Glosy - beauty marketplace
Legal
Politica de confidențialitate
Last updated: 29 June 2026
1. Data controller and contact details
- This policy explains how the operator of the Glosy platform processes personal data.
- The Controller’s identity and complete legal details are available on the Legal information page.
2. Scope and relationship with Providers
- This Policy covers the website, mobile/PWA apps, accounts, public profiles, webspaces, bookings, Glosy payments, gift cards, B2B marketplace, communications, and management dashboards.
- Glosy is controller for Platform/account administration, security, Glosy Products, its own billing, moderation, and legal duties. The selected Provider is usually an independent controller for service performance, professional records, invoicing, and its own marketing.
- Where Glosy processes data solely on a Provider’s instructions, it may act as a processor. [TO VERIFY: controller/joint-controller/processor allocation and GDPR agreements with Providers and Distributors.]
- Third-party policies govern processing those parties independently determine, such as card issuers and app stores.
3. Data sources
- We receive data from you at registration, in profiles, settings, questionnaires, bookings, reviews, forms, checkout, marketplace, privacy requests, and support communications.
- Providers, staff, Distributors, or other users may supply data when creating bookings, responding to requests, sending legitimate invitations, or updating relationship status.
- We automatically receive device, browser, cookie, Platform-interaction, log, anti-fraud, payment-provider, email-provider, and push data and, when location is requested, geocoding or IP-based estimation data.
- Professional details may be checked against official registers or other lawful public sources where verification is necessary and proportionate. [TO COMPLETE: sources used and verification frequency.]
4. Account, profile, and authentication data
- Identity/contact: name, email, optional phone, role, language, time zone, avatar, address, and preferences.
- Authentication/security: password hash, email verification, sessions and pseudonymous identifiers, IP, user-agent, registration/login attempts, confirmation/reset/deletion tokens, and security events.
- Settings: operational notifications, email/SMS/push marketing consents, personalised recommendations, optional sharing, processing objection, accessibility, and account retention controls.
- Passwords are not stored in plain text. Do not place unnecessary information in your profile.
5. Professional data and public content
- Provider data may include professional/business name, legal form and identifiers supplied, city, work address, coordinates, speciality, experience, certifications, languages, description, services, prices, schedule, locations, staff, travel policies, images, and portfolio.
- Distributor data may include company, tax ID, contact, address, logo, description, commercial terms, categories, catalogue, variants, SKU, stock, prices, and orders.
- Public Content includes profiles, webspaces, campaigns, offers, recruitment/chair-rental listings, posts, rating, reviews, and responses. It can be viewed by anyone and indexed by search engines.
- Moderation data includes reports, reasons, approvals, administrative notes, appeals, and action history.
6. Bookings and the Customer–Provider relationship
- We process Customer/contact, Provider, location and staff, one or more services, date/time, duration, time zone, home-service address, status, and change history.
- We may process service-name/price snapshots, discount/campaign, gift-card code and redeemed amount, payment method/status where present, notes, cancellation reason, waitlist, customer block, and notification metadata.
- Necessary data goes to the selected Provider and authorised staff. The Customer receives data needed to identify and contact the Provider.
- Do not add sensitive information to notes unless indispensable. The Provider must identify a separate lawful basis for necessary medical/allergy information.
7. Payments, billing, digital products, and gift cards
- For Glosy Products and gift cards we process product, price, currency, VAT, Stripe checkout/payment/subscription/invoice/customer IDs, status, attempts and anti-fraud signals, credits, entitlements, expiry, refunds/chargebacks, and accounting ledger.
- Gift-card data includes code, purchaser, recipient, recipient email, message, value, balance, expiry, and redemptions. Treat the code as confidential.
- Stripe directly receives card/payment data; Glosy does not store full card number or CVC. Banks, Stripe, and card schemes may be independent controllers for their duties.
- For Provider services we retain only payment information present in the Booking flow; the Provider controls its own collection and invoices unless Glosy is expressly identified as merchant.
8. Marketplace, partnerships, and recruitment
- The B2B marketplace processes buyer, Distributor, items, quantities, estimated price, currency, notes, status, history, and actors making changes. Parties control off-platform payment and delivery.
- Partnership, chair rental, recruitment, invitations, and referrals may contain identity, contact, company, offer, fee/rent, duration, description, response, status, and communication history.
- Do not upload IDs, criminal records, medical data, or other sensitive documents except through an approved channel after receiving specific information.
9. Device, usage, location, and notification data
- We process IP, date/time, URL/route, method, response/errors, browser/device type, OS, language, network, technical identifiers, security events, and performance. IP may be hashed in some logs.
