Privacy Policy
This Privacy Policy explains what data the InviBook application collects, how it is used, with whom it is shared, and what your rights are. It applies to our website invibook.app, the backoffice (bo.invibook.app), and the public booking pages you create through the service, as well as the InviBook mobile app for Android.
1. Who we are
The InviBook service is provided and operated by:
2. Data controller and processor
The roles depend on whose data is involved:
- Account owner (business) data — for this data, Invictus Softwares d.o.o. is the data controller.
- Data of clients who book an appointment with a business — for this data, that business is the controller, and InviBook acts as a processor on behalf of and under the instructions of that business.
3. What data we collect
- Account data: first and last name, email, phone number, business name and activity, working hours, services, and prices. Passwords are stored solely as a cryptographic hash, never as plain text.
- Booking data: the selected service, staff member, date and time, status, and any notes attached to the booking.
- Client data: the name, email, and/or phone number the client provides when booking an appointment.
- Payment data: where charging or deposits are active, transactions are handled by authorized payment processors. We do not store full payment card numbers.
- Mobile app data: if you use the Android app, we store a device messaging identifier (Firebase registration token), the platform name and your device name (manufacturer and model) alongside your sign-in, so we can deliver push notifications and show you which devices are signed in. The app does not collect location, contacts or device content.
- Technical data: IP address, device and browser type, log records, and cookies.
- Google account data: only if you connect your Google Calendar yourself — see section 5.
4. How we use data
- to provide and maintain the online booking service;
- to send automated confirmations and reminders (email, WhatsApp, SMS) to clients;
- to process payments and deposits, where active;
- for customer support and communication with you;
- for security, prevention of abuse, and troubleshooting;
- to improve the service and analyze usage;
- to comply with legal obligations.
5. Google user data (Google Calendar integration)
Connecting your Google Calendar is optional and only happens when you start it yourself from the backoffice. This section describes, specifically for Google user data, what we access, how we use it, whether we share it, how we protect it, and how long we keep it. For Google user data it takes precedence over the general sections of this policy.
What Google user data we access. With your authorization we request only the following Google scopes, and nothing more:
- .../auth/calendar.events — to create, update and delete calendar events for bookings made through InviBook, and to add a Google Meet link for online appointments;
- .../auth/calendar.freebusy — to read your free/busy times so we do not offer slots when you are already busy;
- .../auth/calendar.calendarlist.readonly — to list your calendars so you can choose which one to sync;
- openid, email — to identify which Google account is connected, shown in your backoffice.
We do not request calendar.readonly, and we never read the title, description, attendees or contents of your existing events.
How we use Google user data. We use it solely to operate the booking feature: to block times when you are busy so customers cannot double-book you, and to create, reschedule or cancel the calendar event (with a Meet link where applicable) that corresponds to a booking. We do not use Google user data for advertising, and we do not use it to develop, improve or train generalized artificial-intelligence or machine-learning models.
What we store. From your calendar we store only busy time intervals (start and end times) — never event titles, attendees or content. Your Google access and refresh tokens are stored encrypted so the calendar can stay in sync.
Sharing and disclosure. We do not sell, share, transfer or disclose Google user data to any third party. It is not shared with advertisers, with other InviBook customers, or across any other service. The only exception is disclosure required by law or valid legal process.
How we protect it. Google user data is protected in transit with HTTPS/TLS and at rest with encryption of sensitive fields (including your Google tokens), access controls that limit access to authorized personnel only, and standard operational-security practices.
Retention and deletion. We keep Google user data only for as long as your Google Calendar stays connected. You can disconnect it at any time from the backoffice; on disconnection we delete the stored tokens and busy intervals. The same data is deleted when your InviBook account is closed. You can also review or revoke InviBook's access at any time from your Google account permissions page, which invalidates the tokens we hold.
Limited Use. InviBook's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. Cookies and analytics
We use necessary cookies to operate the site and, with your consent where applicable, analytics and advertising tools: Google Analytics, Google Ads, and Meta Pixel. These may set their own cookies. You can control cookie settings in your browser.
7. Data sharing and processors
We do not sell your data. We share it only with trusted service providers who act on our behalf and under our instructions: hosting and infrastructure, sending email, WhatsApp, and SMS messages, payment processors, Google (calendar, analytics and Firebase Cloud Messaging for push notifications in the mobile app), and Meta (ad analytics). We may also disclose data when required by law or a competent authority.
8. Data retention
We retain data for as long as the account is active and for as long as necessary for the purposes set out in this policy or as required by statutory retention periods (e.g., accounting). After an account is closed, we delete or anonymize the data within a reasonable time, except for data we are required to retain by law.
9. Security
We apply technical and organizational protection measures: encryption in transit (HTTPS), encryption of sensitive data in the database (e.g., tokens), access control, and regular maintenance. No system is absolutely secure, but we continuously work to protect your data.
10. Your rights
You have the right to access, rectification, erasure, restriction of, and objection to processing, as well as the right to data portability. If you are a client who booked an appointment with a business, please direct your request first to that business as the controller; as the processor, we will assist it in fulfilling the request. You can exercise your rights by writing to [email protected].
11. International data transfers
Some of our processors may process data outside your country. In those cases, we apply appropriate safeguards in accordance with applicable data protection regulations.
12. Children
The service is not intended for persons under 16 years of age, and we do not knowingly collect their data.
13. Changes to this policy
We may update this policy from time to time. We will publish significant changes on this page along with a new update date at the top.
14. Contact
For any questions about privacy and data protection, write to us at [email protected].