🔒 The most important thing in short
- Your data is processed exclusively for the provision of the app functions – no advertising or marketing profiling.
- Services from Google Firebase and possibly Google Sign-In are used.
- You have access, correction, deletion and objection rights according to GDPR at any time.
- Responsible: Samir Salimovic, Vienna. Contact: privacy@mvm-app.at
- This data protection declaration was originally written in German and is the binding version.
1. General instructions
The protection of your personal data is an important concern for me. This privacy policy explains which personal data is processed when using the Barber app for Android and the associated web functions, for which purposes this is done and on which legal basis the processing takes place.
This privacy policy applies to all users of the Android version of the Barber app and the associated web functions, in particular for:
- Customers
- Hairdressers / Barbers
- Salon Members and Salon Administrators
- User in guest mode (use without registration to a limited extent)
- Users of public barber and salon web profiles
- The Barber app serves in particular to:
- Organization, booking and cancellation of hairdressing appointments
- Management of profiles, services, working hours, barbering and salon information
- Communication between customers and hairdressers
- Presentation of public barber and salon profiles on the website
- Management of reviews, vouchers, loyalty programs, customer lists and statistics
- Processing of support requests and notifications
- Management of notifications and security-relevant account processes
- The use of personal data for advertising or marketing profiling purposes does not take place.
2. Accountable person
Responsible for data processing in the sense of the General Data Protection Regulation (GDPR) is:
3. categories of personal data
Depending on the use of the app and website, in particular the following personal data will be processed:
3.1 Master data
- Name
- Email address
- 3.2 Account information
- User ID
- Role as a customer or hairdresser
- Login information and authentication status
- Membership of a salon and salon administrator status
- 3.3 Profile data
- City, address, postcode
- Bio / Profile description
- Profile picture
- Gallery and portfolio images
- own website and its activation status
- Visibility of the profile (publicly findable or only by link/QR code)
- Status "accepts new customers"
- Average rating and number of ratings
- Currency set
- 3.4 Barber and service data
- Services offered with name, duration, price and activation status
- weekly working hours including breaks
- blocked periods (e.g. leave) and individual day exceptions
- Cancellation deadline
- Currency set
- 3.5 Salon and team data
- Salon name, salon address and city
- Organic and Salon logo
- Join code
- Admin and member roles and team assignments
- salon-related opening hours
- Saloon related visibility information
- 3.6 Dates of appointment and booking
- Date, time and duration
- Selected service
- Price and related currency
- Date status (open, confirmed, cancelled)
- Optional notes for appointment
- Assignment customer / hairdresser as well as if applicable. Salon cover
- If applicable, Voucher code used, discount amount and redemption status
- 3.7 Web booking data
- Name and e-mail address
- desired date and desired service
- Message, i.e. Note:
- Barber or salon cover
- Request processing status
- 3.8 Communication data
- Chat messages and times
- Delivery and reading status and writing status
- Image attachments in chat
- Unread message counters per user
- Display name and profile picture of the interlocutors within the chat
- 3.9 Image data
- Profile pictures
- Gallery / Portfolio Images
- Salon logos
- Chat image attachments
- 3.10 Valuation data
- Star rating and rating text
- Name of the evaluating user
- Date reference
- 3.11 Voucher and Loyalty Program Data
- Voucher code, voucher value and expiration date
- Redeemed vouchers
- Loyalty Program configuration (target number of visits, description of the premium)
- 3.12 Favorite data
- Saved favorite barbers
- 3.13 Customer-related notes of hairdressers
- Voluntary internal notes that hairdressers can leave to individual customers
- Overviews derived from dates, e.g. number of previous visits
- 3.14 Support and reporting data
- Reporting reason and description
- Chat, appointment or user reference
- Processing status and support responses
- 3.15 Technical data
- Device tokens for push notifications
- Notification settings
- App and widget data
- Information about the existence of an Internet connection (purely technical connection check without storage)
- Technical error and system information
- technical usage events
- Security metadata for sensitive account transactions
- 3.16 Authentication data
- Firebase Authentication
- Data from “Login with Google”
- Telephone number with two-step verification enabled
- Verification codes sent by SMS
- Passkey login data (public key / credential ID)
4. Purposes and legal bases of processing
The processing takes place exclusively to the extent necessary to provide the app and web functions.