- Approximate location (city and coarse coordinates) may be estimated by Cloudflare from the IP address normally transmitted to deliver the site. Glosy does not request device GPS or send coordinates to an external geocoding service. The city may be stored locally for 24 hours when functional preferences are enabled.
- Push data includes permission, endpoint/subscription, technical keys, device type, delivery status, and preferences. Browser, OS, Google/Apple, or the relevant push service may receive delivery metadata.
- The installed application may access location, notifications, clipboard, device or network information, and sharing functions only when you use the relevant feature and grant the permission requested by the operating system. [TO VERIFY: Android/iOS declarations and application permissions.]
10. Search, recommendations, favourites, and measurement
- We process queries, filters, city, category, sort, results, and errors to provide search and protect the system. Account favourites are server-side; visitor favourites remain in the browser.
- The recommendation questionnaire processes submitted answers, preferences, categories, and amenities. If personalised recommendations are enabled, interactions may be used under the relevant consent/setting.
- Glosy does not start analytics or marketing trackers without the relevant preference. Providers may enable Meta Pixel in their own webspace, and it loads only after the visitor gives marketing consent. Operational server data may support security, debugging, and aggregate statistics without becoming behavioural advertising.
11. Special-category and children’s data
- The Platform does not ordinarily request GDPR special-category data. Allergy, health, disability, or revealing-image data must be strictly limited and processed only under a valid basis and safeguards.
- Accounts are intended for adults aged 18 or over. For a minor, the parent/representative and Provider are responsible for necessary consent and service information. We do not use children’s data for behavioural advertising.
- If we learn that a child’s data was unlawfully collected, we will erase or restrict it, except where strictly required by law or to protect the child.
12. Purposes and legal bases
- Contract/pre-contract steps — account, authentication, profile, webspace, requested search, bookings, operational notices, marketplace, support, Glosy Products, gift cards, and data export.
- Legal obligation — accounting/tax, authority responses, GDPR rights, consumer law, mandatory records, sanctions, and security incidents where required.
- Legitimate interests — security, fraud/abuse prevention, legal claims, moderation, availability, debugging, aggregate statistics, professional verification, and service improvement after necessity/impact balancing.
- Consent — selected-channel marketing, non-essential functional storage, device precise location, and personalised recommendations/optional sharing where settings require it. Withdrawal does not affect prior lawful processing.
- Vital interests and the establishment, exercise, or defence of legal claims are relied upon only in the limited cases permitted by GDPR. [TO COMPLETE: documented legitimate-interest assessments and the basis for each activity.]
13. Required data and refusal consequences
- Mandatory fields are needed for the account, contract, verification, booking, or legal duties. Without them the relevant function cannot be provided.
- Marketing, functional storage, precise location, and personalised recommendations are optional. Refusal does not block the core service but may remove city memory, push notices, or personalisation.
- Some information may be needed by a Provider to assess safe performance. It must separately explain necessity and avoid excessive collection.
14. Recipients and public disclosure
- Data is accessed by authorised Operator staff/contractors under role-based need and confidentiality.
- The selected Provider and staff receive booking data; Customers receive the Provider’s public/necessary data; Distributors and B2B buyers receive order/contact data.
- Approved profiles, campaigns, listings, posts, and reviews are public. Do not publish home addresses, private phones, or data you do not want indexed.
- Data may go to advisers, auditors, insurers, a business buyer under safeguards, authorities, and courts when lawfully justified.
15. Technical providers and processors
- We use specialised providers only for services necessary to operate the platform: Stripe for payments, subscriptions, invoices, and fraud prevention; Resend for transactional email and delivery metadata; Backblaze for image and file storage; Cloudflare and our hosting provider for platform delivery and security.
- For approximate location we use IP geolocation information supplied by Cloudflare. For notifications, we may transmit strictly necessary data to the relevant Web Push or Google/Apple delivery services.
- These providers receive only the data needed to perform their services and act, as applicable, as the Operator’s processors or as independent controllers under their own terms and privacy notices.
- Platforms through which a native version of the application is distributed and the operating system may separately process installation data, in-store purchases, permissions, and their own telemetry. Details about recipients and international transfers are maintained in the Operator’s records and updated when the providers in use change.
16. International transfers
- Some providers may process outside the EEA. We use adequacy decisions, Standard Contractual Clauses, and supplementary measures where appropriate.
- [TO COMPLETE: relevant countries and entities, applicable Article 46 GDPR mechanism, transfer impact assessment, and hosting location.]
- You may request a copy or description of safeguards, subject to redaction of confidential information.
17. Retention periods
- Account and profile data are kept for the relationship and afterwards only as needed for legal duties, disputes, and safety. Confirmed deletion has a 3-day grace period; the confirmation link expires in 24 hours.
