Privacy Policy
Effective 1 October 2026
This Privacy Policy explains how Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland, NIP 8992994343 (we, us) processes personal data when you use WonderBy: our websites, mobile apps, booking links and related services (the Platform). It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and the privacy laws of US states such as California.
In short: we use your data to run bookings and the Platform, we do not sell it, optional analytics and advertising cookies stay off until you agree, and you can download or delete your data from your profile at any time.
1. Who is responsible for your data
The controller is Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland, NIP 8992994343. For any privacy question or request, write to [email protected]. We have not appointed a data protection officer because the law does not require one for our processing; the address above reaches the people responsible for data protection.
2. Our two roles: controller and processor
We are the controller of your WonderBy account, the Marketplace, reviews, billing of Businesses, security and communications we send about the Platform.
We are a processor when a Business uses WonderBy to manage its own clients: its client list (including clients it adds or imports), the notes it keeps, its calendar, and the reminders and campaigns it sends. In that case the Business is the controller and decides how the data is used; we process it only on the Business's instructions under our Data Processing Agreement.
So if a salon added you to its client base or sent you a message, please contact that salon first. If you write to us instead, we will forward your request to the Business and help it respond.
3. What data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Phone number, first and last name, optional email, gender, profile photo, language, time zone | You |
| Sign-in and security data | One-time SMS codes, session tokens, IP address, device and browser type, a device identifier computed in your browser for session security, sign-in times | You, your device |
| Booking data | Businesses, services, Team members, dates and times, status, cancellations, comments you add | You, the Business |
| Reviews | Rating, text, date, your first name and last-name initial as shown publicly, replies by the Business | You, the Business |
| Client records kept by Businesses | The name a Business uses for you, visit history and spend, notes, social media links, marketing opt-out, blocked status | The Business (we act as processor) |
| Business data | Business name, category, description, addresses and map coordinates, services and prices, photos, opening hours, Team members, settings, country | Business owners and Team members |
| Billing data | Plan, billing interval, number of Team members, purchases of SMS packages, payment status, Stripe customer identifier, invoices. We never receive full card numbers. | Businesses, Stripe |
| Messages | SMS, email and push notifications sent through the Platform and delivery status; Instagram messages when a Business connects the AI assistant | The Platform, the Business, the sender |
| AI inputs | Photos of price lists, service descriptions and messages sent to AI features | Businesses, senders |
| Location | The location you search around; approximate country derived from your IP address; your device location only if you allow it in the app | You, your device, Cloudflare |
| Usage and technical data | Pages visited, errors, performance data, logs of requests to our servers | Your device |
| Support | Messages you send us by email, chat, Telegram or Viber | You |
You do not have to give us your data, but we cannot create an account without a phone number and name, and we cannot process a booking without the booking details.
4. Why we use your data and on what legal basis
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Creating and securing your account, signing you in with SMS codes | (b) contract; (f) legitimate interest in preventing account takeover |
| Making, changing and cancelling bookings, and sending booking confirmations and reminders | (b) contract |
| Showing Businesses on the Marketplace and publishing reviews | (b) contract; (f) legitimate interest in providing reliable information to Clients |
| Running Business accounts, plans, trials and SMS packages | (b) contract |
| Invoicing, accounting and tax records | (c) legal obligation |
| Customer support and complaints | (b) contract; (f) legitimate interest |
| Moderation, handling reports of illegal content, preventing fraud, spam, fake reviews and repeated abuse after account deletion | (c) legal obligation (EU Digital Services Act); (f) legitimate interest in a safe Platform |
| Error monitoring, security logs and service improvement | (f) legitimate interest in a secure and working Platform |
| Analytics (Google Analytics) and advertising measurement (Meta pixel) cookies | (a) consent, which you can withdraw at any time |
| Service announcements, such as changes to these documents or your plan | (b) contract; (c) legal obligation |
| Establishing, exercising or defending legal claims | (f) legitimate interest |
Where we rely on legitimate interests, we have weighed them against your rights. You can object to such processing at any time (see section 10). We do not send you marketing messages from WonderBy without your consent.
5. Sensitive data
We do not ask for special categories of data such as health data. However, some services (for example cosmetology or massage) may lead a Business to note allergies or contraindications about a client. Businesses may only record such information where they have a legal basis, usually your explicit consent, and are responsible for it as controllers. Please do not include sensitive information in booking comments or reviews.
