Privacy policy
Kapturia – PRIVACY POLICY
Last updated: 01/12/2025
1. Introduction
Kapturia (“we”, “us”, “our”) is committed to protecting your personal data.
This Privacy Policy explains:
-
what personal data we collect,
-
how we use and share it,
-
your rights regarding your data,
-
and how we keep it secure.
This Policy applies to all visitors, Customers and Providers (“users”) who access or use the Kapturia platform (the “Platform”).
By using Kapturia, you agree to the practices described in this Privacy Policy.
2. Data Controller
The entity responsible for processing your personal data is:
Kapturia
[email protected]
If you have any questions about this Policy or wish to exercise your rights, you may contact us at:
📩 [email protected]
3. Personal Data We Collect
We collect personal data in several ways:
3.1 Data You Provide Directly
For Customers:
-
Full name
-
Email address
-
Phone number (optional or required depending on booking)
-
Payment information (handled by third-party processor, not stored by Kapturia)
-
Booking details (dates, people, special requests, etc.)
For Providers:
-
Full name
-
Business name / legal entity
-
Email address
-
Phone number
-
Address (for verification purposes)
-
Identification documents (ID, business registration, etc.)
-
Portfolio content (photos, videos)
-
Payment/payout details
3.2 Data Collected Automatically
When accessing the Platform:
-
IP address
-
Device information (browser, OS, version)
-
Cookies (session, authentication, analytics, marketing)
-
Usage data (pages visited, actions performed, preferences)
3.3 Data from Third Parties
We may receive:
-
Payment confirmation & fraud prevention data from Stripe or other payment processors
-
Social login information (e.g., Google, Apple)
-
Reviews or ratings submitted on third-party sites, if applicable
4. How We Use Your Data
We use personal data to:
4.1 Provide and Improve Services
-
Manage accounts (Customer or Provider)
-
Process bookings and payments
-
Facilify communication between Customers and Providers
-
Provide customer support
-
Verify Providers and ensure platform safety
4.2 Marketing & Communication
-
Send booking confirmations, reminders, updates
-
Send promotional content (only with consent)
-
Display personalized recommendations
4.3 Legal & Security Purposes
-
Prevent fraud or abuse
-
Enforce Terms & Conditions
-
Comply with legal obligations (tax, accounting, anti-fraud laws)
5. Sharing Your Data
We do not sell personal data.
We may share your data with:
5.1 Service Providers
Such as:
-
Payment processors (e.g., Stripe)
-
Cloud hosting services
-
Email and communication providers
-
Identity verification services
They only access data as necessary to perform their services.
5.2 Providers (for Customers only)
When you book a service, we share with the Provider:
-
your name
-
booking details
-
communication messages
-
other information strictly needed to fulfill the service
5.3 Customers (for Providers only)
When a Provider accepts a booking, the Customer receives:
-
the Provider’s name / business name
-
portfolio images
-
meeting instructions
-
optional contact details (if allowed)
5.4 Legal or Regulatory Authorities
Only when required by law or necessary to protect rights, safety, or enforce our Terms.
6. Cookies & Tracking Technologies
We use cookies for:
-
Site functionality (authentication, session management)
-
Analytics (understanding usage, improving the Platform)
-
Marketing (personalized ads, retargeting if applicable)
Users can control cookies via browser settings or opt-out options where applicable (e.g., cookie banner).
7. Retention of Personal Data
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
| Data Type | Maximum Retention Duration | Legal Basis / Justification |
| Account Details (Profile, email, name) | Active for the duration of the contractual relationship, then permanently deleted or anonymized within 30 days upon account deletion request. | Performance of a contract. |
| Booking Records & Invoices | 10 years from the end of the relevant fiscal financial year. | Legal compliance (French Commercial Code and tax regulations for accounting records). |
| Messages & Chat History (Inbox) | 3 years from the date of the last contact or interaction with the prospect/customer. | Legitimate interest (commercial follow-up, customer support, and dispute management). |
| Verification Documents (Providers ID) | Deleted immediately after profile validation, or retained for a maximum of 5 ans where ongoing anti-fraud vigilance is required. | Legal compliance and fraud prevention. |
| Marketing Data (Newsletters, AI follow-ups) | 3 years from collection or from the last active contact from the user (unless consent is withdrawn earlier). | Consent and regulatory compliance (CNIL / GDPR guidelines). |
| Google / Outlook Tokens & Caches | Permanently purged immediately (and within a maximum of 30 days for database caches) upon disconnection of the integration or account deletion. | Consent and Google API User Data Policy compliance. |
8. Data Security
We implement technical and organizational measures to protect your data, including:
-
encryption of data in transit (HTTPS)
-
secure storage using reputable cloud providers
-
restricted internal access
-
routine security monitoring
-
compliance with PCI-DSS for payment processing (via Stripe)
However, no system is 100% secure. Users are responsible for protecting their login credentials.