- Exports: 7 days; sessions: up to 30 days; account notifications: 365 days; registration attempts: 30 days; anti-abuse verification records: 24 hours.
- Email delivery metadata is kept for 90 days, after which identifying fields are anonymised; backups rotate within 30 days, subject to holds needed for incidents.
- Glosy transaction records may be kept for up to 10 years to the extent required by applicable financial and accounting obligations.
- Bookings, reviews, messages, closed profiles, marketplace, and moderation: [TO COMPLETE: retention period or criteria for each category]. At expiry, data is erased, anonymised, or restricted; backups age out on rotation.
18. Security and incidents
- We apply appropriate technical and organisational measures, including encrypted communications, protected passwords and sessions, account verification, access controls, abuse prevention, logging, backups, and monitoring.
- Access is need-based and administrative actions/incidents may be audited. No control removes all risk; users must protect accounts and devices.
- We assess incidents and notify the authority and affected people under GDPR deadlines and thresholds. Security contact: [TO COMPLETE].
19. Your rights
- You have rights to information, access, rectification, erasure, restriction, portability, and objection under GDPR.
- You may withdraw consent and object to direct marketing at any time. Legitimate-interest objections may be based on your particular situation.
- You have the right not to be subject to solely automated decisions producing legal or similarly significant effects, subject to lawful exceptions and safeguards.
- You may complain to ANSPDCP (www.dataprotection.ro), your residence/work authority, or a court. Contacting us first is encouraged but never required.
20. How to exercise rights
- Use the account privacy centre or email [email protected] with the right and identifying information. Access, portability, rectification, erasure, restriction, and objection requests are supported.
- Proportionate extra information may be requested for identity verification. A full ID copy is not ordinarily required; if necessary, we explain and minimise it.
- We normally respond within one month, extendable by two months for complexity/volume with notice in the first month. Manifestly unfounded/excessive requests may be charged or refused only within the law.
- Rights may be limited for legal duties, others’ rights, trade secrets, security, or legal claims; a refusal states reasons and remedies.
21. Export and account deletion
- A portable export may include JSON/CSV in a ZIP archive. Others’ data, secrets, and legally restricted information may be omitted.
- Deletion uses a single-use token valid for 24 hours and is currently scheduled after a 3-day grace period during which cancellation may be available as shown.
- Eligible data is erased/anonymised, sessions revoked, and profiles de-indexed; legally required records remain segregated and external erasure is tracked.
22. Automated decisions and profiling
- Search/recommendations rank by relevance, filters, rating, price, review count, recency, and promoted/premium/verified status. The questionnaire uses user-entered preferences.
- These systems do not make solely automated decisions with legal or similarly significant effects. Moderation may use automated signals, while challenged actions can receive human review.
- You can change filters/sort, withdraw personalised recommendations, and request meaningful logic information subject to security and trade-secret limits.
23. Cookies and device storage
- Necessary: __Host-glosy_session or glosy_session (maintaining the authenticated session for up to 30 days), __Host-glosy_csrf or glosy_csrf (protecting account requests for the session), and glosy_cookie_consent / glosy_cookie_preferences (remembering preference choices and version for 12 months).
- Functional, with preference: glosy_detected_city (city, 24 hours), favorite_salons and favorite_technicians (visitor favourites until deletion), glosy-mobile-app-install-dismissed / glosy-ios-pwa-install-dismissed (mobile/PWA prompt dismissal until deletion).
- Storage used at your request may retain information needed to unsubscribe from notifications, notification state, and preferences for the installed application.
- Analytics or marketing trackers do not start without the relevant preference. Provider webspaces may load Meta Pixel only when the provider configured it and the visitor accepted marketing.
- Change choices through Cookie Preferences, browser/device controls, or storage deletion. Blocking necessary cookies may break authentication/security.
24. Marketing and preferences
- Marketing is separately controllable for email, SMS, and push. Withdrawal applies to future campaigns but not strictly operational account, security, booking, or payment messages.
- We do not sell personal data. Any optional sharing based on consent will identify the recipient, data, and purpose beforehand. [TO VERIFY: data-sharing consent remains inactive until granular notice is implemented.]
- Consent and withdrawal evidence is retained for accountability/legal claims without continuing the withdrawn purpose.
25. Changes and contact
- The date/version is published. Material changes are notified through the Platform, email, or another appropriate means before application unless urgent legal/security action is required.
- A new incompatible purpose or consent-based change receives prior notice and choice.
- Questions, rights requests, and complaints: [email protected]. The Operator’s other contact details are available on the Legal information page.
To exercise your rights, contact [email protected].