Privacy Policy

Last updated: 27.08.2026

This Privacy Policy explains how Taimli, operated by IiroMan OÜ (“Taimli”, “we”, “us”), processes personal data when you use our services. We are committed to protecting the privacy of salon owners, salon staff, and individuals who book appointments through salon pages hosted by Taimli.

We comply with the EU General Data Protection Regulation (GDPR) and applicable Estonian data protection laws.


1. Who We Are

IiroMan OÜ
Sepapaja tn 6
Tallinn 15551, Estonia
Email: [email protected]

For data protection matters, you can contact us at the same email address.


2. Roles Under GDPR

Taimli processes different categories of data under different GDPR roles:

Taimli as Data Controller

We are the Data Controller for:

  • Salon owner account data
  • Business information (email, address, registration number)
  • Platform usage data
  • Communication sent by us (e.g., transactional emails)
  • Billing and subscription information (processed via Stripe)
  • Stripe Connect connection metadata used to let authorized salon representatives set up and monitor the salon's connected Stripe account
  • In-app product update announcements shown to salon staff
  • Support requests and other inbound email sent to Taimli

Taimli as Data Processor

Salon owners are independent Data Controllers for data about their clients.

We process salon client data on behalf of the salon, including:

  • Client name
  • Email
  • Phone number
  • Booking information (services, staff, time)
  • Waitlist preferences, if the client joins a waitlist (requested services, preferred dates and time ranges, worker preference, name, and email)
  • Notes added by the client or the salon

A separate Data Processing Agreement (DPA) is available to salon owners.


2.1 Salon Data Ownership

Salon business data—including customer lists, booking history, services, staff, working hours, and related records—belongs to the salon. Taimli processes it only on behalf of the salon.

Taimli will not remove self-service export tools to make leaving harder, charge for standard self-service exports of a salon's own data, require support tickets for basic exports, offer intentionally crippled exports, or use intimidating legal language to restrict reasonable access to that data.

On reasonable request, Taimli will help salon owners understand exported files and provide migration-related assistance, including helping a future provider understand the export when needed.


3. Personal Data We Collect

3.1 Salon Owners

We collect:

  • Name
  • Email address
  • Business details (name, address, registration code)
  • Bank account details / payout details (if applicable)
  • Subscription & billing information (via Stripe)
  • Connected Stripe account identifier and account-readiness information, if the salon chooses to set up Stripe Connect
  • Support communications

We do not collect IP addresses or device fingerprints.

3.2 Salon Clients (on behalf of each salon)

When clients make a booking, we collect:

  • Name
  • Email
  • Phone number
  • Appointment details
  • Waitlist preferences, if the client joins a waitlist
  • Optional notes (e.g., preferences)
  • Optional treatment-progress photos attached to internal salon notes, if the salon chooses to use this feature

This data belongs to the salon. Taimli processes it only as instructed by the salon. Treatment-progress photos may include health information or other special-category personal data. The salon is responsible for deciding whether to collect such photos and for having an appropriate GDPR Article 6 lawful basis and, where special-category data is involved, a GDPR Article 9 condition for processing.

3.3 Automatically Collected Data

  • Minimal operational logs required for service reliability
  • Privacy-friendly analytics on Taimli-controlled pages via Plausible (cookie-free analytics provider)
  • Product analytics in the authenticated salon admin interface via PostHog EU only
  • In-app product update announcements in the authenticated salon admin interface via Ferndesk, when Taimli has enabled this feature

These analytics are configured without analytics cookies. Depending on the page, limited technical and usage data such as page path, referrer, approximate location derived from the request, browser/device information, language, and similar visit metadata may be processed for aggregated traffic statistics and product improvement. PostHog is loaded only in the authenticated salon admin interface, uses PostHog's EU endpoint, and is not used on public marketing pages or hosted booking pages. We do not use these analytics for advertising or cross-site profiling.


4. How We Use Personal Data

4.1 Purposes as Data Controller

We use salon owner data to:

  • Provide and operate the Taimli platform
  • Create and manage user accounts
  • Provide hosted booking pages
  • Process subscription payments
  • Send necessary notifications (e.g., booking confirmations for salons, service updates)
  • Maintain security and prevent misuse
  • Handle support requests and other inbound email

4.2 Purposes as Data Processor

For salon clients, we process data to:

  • Create and manage bookings
  • Notify the salon of upcoming appointments
  • Send email and SMS booking confirmations and reminders through our providers, Mailgun and Prelude
  • Send waitlist notification emails if the client joins a waitlist and matching appointment times become available
  • Allow salons to manage their customer relationships, including internal salon notes and optional treatment-progress photos if the salon chooses to use that feature

We do not use client data for our own marketing or analytics.

