Legal

Privacy policy

Last updated September 24, 2026

This explains what information Manito keeps, why, who helps us process it, and how you can have it corrected or deleted. We’ve kept it in plain language; if anything is unclear, ask us.

1.Who we are and our role

Manito Appointments (“Manito”, “we”) runs booking software for businesses that work by appointment.

We handle two kinds of information, and our role differs for each:

  • Your business account. When you sign up and run a business on Manito, we decide how that information is used. For it, we are the controller.
  • Your customers’ details. The names, contact details, notes and bookings a business keeps in Manito belong to that business. We store and process them only to provide the service, on the business’s instructions. For that information, the business is the controller and we are its processor.

If you booked with a business and want to know what it holds about you, ask the business first. It can see, correct and delete your details directly.

2.What we collect

About people who run or work at a business:

  • Name, email address and, if you sign in with Google or Apple, the account identifier they give us.
  • The businesses you belong to and your role in each.
  • Plan and billing status. Card details go straight to our payment provider; we never see or store them.

About a business’s customers, as entered by the business or by the customer when booking:

  • Name, phone number and email address.
  • Appointments and classes booked, attended or cancelled.
  • Notes and photos the business chooses to add. Photos are never public; only signed-in staff of that business can open them.
  • A record of the reminders and confirmations sent, so the same message isn’t sent twice.

We don’t use advertising or analytics trackers, and we don’t buy or sell personal information.

3.How we use it

  • To let you sign in and keep your account secure.
  • To show each business its own calendar, customers and bookings, and nobody else’s.
  • To send the booking confirmations and reminders a business has switched on, by email or text message.
  • To charge for paid plans and keep the records the law requires for payments.
  • To fix problems, using technical logs that are kept for a short time.

Our legal bases are the contract with you (to run the service you signed up for), legal obligations (such as keeping billing records), and our legitimate interest in keeping the service secure and working.

4.Who else handles it

A few companies process information for us, each only for the job listed:

  • Google Firebase — signing in, including with Google or Apple.
  • Stripe — taking payment for paid plans.
  • Mailgun, using its EU region — sending emails.
  • SMS.to — sending text-message reminders.
  • Cloudflare — delivering the site securely and protecting it from attacks.

Some of these companies are based outside the European Economic Area. Where information leaves it, the transfer is covered by the safeguards the law requires, such as the European Commission’s standard contractual clauses.

5.Cookies and local storage

We set one cookie, and only after you sign in. It tells the site you’re signed in so it can take you straight to your calendar. It lasts up to 14 days and is removed when you log out.

Your browser also remembers a few preferences on your device, such as light or dark mode and the calendar view you last used. None of this is shared with anyone, and there are no advertising cookies, so there is nothing to accept or decline.

6.How long we keep it

  • Account information, for as long as you have an account.
  • A business’s customer details, until the business deletes them or closes its account.
  • Billing records, for as long as tax and accounting law requires.
  • Technical logs, for a short period needed to investigate problems.

7.Your rights

You can ask to see the information we hold about you, have it corrected or deleted, receive a copy in a common format, or object to how we use it. You can also complain to your data protection authority; in Cyprus, that is the Commissioner for Personal Data Protection.

If a business holds your details as its customer, send the request to the business. We’ll help it respond.

8.Security

Every connection is encrypted. Each business’s data is kept separate from every other business’s, and staff only see the business they belong to. No system is perfectly secure, but if a breach affects your information, we’ll tell you and the authorities as the law requires.

9.Changes to this policy

If we change what we collect or who handles it, we’ll update this page and its date. For significant changes, we’ll also tell account holders by email before they take effect. Read it together with our terms of service.

10.Contact us

A dedicated address for privacy requests will be published here before Manito opens to the public.

If you booked with a business, contact the business directly: it can see, correct and delete your details itself.