Skip to content
AMOLIE

Privacy Policy

How AMOLIE handles the personal data of masters, their clients, and visitors to this site.

Revision of 2026-08-25

Contents

  1. 1. Who is responsible
  2. 2. Two roles: controller and processor
  3. 3. The master’s data
  4. 4. The clients’ data
  5. 5. Visitors to this site
  6. 6. Who processes data on our behalf
  7. 7. Transfers outside the EEA
  8. 8. How long we keep it
  9. 9. Your rights
  10. 10. How to exercise them
  11. 11. Complaints
  12. 12. Security
  13. 13. Age
  14. 14. No automated decisions
  15. 15. Changes to this policy

1. Who is responsible

AMOLIE (amolie.com) is operated by the AMOLIE team, established in Latvia, European Union. Company registration details will be published here once incorporation is complete.

For anything concerning personal data, write to privacy@amolie.com. We answer within 30 days — the outer limit set by Article 12(3) GDPR; in practice, sooner.

No Data Protection Officer has been appointed: the scale and nature of our processing do not meet the Article 37 threshold. The address above receives every request.

2. Two roles: controller and processor

AMOLIE is a platform on which a master runs her own booking. That gives us two distinct roles, and your rights differ between them.

  • For the master’s own data — account, subscription, page settings — we are the controller: we decide why and how it is processed.
  • For her clients’ data — name, phone, visit history — we are a processor. The controller is the master: she collects it, she decides its fate, and we act on her instruction and never for our own purposes.

What this means for a salon client: a deletion or access request goes to the master you booked with. Write to us and we will pass it on and help her act on it, but the decision is hers. The terms of our instruction are set out in the “Processing of client data” section of the Terms of Use.

3. The master’s data

WhatWhyLegal basisKept for
Name, email, phone, password hashAccount, sign-in, account recoveryPerformance of a contract, Art. 6(1)(b)As long as the account exists
Business name, address, description, page photographsThe public booking page the contract is forPerformance of a contract, Art. 6(1)(b)As long as the account exists
Plan, subscription status, payment historyInvoicing and accountingContract and legal obligation, Art. 6(1)(b) and 6(1)(c)5 years after the last transaction, under Latvian accounting law
Internal audit log of actions in the dashboardIncident investigation, protection against unauthorised accessLegitimate interest, Art. 6(1)(f)12 months
Push notification subscription endpointAlerts about new bookingsConsent, Art. 6(1)(a) — given when you allow notifications in the browserUntil the permission is withdrawn
IP address and server logsAvailability, protection against brute force and abuseLegitimate interest, Art. 6(1)(f)Up to 30 days

We neither collect nor ask for special categories of data (Article 9 GDPR). Client notes are a free-text field, and the master is responsible for keeping health information out of it.

4. The clients’ data

When someone books through a master’s page, we store their name and phone, optionally email or Instagram, the services chosen, the date and time of the visit, and any note the master adds.

Only the master who was booked can see it. Other masters on the platform have no access to another address book — the separation is enforced at the database query level, not by hiding buttons.

We do not sell this data, do not pass it to ad networks, and do not use it to train models. The only parties that touch it are the processors in section 6, and only so that the service runs.

5. Visitors to this site

This site needs no analytics counter, no advertising pixel, no social widget — and carries none. We keep 7 entries on a visitor’s device, all of them strictly necessary: interface language, your answer to the storage notice, the sign-in session, and a client device’s memory of its own recent bookings.

EntryWhereKept for
amolie_localeCookie365 days
amolie_storage_consentCookie180 days
access_tokenCookie12 hours
impersonator_tokenCookie30 minutes
amolie.device-visits.v1localStorageuntil storage is cleared
amolie.device-guest.v1localStorageuntil storage is cleared
themelocalStorageuntil storage is cleared

Each entry is described in full in the Cookie Policy. We do not profile visitors.

6. Who processes data on our behalf

We do not run our own data centre. Data sits with the providers below, each under an Article 28 GDPR data processing agreement.

