Slotora
Log inSign up free

Privacy Policy

Last updated: 26 July 2026

1. Who controls your data

Slotora online booking software is operated by Belavin Limited, (company no. 16735157), 6 Salstar Close, Birmingham, B6 4PP, United Kingdom. For privacy matters contact hello@slotora.io. We are registered with the UK ICO (registration 00014129250).

2. Two roles

For your own account and our marketing, Slotora is the data controller. For your clients' booking data (what your customers submit on your booking page), YOUR business is the controller and Slotora is a processor acting on your instructions — governed by the data-processing section of our Terms.

3. What we collect

  • Account data: name, email, password (hashed), role.
  • Business data: business name, services, prices, working hours, images.
  • Booking/client data: the guest's name, email, phone, appointment details and intake-form answers.
  • Technical data: logs, device/browser info; on the marketing site, cookieless anonymous visit counting (a daily-salted hash, not personally identifying).

4. Legal bases

  • Performance of a contract (Art. 6(1)(b)): running your account and bookings.
  • Legitimate interests (Art. 6(1)(f)): service security, improvement, abuse prevention.
  • Legal obligation (Art. 6(1)(c)): e.g. accounting duties for paid plans.
  • Consent (Art. 6(1)(a)): where we ask for it (e.g. non-essential communications).

5. How we use it

Solely to run the service: showing availability, creating bookings, and sending transactional emails (confirmations, reminders, cancellations, waitlist notices). We do not sell data and we do not run third-party advertising trackers.

6. Recipients and processors

We keep data confidential; our sub-processors are: Neon (database hosting, EU/London), Netlify (application hosting/CDN), Resend (transactional email), Google Firebase (mobile push notifications), and — only if you subscribe to a paid plan — Stripe (payments). Each processes data under a data-processing agreement and only as needed to run the service.

7. International transfers

Data is primarily stored in the EU/EEA and the United Kingdom. Where a transfer occurs, it is protected by an adequacy decision or the European Commission's Standard Contractual Clauses (and the UK IDTA).

8. Retention and deletion

Data is retained while an account is active. Request deletion at hello@slotora.io; we action requests within 30 days. Data we are legally required to keep (e.g. invoicing) is retained for the mandatory period.

9. Your rights

  • Access, rectification, erasure, restriction, portability and objection.
  • Withdraw consent at any time (without affecting prior lawful processing).
  • Complain to a supervisory authority: the ICO (ico.org.uk) in the UK, or the NAIH (naih.hu) in Hungary.

10. Cookies

We use strictly necessary cookies only (your login session and language preference). See our Cookie Policy for detail.

11. Children

The service is for businesses, not for under-16s. We do not knowingly collect data from children.

12. Security

Encrypted transport (HTTPS), password hashing, access controls and regular backups protect your data.

13. Changes

We may update this policy; we will notify you of material changes. Last updated: 26 July 2026.

Sign up free