Legal
Effective date: 22 May 2026 · Last updated: 17 September 2026
The MyBarb platform is operated by:
For the purposes of data protection law, the operator above is the data controller for personal data of registered users (shop owners and barbers).
For personal data of end-clients entered by barbershops into the system, the barbershop owner is the data controller and MyBarb acts only as a data processor. A Data Processing Agreement (DPA) is available on request.
We collect only what is strictly necessary to operate the Service:
| Category | Data | Purpose |
|---|---|---|
| Account data | Username, hashed password, shop email address, account creation date | Sign-in, account management and account recovery (we email a recovery link to the shop email) |
| Shop information | Shop name, description, address, city, country, time zone, phone, logo, opening hours, profile slug, social media links | Running your barbershop profile and public page, and timing client reminders |
| Staff profiles | Barber names, nicknames, usernames, hashed PINs, role, optional photo, slot interval setting | Multi-staff access management |
| Client records | Client name and phone number, visit history and the total amount each client has spent at the shop, and an email address only if the client gives one when booking online | CRM, appointment history, booking confirmations and reminders |
| Appointment records | Date, time, barber, service, price, status, duration | Calendar management and revenue overview |
| Revenue records | The shop's revenue per day, month and year and per barber, stored with your account and calculated from appointment prices | Revenue overview for the shop |
| Service catalogue | Service names, prices, duration | Booking and public profile |
| User preferences | Language, theme, notification settings, WhatsApp message templates | Personalisation and client messages |
| Photos you upload | Shop logo, staff photos, up to 6 gallery photos | Shown in the app and on your public page. The camera and photo library open only when you choose to add a photo. |
| Reviews | Name, star rating and text left by a client on your public page, or added by you | Shown on your public page. You can hide or delete them. |
| Push notification token | A device token issued through Google Firebase Cloud Messaging (on iPhone together with Apple Push Notification service), the device platform (iOS, Android or web) and the account it belongs to | Delivering booking alerts to the devices where you turned notifications on |
| Usage events | Page visits (page address, referring page, time) and a few in-app actions, for example opening the share screen or sharing your booking link, linked to your shop account | Understanding which features are used and fixing problems. Stored on our own server only. |
| Billing status | Plan, billing cycle, subscription status, and the customer and subscription IDs issued by our payment processor Stripe | Applying your plan. We never receive or store card numbers. |
| Server access logs | IP address, browser or device type, access time. Deleted after 30 days. | Security and abuse prevention only |
We do not use your data for advertising, profiling, or marketing. We do not sell, rent, or trade personal data to any third party.
For users in the European Economic Area (EEA), processing is based on the following GDPR Article 6 grounds:
| Purpose | Legal Basis |
|---|---|
| Delivering the Service (account, calendar, CRM, account recovery) | Performance of a contract, Art. 6(1)(b) |
| Push notifications on a device where you turned them on | Consent, Art. 6(1)(a). You can withdraw it at any time in your phone or browser settings. |
| Security logs and abuse prevention | Legitimate interests, Art. 6(1)(f) |
| Legal obligations and authority requests | Legal obligation, Art. 6(1)(c) |
| Usage events for product improvement | Legitimate interests, Art. 6(1)(f) |
MyBarb stores data in two places:
| Data type | How long we keep it |
|---|---|
| Active account and business data | For the lifetime of the active account |
| After account deletion | Permanently purged within 30 days |
| Push notification tokens | Until you sign out on that device, delete the account, or the push service reports the token as no longer valid |
| Usage events | 12 months, then deleted |
| Account recovery links | Single use, expire automatically |
| Server access logs | 30 days, then automatically deleted |
| Backups | Rolling 7-day server backups (overwritten) |
We share personal data only in the following limited situations:
Our database is hosted by Bluehost (Endurance International Group, United States). They act as a sub-processor under their own terms of service and privacy policies. We rely on Bluehost's security and data protection measures for server-side data storage. You can review Bluehost's privacy practices at bluehost.com/privacy.
