Privacy statement — plevry
Version 2026-09.5 · in force from 24 September 2026
This statement explains which personal data we process, for what purpose, on what legal basis and for how long. It is information for you — not a contract, and there is nothing to "accept".
Which cookies and similar techniques we use is set out in the cookie statement. That list is generated and maintained by the cookie banner itself, so it follows the site instead of going stale in a hand-written table.
The Dutch text is the authoritative version. This English translation is provided for convenience. Where the two differ, the Dutch privacyverklaring prevails.
Privacy statement
1. What this statement covers
plevry is a booking and calendar platform for independent business owners such as barbers, hairdressers and nail technicians. This statement explains which personal data we process, for what purpose, on what legal basis, how long we keep it and what rights you have.
This statement applies to:
- the plevry operator app (the app for business owners);
- the booking page
book.plevry.app/<name>where consumers book an appointment; - the marketing website
plevry.com; - plevry's internal admin dashboard.
2. Who is responsible — and why that depends on the situation
This is the most important part of this statement, because plevry has two roles.
| Situation | Who is the controller? | plevry's role |
|---|---|---|
| You book an appointment with a business: your name, contact details, treatment, time and comments | The business you book with | Processor (on their instructions) |
| You pay for your appointment: payment reference, amount, payment status and Mollie payment ID | The business you book with | Processor (on their instructions) |
| You have a plevry account as a business owner | plevry | Controller |
| You have a plevry Pro subscription: which subscription, its status and its term | plevry | Controller |
| You visit plevry.com | plevry | Controller |
| You email [email protected] | plevry | Controller |
| The payment itself (execution, fraud checks, a payment service's retention duties) | Mollie B.V., alongside the business | None — plevry is not a party |
| Billing for the Pro subscription (collection, invoicing, refunds) | Apple or Google, depending on where you subscribed | None — plevry is not a party |
What does that mean in practice?
- For the data relating to your appointment, the business decides what happens with it. plevry may only use that data to provide the booking service, not for its own purposes. This is set out in a data processing agreement between plevry and that business.
- plevry charges you nothing as a consumer. You pay the treatment price and any transaction fee charged by the business to the business itself, into its own Mollie account. plevry collects none of it and is not a party to that payment. The payment data we do record, we process on the business's instructions; see §4.
- plevry earns money solely from the business owner's plevry Pro subscription (€ 9.99 per month). That subscription is billed through Apple's App Store or Google Play, not by plevry. We see no payment details in the process; see §5.
Controller, where plevry is the controller:
Falley B.V., trading under the business name "plevry" registered with the Dutch Chamber of Commerce Oder 20, 2491 DC The Hague, the Netherlands Chamber of Commerce no. 91810760 Email: [email protected]
3. If you book an appointment (plevry = processor)
For this data the business is responsible. The legal basis below is the basis the business relies on; plevry processes solely on its instructions.
| Data | Purpose | Legal basis (of the business) | Retention |
|---|---|---|---|
| Name | Recording the appointment and recognising you | Performance of the contract (art. 6(1)(b) GDPR) | Determined by the business |
| Email address and/or telephone number | Confirmation, reminder and contact about the appointment | Performance of the contract | Determined by the business |
| Chosen treatment(s), date, time, duration, amount | Carrying out and scheduling the appointment | Performance of the contract | Determined by the business; 7-year tax retention duty |
| Comments you enter yourself | Taking account of what you tell us | Performance of the contract | Determined by the business |
| Booking reference and payment status | Linking the appointment to the payment | Performance of the contract | Determined by the business; 7-year tax retention duty |
What plevry does not do with this data: use it for its own marketing, sell it, or share it with other businesses. Every business sees only its own clients; that is enforced technically at database level.
Take care with sensitive information. Do not enter medical or other sensitive data in the comments field unless the business expressly asks for it and explains why.
