Privacy Policy
Last updated: 21 February 2026
1. Introduction
Beepify B.V. ("we", "us", "Beepify") respects your privacy and is committed to protecting your personal data. This privacy policy informs you about how we handle your personal data when you visit our website or use our services.
We process personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy legislation.
2. Data Controller
The data controller for your personal data is:
Beepify B.V.
Email: privacy@beepify.app
Chamber of Commerce number: 94654069
3. What Data Do We Collect?
We collect and process the following categories of personal data:
3.1 Account Data (Salon owners)
- Name and contact details (email address, phone number)
- Business name and address
- Chamber of Commerce and VAT number
- Login credentials (email and encrypted password)
- Payment details (processed via our payment processor)
3.2 Customer Data (End customers of salon owners)
- Name (if provided)
- Email address or phone number (optional)
- Stamp history and rewards
- Unique identification code for the stamp card
3.3 Technical Data
- IP address
- Browser type and version
- Device information
- Timezone and location (country)
- Usage data and analytics
4. Purposes of Processing
We process your personal data for the following purposes:
- Service delivery: Providing and managing your account and stamp cards
- Payment processing: Processing subscription payments via our payment processor
- Communication: Sending service-related messages and updates
- Analytics: Improving our services based on usage data
- Security: Protecting our systems and preventing fraud
- Legal obligations: Complying with fiscal and administrative obligations
5. Legal Bases for Processing
We process your personal data on the basis of:
- Contract performance: Necessary for delivering our services
- Legitimate interest: For analytics, security and service improvement
- Legal obligation: For fiscal and accounting obligations
- Consent: For marketing communication (where applicable)
6. Sharing with Third Parties
We share your personal data with the following parties:
6.1 Payment processor
For processing payments. Our payment processor is PCI-DSS Level 1 certified.
More about our sub-processors
6.2 Database and authentication provider
For database hosting and authentication. Our provider is SOC 2 Type II certified.
More about our sub-processors
6.3 Application hosting and CDN
For hosting our application. Our hosting partner is SOC 2 Type II and ISO 27001 certified.
More about our sub-processors
6.4 Apple and Google (Wallet integration)
For adding stamp cards to Apple Wallet and Google Wallet. Only necessary card data is shared.
7. Cookies
We use the following types of cookies:
7.1 Necessary cookies
These cookies are essential for the functioning of the website, such as session cookies for authentication.
7.2 Analytical cookies
We use anonymized analytics to understand and improve the use of our website.
You can manage cookies via your browser settings. Disabling necessary cookies may limit functionality.
8. Retention Periods
We do not retain your personal data longer than necessary:
- Account data: Up to 30 days after termination of the subscription
- Customer data: Up to 30 days after termination of the salon owner's account
- Invoice data: 7 years (legal retention obligation)
- Analytics: Maximum 26 months
9. Your Rights
Under the GDPR you have the following rights:
- Right of access: You can request which data we process about you
- Right to rectification: You can have incorrect data corrected
- Right to erasure: You can request to have your data deleted
- Right to restriction: You can have processing restricted
- Right to data portability: You can request your data in a structured format
- Right to object: You can object to certain processing
- Right to withdraw consent: Where processing is based on consent
To exercise your rights, you can contact us via our contact form. We respond within 30 days.
10. Security
We take appropriate technical and organizational measures to protect your personal data:
- Encrypted connections (HTTPS/TLS)
- Encrypted storage of passwords (bcrypt)
- Regular security audits
- Access control and logging
- Backups and disaster recovery
11. International Transfers
Some of our service providers are located outside the EEA. We ensure that transfers take place with appropriate safeguards, such as Standard Contractual Clauses (SCC) or adequacy decisions.
12. Changes to this Privacy Policy
We may update this privacy policy from time to time. Material changes are announced at least 30 days in advance via email or a notification in the application.
13. Complaints
If you have a complaint about our processing of personal data, you can contact us via our contact form. You also have the right to file a complaint with the Data Protection Authority: autoriteitpersoonsgegevens.nl
14. Contact
For questions about this privacy policy or about your personal data, you can contact us via our contact form.
Beepify B.V.
Website: www.beepify.app
See also our Terms and Conditions for the terms of use of our service.