnect the calendar integration in your account settings, all associated access tokens and synchronization data are immediately deleted from our database. Calendar entries in your Google Calendar remain untouched. You can revoke your consent at any time in your Google Account settings under 'Apps with access to your account'.
Third country transfer: Google is certified under the EU-US Data Privacy Framework.
Privacy policy: https://policies.google.com/privacy
Apple iCloud Calendar (CalDAV)
Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
When using Apple Calendar integration, your booking data is synchronized with your iCloud Calendar via the CalDAV protocol.
Data processed: Calendar entries (title, date, time, description), Apple ID credentials (for authentication only, not stored).
Purpose of processing: Synchronization of booking appointments with your Apple Calendar.
Legal basis: Art. 6(1)(a) GDPR (consent). You can revoke your consent at any time in your account settings.
Privacy policy: https://www.apple.com/legal/privacy/
Note on the Responsible Party
The party responsible for data processing on this website is:
Eazy Logistics GmbH
Γberseetor 24
28217 Bremen
Germany
Telefon: 015678 371650
E-Mail: info@eazybooking.de
7. Booking System and Payment Processing
Processing of Customer and Booking Data
We collect, process and use personal customer and booking data for:
- β’ Establishment, content design or modification of the booking relationship
- β’ Appointment management and calendar synchronization
- β’ Sending reminders and confirmations
- β’ Invoicing and payment processing
Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance)
Data Transmission in Booking Processing
We only transfer personal data to third parties when necessary for booking processing:
- β’ To the respective service provider for appointment confirmation
- β’ To email service providers for notifications (Resend)
- β’ To calendar services for synchronization (CalDAV/iCloud)
- β’ To payment service providers for paid services
Retention period: Booking data is stored for 3 years after completion of the appointment (tax retention obligation).
Analytics & Marketing
With your consent via the cookie banner, we use services that help us improve our product (Analytics) or recognize you on our site (Marketing). You can withdraw your consent at any time via the cookie banner or privacy settings.
PostHog (Product analytics, optional)
Provider: PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. EU hosting (Frankfurt) used exclusively.
If you consent to "Analytics cookies", PostHog collects anonymized usage data (e.g., which pages you visit, which onboarding-wizard steps you complete). We only use EU servers (Frankfurt). All form inputs are masked in session replays.
Data processed: Anonymized device/browser info, click/navigation events, truncated IP, user ID after login. No input field content.
Purpose: Improving the onboarding flow, identifying drop-off points, conversion analysis.
Legal basis: Art. 6(1)(a) GDPR (consent). No processing before consent.
Retention: Up to 7 years on EU servers; deletion on request.
Third-country transfer: Processing exclusively in the EU (Frankfurt).
Privacy policy: https://posthog.com/privacy
Microsoft Clarity (Session analytics, optional)
Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. Microsoft Ireland Operations Limited as EU representative.
If you consent to "Analytics Cookies", Microsoft Clarity records anonymized heatmaps and session replays to identify where visitors drop off. All input fields are masked in replays.
Data processed: Mouse movements, clicks, scroll behavior, screen size, anonymized IP. No input field contents.
Purpose: Identify friction points and drop-off in the onboarding and booking flow.
Legal basis: Art. 6(1)(a) GDPR (consent). No processing occurs before consent.
Retention: Up to 13 months, then automatic deletion.
Third-country transfer: Microsoft is certified under the EU-US Data Privacy Framework; standard contractual clauses in place.
Privacy policy: https://privacy.microsoft.com/en-us/privacystatement
Sentry (Error monitoring)
Provider: Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Sentry automatically captures technical errors so we can fix issues quickly. Personal data in error messages is largely scrubbed automatically.
Data processed: Error stack traces, technical browser/device info, IP address, user ID (if logged in) for correlation.
Purpose: Error identification, stability and security monitoring.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation).
Retention: 90 days, then automatic deletion.
Third-country transfer: Sentry is certified under the EU-US Data Privacy Framework; SCC + DPA in place.
Privacy policy: https://sentry.io/privacy/
Google Ads (Marketing, optional)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
If you consent to "Marketing cookies", we use Google Ads conversion tracking to measure ad effectiveness. Without consent, no script loads and no cookie is set.
Data processed: Cookie ID, IP address, conversion events (e.g., signup).
Purpose: Measuring ad performance, re-marketing.
Legal basis: Art. 6(1)(a) GDPR (consent).
Retention: Up to 540 days per Google default settings.
Third-country transfer: Google LLC is certified under the EU-US Data Privacy Framework.
Privacy policy: https://policies.google.com/privacy
Resend (Email delivery)
Provider: Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
Resend sends our transactional emails (booking confirmations, payment receipts, account emails). Content is processed only for delivery.
Data processed: Email address, name, email content, delivery status.
Purpose: Sending contractually necessary emails to you as a user/customer.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Retention: Delivery logs for up to 30 days.
Third-country transfer: SCC + DPA in place.
Privacy policy: https://resend.com/legal/privacy-policy
Your choice, revocable at any time
You have the right to withdraw your consent at any time with effect for the future. You can reach the cookie banner by clearing the "cookie-consent" entry from your browser localStorage, or contact us at the email above. We are working on a settings page for managing your consents conveniently.
This privacy policy was last updated on 7/18/2026.
If you have any questions, please contact: info@eazybooking.de