Privacy Policy

Effective 1 October 2026

This Privacy Policy explains how Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland, NIP 8992994343 (we, us) processes personal data when you use WonderBy: our websites, mobile apps, booking links and related services (the Platform). It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and the privacy laws of US states such as California.

In short: we use your data to run bookings and the Platform, we do not sell it, optional analytics and advertising cookies stay off until you agree, and you can download or delete your data from your profile at any time.

1. Who is responsible for your data

The controller is Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland, NIP 8992994343. For any privacy question or request, write to [email protected]. We have not appointed a data protection officer because the law does not require one for our processing; the address above reaches the people responsible for data protection.

2. Our two roles: controller and processor

We are the controller of your WonderBy account, the Marketplace, reviews, billing of Businesses, security and communications we send about the Platform.

We are a processor when a Business uses WonderBy to manage its own clients: its client list (including clients it adds or imports), the notes it keeps, its calendar, and the reminders and campaigns it sends. In that case the Business is the controller and decides how the data is used; we process it only on the Business's instructions under our Data Processing Agreement.

So if a salon added you to its client base or sent you a message, please contact that salon first. If you write to us instead, we will forward your request to the Business and help it respond.

3. What data we collect

CategoryExamplesSource
Account dataPhone number, first and last name, optional email, gender, profile photo, language, time zoneYou
Sign-in and security dataOne-time SMS codes, session tokens, IP address, device and browser type, a device identifier computed in your browser for session security, sign-in timesYou, your device
Booking dataBusinesses, services, Team members, dates and times, status, cancellations, comments you addYou, the Business
ReviewsRating, text, date, your first name and last-name initial as shown publicly, replies by the BusinessYou, the Business
Client records kept by BusinessesThe name a Business uses for you, visit history and spend, notes, social media links, marketing opt-out, blocked statusThe Business (we act as processor)
Business dataBusiness name, category, description, addresses and map coordinates, services and prices, photos, opening hours, Team members, settings, countryBusiness owners and Team members
Billing dataPlan, billing interval, number of Team members, purchases of SMS packages, payment status, Stripe customer identifier, invoices. We never receive full card numbers.Businesses, Stripe
MessagesSMS, email and push notifications sent through the Platform and delivery status; Instagram messages when a Business connects the AI assistantThe Platform, the Business, the sender
AI inputsPhotos of price lists, service descriptions and messages sent to AI featuresBusinesses, senders
LocationThe location you search around; approximate country derived from your IP address; your device location only if you allow it in the appYou, your device, Cloudflare
Usage and technical dataPages visited, errors, performance data, logs of requests to our serversYour device
SupportMessages you send us by email, chat, Telegram or ViberYou

You do not have to give us your data, but we cannot create an account without a phone number and name, and we cannot process a booking without the booking details.

4. Why we use your data and on what legal basis

PurposeLegal basis (GDPR Art. 6(1))
Creating and securing your account, signing you in with SMS codes(b) contract; (f) legitimate interest in preventing account takeover
Making, changing and cancelling bookings, and sending booking confirmations and reminders(b) contract
Showing Businesses on the Marketplace and publishing reviews(b) contract; (f) legitimate interest in providing reliable information to Clients
Running Business accounts, plans, trials and SMS packages(b) contract
Invoicing, accounting and tax records(c) legal obligation
Customer support and complaints(b) contract; (f) legitimate interest
Moderation, handling reports of illegal content, preventing fraud, spam, fake reviews and repeated abuse after account deletion(c) legal obligation (EU Digital Services Act); (f) legitimate interest in a safe Platform
Error monitoring, security logs and service improvement(f) legitimate interest in a secure and working Platform
Analytics (Google Analytics) and advertising measurement (Meta pixel) cookies(a) consent, which you can withdraw at any time
Service announcements, such as changes to these documents or your plan(b) contract; (c) legal obligation
Establishing, exercising or defending legal claims(f) legitimate interest

Where we rely on legitimate interests, we have weighed them against your rights. You can object to such processing at any time (see section 10). We do not send you marketing messages from WonderBy without your consent.

5. Sensitive data

We do not ask for special categories of data such as health data. However, some services (for example cosmetology or massage) may lead a Business to note allergies or contraindications about a client. Businesses may only record such information where they have a legal basis, usually your explicit consent, and are responsible for it as controllers. Please do not include sensitive information in booking comments or reviews.