4.3 Optional Google Calendar Integration

If a salon worker chooses to connect their Google account, Taimli can sync that worker's bookings from Taimli to a Google Calendar created or used for that integration.

For this feature, Taimli may process:

  • the connected Google account email address
  • OAuth tokens required to maintain the connection
  • the worker identifier and salon identifier linked to the connection
  • booking data needed to create calendar events, such as booking time, service names, salon location, and a Taimli manage link

This integration is:

  • optional and initiated by the user
  • one-way only from Taimli to Google Calendar
  • limited to bookings assigned to the connected worker

Changes made in Google Calendar do not sync back into Taimli.

We use Google Calendar data only to provide and maintain this integration. We do not use it for advertising, profiling, or unrelated purposes.

4.4 Optional Stripe Connect Account Setup

If an authorized salon representative chooses to set up the salon's connected Stripe account, Taimli sends limited account and connection information to Stripe to create and maintain that connection.

Taimli may process:

  • the salon's email address
  • the internal salon identifier
  • the Stripe connected account identifier
  • onboarding status and whether Stripe reports that account details, charges, and payouts are enabled
  • limited requirement status returned by Stripe, such as the names of outstanding fields and a disabled-reason code

Stripe hosts the onboarding form and collects identity, business, tax, bank account, verification-document, and other compliance information directly from the salon's representative. Taimli does not receive or store the full information entered into Stripe-hosted onboarding.

For Stripe Connect onboarding and the operation of the connected account, Stripe acts as an independent controller under its own privacy policy and legal obligations. Taimli acts as controller for the limited connection metadata it keeps to provide and secure the integration.

Setting up Stripe Connect does not currently enable salon-client payments in Taimli. If customer payment features are introduced, this Privacy Policy and the applicable salon notices will be updated as needed before additional payment data is processed.

4.5 In-app changelog announcements

When Taimli enables in-app product update announcements in the authenticated salon admin interface, Taimli loads Ferndesk so salon staff can see announced changelog entries.

For this feature, Taimli may send to Ferndesk:

  • the staff user's internal identifier
  • email address
  • display name, if a worker profile name is available

This is used only to show announced product updates and to remember which announcements a signed-in staff user has already seen, including across devices. Ferndesk may also process limited technical data needed to display the widget. Ferndesk is not loaded on public marketing pages or hosted booking pages, and it is not used for salon-client data.

Ferndesk is operated by Work Paragon in the United States. Transfers are protected by Standard Contractual Clauses and other GDPR-compliant safeguards.

4.6 Support and inbound email

Taimli uses Fernand to receive and manage support requests and other inbound email sent to Taimli, such as messages to [email protected].

For this purpose, Fernand may process:

  • the sender's name and email address
  • the message content and any attachments
  • limited account or salon information looked up from the sender's email so Taimli can respond

This is used only to handle correspondence with Taimli. Fernand is not used to send booking confirmations or other salon-client transactional messages.

Fernand is operated by Fernand SAS in France. Data is hosted in the EU.


5. Legal Bases (GDPR)

We process personal data under the following legal bases:

For salon owners:

  • Performance of contract — providing the Taimli platform
  • Legal obligation — invoicing, accounting
  • Legitimate interest — security, fraud prevention, service improvement

For salon clients (on behalf of salons):

  • Performance of contract (between client and salon)
  • Consent, where required by the salon (e.g., marketing)

Where salons use Taimli to store treatment-progress photos or other information that may reveal health data, the salon must also identify and document the applicable GDPR Article 9 condition for processing that special-category data.


