Privacy Notice
Last updated 2026-07-29
How StillOpen handles personal data — what we collect, why, who we share it with, how long we keep it, and the rights you can exercise.
1.Two roles, two sets of rules
StillOpen sits between two groups of people, and our legal role is different for each. Read the part that applies to you.
- Business owners and their staff. When you sign up, subscribe, or use the dashboard, StillOpen is the controller of your account data. We decide what we collect and why, and this notice is our explanation to you.
- People who book an appointment. When you book through a business’s StillOpen page, that business is the controller of your data. StillOpen is its processor— we store and handle your details on that business’s instructions, under a Data Processing Agreement. The business’s own privacy notice governs what it does with your data; this notice tells you what we do with it on their behalf.
Our Data Processing Agreement is the contract behind the second role. It sets out the purposes we may process for, the security measures we apply, breach notification, audit rights and sub-processor management. Business owners can request a copy — including a countersigned PDF — from legal@stillopen.app.
2.What we collect
From business owners (we are the controller)
- Account — name, email address and password. Passwords are stored only as a hash by our authentication provider; we never see them in plain text.
- Business profile — business name, page slug, category, address, phone number, timezone, currency, opening hours, logo and page content, plus the staff members, services and availability you configure.
- Billing — plan, billing interval, currency, subscription status, and the Stripe customer and subscription identifiers. Payments are taken by Stripe; StillOpen never receives or stores card numbers. If you enable payments, your bank and identity details go directly to Stripe as part of its onboarding — they do not pass through us.
- Support and contact — messages, issue reports and any attachments you send us, and the email address you used.
- Technical and usage — IP address (stored only as a salted hash), browser user-agent, timestamps, feature usage, and entries in our audit log recording privileged actions taken in your account.
- Waitlist — if you join the pre-launch waitlist, the email address you submit and where you submitted it from.
From people who book (we are the processor)
- Identity and contact — name, email address, phone number.
- Booking history — the appointments you book, the service and staff member, date and time, status, notes and any free-text answers to questions the business asks at booking, plus reviews, favourites, loyalty balances, gift cards, packages and memberships.
- Payment metadata— amount, currency, payment status, tips, and the Stripe identifiers for the transaction. Card details are entered on Stripe’s hosted checkout and never reach StillOpen’s systems.
- Interaction data — visit timestamps and device user-agent, message and call records where the business has enabled SMS, WhatsApp or the AI voice receptionist, and transcripts of conversations with the booking-page concierge.
We do not ask for special-category data (health, biometrics, beliefs). A business may collect it through its own intake questions; if it does, that business is responsible for the additional conditions that apply.
3.Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account; publishing your booking page; taking and managing bookings | Performance of a contract |
| Billing, invoicing and collecting subscription fees | Performance of a contract; legal obligation |
| Sending transactional messages — booking confirmations, reminders, cancellations, receipts, payment failures | Performance of a contract; the business’s instruction where it is the controller |
| Support, security, fraud and abuse prevention, rate limiting, bot protection and audit logging | Legitimate interests — keeping the service safe and available |
| Diagnosing errors and improving the product using aggregated, non-identifying metrics | Legitimate interests |
| Product announcements and marketing email to business owners | Consent, or legitimate interests where you are an existing customer — withdrawable at any time |
| Keeping booking and payment records for tax and audit | Legal obligation |
We do not sell personal data, and we do not use it to build advertising profiles or serve targeted advertising.
4.AI features
Several features send content to AI models run by our sub-processors: theme and page generation, the dashboard copilot, the booking-page concierge, marketing content generation, image generation and the AI voice receptionist. What is sent is the content needed for the task — for example your page copy and brand settings for theme generation, or the conversation and your service list for the concierge.
Our AI providers process this data as our sub-processors, under their commercial API terms, which do not grant them the right to train their models on the content we send. Output is generated for you and is not shared with other businesses.
6.Where your data is stored
Our database, authentication and file storage run in the European Union — the eu-central-1 region in Frankfurt, Germany. Businesses with a US or Asia-Pacific region pinned on their account are stored in that region instead.
Some sub-processors operate in the United States or globally — payment processing, email delivery, AI and error monitoring in particular. Where personal data leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (Module Two: controller to processor) together with the vendor’s own safeguards, including EU-US Data Privacy Framework certification where the vendor holds one.
7.How long we keep it
- Active accounts — for as long as the account exists.
- After cancellation or closure — 30 days, so the account can be exported or restored. After that the business and its operational data (services, staff, bookings, customers, uploaded files) are permanently deleted.
- Booking records — a business can set its own retention period, at least 30 days and at most 20 years. Bookings older than that period are deleted automatically by a daily job.
- Financial and tax records — invoices, payment records and the associated booking references are kept for 10 years to meet tax and audit obligations, and survive account closure.
- Audit logs — retained on their own schedule for security investigation, with sensitive fields redacted when the entry is written.
- Backups — point-in-time recovery covers a rolling 7-day window; deleted data disappears from backups as that window rolls forward.
- Waitlist emails — until we launch and contact you, or until you ask us to remove you.
8.Your rights and how to use them
Under the GDPR and equivalent laws you can ask for access to your data, correction of it, deletion of it, a portable copy of it, restriction of processing, and you can object to processing based on legitimate interests. You can withdraw consent at any time without affecting what we did before you withdrew it. You will not be charged for exercising these rights, and we will not treat you differently for doing so.
If you are a business owner — email legal@stillopen.app. We respond within 30 days. You can also correct most of your data yourself in dashboard settings, and close your account from there.
If you booked with a business — the business is the controller, so send your request to it directly and it must answer within 30 days. In the dashboard we give every business the tooling to act on your request: a one-click export of your record as a JSON file containing your contact details and full booking history, and a “forget” action that erases your personal details from its customer roster. Businesses on the Business plan can also run the same export through our API. If you cannot reach the business, or it does not respond, contact us at legal@stillopen.app and we will pass the request on and assist. Where we verify a request by emailing you a confirmation link, that link is valid for 24 hours.
Erasure is not always absolute: we keep the financial and tax records described above, and we may keep a minimal record that a deletion request was made so we can evidence that we honoured it.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to your national data protection authority.
10.How we protect it
- TLS 1.3 in transit on every public route; AES-256 at rest.
- Row-level security on every database table, so one business can never read another’s data.
- Least-privilege access for our own staff, under confidentiality obligations, with privileged actions written to an audit log that redacts sensitive fields at write time.
- Dependency scanning on every change, point-in-time database recovery over a rolling 7-day window, and daily off-platform backups.
- Rate limiting and optional bot protection on public forms and the API.
If a personal data breach affects you, we will notify the relevant supervisory authority within 72 hours of confirming it, and tell affected business owners within the same window so they can meet their own obligations to their customers.
11.Children
StillOpen is a tool for businesses and is not directed at children. You must be 18 or over to create an account. A business may take a booking on behalf of a child — for example a family appointment — in which case the business is responsible for obtaining any consent its local law requires. We do not knowingly collect data directly from children; if you believe we have, tell us and we will delete it.
12.Changes to this notice
We update this notice when what we do changes. The date at the top shows the current version. For material changes affecting business owners we email the address on the account before the change takes effect. When we engage a new sub-processor, business owners are notified and have 14 days to object.
13.Contact us
For anything in this notice — a data request, a copy of the Data Processing Agreement, or a question about how something works — email legal@stillopen.app. For general support or to report a problem, use our contact page.