4. If you pay for your appointment (plevry = processor)
Payments run through Mollie, into the business's own account. plevry records the data needed to link the booking to the payment. This happens on the instructions of the business, which is the controller for it. The seven-year tax retention duty (art. 52 of the Dutch General Tax Act) rests on the business, in whose accounts the payment belongs; plevry keeps the data as a processor for as long as that business's account exists.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Payment reference, amount, currency, payment status, payment method, time, Mollie payment ID, test or live payment | Linking the booking to the payment and completing it | Performance of the contract between you and the business (art. 6(1)(b)) | Determined by the business; 7-year tax retention duty |
| The same data, in aggregate | Detecting and preventing abuse of the booking and payment process | plevry's legitimate interest: a safe, working platform (art. 6(1)(f)) | As long as the business's account exists |
| Refunds and their amounts | Handling and recording a cancellation correctly | Performance of the contract; the business's legal obligation | Determined by the business; 7-year tax retention duty |
plevry receives no bank or card details from Mollie: only the status, the amount and a reference. For the payment itself Mollie is an independent party with its own privacy statement.
5. If you have a business account (plevry = controller)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address (sign-in) and password data in encrypted form | Access to your account, password recovery | Performance of the contract | Until you delete your account |
| Your business name, its address with the matching coordinates, booking name (slug), time zone, opening hours, treatments and prices | Making your booking page and calendar work. If you enter an address we look it up through LocationIQ (§9, §10), derive your time zone from it and show it to your clients in the confirmation and reminder email | Performance of the contract | Until you delete your account |
| Your Mollie connection: organisation and profile ID and encrypted access and refresh tokens | Being able to create payments in your own Mollie account | Performance of the contract | Until you remove the connection or delete your account |
| Your plevry Pro subscription: your internal user ID, which subscription product, the status (trial, active, cancelled, expired), which store you subscribed through, the end of the current period, whether it renews automatically, and the price and currency | Keeping track of whether you have Pro and which features are open to you, and administering your subscription | Performance of the contract | Until you delete your account |
| Events relating to your subscription (purchase, renewal, cancellation, refund, expiry) with the matching event ID and time | Being able to establish why your subscription has the status it has, and to answer your questions about it | Performance of the contract; legitimate interest (support and evidence) | Until you delete your account |
| The 14 days of Pro you receive at the start: start date, end date and the fact that plevry granted it itself | Running the trial and letting it end on time | Performance of the contract | Until you delete your account |
| Record of your acceptance of the terms: which document, which version, the moment, the app version and the platform | Being able to demonstrate which agreements were made (including art. 28(9) GDPR) | Legal obligation and legitimate interest (evidence) | Until you delete your account. After that we keep the record without the link to you: that version X was accepted at moment T remains, but not by whom. See §12 |
| Record of your privacy choices: which business and which control it concerns, which choice you made (consent given, refused or withdrawn; objection raised or withdrawn), the moment, who made the choice, which version of this statement applied, and the app version and platform | Being able to demonstrate that consent was given (art. 7(1) GDPR), and not asking you again what you have already answered | Legal obligation (evidence) and legitimate interest (art. 6(1)(f) GDPR) for recording a refusal | Until you delete your account |
| "Where did you find plevry?" (advertisement, Google, colleague, other) | Knowing which channels work and accounting for marketing spend | Legitimate interest (art. 6(1)(f) GDPR) | Until you delete your account |
| Device token for push notifications and your notification preferences | Being able to send notifications about new bookings and your daily overview | Performance of the contract; your setting in the app | Until you remove the device or delete your account |
| Sign-in and security logs | Detecting and preventing account abuse | Legitimate interest | See §8 |
plevry Pro, the stores and RevenueCat. plevry Pro costs € 9.99 per month and is billed through Apple's App Store or Google Play — not by plevry itself. We therefore see no payment details of yours: no card or account number and no invoice data. All we get back is whether your subscription is running and until when.
To keep track of that we use RevenueCat. The app passes your internal plevry user ID to RevenueCat — a random number, no name and no email address — and RevenueCat attaches the store's subscription data to it: which product you bought, in which store, when, how long the period runs, whether it was cancelled or refunded, and the amount. That data comes back to plevry and determines whether Pro is open to you. We send no name, email address, telephone number, business data or client data to RevenueCat, and of the messages we receive back from RevenueCat we keep only the fields we need to explain and support your subscription status. RevenueCat is a US party; see §10.