If you turn on notifications in the MyBarb iPhone or Android app, the app registers with Google Firebase Cloud Messaging (FCM). On iPhone, FCM delivers through Apple Push Notification service (APNs). The Firebase SDK in the app creates an installation ID and a device token and sends Google basic technical information (such as device model, operating system version, language and time zone) needed to deliver messages, and it reports message delivery statistics to Google. We store the token with your account on our server. When a booking arrives, our server sends the alert text to FCM, which delivers it to your device. Google's and Apple's terms apply to that delivery: firebase.google.com/support/privacy and apple.com/legal/privacy. You can turn notifications off at any time in your phone's settings.
If you allow notifications in a web browser, the browser's own push service (for example Google, Apple or Mozilla) delivers them. We store the subscription address the browser gives us and remove it when you sign out.
Subscription payments are processed by Stripe, which collects card details directly. We receive only the customer and subscription IDs and the subscription status. See stripe.com/privacy.
Account recovery emails, and booking confirmations and reminders for clients who gave an email address, are sent from our server through our hosting provider's mail service.
The app loads its typeface from Google Fonts, so your device's IP address is sent to Google when the font files are fetched.
When you open your shop's QR code, the public link of your shop page is sent to api.qrserver.com (goQR.me) to draw the image. No personal data is included.
The app includes an optional button that opens the WhatsApp app pre-filled with a reminder message for a client. This action is initiated entirely by you (the shop owner). MyBarb does not send anything automatically; it only opens a link. When WhatsApp opens, Meta's own privacy policy governs that interaction. MyBarb does not transmit data to Meta.
We may disclose data if required by a court order, law enforcement agency, or regulatory authority with legal jurisdiction over us. We will notify you where legally permitted to do so.
Our servers are located in the United States. If you are based in the EEA or the UK, transferring personal data to the US requires safeguards under GDPR Chapter V.
We rely on Bluehost's applicable data transfer mechanisms and compliance framework for this transfer. By using the Service, you acknowledge that your data will be processed on servers located in the United States under these conditions.
If you require a formal Data Processing Agreement (DPA) including specific transfer clauses for your own GDPR compliance as a data controller, please contact us and we will provide one.
MyBarb does not use tracking cookies, advertising cookies, or third-party analytics cookies.
The app uses the localStorage API of your browser or of the MyBarb app to store application data on your device. Unlike cookies, localStorage data is not sent to any server automatically; it stays on your device. The data stored locally is:
| localStorage Key | Contains |
|---|---|
| berberia-shop | Shop name, address, hours, logo, social links |
| berberia-barbers | Staff list and settings |
| berberia-session | Current login session (username, role) |
| berberia-appointments | Appointment records |
| berberia-clients | Client names and phone numbers |
| mybarb-services | Service catalogue |
| mybarb-subscription | Active plan information |
| mybarb-token | Server authentication token |
| mybarb-native-token | This phone's push notification token (MyBarb apps only), removed when you sign out |
| mybarb_lang | Display language preference |
| berberia-theme | Dark/light theme preference |
In web browsers, the Service Worker also caches the app's own code files (HTML, CSS, JS, images) for offline use. This cache contains no personal data, only application code.
If you are in the European Economic Area or the United Kingdom, you have the following rights:
To exercise any right, contact us at info@bujaabeats.com. We will respond within 30 days. Identity verification may be required before we act on a request.
You may also lodge a complaint with your national data protection authority at any time. You do not need to contact us first, though we encourage you to do so.
We implement the following technical and organisational security measures:
No system is completely immune to security incidents. In the event of a data breach that creates a high risk to your rights and freedoms, we will notify you and the competent supervisory authority within 72 hours, as required by GDPR Article 33, where notification is feasible.
MyBarb is a professional business management tool for adults. We do not knowingly collect personal data from anyone under 16 years of age. If you believe a minor has provided data to us, please contact us immediately and we will delete it.
This Privacy Policy forms part of our Terms of Service, which govern the overall legal relationship between you and MyBarb, including liability limitations, indemnification, dispute resolution, governing law, and the B2B nature of the Service. By using MyBarb, you agree to both documents.
We may update this Privacy Policy to reflect changes in our practices or legal obligations. We will notify you of material changes at least 14 days in advance via in-app notification. Minor clarifications may be made without notice.
The current version is always available at mybarb.app/privacy.html. The "Last updated" date at the top of this page reflects the most recent revision.
For privacy questions, data subject requests, or to report a concern:
If you are unhappy with our response, you have the right to lodge a complaint with your national data protection supervisory authority.