Legal

Privacy Policy

Effective date: 22 May 2026 · Last updated: 17 September 2026

In plain language: We collect only what is needed to run your barbershop. We do not sell your data. You can delete everything at any time from inside the app. If you are in the EU, you have GDPR rights which we respect.

1. Who We Are (Data Controller)

The MyBarb platform is operated by:

Legal name: BuJaa Beats SH.P.K.
Country: Kosovo
Privacy contact: info@bujaabeats.com

For the purposes of data protection law, the operator above is the data controller for personal data of registered users (shop owners and barbers).

For personal data of end-clients entered by barbershops into the system, the barbershop owner is the data controller and MyBarb acts only as a data processor. A Data Processing Agreement (DPA) is available on request.

2. Data We Collect

We collect only what is strictly necessary to operate the Service:

CategoryDataPurpose
Account data Username, hashed password, shop email address, account creation date Sign-in, account management and account recovery (we email a recovery link to the shop email)
Shop information Shop name, description, address, city, country, time zone, phone, logo, opening hours, profile slug, social media links Running your barbershop profile and public page, and timing client reminders
Staff profiles Barber names, nicknames, usernames, hashed PINs, role, optional photo, slot interval setting Multi-staff access management
Client records Client name and phone number, visit history and the total amount each client has spent at the shop, and an email address only if the client gives one when booking online CRM, appointment history, booking confirmations and reminders
Appointment records Date, time, barber, service, price, status, duration Calendar management and revenue overview
Revenue records The shop's revenue per day, month and year and per barber, stored with your account and calculated from appointment prices Revenue overview for the shop
Service catalogue Service names, prices, duration Booking and public profile
User preferences Language, theme, notification settings, WhatsApp message templates Personalisation and client messages
Photos you upload Shop logo, staff photos, up to 6 gallery photos Shown in the app and on your public page. The camera and photo library open only when you choose to add a photo.
Reviews Name, star rating and text left by a client on your public page, or added by you Shown on your public page. You can hide or delete them.
Push notification token A device token issued through Google Firebase Cloud Messaging (on iPhone together with Apple Push Notification service), the device platform (iOS, Android or web) and the account it belongs to Delivering booking alerts to the devices where you turned notifications on
Usage events Page visits (page address, referring page, time) and a few in-app actions, for example opening the share screen or sharing your booking link, linked to your shop account Understanding which features are used and fixing problems. Stored on our own server only.
Billing status Plan, billing cycle, subscription status, and the customer and subscription IDs issued by our payment processor Stripe Applying your plan. We never receive or store card numbers.
Server access logs IP address, browser or device type, access time. Deleted after 30 days. Security and abuse prevention only

What We Do NOT Collect

3. How We Use Your Data

We do not use your data for advertising, profiling, or marketing. We do not sell, rent, or trade personal data to any third party.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), processing is based on the following GDPR Article 6 grounds:

PurposeLegal Basis
Delivering the Service (account, calendar, CRM, account recovery)Performance of a contract, Art. 6(1)(b)
Push notifications on a device where you turned them onConsent, Art. 6(1)(a). You can withdraw it at any time in your phone or browser settings.
Security logs and abuse preventionLegitimate interests, Art. 6(1)(f)
Legal obligations and authority requestsLegal obligation, Art. 6(1)(c)
Usage events for product improvementLegitimate interests, Art. 6(1)(f)

5. Data Storage & Retention

Where your data is stored

MyBarb stores data in two places:

Retention periods

Data typeHow long we keep it
Active account and business dataFor the lifetime of the active account
After account deletionPermanently purged within 30 days
Push notification tokensUntil you sign out on that device, delete the account, or the push service reports the token as no longer valid
Usage events12 months, then deleted
Account recovery linksSingle use, expire automatically
Server access logs30 days, then automatically deleted
BackupsRolling 7-day server backups (overwritten)

6. Third Parties & Data Sharing

We share personal data only in the following limited situations:

Hosting: Bluehost (USA)

Our database is hosted by Bluehost (Endurance International Group, United States). They act as a sub-processor under their own terms of service and privacy policies. We rely on Bluehost's security and data protection measures for server-side data storage. You can review Bluehost's privacy practices at bluehost.com/privacy.

Push notifications: Google Firebase Cloud Messaging and Apple Push Notification service

If you turn on notifications in the MyBarb iPhone or Android app, the app registers with Google Firebase Cloud Messaging (FCM). On iPhone, FCM delivers through Apple Push Notification service (APNs). The Firebase SDK in the app creates an installation ID and a device token and sends Google basic technical information (such as device model, operating system version, language and time zone) needed to deliver messages, and it reports message delivery statistics to Google. We store the token with your account on our server. When a booking arrives, our server sends the alert text to FCM, which delivers it to your device. Google's and Apple's terms apply to that delivery: firebase.google.com/support/privacy and apple.com/legal/privacy. You can turn notifications off at any time in your phone's settings.

