Garmel
How it worksPricingContactSign inStart free

Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains how Garmel ("Garmel", "we", "us"), collects and uses personal data when you use the Garmel platform, whether as a business owner, a staff member, or a customer of a business that uses Garmel.

1. Who is responsible for your data?

For business accounts and our own website, we are the data controller. For the customer data that businesses collect through their loyalty programs (names, emails, dates of birth, visit history), the business is the controller and we are the processor, acting under our Data Processing Agreement.

Privacy contact / DPO: [email protected]. We respond to privacy requests within 30 days (GDPR Art. 12).

2. What we collect

  • Business owners & staff: name, email, password (hashed), business details, website URL, billing data (handled by Stripe, card numbers never touch our servers).
  • Customers of businesses: name, email, password (hashed), optional phone and date of birth, visit and points history, reward redemptions, marketing preferences.
  • Technical data: IP address (for rate limiting and security), device/browser information, error logs.
  • Contact form: name, email, and your message, used only to reply to you.

3. Lawful bases

  • Contract, providing the Service you signed up for.
  • Consent, marketing emails, push and SMS (all opt-in, default off; withdraw anytime).
  • Legitimate interests, securing the platform, preventing fraud and abuse.
  • Legal obligation, tax and financial record-keeping.

4. Who processes data for us (sub-processors)

ProcessorPurposeData
SupabaseDatabase, authentication & storageAccount & program data
StripeSubscription billing & membership payments (Stripe Connect)Billing & payment data
Firebase (Google)Push notificationsDevice push tokens
ResendTransactional & marketing emailEmail address, message content
InngestBackground jobs (birthday gifts, win-back, trial expiry)Event payloads incl. customer identifiers
OpenAIAI onboarding extraction (logo/colors/services from your website)Public website content you provide
FirecrawlWebsite scraping during onboardingYour public website URL & content
Upstash RedisRate limitingIP addresses, request metadata
SentryError monitoringError context (scrubbed)
NetlifyHosting & deliveryRequest logs, IP addresses

AI-assisted onboarding is used only when a business supplies a public website for extraction. Businesses should avoid submitting confidential or special-category personal data through that feature.

5. Your rights

Under the GDPR (and UK GDPR) you have the right to:

  • Access your data and receive a copy (export available in-app from your profile).
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten", account deletion available in-app).
  • Port your data to another service (in-app export, machine-readable).
  • Object to or restrict certain processing.
  • Withdraw consent for marketing at any time (every marketing message includes an unsubscribe option).

To exercise any right, use the in-app tools or email [email protected]. You may also lodge a complaint with the competent data-protection authority in your country.

6. Retention

We keep personal data while your account is active. After account deletion, data is removed except where retention is legally required. Financial transaction records are kept for 7 years for tax purposes. Inactive customer data is purged on a defined schedule.

7. Cookies

We only use strictly necessary session and authentication cookies, no analytics or advertising cookies. Full details, including each cookie's name, purpose, and duration, are in our Cookie Policy.

8. International transfers

Some processors may process data outside the EU/EEA. Where this happens, transfers are protected by the EU Standard Contractual Clauses or an adequacy decision.

9. Security

Data is encrypted in transit (TLS) and at rest, business data is isolated with database row-level security, all destructive actions are audit-logged, and access is restricted on a need-to-know basis. No card numbers ever touch our servers.

10. Changes

We will post any changes to this policy here and, for material changes, notify account holders by email.

11. Contact

Garmel · [email protected]

Garmel

Your shop, your app, your name. White-label loyalty for barbers, salons, gyms & small shops.

Product

  • How it works
  • Pricing
  • Contact
  • Sign in
  • Start free trial

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund Policy
  • Subscriber Agreement
  • Data Processing Agreement
  • Acceptable Use Policy
© 2026 Garmel · Your shop, your app, your name.