Privacy Policy

Last updated: 3 September 2026

This policy is provided for transparency and is not legal advice. Tibo is currently operated by an individual in Slovenia while a formal business entity is being established; the controller details will be updated when it is registered.

This policy explains what personal data the Tibo online booking service collects, why, and what rights you have. The data controller is Tibo, contactable at info.tibobooking@gmail.com.

1. What we collect

Booking details you enter: your name, email address, phone number, and the service, staff member, date and time you choose.

If you message TIBO, our AI booking assistant: the content of that conversation, and any specific fact or preference (like a preferred staff member) you or the shop ask it to remember for next time.

Photos a shop chooses to upload: its own shop photos, and photos of its staff members.

Technical data needed to run the service safely: your IP address (used only for short-term rate limiting to prevent spam bookings) and small cookies that remember your language, theme, and — for shop owners — a signed dashboard session.

2. Why we use it (legal bases)

To create and manage your appointment, and let the shop contact you about it — this is necessary to perform the booking you request (contract).

To keep the service secure and prevent abuse — this is our legitimate interest. We do not use your data for advertising and we do not sell it.

3. Cookies

We use only functional cookies: your chosen language, your light/dark theme preference, and an authenticated session cookie for the owner dashboard. There are no third-party advertising or tracking cookies.

4. Who we share it with

The shop you book with, so it can prepare for and honour your appointment.

Service providers that process data on our behalf as processors: Vercel (hosting — runs the application itself, so it processes booking data in the course of handling each request, not just IP addresses and logs), Supabase (our database and file storage provider, storing data in the EU (Frankfurt) region), Resend (which delivers your booking confirmation, reminder and cancellation emails), Anthropic (which powers TIBO, our AI booking assistant — if you message TIBO, that conversation is sent to Anthropic to generate a reply), and Twilio (which can deliver an SMS alert to a shop's owner when your conversation is escalated for their personal attention — that message may include your name and a short description of the issue).

If a shop has connected its own Gmail or Google Calendar, Google also processes related data (such as booking confirmations sent from that inbox, or calendar events) on that shop's behalf — this only happens for shops that choose to connect those accounts.

Our processors act under contract and may not use your data for their own purposes. We do not sell or otherwise share your personal data.

5. How long we keep it

We keep booking records only as long as needed to run the service and meet legal or accounting obligations. Booking data — your name, email and phone number — is deleted or anonymised 12 months after the appointment date.

Facts or preferences TIBO remembers about you from a conversation are kept until you or the shop asks us to delete them, or automatically removed after 12 months with no activity between you and that shop.

You can ask us to delete your data sooner by emailing info.tibobooking@gmail.com.

6. Where your data is stored

The site is hosted on Vercel; data is stored on Supabase infrastructure in the EU (Frankfurt) region, and email is delivered through Resend. Where a processor operates outside the EEA — including Vercel's application servers, Anthropic, and Twilio, none of which are restricted to the EEA, and Google if a shop has connected Gmail or Calendar — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

7. Your rights

You can ask to access, correct, delete, restrict, or export your personal data, and object to certain processing. To exercise these, contact us at info.tibobooking@gmail.com.

If you are in the EU and believe your data is mishandled, you may complain to your supervisory authority — in Slovenia, the Information Commissioner (Informacijski pooblaščenec).

8. Security

Access to the database is restricted to our server using secret keys that are never exposed to your browser, row-level security is enabled on every table, and traffic is encrypted in transit. No system is perfectly secure, but we take reasonable measures to protect your data.

9. Changes and contact

We may update this policy; the date at the top shows the latest revision. Questions or requests? Contact Tibo at info.tibobooking@gmail.com.

Privacy Policy — Tibo