ProviderPurposeHostingPolicy
Vercel Inc.Hosting for the site and dashboardEU (fra1)vercel.com/legal/privacy-policy
Fly.io, Inc.Hosting for the backendEU (arn, Stockholm)fly.io/legal/privacy-policy
Supabase, Inc.DatabaseEU (eu-north-1, Stockholm)supabase.com/privacy
Resend, Inc.Transactional email — confirmations, account recoveryEU / USresend.com/legal/privacy-policy

Push notifications are delivered by the browsers’ own services (Google, Apple, Mozilla). They receive a subscription endpoint and an encrypted payload, never the client address book.

We disclose data to public authorities only on a valid, reasoned legal request, and notify the affected master whenever the law permits.

7. Transfers outside the EEA

The database and backend run in Stockholm, the site in Frankfurt. By default, data does not leave the European Economic Area.

Some providers are incorporated in the United States and may, in specific cases (support, disaster recovery), access data from there. Those transfers are covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914) and, where the provider participates, the EU–US Data Privacy Framework. A copy of the clauses is available on request to the address in section 1.

8. How long we keep it

Per-category periods are in the table in section 3. The general rule: data lives as long as the account and is deleted with it.

  • When a master deletes her account, the data is marked deleted at once and erased from the live database within 30 days.
  • Backups roll over within 35 days; deletion reaches them with that delay.
  • Records the law requires us to keep — invoices and accounting entries — remain for their statutory period and are not deleted on request.

9. Your rights

Under Chapter III of the GDPR you may:

  • obtain a copy of your data and information about the processing (Art. 15);
  • have inaccuracies corrected (Art. 16);
  • request erasure (Art. 17);
  • restrict processing while a dispute is resolved (Art. 18);
  • receive your data in a machine-readable format and port it (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time — withdrawal does not affect the lawfulness of processing before it (Art. 7(3)).

We export or delete an account’s data on written request from the address on file. The copy arrives as a machine-readable file.

10. How to exercise them

Write to privacy@amolie.com from the address on your account. We answer within 30 days; a complex request may extend that by up to two further months, and we will tell you if it does.

There is no charge. We may ask you to confirm your identity if a request arrives from an unfamiliar address — but confirming should never be harder than the request itself.

11. Complaints

If our answer does not satisfy you, you may complain to the Latvian Data State Inspectorate (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, pasts@dvi.gov.lv, dvi.gov.lv.

A resident of another EU country may instead complain to the authority where they live or where the alleged infringement took place.

12. Security

  • All traffic runs over TLS; the server refuses unencrypted connections.
  • Passwords are stored as Argon2id hashes and cannot be recovered, by us either.
  • The database sits on a private network; access to production is limited to those who need it and goes through two-factor authentication.
  • Data separation between masters is covered by automated tests that run on every change.

A breach likely to affect your rights is reported to the supervisory authority within 72 hours and to you without undue delay (Articles 33 and 34 GDPR).

13. Age

The service is not intended for anyone under 16 — the Article 8 GDPR threshold as set in Latvian law. We do not knowingly create accounts for them and delete such data when we learn of it.

14. No automated decisions

We take no decisions producing legal effects for you by automated means alone, and we do not profile within the meaning of Article 22 GDPR.

15. Changes to this policy

The date of the current edition appears at the top. We notify masters by email at least 14 days before a material change takes effect; minor clarifications are published here without a separate message.

Still have questions?

Write to privacy@amolie.com — we answer within 30 days, usually sooner.

privacy@amolie.com

Other documents

  • Cookie Policy
  • Terms of Use

AMOLIE

Online booking for beauty professionals.

Latvia and the Baltics
Data kept in the European Union, under GDPR

Product

  • What it looks like
  • How it works
  • Questions
  • Log in
  • Sign up

Legal

  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • What is stored on your device

Contact

  • Support
  • Data and GDPR
  • Contracts and claims

© 2026 AMOLIE. All rights reserved.

AMOLIE processes client data on the master’s behalf; the master is the controller (Art. 4 GDPR).

We store only what is necessary on your device

No analytics, no advertising pixels, no third-party scripts. Interface language, the sign-in session, and this answer — that is the whole list. See what is stored