6. Cookies & Tracking

  • We do not use analytics cookies on the website or on hosted booking pages.
  • Taimli uses Plausible Analytics for privacy-friendly, cookie-free traffic measurement on Taimli-controlled pages.
  • Taimli uses PostHog EU for product analytics in the authenticated salon admin interface only. PostHog is not loaded on public marketing pages or hosted booking pages.
  • When Taimli has enabled in-app changelog announcements, Ferndesk is loaded only in the authenticated salon admin interface. It is not loaded on public marketing pages or hosted booking pages.
  • Cloudflare may temporarily process IPs to provide security and performance services.
  • Cloudflare Turnstile is used on booking pages for bot protection. It does not use cookies and processes minimal data (such as browser characteristics and interaction patterns) to distinguish humans from bots. This processing is based on legitimate interest (GDPR Article 6(1)(f)) for security purposes.

7. Data Sharing

We share data only with essential service providers, all of whom operate in the EU or provide GDPR-compliant safeguards:

  • Stripe — Taimli subscription payment processing and optional Stripe Connect account onboarding
  • Hetzner & Servinga — VPS hosting (EU)
  • PlanetScale — managed PostgreSQL database (EU region)
  • Cloudflare — DNS and security; some routing may occur outside the EU under Standard Contractual Clauses
  • Cloudflare R2 — storage for salon images (EU region)
  • Cloudflare Turnstile — bot protection on booking pages (no cookies, minimal data processing)
  • Mailgun — transactional email (EU region)
  • Fernand — support and other inbound email (EU)
  • Prelude — SMS delivery for booking confirmations and reminders (EU region)
  • Plausible — privacy-friendly website analytics (cookie-free)
  • PostHog EU — product analytics for the authenticated salon admin interface only
  • Ferndesk — in-app changelog announcements for the authenticated salon admin interface only (United States; Standard Contractual Clauses apply)

If a salon worker enables the optional Google Calendar integration, relevant booking data is also sent to Google to create, update, and delete calendar events for that worker.

If an authorized salon representative enables optional Stripe Connect account setup, the limited salon and connection data described in section 4.4 is sent to Stripe. Stripe independently collects and controls the onboarding and compliance information entered on its hosted pages.

We do not sell personal data.


8. International Data Transfers

Taimli stores and processes data primarily within the EU.

Some providers (such as Cloudflare, Mailgun, or Ferndesk, depending on configuration) may transfer data outside the EU.
In these cases, transfers are protected by Standard Contractual Clauses (SCCs) and other GDPR-compliant safeguards.

We aim to keep all data processing within the EU whenever technically possible.


9. Data Retention

We follow a minimal retention policy:

Salon Owner Data

  • Retained only while the account is active
  • Deleted immediately upon account deletion, except where retention is required by law (e.g., accounting records)

Salon Client Data

  • Retained only while the salon’s account is active
  • Deleted immediately when:
    • the salon deletes it, or
    • the salon’s account is deleted

Waitlist entries and notification history are treated as salon client data and are retained only while the salon's account is active, unless deleted earlier.

Salon owners can use Taimli's self-service export tools to download their salon data before canceling or deleting their account. These exports are intended to support backups, reporting, GDPR portability requests, and migration to another provider. Taimli maintains these export tools so salons can take their data with them when they leave.

Backups

Service provider backups (e.g., PlanetScale database backups) may retain deleted data for 30–90 days, after which it is automatically purged.

We do not retain additional internal backups.


10. Your Rights (GDPR)

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion
  • Request data export
  • Object to processing
  • Withdraw consent (if processing is based on consent)

For salon clients:

  • Requests should be made to the salon, as the data controller.
  • Taimli will assist salons in fulfilling these requests.

To exercise your rights, contact [email protected].

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate.


11. Children’s Data

Taimli may process data about children only when submitted by a parent/guardian or by a salon in the context of providing services to the child (e.g., a haircut).

We do not knowingly allow account registration by minors.


12. Security Measures

We use modern security practices to protect data, including:

  • HTTPS encryption
  • Encryption at rest where supported by providers (e.g., PlanetScale, Cloudflare R2)
  • Access control and authentication
  • Password hashing (e.g., Argon2) for future password features
  • Regular monitoring and security updates

No system is perfectly secure, but we continuously work to protect personal data.


13. Automated Decision-Making

Taimli does not use automated decision-making or AI for user profiling.
Simple automated operations (such as round-robin staff assignment) are performed solely to fulfill booking functionality.


14. Changes to This Policy

We may update this Privacy Policy when needed.
We will post updates on our website and update the “Last Updated” date.


15. Contact

For questions, concerns, or data requests, contact:

[email protected]