6. Who receives your data

Businesses you book with receive the data needed for the booking (name, phone number, booking details, comments) and your booking history with them. Other users see your public review with your first name and last-name initial. Team members of a Business see the bookings and clients they work with.

We use the following service providers. They process data on our behalf under data processing agreements, except where noted as independent controllers.

ProviderPurposeLocation and safeguard
Amazon Web Services EMEAHosting, file storage, cache, logsEU (Frankfurt)
PlanetScaleDatabase hostingEU/USA; EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs)
CloudflareContent delivery, protection against attacks, country detectionGlobal network; DPF and SCCs
Twilio (including SendGrid)SMS and email deliveryUSA; DPF and SCCs
AlphaSMS, OmnicellSMS delivery, including Business campaignsUkraine; SCCs
OneSignalPush notifications in the appsUSA; DPF and SCCs
StripePayments for Business plans. Where Stripe acts as merchant of record, it is an independent controller for the payment.Ireland/USA; DPF and SCCs
OpenAIAI features (price-list import, suggested content, Instagram assistant)USA; SCCs. Data sent via the API is not used to train models.
Meta Platforms IrelandInstagram and Messenger features connected by a Business; Meta pixel only with your consentIreland/USA; DPF and SCCs
Google IrelandMaps on the Marketplace, Google Analytics only with your consent, app linksIreland/USA; DPF and SCCs
Functional Software (Sentry)Error monitoring, with personal data filtered outUSA; DPF and SCCs
HelpCrunchSupport chat, loaded only when you open itEU/USA; SCCs
OpenStreetMap Foundation (Nominatim)Converting Business addresses to map coordinatesUnited Kingdom; adequacy decision
Apple, GoogleApp distribution through their stores (independent controllers)USA; DPF

We may also disclose data to courts, law enforcement and authorities when the law requires it, to professional advisers under confidentiality, and to a buyer or successor if the Platform is sold or reorganised, in which case this Policy continues to protect your data. Our support staff can access an account only to resolve an issue you raised or to investigate abuse, and every such access is logged.

7. International transfers

Our main infrastructure is in the European Union. Some providers are in the United States, Ukraine or other countries outside the European Economic Area. Where a country does not have an EU adequacy decision, we rely on the European Commission's Standard Contractual Clauses, or for certified US companies the EU-US Data Privacy Framework, together with additional safeguards such as encryption in transit. You can ask us for a copy of the relevant safeguards.

8. Cookies and similar technologies

We use a small number of essential cookies and browser storage entries to keep you signed in, remember your language and your privacy choices. Optional analytics and advertising technologies load only after you allow them in the cookie banner, and you can change your choice at any time with Your privacy choices at the bottom of every page. Your choice is kept for 180 days, after which we ask again. If your browser sends a Global Privacy Control signal, we treat it as a refusal of advertising cookies.

NameTypePurposeDuration
wonderbyRefreshTokenEssential cookie (HTTP-only)Keeps you signed inUntil you sign out, up to 60 days
wonderbyLocaleEssential cookieRemembers the language you chose1 year
wonderbyConsentDeniedEssential cookieRemembers a refusal if your browser cannot store your choice180 days
wonderby.consent.v1Essential local storageStores your cookie choices180 days
wonderby.auth.userEssential local storageShows your name and photo without reloading themUntil you sign out
wonderby.billing.*Essential local/session storageCompletes a plan purchase you startedUntil the purchase finishes
Device identifierComputed in memory, not storedBinds your session to your device to prevent session theftNot stored in your browser
_ga, _ga_*Analytics cookies (Google Analytics)Counts visits and selected actions, with IP-based data minimisedUp to 2 years, only with consent
_fbp, _fbcAdvertising cookies (Meta pixel)Measures visits for advertisingUp to 90 days, only with consent
HelpCrunch storageFunctionalRuns the support chat after you open itSet by HelpCrunch

Google Maps on the Marketplace connects to Google to display the map, which reveals your IP address to Google. Error monitoring (Sentry) does not use cookies. We do not respond to the legacy Do Not Track signal, because there is no common standard for it, but we honour Global Privacy Control as described above.