6. Who receives your data
Businesses you book with receive the data needed for the booking (name, phone number, booking details, comments) and your booking history with them. Other users see your public review with your first name and last-name initial. Team members of a Business see the bookings and clients they work with.
We use the following service providers. They process data on our behalf under data processing agreements, except where noted as independent controllers.
| Provider | Purpose | Location and safeguard |
|---|---|---|
| Amazon Web Services EMEA | Hosting, file storage, cache, logs | EU (Frankfurt) |
| PlanetScale | Database hosting | EU/USA; EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) |
| Cloudflare | Content delivery, protection against attacks, country detection | Global network; DPF and SCCs |
| Twilio (including SendGrid) | SMS and email delivery | USA; DPF and SCCs |
| AlphaSMS, Omnicell | SMS delivery, including Business campaigns | Ukraine; SCCs |
| OneSignal | Push notifications in the apps | USA; DPF and SCCs |
| Stripe | Payments for Business plans. Where Stripe acts as merchant of record, it is an independent controller for the payment. | Ireland/USA; DPF and SCCs |
| OpenAI | AI features (price-list import, suggested content, Instagram assistant) | USA; SCCs. Data sent via the API is not used to train models. |
| Meta Platforms Ireland | Instagram and Messenger features connected by a Business; Meta pixel only with your consent | Ireland/USA; DPF and SCCs |
| Google Ireland | Maps on the Marketplace, Google Analytics only with your consent, app links | Ireland/USA; DPF and SCCs |
| Functional Software (Sentry) | Error monitoring, with personal data filtered out | USA; DPF and SCCs |
| HelpCrunch | Support chat, loaded only when you open it | EU/USA; SCCs |
| OpenStreetMap Foundation (Nominatim) | Converting Business addresses to map coordinates | United Kingdom; adequacy decision |
| Apple, Google | App distribution through their stores (independent controllers) | USA; DPF |
We may also disclose data to courts, law enforcement and authorities when the law requires it, to professional advisers under confidentiality, and to a buyer or successor if the Platform is sold or reorganised, in which case this Policy continues to protect your data. Our support staff can access an account only to resolve an issue you raised or to investigate abuse, and every such access is logged.
7. International transfers
Our main infrastructure is in the European Union. Some providers are in the United States, Ukraine or other countries outside the European Economic Area. Where a country does not have an EU adequacy decision, we rely on the European Commission's Standard Contractual Clauses, or for certified US companies the EU-US Data Privacy Framework, together with additional safeguards such as encryption in transit. You can ask us for a copy of the relevant safeguards.
8. Cookies and similar technologies
We use a small number of essential cookies and browser storage entries to keep you signed in, remember your language and your privacy choices. Optional analytics and advertising technologies load only after you allow them in the cookie banner, and you can change your choice at any time with Your privacy choices at the bottom of every page. Your choice is kept for 180 days, after which we ask again. If your browser sends a Global Privacy Control signal, we treat it as a refusal of advertising cookies.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| wonderbyRefreshToken | Essential cookie (HTTP-only) | Keeps you signed in | Until you sign out, up to 60 days |
| wonderbyLocale | Essential cookie | Remembers the language you chose | 1 year |
| wonderbyConsentDenied | Essential cookie | Remembers a refusal if your browser cannot store your choice | 180 days |
| wonderby.consent.v1 | Essential local storage | Stores your cookie choices | 180 days |
| wonderby.auth.user | Essential local storage | Shows your name and photo without reloading them | Until you sign out |
| wonderby.billing.* | Essential local/session storage | Completes a plan purchase you started | Until the purchase finishes |
| Device identifier | Computed in memory, not stored | Binds your session to your device to prevent session theft | Not stored in your browser |
| _ga, _ga_* | Analytics cookies (Google Analytics) | Counts visits and selected actions, with IP-based data minimised | Up to 2 years, only with consent |
| _fbp, _fbc | Advertising cookies (Meta pixel) | Measures visits for advertising | Up to 90 days, only with consent |
| HelpCrunch storage | Functional | Runs the support chat after you open it | Set by HelpCrunch |
Google Maps on the Marketplace connects to Google to display the map, which reveals your IP address to Google. Error monitoring (Sentry) does not use cookies. We do not respond to the legacy Do Not Track signal, because there is no common standard for it, but we honour Global Privacy Control as described above.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| One-time sign-in codes | 24 hours |
| Sessions and their IP address and device data | Until they expire (up to 60 days) or you sign out |
| Content of SMS, email and push messages | 90 days; delivery records are kept for billing and dispute purposes |
| Last IP address and activity time on your account | Up to 12 months of inactivity |
| Booking history | As long as the Business that holds it keeps it; after you delete your account, bookings stay with the Business without your identity |
| AI request logs | 30 days |
| Instagram assistant conversations | 12 months |
| Server logs | 30 days |
| Invoices, payments and accounting records | 5 years from the end of the year in which the tax obligation arose (Polish tax law) |
| A one-way cryptographic hash of the phone number of a deleted account | 24 months, only to prevent repeated abuse such as fake bookings |
| Data needed for a pending dispute or legal claim | Until it is resolved |
When you delete your account, we erase or irreversibly anonymise your name, phone number, email, photo, sessions, sign-in codes, activity records and message contents, remove your reviews, remove your details from Businesses' client lists and cancel your upcoming bookings. Backup copies are deleted automatically as the backup cycle rotates and are never used to restore deleted accounts.