The first 14 days of Pro come from plevry itself, without you providing any payment method. No store and no RevenueCat are involved until you take out a subscription yourself.
Analytics and advertising measurement for business owners. When you use plevry as a business owner, we record a limited number of events relating to your account: that you created an account, that your trial started, that you connected a payment provider, that your first booking came in, that your first customer booked through your booking page, and that you started, renewed, cancelled or ended a subscription.
This processing is separate from the cookies on plevry.com (§6). The data is processed from our own servers; nothing is placed on or read from your device in the process. The cookie banner is about what is put in your browser; this is about what our server passes on afterwards about an event that has already happened.
Nothing about your clients is included. No names, no email addresses, no telephone numbers, no appointments. This is solely about you as a business owner and about events in your own account.
Google Analytics — on the basis of legitimate interest
We send a limited part of these events to Google Analytics 4, to understand through which channels business owners find plevry and which channels actually lead to active use or a subscription. In doing so we send an internal account ID, the type of event and the data belonging to it — such as language, source channel, product, currency and amount. We send no name, email address, telephone number or address to Google for this purpose.
We use this data solely for analysis and channel attribution. We do not use it for remarketing, for building advertising audiences or for personalised advertising.
The legal basis is legitimate interest (art. 6(1)(f) GDPR): being able to account for which marketing spend works. We have recorded that balancing test in writing and reconsider it whenever the purpose or the scope changes. Google LLC may process data in the United States and participates in the EU-US Data Privacy Framework; see §9 and §10.
Meta — only with your consent, and off by default
With your consent we pass three of the events named above to Meta, to measure whether advertisements on Facebook and Instagram bring in new customers, and to optimise our advertising. It is exactly three, and no more:
- that you created an account;
- that your first customer booked through your booking page;
- that you took out a subscription.
Of that first customer booking, only the fact that a booking happened is included. Who booked, when, and for what stays with us.
The remaining events in the list above — that your trial started, that you connected a payment provider, that your first booking came in, and that your subscription was renewed, cancelled or ended — never go to Meta. They say nothing about whether an advertisement worked, and so are no business of Meta's.
This list may change as we measure better, or less. Your consent is about the purpose (measuring which advertisements bring in new customers) and the recipient (Meta), and neither of those changes when the list does. If another recipient or another purpose is added, we ask you for consent again — this consent is not meant for that and cannot be used for it. If the list changes, the current version is always the one you can read here.
To be able to link an event to a Meta account, Meta receives a cryptographic hash of your email address and, if you have entered them, of your telephone number and the city, postcode and country of your business. Meta also receives the internal account ID and information about the event itself.
Hashing does not make this data anonymous. Meta uses the hashes precisely to check whether they match the details of a Meta user, and so to make an individual match. It therefore remains personal data.
Also data about your device — this is new in this version.
Until now we sent these events only from our own servers. The app now also contains software from Meta itself. If you give consent, more goes along with it than just the encrypted email address above:
- an installation ID: a number tied to your installation of the app, not to you personally, but one that stays the same for as long as you do not remove the app;
- device characteristics: model, operating system, language, time zone, screen size and similar data;
- on an iPhone or iPad, and only there: your advertising ID, but only when you have also given consent in Apple's own prompt.
This is a fundamentally different kind of data than an encrypted email address. An email address says something about your account with us; a device ID can be used by Meta to recognise you in other apps and on other websites. That is precisely why we ask you again, even if you had already said yes before: your consent from back then was about a text that did not describe this.
Apple's prompt. If you say yes with us, iOS then shows its own prompt about tracking your activity. That is not a second question about the same thing — it is how iOS carries out our question. If you say no to Apple, the Meta software stays dormant and nothing goes to Meta, even if you had said yes with us. The stricter of the two answers always wins. On Android, Apple's prompt does not exist; there only your answer with us applies.