9. How long we keep data

DataRetention
Account and profileUntil you delete your account
One-time sign-in codes24 hours
Sessions and their IP address and device dataUntil they expire (up to 60 days) or you sign out
Content of SMS, email and push messages90 days; delivery records are kept for billing and dispute purposes
Last IP address and activity time on your accountUp to 12 months of inactivity
Booking historyAs long as the Business that holds it keeps it; after you delete your account, bookings stay with the Business without your identity
AI request logs30 days
Instagram assistant conversations12 months
Server logs30 days
Invoices, payments and accounting records5 years from the end of the year in which the tax obligation arose (Polish tax law)
A one-way cryptographic hash of the phone number of a deleted account24 months, only to prevent repeated abuse such as fake bookings
Data needed for a pending dispute or legal claimUntil it is resolved

When you delete your account, we erase or irreversibly anonymise your name, phone number, email, photo, sessions, sign-in codes, activity records and message contents, remove your reviews, remove your details from Businesses' client lists and cancel your upcoming bookings. Backup copies are deleted automatically as the backup cycle rotates and are never used to restore deleted accounts.

10. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy;
  • portability: receive your data in a machine-readable format (use Download my data in your profile);
  • rectification of inaccurate data (most of it you can edit in your profile);
  • erasure (use Delete account in your profile);
  • restriction of processing;
  • object to processing based on legitimate interests, and at any time to direct marketing;
  • withdraw consent at any time, without affecting processing carried out before withdrawal (use Your privacy choices for cookies);
  • lodge a complaint with a supervisory authority. Our lead authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl. You can also complain to the authority in the country where you live or work.

Send other requests to [email protected] from the phone number or email linked to your account, or tell us how to verify you. We answer within one month; for complex requests this may be extended by two further months, and we will tell you why. Requests are free unless they are manifestly unfounded or excessive. If your request concerns data a Business holds about you, see section 2.

11. Additional information for US residents

This section applies to residents of California and other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others).

Categories we collected in the last 12 months: identifiers (name, phone number, email, IP address, device and account identifiers); commercial information (bookings, plans and purchases); internet or other network activity (usage, errors, and analytics only with consent); approximate geolocation (from IP address) and location you choose to search around; audio or visual information (profile and business photos); professional information (for Business accounts); and the content of messages sent through the Platform. We collect them from the sources and for the purposes described in sections 3 and 4, disclose them to the categories of recipients in section 6, and keep them as described in section 9.

Sensitive personal information: your account sign-in data is protected by one-time codes; we use it and any precise location you share only to provide the Platform, and not to infer characteristics about you.

We do not sell your personal information and do not knowingly sell or share personal information of consumers under 16. If you allow advertising cookies, our use of the Meta pixel may be considered sharing for cross-context behavioural advertising. You can opt out at any time with Your privacy choices at the bottom of every page, and we honour the Global Privacy Control signal as an opt-out.

Your rights: to know and access the personal information we hold, to correct it, to delete it, to receive a portable copy, to opt out of sale, sharing, targeted advertising and profiling, and to limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. You may use an authorised agent, whose authority we may ask to verify. If we refuse a request, you may appeal by replying to our decision; if the appeal is denied you may contact your state attorney general.

To exercise your rights, email [email protected] or use the self-service tools in your profile.

12. Children

The Platform is not directed at children. You must be at least 16 to create an account. We do not knowingly collect personal data from children under 13 (or under 16 in the EU without parental consent). If you believe a child has given us personal data, contact us and we will delete it.

13. How we protect data

We use encryption in transit (TLS) for all connections, encrypted sign-in handshakes, HTTP-only cookies for sessions, short-lived access tokens, rate limits on sign-in attempts, role-based access for our staff, audit logs of support access, removal of personal data from error reports and logs, and infrastructure hosted in the EU with providers that encrypt stored data. No system is completely secure; if a personal data breach is likely to result in a high risk to you, we will inform you without undue delay.

14. Automated decisions and AI

We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. Marketplace ranking (see our Terms) and automated spam and abuse checks are automated, and a person reviews any decision to suspend an account. AI features used by Businesses process the content submitted to them to generate suggestions or replies; automated Instagram replies are labelled as coming from an AI assistant.

15. Changes to this Policy

We will update this Policy when our processing changes. We will tell you about material changes in advance by email, in the app or on the website. The date at the top shows when it last changed.

16. Contact

Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland. NIP: 8992994343. Email: [email protected].