Legal
Privacy Policy
Last updated · version 1.1
The English text is a translation of the Lithuanian original; in case of conflict the Lithuanian version prevails.
1.Who processes your data
Your personal data is processed by Gloumi as the data controller. The data is processed in accordance with the General Data Protection Regulation (GDPR).
2.What data we collect
We only collect the data needed for the app to work:
- Account data: name, username, email address, phone number (optional), profile photo.
- Master data: service list, prices, working hours, city, portfolio photos.
- Booking data: the chosen service, date, time, status and deposit information.
- Content: Stories, posts, reviews and chat messages.
- Location data: approximate or precise location – only if you grant permission, and only to find nearby masters.
- Technical data: device type, OS version, push notification token, crash reports.
3.Why and on what legal basis
We process data for the following purposes and legal bases:
- Performance of a contract – account administration, bookings, payments.
- Consent – location, notifications, marketing messages. You can withdraw consent at any time.
- Legitimate interest – security, fraud prevention, improving the service.
- Legal obligation – accounting and tax requirements.
5.A master’s private notes
A master can write private notes about a client (for example colour formulas or allergies). These notes are visible only to the master who wrote them. The master is responsible for not keeping excessive or sensitive data in them without your consent.
6.How long we keep data
- Account data – while the account is active, and for 30 days after deletion.
- Booking and payment records – up to 10 years (accounting requirements).
- Chat messages – while the account is active or until you delete them.
- Stories – automatically stop being shown after 24 hours.
7.Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- request correction of inaccurate data;
- request erasure of your data (the "right to be forgotten");
- restrict or object to processing;
- transfer your data to another service provider;
- withdraw a consent you have given;
- lodge a complaint with the State Data Protection Inspectorate (vdai.lrv.lt).
8.Data security
Data is transmitted over an encrypted connection (TLS). Account and booking data is stored in the Supabase infrastructure with row-level access rules, and photos and other files in Cloudflare R2 storage. Passwords are stored only as encrypted hashes – we cannot see them.
No system is completely secure, so we recommend using a unique password.
9.Children's privacy
Gloumi is not intended for people under 16. If we learn that data of a person of that age has been collected, we will delete it without delay.