One thing happens before you answer, and it stays on your device. On Android, the Meta software writes a random number into the app's own storage the first time the app starts. That number belongs to your installation rather than to you personally, and nothing is done with it unless you give permission: it is not sent anywhere. If you do give permission later, it becomes one of the items that are shared — listed above as the installation ID. Delete the app and it is gone.
Push notifications on Android go through Google, and that starts straight away. So that we can notify you when a booking comes in, the app uses Google's messaging service (Firebase Cloud Messaging) on Android. It records an installation number the first time the app starts and registers your installation with Google — that also happens before you have set anything, because a device that is not registered cannot be sent a notification. It concerns your installation of the app rather than you personally, and no name, email address or booking detail goes with it. This is separate from Meta and from your choice there: it belongs to delivering notifications. Turn notifications off and we send you none.
This transfer is off by default. We send nothing to Meta until you have given your own, express consent for it, separately from the terms and conditions and separately from your subscription. You can keep using plevry in full if you do not give that consent — it has no effect whatsoever on your calendar, your bookings, your payments or your subscription.
When we ask. Once, on a screen of its own, immediately after you have created your business — so after the creation has already succeeded, and never as a condition of it. If you do not answer the question and close the app, we do not count that as an answer: we ask once more the next time you open the app, and after that not again. You can always make your choice later through Settings › Privacy.
We record your choice — including when you say no. For every choice we keep: which business it concerns, who made the choice, the moment, which choice it was, which version of this statement applied at that moment, and with which app version and on which platform. We do this for two reasons: we must be able to demonstrate that consent was actually given (art. 7(1) GDPR), and we do not want to bother you again with a question you have already answered. For recording a refusal the legal basis is our legitimate interest (art. 6(1)(f) GDPR): without that record we cannot distinguish "said no" from "never asked", and we would keep asking. This record is never used to make any decision about you and does not leave plevry. See §12 for what happens to it when you delete your account.
You can withdraw your consent at any time, as easily as you gave it: with a single message to the address in §15, and in the app through Settings › Privacy. From that moment we send no new events to Meta for this purpose. Withdrawal does not affect the lawfulness of processing carried out before it. Meta Platforms, Inc. may process data in the United States and participates in the EU-US Data Privacy Framework; see §9 and §10.
Objecting to marketing analysis
You have the right to object to the use of your personal data for our marketing analysis on the basis of legitimate interest.
Do you want us to stop sending your account data to Google Analytics for this analysis? Send a message to the address in §15, or switch it off in the app through Settings › Privacy. We do not ask for a reason and do not weigh your objection against our own interest — your objection is enough. It has no effect whatsoever on your subscription, your booking page or any part of plevry.
Insofar as personal data is processed for direct marketing, you may object to that at any time, free of charge. After your objection we no longer use your personal data for that purpose.
This right is set out in article 21 GDPR and applies alongside all other rights in §13.
6. If you visit plevry.com (plevry = controller)
On the marketing website plevry.com we measure how the site is used and how effective our advertising is. For that we use three services: Google Analytics 4, the Meta pixel (Facebook and Instagram) and Microsoft Clarity. We use no more than these three.
What Microsoft Clarity does, and why we name it separately. Clarity records how visitors move around the page — where you click, how far you scroll, where you linger — and turns that into heatmaps and replayable session recordings. That goes further than counting visitors, which is why we name it separately here instead of letting it disappear under "statistics". Clarity runs only on plevry.com and is not on the booking page and not in the app. Microsoft also uses the data for its own purposes, under Microsoft's terms.
- All three are placed only after you have given consent for them through the cookie banner (art. 11.7a of the Dutch Telecommunications Act and art. 6(1)(a) GDPR). If you do not consent, the scripts from Google, Meta and Microsoft are blocked and no request at all goes to those parties. The site works fully without consent. You can change or withdraw your choice at any time through "Cookie settings" at the bottom of every page.
- We record which choice you made and when, so that we can demonstrate that consent was given or refused (art. 7(1) GDPR). That record contains no name and no email address, and is kept for 12 months.
- Google Analytics processes the data as a processor for plevry, under Google's terms.
