Skip to main content

Privacy Policy

Last updated: August 1, 2026

Explains what personal data Meeti Me collects, why, who receives it, and how you can exercise your rights.

This translation is provided for convenience. The UK version is the binding one.

1. Introduction

This Privacy Policy explains how personal data of users of the Meeti Me platform is processed. The platform is available at meeti.me, in our mobile app, and through a Telegram bot.

Meeti Me does two things:

  • it gives beauty salons and other businesses (the salons) subscription software for managing appointments;
  • it gives consumers a public marketplace where they can find a salon and book an appointment.

We act as an intermediary for bookings. The service itself (a haircut, a manicure, a cosmetic treatment and so on) is provided by the salon, not by us. Payment for the service happens directly between the client and the salon, outside the platform. We do not collect client payments for salon services.

The Policy covers two groups of data subjects:

  • clients (consumers) who use the marketplace to find salons and book appointments;
  • salon representatives who use the subscription service.

The Policy is drafted with regard to the Law of Ukraine "On Personal Data Protection", the Law of Ukraine "On Electronic Commerce" and the Law of Ukraine "On Consumer Rights Protection". The operator is a non-resident supplier of electronic services to Ukraine.

Current version: 2026-08-01. Effective date: 2026-08-01.

2. Who we are and how to reach us

The data controller (володілець персональних даних) is DOKUMENT.PL sp. z o.o., a company registered in the Republic of Poland, address: Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland, tax number (NIP): 5242982251, court register number (KRS): 0001055336.

Contacts:

  • personal data questions and rights requests: meetime.company@gmail.com
  • data protection contact: meetime.company@gmail.com
  • general support: meetime.company@gmail.com

Please note how roles are split. For account data, marketplace operation, subscription payments and technical infrastructure, DOKUMENT.PL sp. z o.o. is the controller. For data that a salon enters about its own clients in its own records (client notes, treatment history, preferences, contraindications the client told the salon), the salon is the controller and we act as a processor, meaning we process that data on the salon's instructions only. If your request concerns data entered by a salon, we will forward it to that salon and let you know.

3. What data we collect

3.1. Account data

Name or nickname, email address, phone number, password stored as a cryptographic hash, interface language, region, time zone, profile picture if you added one. For salon representatives we additionally collect: salon name, address, description, opening hours, list of services and prices, photos, contact details for clients, and billing details for the subscription.

3.2. Booking data

Date and time of the appointment, chosen salon and staff member, chosen service and its duration, booking status (confirmed, cancelled, no-show, completed), history of previous bookings, and any comment you left when booking. A salon may also keep its own notes about you in its records. The salon decides what those notes contain, and we do not use them for our own purposes.

3.3. Payment data

We only process payments from salons for the service subscription. Payments are handled by Stripe. We do not store and do not see the full card number, expiry date or CVC code: you enter these directly in the provider's secure form. We store the payer identifier in the provider's system, the last four digits of the card, card type, amount, currency, date and status of the transaction, and the details needed to issue an invoice.

Consumers do not pay through the platform, so we do not process their payment data.

3.4. Technical data

IP address, browser type and version, operating system, device model, push notification device token, system language, date and time of the request, pages viewed, actions in the interface, referral source, and session identifiers stored in cookies. Server logs record the fact of a request and any errors.

3.5. Consents and settings

We record the fact, date, time and scope of any consent you give (for example, to marketing messages or to analytics cookies), and the fact of its withdrawal. We need this to be able to demonstrate that processing was lawful.

We do not deliberately collect health data. If you voluntarily tell a salon something that may relate to health (for example, an allergy to a particular product), that information goes into the salon's records under the salon's responsibility and on the basis of the separate consent you gave the salon.

4. Legal grounds for processing

We process personal data on the following grounds set out in Article 11 of the Law of Ukraine "On Personal Data Protection":

  • Performance of a contract. Account registration, operation of the marketplace, creating and confirming bookings, providing the subscription service to salons, processing subscription payments, and service notifications about your booking.
  • Consent of the data subject. Marketing messages, analytics cookies, connecting the Telegram bot, and receiving notifications through channels you additionally chose.
  • Compliance with a legal obligation. Retention of accounting and tax records, and responding to lawful requests from competent authorities.
  • Legitimate interest of the controller. Keeping the platform secure, preventing abuse and fraud, defending against automated attacks, keeping technical logs, and establishing or defending legal claims. We rely on this ground only where your rights and interests do not override it.