9. International Transfers
Your data may be transferred to servers located outside your country, including in jurisdictions with different data protection laws.
In such cases, Kapturia ensures appropriate safeguards (e.g., standard contractual clauses, certified providers).
10. Your Rights
Depending on your jurisdiction (e.g., GDPR in the EU, CCPA in California), you may have the right to:
-
Access your data
-
Correct inaccurate data
-
Delete your data
-
Restrict processing
-
Object to certain processing
-
Withdraw consent (e.g., for marketing)
-
Data portability
-
File a complaint with a data protection authority
To exercise your rights, contact:
📩 [Insert Data Protection Email]
We may require proof of identity before processing requests.
11. Children’s Privacy
Kapturia is not intended for individuals under 18.
We do not knowingly collect data from minors. If data has been collected inadvertently, contact us to request deletion.
12. Third-Party Links
The Platform may contain links to third-party websites.
Kapturia is not responsible for the privacy practices of these external sites.
13. Changes to This Privacy Policy
We may update this Policy to reflect technical, legal or operational changes.
When changes are significant, we will notify users via:
-
email,
-
Platform notifications,
-
or updated banner.
Continued use of the Platform after changes means you accept the updated Policy.
14. Contact Information
For questions about this Policy or your personal data rights, contact us at:
📩 [email protected]
🏢 Kapturia 7 rue du levant 93100 Montreuil
15. Google API Services User Data Policy Disclosure
15. Google API Services User Data Policy Disclosure
To enable automated scheduling and booking features, Kapturia integrates with Google Calendar API services. In strict compliance with the Google API Services User Data Policy, we disclose the following practices regarding Google user data:
15.1 Data Accessed & Collected
Through the OAuth consent screen, Kapturia requests access to your Google Calendar scopes (e.g., `https://www.googleapis.com/auth/calendar.readonly` or `https://www.googleapis.com/auth/calendar.events`). We only access:
* Your calendar time zones, free/busy slots, and existing event titles/durations.
* No other Google services, emails, or personal drive data are accessed, read, or collected.
15.2 Data Usage & Purpose We process your Google Calendar data strictly to power our core platform booking functionality. Specifically, we use this data to:
Display your availability inside your Kapturia provider dashboard.
Read your free/busy blocks so that clients browsing the Kapturia platform can only book available slots, preventing any double-bookings.
Automatically insert and sync new confirmed bookings generated on Kapturia directly into your Google Calendar. We do NOT use this data for profiling, advertising, or marketing purposes.
15.3 Data Sharing & Third-Party Restrictions
Kapturia does NOT sell, rent, or trade your Google user data. Google Calendar information is kept strictly internal. We only share specific event data (such as booking times and customer names) with the direct contractors you explicitly assign to that event (e.g., your assigned makeup artists or photographers) to fulfill the service. We do not share Google user data with external AI training models or any other third-party platforms.
15.4 Data Storage, Retention, and Deletion
* **Storage:** Google OAuth access tokens and refresh tokens are securely encrypted and stored using industry-standard cryptographic practices on our secure hosting infrastructure.
* **Retention:** We only retain calendar event data for as long as your Kapturia account is active, up to a maximum of 30 days in our local cache following account closure or disconnection, as detailed in Section 7.
* **Deletion:** You can revoke Kapturia's access to your Google account at any time directly through your Google Security Settings page, or by clicking "Disconnect Google Calendar" in your Kapturia Integration settings. Upon account deletion, all associated Google OAuth tokens and synced calendar caches are permanently purged from our databases within 30 days.
