Last updated: August 2026
Privacy Policy
This policy explains what personal data Hora collects, why, and how we protect it. It covers the Hora web app and this website.
01 Data controller Hora is run by one person, Petar, and that is who you write to.
Hora is operated by Petar Hajak, Croatia. For privacy questions, contact info@hora-booking.com.
02 Our role and yours Your salon data is yours. Client data is your responsibility; we process it for you.
It depends whose data it is. For your account and salon data, Hora is the controller. For the data of your clients that you enter or that a client provides when booking, you are the controller and Hora is a processor that handles it only on your instructions. If a client opens their own Hora account, Hora is the controller for that account data and answers to the client directly.
03 Data we collect What you enter about the salon and its appointments, plus the technical minimum to run it.
Account and salon data (name, email, salon name and description, address, phone, photos, staff), appointment and client data you enter or a client provides when booking (name, phone, email, appointment history and notes), a client account if one is opened (name and email), reviews a client leaves, technical data needed to run the service (such as IP address and sign-in details), and billing data.
04 Why we process data To make booking work and confirmations arrive. We never sell it or advertise with it.
To provide the booking service and send confirmations and reminders (performance of a contract), to run and improve the product and prevent abuse (legitimate interest), to meet legal obligations (such as accounting), and on consent where required. We do not sell your data and do not use it for advertising.
05 Google Calendar connection Optional. Hora writes to a calendar it creates and reads nothing from your Google.
Connecting is optional and you turn it on yourself. Hora requests only the calendar.app.created scope, which grants access solely to the calendar Hora itself creates in your Google account, plus your email address so we can show which account is connected. Hora cannot read, change or delete your existing calendars. The sync is one-way: Hora appointments are written into that calendar and nothing is read back from Google. An event carries the service name, and, if you turn on detail display, the client name, phone and note. Access and refresh tokens are stored encrypted (AES-256-GCM) and used only for this sync. You can disconnect at any time in Hora settings or at myaccount.google.com/permissions, which deletes the stored tokens.
06 Limited use of Google data We never sell Google data, advertise with it, or train models on it.
Hora's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell that data, do not use it for advertising, and do not use it to develop or train artificial intelligence models. We do not share it with third parties except as necessary to provide the service itself, for security purposes, or where required by law.
07 Reviews A rating and a shortened name are published, never a surname, phone or email.
After a completed appointment a client can leave a rating, a short comment and tags. The review is published on the salon’s public profile with a shortened name (for example "Ana K."), never with a full surname, phone or email. Reviews are voluntary, and removal can be requested at info@hora-booking.com.
08 Map on the salon profile If a salon has an address, Google loads the map and sees your IP address.
If a salon enters an address, its public profile shows a map loaded from Google (Maps Embed API). Opening such a profile sends a request from your browser to Google, including your IP address, subject to Google's privacy policy. The map loads only on profiles with a saved address.
09 Who we share data with Only the providers the service cannot run without. Never for advertising.
Only with trusted service providers that help us operate, acting as processors: Supabase (database and sign-in, EU region Ireland), Resend (sending email), Cloudflare (hosting and site delivery), and Google, only if you connect Google Calendar yourself or open a salon profile showing a map. We do not share data for advertising. When we introduce SMS reminders and subscription billing through a payment provider, we will name those providers here before turning them on.
10 Where data is stored In the European Union, in Ireland.
Data is primarily stored in the European Union (Supabase, Ireland region). Google may process data outside the EU if you use calendar sync or open a profile with a map, under standard contractual clauses and other safeguards provided by the GDPR.
11 How long we keep data While your account is open. About 30 days after closing, minus what the law requires.
While your account is active. After an account is closed, we delete or anonymize personal data within about 30 days, and backups expire shortly after. Invoices and tax records are kept for as long as Croatian law requires (currently up to 11 years for accounting documents).
12 Your rights You can export your data and delete your account yourself, without waiting on us.
You have the right to access, correct, delete and port your data, and to restrict or object to processing. In the app you can export your data and delete your account yourself, and you can also send a request to info@hora-booking.com. For data a salon entered into Hora, you exercise your rights directly with that salon. You may also lodge a complaint with the Croatian Data Protection Agency (AZOP).
13 Cookies and data on your device No tracking, no analytics. Only what sign-in and your bookings need.
This website uses no tracking or analytics cookies. The app uses only the cookies needed to sign in and run the service. If you request an appointment without an account, the booking page stores a random key for that appointment on your device so you can view and cancel it without signing in. That key is not your name or contact details. Clearing browser data loses access to the appointment from that device, but the appointment still exists with the salon. With a Hora account, appointments are tied to the account rather than the device.
14 Security Access is restricted, transfers encrypted, sensitive tokens encrypted at rest too.
Access to data is restricted by database-level policies, transfers are protected with encryption, and sensitive tokens such as those for Google Calendar are encrypted at rest as well. No system is fully secure, but we take reasonable measures to protect your data.
15 Changes If something significant changes, we will tell you.
We may update this policy from time to time. The last-updated date is shown at the top, and we will notify you of significant changes.
16 Contact Write to info@hora-booking.com and Petar answers.
For any privacy questions, contact info@hora-booking.com.