- For the Meta pixel, Meta also uses the data for its own purposes; plevry and Meta are to a significant extent independently responsible for that, partly as joint controllers. What Meta itself does with the data is set out in Meta's privacy policy.
- Google, Meta and Microsoft are US parties; see §10.
- Exactly which cookies and similar techniques these are — with name, provider, purpose and retention — is set out in the cookie statement. That list is updated automatically when something on the site changes.
On the booking page book.plevry.app there are no analytics, no advertising trackers and no pixels,
and no measurement script of plevry's own either. That is a deliberate choice: someone booking an
appointment is not tracked. That is also why no cookie banner is needed there.
7. If you contact us
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Your email address, the content of your message and our reply | Handling your question or complaint | Performance of the contract; legitimate interest | 2 years after resolution |
Do not include data about your own clients in a support message unless it is needed to answer the question.
8. Error reports and diagnostics
To find and fix faults we use Sentry. If an error occurs in the app or on the website, a technical report is sent: the type of error, the place in the code, the version of the app and the kind of device.
We have deliberately set this up so that no personal data of clients ends up in those reports:
- names, email addresses, telephone numbers, addresses, tokens and payment data are stripped before the report is sent;
- the content of forms and requests is not sent at all;
- at most an internal ID is sent for a user, never an email address or IP address;
- no recording of any kind is made of image, screen or session. Session Replay is deliberately switched off and is not used.
Legal basis: legitimate interest (a working and secure service). Sentry processes the reports in the EU region (Germany) and keeps them for 90 days; after that they are deleted.
9. Who we engage
We share data only with parties needed to make plevry work, and only for that purpose.
| Party | For what | Where |
|---|---|---|
| Supabase | Database, sign-in and server functions — nearly all data | EU (Frankfurt) |
| Mollie B.V. | Payments | The Netherlands |
| DigitalOcean | Hosting of the booking page and the internal dashboard | EU (Amsterdam) |
| Resend | Sending confirmation and reminder emails | United States — see §10 |
| Sentry | Error reports and diagnostics (§8) | EU |
| Cloudways | Hosting of plevry.com and the record of your cookie choice | EU (Amsterdam) |
| LocationIQ | Looking up the business address and determining the time zone (§5) | Outside the EU — see §10 |
| Expo | Delivering push notifications to the business owner's device | United States — see §10 |
| RevenueCat | Keeping track of business owners' plevry Pro subscriptions (§5) | United States — see §10 |
| Apple, Google | Distribution of the app, delivery of push notifications and billing of plevry Pro | Worldwide, under their own terms |
| Statistics on plevry.com (§6, only after your consent) and analysis of events relating to business accounts from our servers (§5, on the basis of legitimate interest) | United States — see §10 | |
| Meta | Advertising measurement on plevry.com (§6, only after your consent) and around business accounts from our servers (§5, only after your express consent) | United States — see §10 |
| Microsoft | Heatmaps and session recordings on plevry.com through Clarity (§6, only after your consent) | United States — see §10 |
We keep the current and complete list, with the safeguards that go with it, in our Sub-processor annex to the data processing agreement.
In addition, the data of your appointment is visible to the business you book with. That business is responsible for it itself.
We do not sell personal data and do not use it for automated decision-making or profiling with legal effects.
10. Transfers outside the European Economic Area
We keep processing inside the EU as much as possible, but not all processing stays in the EU:
- Resend handles our email and is a US party. When a confirmation or reminder email is sent, the email address, the name and the appointment details contained in the message go to the United States.
- Expo delivers push notifications to the business owner's app and is likewise a US party.
- LocationIQ (Unwired Labs) looks up the business address and derives the time zone from it. What goes there is solely what the business owner types about their own business — the search term and, on saving, the coordinates of the chosen address. Client or booking data never goes there. If a business owner enters no address, this party is not called for their business at all.
- RevenueCat keeps track for us of which business owner has a running plevry Pro subscription and is a US party. Only the business owner's internal user ID and the subscription data belonging to the store purchase go there (§5). No names, no email addresses and no client or booking data go there.
- Apple and Google bill the Pro subscription themselves and process the associated data as independent parties, under their own terms and privacy policies.