4.1 Registration, registration and user account
Purpose: Registration, login, authentication, management of the user account
Legal basis: Article 6(3) 1 lit. b GDPR
4.2 Appointment and booking organization
Purpose: Creating, displaying, updating, postponing, confirming, rejecting and cancelling appointments and booking requests as well as synchronization between customers and hairdressers Salons
Legal basis: Article 6(3) 1 lit. b GDPR
4.3 Availability and working time management
Purpose: Determination and display of bookable time windows, breaks, holiday times and individual day exceptions as well as calculation of free appointment slots
Legal basis: Article 6(3) 1 lit. b GDPR
4.4 Communication within the app
Purpose: Exchange of messages between customers and hairdressers, technical display of delivery, read and write status and display of unread messages
Legal basis: Article 6(3) 1 lit. b GDPR
4.5 Profile functions and public barber and salon profiles
Purpose: Display and management of profile information, services, galleries, ratings, barber and salon information and public web profiles
Legal basis: Article 6(3) 1 lit. b GDPR
If voluntary additional information is provided, e.g. organic, gallery, own website: additionally art. 6 par. 1 lit. a GDPR
4.6 Assessments
Purpose: Create, display and manage barber reviews related to completed appointments
Legal basis: Article 6(3) 1 lit. b GDPR
4.7 Favorites
Purpose: Saving and Displaying Preferred Barbers
Legal basis: Article 6(3) 1 lit. b GDPR
4.8 Vouchers, loyalty programs and barber offers
Purpose: Management of coupon codes, coupon values, expiration dates, redemptions and loyalty program configurations
Legal basis: Article 6(3) 1 lit. b GDPR
4.9 Customer management by hairdressers
Purpose: Overview of customers of a hairdresser, display of previous appointments and voluntary internal notes for support
Legal basis: Article 6(3) 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR
4.10 Statistics and evaluations for hairdressers
Purpose: Presentation of aggregated evaluations on own dates and turnovers of the respective hairdresser, e.g. daily, weekly and monthly values
Legal basis: Article 6(3) 1 lit. b GDPR
There is no evaluation of the usage behavior for advertising purposes.
4.11 Push notifications
Purpose: Notifications about appointment changes, new messages, support responses and similar functional events
Legal basis: Article 6(3) 1 lit. b GDPR
If the activation is voluntary: additional art. 6 par. 1 lit. a GDPR
4.12 Optional news and update notifications
Purpose: Send optional news and update notifications to users who have explicitly enabled this feature
Legal basis: Article 6(3) 1 lit. a GDPR
4.13 System emails and functional notifications
Purpose: Verification emails, appointment confirmations including a cancellation link, appointment-related information and technical or functional notifications
Legal basis: Article 6(3) 1 lit. b GDPR
4.14 Support, reporting and abuse prevention
Purpose: Receiving and processing support requests and reports, abuse prevention, quality assurance, secure operation
Legal basis: Article 6(3) 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR
4.15 IT security, stability and troubleshooting
Purpose: Secure operation, error analysis, technical maintenance, network connection testing, protection against misuse
Legal basis: Article 6(3) 1 lit. f GDPR
4.16 Product improvement on a technical scale
Purpose: Improvement of central functions and usability of the app, as far as technical usage events are processed within the app or the associated systems
Legal basis: Article 6(3) 1 lit. f GDPR
4.17 Salon, team and member management
Purpose: Creation, management and presentation of salons, team members, salon-related opening hours, join code processes and assignment of hairdressers to a salon
Legal basis: Article 6(3) 1 lit. b GDPR
4.18 Account security and security-related operations
Purpose: Securing sensitive account processes, in particular re-authentication against security-related changes, password change, e-mail change, account deletion and sending security-related notifications. In particular, time, platform and device information can be processed.
Legal basis: Article 6(3) 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR
4.19 Two-step verification (2FA) and passkey registration
The app offers an optional two-stage verification via SMS as well as registration via passkey (FIDO2/WebAuthn). In the case of two-step verification, the telephone number is processed and a code is sent by SMS. a cryptographic public key is stored during the passkey registration; the private key remains exclusively on the device or in the keychain of the operating system (e.g. Google Password Manager).