Providing data is voluntary, but without account data and booking data we cannot deliver the service: we cannot create an account, tell the salon who booked, or send you a confirmation.

5. Purposes of processing

  • creating and maintaining your account, authentication and access recovery;
  • searching for salons, showing available slots, creating, changing and cancelling bookings;
  • passing to the salon the information it needs to receive you as a client;
  • service notifications: booking confirmation, appointment reminder, change or cancellation, changes to the terms of service;
  • providing salons with the subscription service, subscription accounting, invoicing and refunds;
  • user support and handling enquiries;
  • product improvement: analysing which features are used and where users run into difficulty (only if you consented to analytics);
  • marketing communications about platform news and offers (only with separate consent);
  • security: detecting suspicious activity, blocking intrusion attempts, preventing fake bookings;
  • complying with legal requirements and handling claims.

We do not take decisions producing legal effects for you based solely on automated processing, and we do not profile you to evaluate your personality.

6. Notifications and marketing consent

There are two types of messages.

Service (transactional) messages relate to your booking or your account: booking confirmation, a reminder the day before the appointment, notice that the salon cancelled or rescheduled, password change confirmation, subscription charge notice. They are part of the service and are sent on the basis of the contract. You cannot opt out of them while you use the platform, but you can choose the delivery channel.

Marketing messages cover platform news, promotions, new features and offers. They are sent only after your separate, prior and clearly expressed consent (a standalone checkbox that is not pre-ticked). Marketing consent is independent of registration: refusing it does not limit your use of the platform.

Delivery channels: email, SMS, push notifications in the app, and the Telegram bot. Consent is given separately for each channel. The Telegram bot is connected only on your initiative; once connected, we receive your Telegram user identifier so that we can send you messages.

You can withdraw consent at any time and without giving a reason: in the notification settings of your account, via the unsubscribe link at the bottom of an email, with the stop command in the bot, by turning off push notifications in your device settings, or by writing to meetime.company@gmail.com. Withdrawal does not affect the lawfulness of processing carried out before it.

7. Who we share data with

We do not sell personal data and do not share it with third parties for their own marketing purposes.

Salons. When you book an appointment, the salon receives your name, phone number, email address, the chosen service, the date and time, your comment, and the history of your visits to that salon. This is necessary so the salon can receive you and contact you. The salon is an independent controller for the data it then keeps in its own records.

Service providers (processors) acting on our instructions:

| Provider | Purpose | Data categories | | --- | --- | --- | | Stripe | Collecting salon subscription payments, invoicing, fraud prevention | Salon payment details, amount, transaction identifier, technical payment session data | | Amazon SES | Email delivery (service emails and, with consent, marketing emails) | Email address, name, message content, delivery status | | Amazon S3 | File storage: salon photos, profile images, attachments | Uploaded files and their metadata | | PostHog (EU hosting) | Product analytics: how platform features are used. Only with your consent | Pseudonymous visitor identifier, interface events, device type, truncated IP address | | Telegram | Delivering notifications through the bot, if you connected it | Telegram user identifier, message content | | SMS provider | Delivering SMS notifications | Phone number, message text, delivery status |

Each processor is bound by a contract requiring it to process data only on our instructions, keep it confidential, and maintain an appropriate level of protection.

Other recipients. Data may be disclosed to our legal, accounting and audit advisers on a need-to-know basis, and to public authorities where the law requires it and a proper legal basis exists. In a reorganisation or sale of the business, data may pass to the successor; we will inform you in advance.

We do not integrate advertising networks and do not use any third-party advertising or targeting trackers.

8. Cross-border transfers

The operator is a non-resident of Ukraine. This means your data is processed outside Ukraine, primarily in the Republic of Poland and other European Union member states where our infrastructure is located.

Article 29 of the Law of Ukraine "On Personal Data Protection" permits transfers to foreign parties in states that provide adequate protection. Member states of the European Economic Area are among such states.

Our main servers, databases and file storage are located in European Union regions. PostHog product analytics uses EU hosting.

Some providers have entities outside the European Economic Area. For Stripe and Telegram, transfers may involve the United States and other jurisdictions. In those cases protection is ensured by contractual mechanisms, in particular the European Commission's standard contractual clauses, and the volume of transferred data is kept to the minimum necessary.

You can request further information about the safeguards applied by writing to meetime.company@gmail.com.

