Last updated 1 August 2026

Privacy policy

What we collect, why we collect it, who sees it, and how to get it back or have it deleted.

The short version

We collect the minimum needed to run a booking platform: who you are, what you booked, and how to remind you about it. We do not sell personal data, and we do not share your contact details with anyone other than the business you chose to book with.

Because reservi covers medical, dental, veterinary and legal appointments, some of what you book reveals sensitive information about you. We treat the fact and subject of those bookings as special-category data: it is encrypted, access is tightly restricted, it is never used for advertising, and it is never visible to any business other than the one you booked.

What we collect

We collect information you give us and a small amount generated by using the service.

  • Account details: name, phone number, email address, and password credentials.
  • Booking details: the business, service, practitioner, time, price and any notes you add.
  • Payment data for deposits, processed by our payment provider — we never store full card numbers.
  • Technical data: device type, browser, IP address and pages visited, used for security and aggregate analytics.

Why we use it

To take and confirm your bookings, send reminders, keep your appointment history, prevent fraud and abuse, provide support, meet legal obligations, and understand in aggregate which parts of the product work.

Marketing email is opt-in and separate from transactional messages about your appointments. You can unsubscribe from the former without losing the latter.

Who we share it with

The business you book with receives your name, contact details and booking notes — they need them to see you. Beyond that, we share data only with processors acting on our instructions: hosting, email and SMS delivery, payments, and error monitoring. Clinical and case records created during your appointment stay with the practice under their own obligations; we never receive them.

We disclose data to authorities only where legally required, and we tell you unless we are prohibited from doing so.

How long we keep it

Account and booking records are kept while your account is open and for six years afterwards, which is the retention period applicable to financial records. Technical logs are kept for 90 days. Deleted accounts are purged from backups within 35 days.

Your rights

Under the GDPR you can access, correct, export, restrict, object to and delete your personal data.

  • Export or delete your account from account settings, without contacting us.
  • Email hello@reservi.app for anything the settings page does not cover — we respond within 30 days.
  • You may complain to ANSPDCP, the Romanian supervisory authority, at any time.

Cookies

We use strictly necessary cookies for sign-in and security, and aggregate analytics cookies that you can decline without losing functionality. We do not run third-party advertising trackers.

Security and transfers

Data is encrypted in transit and at rest, access is restricted to staff who need it, and we review that access quarterly. Our infrastructure is hosted in the EU; where a processor operates outside it, transfers rely on the European Commission's standard contractual clauses.

Contact

Our data protection contact is hello@reservi.app. We will update this page when our practices change and note the date at the top.