Purpose: Securing the user account, secure login, protection against unauthorized access
Legal basis: Article 6(3) 1 lit. b GDPR as well as, insofar as the activation is voluntary, Art. 6 para. 1 lit. a GDPR; additional art with regard to account security. 6 par. 1 lit. f GDPR
4.20 Introduction process and local presets
Purpose: Preparation of the user account based on voluntary information in the introduction process and storage of operating and display settings on the device
Legal basis: Article 6(3) 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR
There is no use for advertising or marketing profiling purposes.
5. Sign up with email, Google or Passkey
The Barber app for Android allows you to register by:
- Email address and password
- “Register with Google”
- Registration by Passkey (FIDO2/WebAuthn)
- The information transmitted by the respective authentication service is processed, in particular user ID, display name and e-mail address.
The app can also be used in a restricted guest mode without logging in. In this case, no account data will be processed; for booking-related functions, a notification is required.
Legal basis: Article 6(3) 1 lit. b GDPR
6. Appointments, bookings and cancellations
In the context of appointment management and booking processing, the following data in particular are processed:
- Customer / hairdresser / if applicable. Salon
- Date, time, duration
- Selected service
- Price and related currency
- Terms of Reference
- Optional notes
- If applicable, Voucher information
- This data is used exclusively for scheduling, synchronization and communication between the parties involved.
Booking requests can have the status “open”, “confirmed” or “cancelled”. hairdressers can accept or reject open requests; the participants are informed of the respective status.
Cancellation deadline: Hairdressers can set a deadline by which customers can cancel an appointment themselves. For this purpose, the specified deadline and the date are processed in order to calculate and indicate until when an independent cancellation is possible.
Cancellation link: For appointments made via a web booking request, the confirmation email may contain a cancellation link. If it is called, the appointment identifier and the time of the call are processed in order to check compliance with the cancellation deadline and cancel the appointment if necessary.
Legal basis: Article 6(3) 1 lit. b GDPR
7. Web bookings and public barber or salon web profiles
If booking requests are transmitted via the website or a public barber or salon profile, the data provided will be processed in order to assign and process the request to the relevant barber or salon.
Public barber and salon web profiles may in particular contain the following data:
- Name
- City and address
- Bio
- Services, prices and duration
- Assessments
- Gallery / Profile Pictures
- Team members
- If applicable, Publicly released website information
- If applicable, Bookable time windows and salon-related opening hours
- Web booking requests can be displayed in the app and assigned and processed by the barber or in the salon context to the responsible team member. Upon acceptance of a web booking request, an appointment is created and a confirmation email is sent to the specified email address.
Users can control the visibility of their profile themselves and determine whether it can be found publicly or only via a link. QR code is accessible.
Legal basis: Article 6(3) 1 lit. b GDPR
8. Communication within the app (chat)
The Barber app offers an internal messaging system for communication between customers and hairdressers. Processed:
- Message content and time points
- If applicable, Image attachments
- Technical delivery, read and write status information
- Number of unread messages per user to display a corresponding message in the app
- Display name and profile picture of the interlocutors for presentation in chat
- The content is intended only for the users involved in the communication. An automatic content analysis for advertising or profiling purposes does not take place.
In addition, users can report chat content or other content to support. The reason for the message, description, user identifiers involved, chat reference, support responses and processing status can be processed.
9. Profile pictures, gallery pictures and chat pictures
Users can voluntarily upload images, in particular:
- Profile pictures
- Gallery / Portfolio Images
- Salon logos
- Chat image attachments
- The selection of the images takes place via the image selection of the operating system. The images are used exclusively to provide the respective function and stored in a secure cloud storage.
- Legal basis: Art. 6 para. 1 lit. b GDPR
- In the case of voluntary additional profile and gallery information: Art. 6 para. 1 lit. a GDPR
10. Push notifications and notification settings
For the technical delivery of push notifications, in particular a device token is processed, for example a Firebase Cloud Messaging Token. Since an account can be used on multiple devices, multiple device tokens can be stored.
In addition, notification settings can be stored in the user account, in particular:
- Activation or deactivation of general push notifications
- Activation or deactivation of optional news and update notifications
- Taping on a notification can open the app in the associated location, such as a chat or a barber profile. The respective identifier is technically processed.