- Google processes data partly in the United States, along two routes each with its own legal basis. The statistics data from plevry.com (§6) goes only if you have consented in the cookie banner. The events relating to your business account (§5) are passed on from our own servers on the basis of legitimate interest — you can object to that; see §5 and §15.
- Meta receives data along two routes, both with consent: on plevry.com through the pixel, if you accept marketing in the cookie banner (§6), and around your business account only when you have given your own, express consent in the app (§5). If you do not give it, or you withdraw it, nothing goes to Meta.
- Microsoft receives, through Clarity, data about your behaviour on plevry.com — clicks, scrolling and a replayable recording of your visit — and only if you have consented in the cookie banner (§6). This concerns the marketing website only; not the booking page, not the app and not data from your account.
- Google LLC and Meta Platforms, Inc. are both certified under the EU-US Data Privacy Framework, on which we rely for these transfers — not on the standard contractual clauses below.
For transfers to Resend and Expo we rely on the European Commission's standard contractual clauses (SCCs), supplemented by an assessment of the risks of the transfer and by additional measures where needed.
11. How we secure data
- Separation per business at database level: every business owner can access only their own data. This is tested automatically on every change to the software.
- Encryption of payment tokens and of all traffic between device and server.
- plevry's internal admin dashboard shows no personal data of clients: no names, email addresses or telephone numbers. A booking is visible there only as date, time, treatment, amount and status.
- Administrators are on a fixed list and every action by an administrator is recorded in a log that cannot be altered or erased.
- No bulk export of personal data is made from the internal dashboard.
- Security and access logs (sign-in attempts, administrative actions) are kept for 90 days.
In the event of a data breach involving client data, the business is the one who notifies the Dutch data protection authority and the individuals concerned where necessary; plevry reports the breach to the business without undue delay and assists with the investigation. This is set out in the data processing agreement.
12. Retention periods in brief
| What | How long |
|---|---|
| Data about your appointment | Determined by the business you booked with |
| Payment data for your booking (§4) | Determined by the business, on whom the 7-year tax retention duty rests |
| Business account and business data | Until the account is deleted |
| plevry Pro subscription data (§5) | Until the account is deleted |
| Acceptance of the terms | Until you delete your account; kept anonymised after that (§5) |
| Record of your privacy choices (§5) | Until you delete your account; fully deleted after that |
| Support correspondence | 2 years after resolution |
| Error reports (Sentry) | 90 days |
| Record of your cookie choice | 12 months |
| Cookies and similar techniques | See the cookie statement |
If your plevry Pro expires or you cancel it, your account falls back to Free, but nothing is deleted: your treatments, opening hours, bookings, your Mollie connection and your deposit settings all stay as they were. If you subscribe again later, everything works again without you having to set anything up afresh.
If a business owner deletes their account, the business, the bookings, the client data and the subscription data are permanently deleted and the Mollie connection is revoked. This cannot be undone.
13. Your rights
You have the right to:
- obtain access to the data processed about you;
- have incorrect data corrected;
- have data erased;
- have processing restricted;
- object to processing based on legitimate interest;
- receive or have transferred your data in a common format;
- withdraw consent you have given (for cookies, for example), without that affecting what has already happened.
Where should you go?
- If it concerns an appointment you booked or the payment for it, contact the business you booked with. They are responsible for it. We help that business to carry out your request.
- If it concerns your plevry account or plevry.com, email [email protected].
- If it concerns billing of your plevry Pro subscription, that runs through the App Store or Google Play: cancellation and refunds are arranged there, in your own account settings. If the status in the app does not match what the store shows, email [email protected] — we can help with that.
We respond within one month. If we cannot establish who you are, we may ask for additional information.
You may also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
14. Changes
We may amend this statement, for example if we engage a new party or add a new feature. The current version is always at /en/privacy, with the date of the last change. In the event of an important change we inform business owners by email or in the app.
15. Contact
Falley B.V. (trading as "plevry") Oder 20, 2491 DC The Hague, the Netherlands Chamber of Commerce no. 91810760 [email protected]