Notifications in web browsers

If you allow notifications in a web browser, the browser's own push service (for example Google, Apple or Mozilla) delivers them. We store the subscription address the browser gives us and remove it when you sign out.

Payments: Stripe

Subscription payments are processed by Stripe, which collects card details directly. We receive only the customer and subscription IDs and the subscription status. See stripe.com/privacy.

Email delivery

Account recovery emails, and booking confirmations and reminders for clients who gave an email address, are sent from our server through our hosting provider's mail service.

Fonts: Google Fonts

The app loads its typeface from Google Fonts, so your device's IP address is sent to Google when the font files are fetched.

QR code images: api.qrserver.com

When you open your shop's QR code, the public link of your shop page is sent to api.qrserver.com (goQR.me) to draw the image. No personal data is included.

WhatsApp / Meta (optional, user-initiated)

The app includes an optional button that opens the WhatsApp app pre-filled with a reminder message for a client. This action is initiated entirely by you (the shop owner). MyBarb does not send anything automatically; it only opens a link. When WhatsApp opens, Meta's own privacy policy governs that interaction. MyBarb does not transmit data to Meta.

Legal requests

We may disclose data if required by a court order, law enforcement agency, or regulatory authority with legal jurisdiction over us. We will notify you where legally permitted to do so.

We never sell, rent, exchange, or share your personal data with advertisers, data brokers, or any third party for commercial purposes.

7. International Data Transfers

Our servers are located in the United States. If you are based in the EEA or the UK, transferring personal data to the US requires safeguards under GDPR Chapter V.

We rely on Bluehost's applicable data transfer mechanisms and compliance framework for this transfer. By using the Service, you acknowledge that your data will be processed on servers located in the United States under these conditions.

If you require a formal Data Processing Agreement (DPA) including specific transfer clauses for your own GDPR compliance as a data controller, please contact us and we will provide one.

8. Cookies & Local Storage

MyBarb does not use tracking cookies, advertising cookies, or third-party analytics cookies.

The app uses the localStorage API of your browser or of the MyBarb app to store application data on your device. Unlike cookies, localStorage data is not sent to any server automatically; it stays on your device. The data stored locally is:

localStorage KeyContains
berberia-shopShop name, address, hours, logo, social links
berberia-barbersStaff list and settings
berberia-sessionCurrent login session (username, role)
berberia-appointmentsAppointment records
berberia-clientsClient names and phone numbers
mybarb-servicesService catalogue
mybarb-subscriptionActive plan information
mybarb-tokenServer authentication token
mybarb-native-tokenThis phone's push notification token (MyBarb apps only), removed when you sign out
mybarb_langDisplay language preference
berberia-themeDark/light theme preference

In web browsers, the Service Worker also caches the app's own code files (HTML, CSS, JS, images) for offline use. This cache contains no personal data, only application code.

9. Your GDPR Rights

If you are in the European Economic Area or the United Kingdom, you have the following rights:

👁
Right of Access
Request a copy of all personal data we hold about you.
✏️
Rectification
Correct inaccurate or incomplete data. Most data can be corrected directly in the app.
🗑️
Erasure
Delete your account and all its data in the app: Dashboard tab, "Delete Shop & Close Account". Server data is purged within 30 days.
📦
Data Portability
Request your data in a structured, machine-readable format.
🚫
Right to Object
Object to processing based on legitimate interests.
⏸
Restriction
Request that we restrict processing in certain circumstances.

To exercise any right, contact us at info@bujaabeats.com. We will respond within 30 days. Identity verification may be required before we act on a request.

You may also lodge a complaint with your national data protection authority at any time. You do not need to contact us first, though we encourage you to do so.

10. Security Measures

We implement the following technical and organisational security measures:

No system is completely immune to security incidents. In the event of a data breach that creates a high risk to your rights and freedoms, we will notify you and the competent supervisory authority within 72 hours, as required by GDPR Article 33, where notification is feasible.

11. Children's Privacy

MyBarb is a professional business management tool for adults. We do not knowingly collect personal data from anyone under 16 years of age. If you believe a minor has provided data to us, please contact us immediately and we will delete it.

12. Relationship to Terms of Service

This Privacy Policy forms part of our Terms of Service, which govern the overall legal relationship between you and MyBarb, including liability limitations, indemnification, dispute resolution, governing law, and the B2B nature of the Service. By using MyBarb, you agree to both documents.

13. Updates to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal obligations. We will notify you of material changes at least 14 days in advance via in-app notification. Minor clarifications may be made without notice.

The current version is always available at mybarb.app/privacy.html. The "Last updated" date at the top of this page reflects the most recent revision.

14. Contact

For privacy questions, data subject requests, or to report a concern:

MyBarb Privacy
Operated by: BuJaa Beats SH.P.K.
Email: info@bujaabeats.com
Response time: within 30 days
Website: mybarb.app · Help: mybarb.com/support.html

If you are unhappy with our response, you have the right to lodge a complaint with your national data protection supervisory authority.