This information serves exclusively for the technical delivery and control of the notifications requested by the user. Use for advertising profiling purposes does not take place.
- Legal basis: Art. 6 para. 1 lit. b GDPR
- If optional news and update notifications are activated: additionally art. 6 par. 1 lit. a GDPR
Note: Push notifications and news notifications can be changed or disabled at any time in the app or device settings.
Widgets (Android)
If widgets are used, certain summary data can be processed locally on the device or within the app/widget environment, such as:
- Upcoming dates with time and title
- Number of appointments or booking requests
- Barber reviews
- These data are used exclusively for the widget function and are not evaluated for other purposes. Please note that widget content on the home screen may also be visible to third parties who have access to the device.
Legal basis: Article 6(3) 1 lit. b GDPR
QR code, PDF and profile sharing functions
The app may provide features to share barber or salon profiles, such as:
- Website links and profile links
- QR codes
- PDF creation and PDF sharing
- Sharing or saving profile information via Android sharing features
- The respectively released profile, barber or salon data are processed in order to enable the desired release or display. Which recipients receive the shared content, the user himself determines via the selected sharing option.
Legal basis: Article 6(3) 1 lit. b GDPR
13. Account security and security-related emails
In the case of sensitive account processes, in particular password change, e-mail change, setup or removal of a pass key, activation or deactivation of the two-step verification or account deletion, additional confirmations, re-authentications and security-related e-mails can be used for security.
In particular, the following data can be processed:
- User identification
- Email address
- Date of the transaction
- Platform
- Device information
- This processing serves exclusively to secure the user account and the traceability of security-relevant processes.
14. Support, notifications and local storage on the device
Technically, support requests and messages can be temporarily cached locally on the device until a successful transmission is possible. This serves exclusively for the reliable provision of the support function.
If support cases are processed, processing statuses, internal feedback and assignment information can also be processed.
In addition, certain information is stored exclusively locally on the device and is not transmitted to the server, in particular:
- information provided in the implementation process (onboarding), e.g. role, name, address, postcode, city and information about a first service
- Settings for notifications
- Notes on what information about innovations has already been displayed
- These locally stored data are used exclusively for the presetting and usability of the app. They are removed with the uninstallation of the app or the deletion of the app data.
Legal basis: Article 6(3) 1 lit. b GDPR and Art. 6 par. 1 lit. f GDPR
15. Use of Firebase / receiver
For the technical operation of the Barber app and associated web functions, services from Google Firebase are used in particular, e.g.:
- Firebase Authentication
- Firebase Authentication with Telephone/Multi-Factor Authentication (SMS for two-step verification)
- Cloud Firestore
- Firebase Cloud Messaging (FCM)
- Cloud Storage for Firebase
- Cloud Functions for Firebase (server-side functions, such as processing cancellations via a cancellation link)
- a server-side email delivery service for the delivery of functional emails, such as appointment confirmations
- If applicable, Firebase hosting
- If Google Login is used, services in connection with Google Sign-In can also be used. For the passkey registration, the login services of the operating system are used.
These services are used to provide the app and web functions, in particular for:
- Authentication
- Database and synchronisation
- Push notifications
- Storage of images and attachments
- Sending functional emails
- Server-side processing of appointment-related processes
- Technical functional and support processes
- In addition, own event and log data can be processed within the used backend and database structure to the extent that this is necessary for stability, support, security or improvement of central functions.
An analysis of usage behavior for advertising or marketing purposes does not take place.
- Further information on data protection at Firebase: firebase.google.com/support/privacy
- Data protection at Google: policies.google.com/privacy
16. Disclosure of data to third parties
A transfer of personal data to third parties only takes place:
- as far as this is necessary for the technical operation of the app and website
- insofar as this is necessary for the fulfillment of the respective function, in particular the transmission of appointment and contact data to the respective involved hairdresser or Salon
- if there is a legal obligation
- Or if there is an explicit consent
- A transfer for advertising or marketing purposes does not take place.
17. Third country transmission
When using Firebase / Google services, the processing of personal data outside the European Economic Area cannot be excluded.