9. Retention periods

| Category | Period | | --- | --- | | Account data | Until the account is deleted, and 3 years after that to defend against possible claims | | Booking history | 3 years from the date of the appointment | | Salon notes about a client | Determined by the salon; after the salon stops using the platform, up to 90 days, after which the data is deleted or returned to the salon | | Accounting and tax records for subscriptions | 7 years from the end of the relevant reporting year | | Records of consents given and withdrawn | 3 years from withdrawal of consent or the end of processing | | Server technical logs | 12 months | | Analytics data (PostHog) | 24 months | | Support correspondence | 2 years from the last message | | Backups | Up to 90 days, then overwritten on the standard cycle |

If litigation or a supervisory authority inspection is pending, the relevant data is retained until it concludes.

10. Your rights and how to exercise them

Under Article 8 of the Law of Ukraine "On Personal Data Protection" you have the right to:

  • know the source of collection, the location of your data, the purpose of processing, and details of the controller;
  • receive information about the conditions of access to your data, including about third parties it is transferred to;
  • access your personal data;
  • receive, within no more than 30 calendar days, an answer to a request about whether your data is processed and what it contains;
  • submit a reasoned demand to change or destroy data if it is processed unlawfully or is inaccurate;
  • protection against unlawful processing and accidental loss of data;
  • complain to the Ukrainian Parliament Commissioner for Human Rights or to a court;
  • use legal remedies in case of a breach of data protection law;
  • withdraw consent where processing is based on consent;
  • know the mechanism of automated processing of your data;
  • be protected against an automated decision that has legal consequences for you.

Many of these rights you can exercise yourself: you can change your account data, notification and consent settings, review your booking history, or start account deletion in your personal cabinet.

For everything else, write to meetime.company@gmail.com or meetime.company@gmail.com. We reply within 30 calendar days of receiving the request. If a request is complex, we will tell you and give an expected response time. To protect your data we may ask you to confirm your identity, for example by sending the request from the email address on the account. Handling a request is free of charge; for manifestly unfounded or excessive repeated requests we may reasonably refuse.

If a request concerns data a salon entered in its own records, we will forward it to that salon as controller and tell you.

11. Security

We apply organisational and technical measures proportionate to the risks:

  • TLS encryption of traffic for all connections;
  • encryption of data at rest and in backups;
  • passwords stored only as cryptographic hashes and cannot be recovered;
  • access rights separated on a least-privilege basis, with mandatory multi-factor authentication for staff access;
  • logging of actions in administrative interfaces;
  • regular backups and restore testing;
  • rate limiting and protection against automated attacks;
  • vetting of providers before integration and data processing agreements with them;
  • staff training and confidentiality undertakings.

No system is perfectly secure. If an incident occurs that may create a significant risk to your rights, we will notify you without undue delay and describe what happened and what steps to take. Please never share your password or one-time confirmation codes: our staff will never ask for them.

12. Children's data

The platform is not intended for persons under 16. We do not knowingly collect their data or create accounts for them.

If an appointment is booked for a minor, the booking must be made by a parent or other legal representative from their own account.

If we learn that an account was created by a person under 16 without the consent of a legal representative, we will delete that account and the related data. If you are a legal representative and believe your child gave us their data, write to meetime.company@gmail.com.

13. Changes to this Policy

We may update this Policy when platform functionality, our list of providers, or legal requirements change.

The current version is always available at meeti.me with its version number and effective date. We will give advance notice of material changes affecting the scope of processing, the purposes or the list of recipients - by email or through an in-product message - at least 14 days before they take effect.

If a change requires new consent, we will ask for it separately. Continuing to use the platform after the changes take effect means you have been informed of the updated version.

Previous versions are archived and available on request.

14. Complaints to the supervisory authority

If you believe that the processing of your personal data breaches the law, you may complain to the supervisory authority:

  • name: Уповноважений Верховної Ради України з прав людини
  • address: вул. Інститутська 21/8, Київ, 01008, Україна
  • website: ombudsman.gov.ua

You also have the right to go to court to protect your rights and claim damages.

We would appreciate it if you contacted us first at meetime.company@gmail.com or meetime.company@gmail.com: most issues can be resolved quickly without involving an authority.

Governing law: law of Ukraine. Disputes are heard by: courts of Ukraine at the consumer place of residence. This does not deprive a consumer of the right to bring a claim at their place of residence under the Law of Ukraine "On Consumer Rights Protection".

---

The Ukrainian version of this document is the legally binding one. This English text is provided for convenience only; in case of any discrepancy, the Ukrainian version prevails.

    Privacy Policy - Meeti Me