10. Your rights
Under the GDPR you have the right to:
- access your data and get a copy;
- portability: receive your data in a machine-readable format (use Download my data in your profile);
- rectification of inaccurate data (most of it you can edit in your profile);
- erasure (use Delete account in your profile);
- restriction of processing;
- object to processing based on legitimate interests, and at any time to direct marketing;
- withdraw consent at any time, without affecting processing carried out before withdrawal (use Your privacy choices for cookies);
- lodge a complaint with a supervisory authority. Our lead authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl. You can also complain to the authority in the country where you live or work.
Send other requests to [email protected] from the phone number or email linked to your account, or tell us how to verify you. We answer within one month; for complex requests this may be extended by two further months, and we will tell you why. Requests are free unless they are manifestly unfounded or excessive. If your request concerns data a Business holds about you, see section 2.
11. Additional information for US residents
This section applies to residents of California and other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others).
Categories we collected in the last 12 months: identifiers (name, phone number, email, IP address, device and account identifiers); commercial information (bookings, plans and purchases); internet or other network activity (usage, errors, and analytics only with consent); approximate geolocation (from IP address) and location you choose to search around; audio or visual information (profile and business photos); professional information (for Business accounts); and the content of messages sent through the Platform. We collect them from the sources and for the purposes described in sections 3 and 4, disclose them to the categories of recipients in section 6, and keep them as described in section 9.
Sensitive personal information: your account sign-in data is protected by one-time codes; we use it and any precise location you share only to provide the Platform, and not to infer characteristics about you.
We do not sell your personal information and do not knowingly sell or share personal information of consumers under 16. If you allow advertising cookies, our use of the Meta pixel may be considered sharing for cross-context behavioural advertising. You can opt out at any time with Your privacy choices at the bottom of every page, and we honour the Global Privacy Control signal as an opt-out.
Your rights: to know and access the personal information we hold, to correct it, to delete it, to receive a portable copy, to opt out of sale, sharing, targeted advertising and profiling, and to limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. You may use an authorised agent, whose authority we may ask to verify. If we refuse a request, you may appeal by replying to our decision; if the appeal is denied you may contact your state attorney general.
To exercise your rights, email [email protected] or use the self-service tools in your profile.
12. Children
The Platform is not directed at children. You must be at least 16 to create an account. We do not knowingly collect personal data from children under 13 (or under 16 in the EU without parental consent). If you believe a child has given us personal data, contact us and we will delete it.
13. How we protect data
We use encryption in transit (TLS) for all connections, encrypted sign-in handshakes, HTTP-only cookies for sessions, short-lived access tokens, rate limits on sign-in attempts, role-based access for our staff, audit logs of support access, removal of personal data from error reports and logs, and infrastructure hosted in the EU with providers that encrypt stored data. No system is completely secure; if a personal data breach is likely to result in a high risk to you, we will inform you without undue delay.
14. Automated decisions and AI
We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. Marketplace ranking (see our Terms) and automated spam and abuse checks are automated, and a person reviews any decision to suspend an account. AI features used by Businesses process the content submitted to them to generate suggestions or replies; automated Instagram replies are labelled as coming from an AI assistant.
15. Changes to this Policy
We will update this Policy when our processing changes. We will tell you about material changes in advance by email, in the app or on the website. The date at the top shows when it last changed.
16. Contact
Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland. NIP: 8992994343. Email: [email protected].