Where necessary, the processing shall be carried out on the basis of appropriate guarantees in accordance with art. 44 ff. DSGVO, in particular standard contractual clauses or other data protection mechanisms provided by the providers.
Information on the guarantees used can be obtained on request at privacy@mvm-app.at to the extent that they are not already made publicly available by the respective provider.
18. Data security
For the protection of personal data, appropriate technical and organisational measures shall be used, in particular:
- Encrypted data transmission
- Access restrictions
- Authentication and authorization concepts
- Server-side access rules for database and file storage
- Optional two-step verification and passkey registration
- Re-authentication before security-relevant account processes
- Secure cloud services
- Role and control configurations
- Despite all the measures, no absolute security can be guaranteed.
19 Storage period and deletion
Personal data will only be stored as long as this is necessary for the provision of the app and website as well as the respective functions or there are legal storage obligations. In principle:
- Account data: until the account is deleted
- Dates and booking dates: as long as required for function and traceability
- Web booking requests: required until processing and for as long as traceability is possible
- Chat data: as long as the communication function is provided or until deletion within the framework of technical possibilities
- Evaluation data: as long as the evaluation and profile system is provided
- Image data: up to the removal by the user or deletion of the account
- Voucher and loyalty program data: as long as these functions are actively used or are necessary for administrative purposes
- Customer-related notes of the hairdressers: until the removal by the respective hairdresser or until the deletion of the account
- Working hours, holiday times and day exceptions: as long as the respective barber profile exists
- Support and reporting data: as long as necessary to process and document the support case
- technical usage and error data: only as long as necessary for operation, security and improvement
- Salon and team data: as long as the salon and team functions are provided or until corresponding assignments are removed
- Notification settings and device tokens: as long as they are required to deliver or control notifications
- Security-related process data: only for as long as necessary to execute, trace and secure security-related account processes
- Locally stored onboarding and settings data: until the app is uninstalled or until the app data is deleted
- locally cached support data: until successful transmission or removal within the framework of technical processes
- Telephone number for two-step verification (2FA): until deactivation by the user or until account deletion
- Passkey login data (public key / credential ID): up to the removal of the passkey by the user or the deletion of the account; the private key is not stored by MVM-APP
- Backups: time delayed in technical processes
- Users can delete their account in the app. In this case, personal data will be removed from active systems as far as technically possible and no legal obligations are in conflict.
20. Rights of data subjects
According to the GDPR, affected persons have the following rights in particular:
- Right of access in accordance with art. 15 GDPR
- Right to correction in accordance with art. 16 GDPR
- Right of cancellation in accordance with art. 17 GDPR
- Right to restriction of processing in accordance with Art. 18 GDPR
- Right to data portability in accordance with art. 20 GDPR
- Right of appeal in accordance with art. 21 GDPR, as far as the processing on art. 6 par. 1 lit. f DSGVO is based on
- Right to withdraw consent with effect for the future in accordance with art. 7 par. 3 GDPR
- Questions may be addressed to: privacy@mvm-app.at
21. Right of appeal to a supervisory authority
You have the right to complain to a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.
The competent supervisory authority in Austria is in particular the Austrian Data Protection Authority (DPA).www.dsb.gv.at)
22. Obligation to provide and consequences of non-provision
Certain personal data are necessary for the use of central functions of the app, such as registration, appointment booking, communication, salon or barber administration.
Without this data, individual functions or the use of the app may be restricted or not possible. An active Internet connection is also required for the use of the app.
23. No automated decision-making
There is no automated decision-making including profiling in the sense of art. 22 GDPR.
24. Use by minors
The use of the Barber app is only permitted for people aged 14 and over. No use by children under 14 years of age is planned.
25. Responsibility of hairdressers and salons
If hairdressers or salons operate their own profiles via the platform and process customer data as part of their services, in particular by maintaining customer lists, customer-related notes, vouchers or loyalty programmes, they can be independently responsible for certain processing operations.
MVM-APP remains responsible for the technical provision of the app and website as well as the associated data processing in its own area of responsibility.
26. Changes to this data protection declaration
This privacy policy can be adapted as technical functions, legal requirements or the app evolve.
The current version is available in the app or via the provided links.
27. Contact details
Questions about data protection can be addressed at any time to: