Privacy Policy

Last Updated: 31. Juli 2026

At Zeity, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our booking platform.

1. Data Controller

Moon Regents is the data controller responsible for your personal data. You can contact us at: Moon Regents 47805 Krefeld Germany Email: info@zeity.me

2. What Data We Collect

When you make a booking through our platform, we collect: • Full Name • Email Address • Phone Number (optional) • Appointment Date and Time • Service Type • Notes or Special Requests This data is necessary to process your appointment request and send you confirmation emails and reminders.

3. Legal Basis for Processing

We process your personal data based on GDPR Article 6(1)(b) - processing is necessary for the performance of a contract (your appointment booking). We may also process data based on your explicit consent for receiving appointment reminders.

4. How We Use Your Data

Your data is used exclusively for: • Processing and confirming your appointment • Sending appointment reminders and notifications • Communicating with you about your booking • Providing you with appointment details and updates We do not sell, rent, or share your data with third parties for marketing purposes.

5. Data Retention

We retain personal data only for as long as necessary, and the retention period depends on whose data it is. (a) Zeity's own data, as controller: • Product analytics (PostHog): 30 days • Error events (Sentry): 90 days • Server logs (Better Stack): 3 days • Your account data: for the life of your account. If you close your account or request erasure, your login access is deleted; the associated records (account, business, staff, appointments, payments) are marked as deleted and pseudonymised — email address and phone number are removed or replaced with placeholders. The records themselves are not physically removed, but retained for as long as statutory retention obligations (§ 147 AO, § 257 HGB — see the next item) or the establishment, exercise and defence of legal claims within the statutory limitation periods require; whichever period is longer applies. We additionally log your acceptance of our legal documents as evidence of our accountability obligation (Art. 5(2) GDPR). We hold the remaining data solely for those purposes; it is not used for marketing, analysis or scoring. • Zeity's own subscription and platform-fee invoices to business owners: 8 years, per § 147 AO / § 257 HGB as amended by the Bureaucracy Relief Act (Bürokratieentlastungsgesetz IV, 2025) — the underlying accounting books and ledgers are kept for 10 years (b) Client booking data, where Zeity acts as a processor on a business's instructions: Your appointment history and client records are retained for as long as the business relationship between you and the business lasts, and are deleted when the business closes its account or instructs us to delete them. Independently of that, you can request deletion of your own data at any time — see our data-deletion process. If you paid online, your payment metadata is held by Stripe under the business's own statutory bookkeeping obligation; retaining the complete payment record of the gross amount you paid is the business's tax duty. In addition, Zeity keeps a record of its own for every online payment: the amounts (total, the business's share, our platform fee), currency, payment and refund status, timestamps and the Stripe identifiers of the transaction. Zeity's own retention-relevant accounting record here is the platform fee — our own revenue — not your gross payment and not your identity. That is why the name and email address in this payment record are removed or replaced with placeholders on erasure, while the amounts and the Stripe identifiers are kept for the duration of the statutory retention period (§ 147 AO, § 257 HGB; legal basis Art. 6(1)(c), Art. 17(3)(b) GDPR). (c) What remains at our payment provider Stripe after erasure: Invoicing and payment data remains stored at Stripe to the extent a statutory retention obligation applies (§ 147 AO, § 257 HGB; legal basis Art. 6(1)(c), Art. 17(3)(b) GDPR). Deleting your account cannot remove that data either. Where Stripe processes that data on our behalf and on our instructions, it is held solely for that purpose for the duration of the retention period and is otherwise restricted from further processing. This has to be distinguished from the part Stripe processes as an independent controller — in particular for fraud prevention, anti-money-laundering, and to meet its own regulatory obligations. That processing is governed by Stripe's own privacy policy, follows its own retention periods and is not restricted by us; we can neither instruct it nor stop it. Please address data subject requests in that respect additionally and directly to Stripe — see section 7.

6. Cookies and Tracking

We use essential cookies that are strictly necessary for the functioning of our service. These remain exempt from consent requirements under § 25 Abs. 2 TDDDG (the German Digital Services Data Protection Act, formerly TTDSG). Essential Cookies: • Session Management: Supabase authentication cookies enable you to stay logged into your account • Language Preference: Stores your selected language (English or German) for a better user experience • Cookie Consent: Remembers whether you have acknowledged this cookie notice These cookies are stored locally in your browser and contain no personal data beyond what is necessary for their specific purpose. Non-essential device storage (§ 25 Abs. 1 TDDDG — only with your consent): • PostHog: product analytics (EU-hosted). PostHog only runs, and only sets non-essential cookies or records which pages you visit, after you opt in through our cookie banner. If you choose "Essential Only", none of this is set or fires. Server-side processing (not a cookie, no consent required): • Sentry: error monitoring. Sentry processes technical data, including your IP address, on the basis of our legitimate interest in keeping Zeity secure and reliable (Art. 6(1)(f) GDPR). This runs on our servers, does not set a cookie in your browser, and is therefore separate from the cookie-consent choice above. We do not use advertising or retargeting cookies, and we do not sell or share cookie data with third parties for marketing purposes.

7. Third-Party Services

We use the following third-party service providers to operate Zeity. Subprocessors of your clients' data (acting on our instructions, under our Data Processing Agreement at https://zeity.me/dpa): • Supabase: database hosting and storage of your data • Resend: transactional and booking emails • Vercel: application hosting and content delivery (CDN) • Better Stack (Logtail): production logging (EU region, with personal data masked) • Stripe: payment processing, where online payments are enabled Stripe also acts as an independent controller of payment data for its own fraud-prevention, anti-money-laundering and legal-compliance purposes, under Stripe's own privacy policy. Vercel processes aggregated service and usage data as a controller under its own privacy policy. Where Stripe processes personal data as an independent controller, we can order neither erasure nor a restriction of processing there. Please address access, rectification, erasure and objection requests in that respect additionally and directly to Stripe; Stripe's contact channels and full privacy policy are available at https://stripe.com/privacy. We also use the following tools to operate, secure and improve Zeity itself, which process usage and technical data rather than your booking clients' records: • PostHog: product analytics (EU-hosted, used only with your consent) • Sentry: error monitoring Except where stated above that a provider acts as an independent controller, these providers process personal data on our instruction under a data-processing agreement and in accordance with the GDPR. Where a provider processes the personal data of a business owner's own clients on that business owner's behalf, it does so as our subprocessor; our Data Processing Agreement (https://zeity.me/dpa) lists those subprocessors.

8. International Data Transfers

Some of the tools we use as controller for Zeity's own operations process personal data outside the European Economic Area (EEA). Error monitoring (Sentry): Technical data, including your IP address, may be accessed and processed in the United States. This transfer relies primarily on the EU-US Data Privacy Framework (an EU adequacy decision) as its legal basis, with the EU Standard Contractual Clauses incorporated as a fallback safeguard, together with supplementary technical measures such as encryption and PII scrubbing. Product analytics (PostHog): EU-hosted — no third-country transfer occurs. A copy of the safeguards referred to above (including the Standard Contractual Clauses) is available on request using the contact details in this Privacy Policy.

9. Your Rights and How to Exercise Them

Under GDPR, you have specific rights regarding your personal data. Here's how to exercise them: 🔍 Right of Access (Article 15) Request a copy of the data held for one business (its appointments, employees, services, client cards, and that business's own master data) in JSON format. Click "Request Data Export" in that business's account settings. If you run more than one business, submit this request separately for each one. For a consolidated copy of everything we hold about you, including account-level data (for example subscription and payment data), email support@zeity.me We will provide your data within 30 days. ✏️ Right to Rectification (Article 16) Correct or update your personal information. Edit your details anytime in your account settings. Changes are effective immediately. 🗑️ Right to Erasure / Right to be Forgotten (Article 17) Request erasure of your personal data. You will receive a confirmation email containing a link that is valid for 7 days. Clicking that link runs the erasure immediately — there is no additional waiting period. If you do not confirm within those 7 days, the link expires and the request lapses unfulfilled; it then has to be submitted again. If you receive no confirmation email or you missed the deadline, write to support@zeity.me — we will then handle your request within one month (Art. 12(3) GDPR). What actually happens, and which records are kept for legal reasons (German tax law, defence of legal claims), is described in section 5. If you delete your account while a paid subscription is active, it ends immediately; the already-paid, unused portion of the billing period is forfeited without a refund. If your account itself is deleted as well, any credit balance then held is likewise forfeited; if your account instead continues to exist, any such credit balance is preserved and is set off against a future invoice — see Section 9 of our Business Terms of Service (https://zeity.me/terms/business) for details. If you would rather keep using the period you have already paid for, cancel your subscription first in your account settings; you will then retain access until the end of the already-paid billing period and may delete your account afterwards at no further cost. 📊 Right to Data Portability (Article 20) Receive your data in a structured, machine-readable format (JSON). Download your data export and import it into other services. ⛔ Right to Object (Article 21) Object to certain processing activities. Contact support@zeity.me to discuss your concerns. 🛑 Right to Restrict Processing (Article 18) Temporarily stop processing of your data while we resolve disputes. Contact support@zeity.me to request restrictions. ⚙️ Right to Withdraw Consent Withdraw consent for non-essential processing at any time. This does not affect the validity of processing before withdrawal. Automated Decision Making (Article 22) We do NOT use automated profiling or decision-making for users. All decisions affecting you involve human review. How to Exercise Your Rights • Dashboard: Use the "Your Data Rights" section in account settings • Email: Send requests to support@zeity.me with proof of identity • Response Time: 30 days (can be extended by 2 months for complex requests) • No Fee: Requests are free unless manifestly unfounded Data Protection Authority If you believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority.

10. Data Security

Your data is protected by: • HTTPS encryption for all data in transit • Encrypted storage in Supabase's secure infrastructure • Access controls limited to authorized personnel only • Regular security audits and updates While we implement strong security measures, no method of transmission over the internet is 100% secure.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at: Email: info@zeity.me Address: 47805 Krefeld, Germany We take your privacy seriously and will respond to all inquiries promptly.