Privacy Policy
Last updated: 28 June 2026
This Privacy Policy explains how Masaro processes your personal data when you use our platform to book or provide local professional services. We process data in line with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). Please read it together with our Terms of Use.
Data controller
Masaro is a service operated by Appsibly ('we', 'us', the 'operator'), which acts as the controller of your personal data and determines why and how it is processed. The operator's company registration number (IČO) and registered office (sídlo) will be inserted here before public launch.
You can reach us on any data-protection matter, including to exercise your rights, at [email protected].
What data we process and why
Account data: your name, email address, password (stored only as a bcrypt hash, never in plain text) and your role (client, provider or administrator). We use this to create your account, sign you in and keep it secure. Legal basis: performance of our contract with you and our legitimate interest in account security.
Social login data: if you sign in with Google, Facebook, Apple or Seznam.cz, we receive your email address and name from that provider to create or match your account. Legal basis: performance of our contract with you.
Booking data: the service and duration you choose, the price, the venue or destination address and any address note, geographic coordinates, notes for the provider, booking status, and payment method and status. We use this to arrange and complete the booked service. Legal basis: performance of our contract with you.
Provider profile data: if you apply as a provider, we process your profession, bio, certifications, years of experience, travel radius, business location and rating. We use this to review your application and show your profile to clients. Legal basis: performance of our contract with you and our legitimate interest in keeping the platform safe and trustworthy.
Reviews: after a completed booking a client can leave a rating and an optional comment about the provider. We use reviews to maintain quality and trust on the platform. Legal basis: our legitimate interest in service quality.
Location data: with your permission we use your browser's geolocation and a geocoding lookup solely to find nearby providers, show venues on the map, or arrange a mobile service. You can decline location access and enter an address manually. Legal basis: your consent.
Technical and analytics data: we keep limited technical logs (such as IP address and request information) to operate and secure the service, and we measure aggregate, anonymous traffic using a cookieless analytics tool. Legal basis: our legitimate interest in security and in understanding overall usage.
Legal bases for processing
We rely on the following legal bases under the GDPR: performance of a contract for creating your account and arranging bookings; your consent for accessing your device location; and our legitimate interests in securing the platform, preventing abuse, measuring aggregate usage and maintaining reviews. Where we rely on consent you can withdraw it at any time, and where we rely on legitimate interest you can object (see Your rights).
Cookies
We use a strictly necessary session cookie to keep you signed in, a functional 'i18n_locale' cookie to remember your language, and a 'masaro_consent' cookie to remember your cookie choices. These are required for the service to work or to honour your preferences.
For analytics we use Cloudflare Web Analytics, which is privacy-friendly and cookieless: it sets no cookies, does not track you across sites and does not build a profile of you.
Who we share data with
We do not sell your personal data. We share it only with service providers (processors) who help us run Masaro, and only as needed: Resend for sending transactional emails (booking offers and status updates); Google, Facebook, Apple and Seznam.cz when you choose to sign in with them; Cloudflare for cookieless analytics and content delivery; a geocoding provider to convert between addresses and coordinates; and our hosting provider (OVH) which stores the data on our behalf.
When you book, the necessary details you provide, including your contact, address where relevant, and notes, are shared with the independent provider delivering the service. We may also disclose data where required by law.
International transfers
We aim to keep your data within the European Union and the European Economic Area. Some processors that operate globally may process data outside the EEA; where this happens, the transfer is protected by appropriate safeguards such as the European Commission's standard contractual clauses or an adequacy decision.
How long we keep your data
We keep your personal data only for as long as necessary. Account data is kept while your account is active and for a reasonable period afterwards; booking and review records are kept as long as needed to provide the service, resolve disputes and meet our legal and accounting obligations, after which they are deleted or anonymised. You can ask us to delete your account at any time, subject to records we are legally required to retain.
Your rights
Under the GDPR you have the right to access your personal data; to rectify inaccurate data; to erase your data (the 'right to be forgotten'); to restrict processing; to data portability; to object to processing based on our legitimate interest; and, where processing is based on consent, to withdraw that consent at any time without affecting processing carried out before withdrawal.
How to exercise your rights and complaints
To exercise any of these rights, contact us at [email protected]. We will respond within the time limits set by the GDPR, normally free of charge.
If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, www.uoou.cz); in Slovakia it is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, www.dataprotection.gov.sk).
Children
Masaro is not directed at children. You must be at least 18 to use the service, and in any case we do not knowingly process the personal data of children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will change the 'last updated' date above and, for significant changes, take reasonable steps to inform you. Please review it periodically.
Note: this document was prepared by the Masaro team and we are not lawyers. The operator's registered company details (IČO, registered office) must be completed and the full text reviewed by a qualified lawyer before launch.