Privacy Policy
Last updated: August 21, 2026
This Privacy Policy explains what data Xantino collects, why, and how it’s handled. It applies whether you’re a Business using Xantino to manage your appointments, or a Customer booking with one.
1. What we collect
Account and business data: When a Business registers, we collect the owner’s name, email, phone number, and business details, including name, address, category, opening hours, staff, services and prices. This appears on the Business’s public booking page as configured by the Business.
Booking and customer data: When a Customer books an appointment, buys a gift card, or places an order, we collect the details needed to complete it, name, email, phone, and the appointment or order details. This is stored against the Business the Customer booked with, each Business can see their own Customers’ data, not other Businesses’.
Payment data: Payments are handled by Stripe. We don’t store full card numbers on our servers, Stripe processes and stores that data under its own privacy policy. We retain the transaction records needed for receipts, refunds, and legal or tax obligations.
Photos and portfolio content: Businesses may upload photos, for example a portfolio, which are displayed publicly on their booking page.
Usage data: We use privacy-friendly, cookieless analytics, Plausible, on booking pages to understand traffic and conversions in aggregate. It doesn’t use cookies or track individuals across sites, and doesn’t collect personal data beyond what’s needed for anonymous, aggregate counts.
2. How we use it
- to provide the Service, bookings, payments, gift cards, staff and calendar management
- to send transactional emails, booking confirmations, cancellations, receipts, account notices
- to process payments and prevent fraud
- to provide customer support
- to maintain and improve the Service’s reliability and features
- to meet our legal and tax obligations
We don’t sell personal data, and we don’t use Customer data to market to them on behalf of a Business beyond what that Business explicitly sends, for example their own booking confirmations.
3. Who we share it with
We share data with the third parties needed to run the Service, each acting under their own privacy terms:
Stripe: payment processing and payouts
Supabase: database, authentication and hosting infrastructure
Zoho / ZeptoMail: sending transactional emails, such as booking confirmations, receipts and account notices
Plausible Analytics: aggregate, cookieless traffic analytics
A Business can see the booking and contact data of its own Customers, since that’s necessary for them to run their business. We don’t share Customer data between unrelated Businesses.
4. Data retention
We keep account and booking data for as long as the account is active, and for a reasonable period afterward to meet legal, tax and fraud-prevention obligations. Business owners can permanently delete their account and associated data at any time from account settings, some records, such as completed transaction history, may be retained longer where required by law.
5. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Business owners can exercise most of these directly from account settings, including full account deletion.
For anything else, or if you’re a Customer and want to exercise these rights, contact us, we’ll usually need to verify your identity, and may need to involve the relevant Business where the data is theirs to manage.
6. International transfers
Our infrastructure and service providers may process data outside your home country. Where that happens, we rely on our providers’ own safeguards, such as standard contractual clauses, for transfers that require them.
7. Security
We use industry-standard measures, including encryption in transit, access controls, and scoped credentials, to protect data. No system is perfectly secure, and we can’t guarantee absolute security, but we take reasonable steps to protect your data and respond quickly to any issue we identify.
8. Children’s privacy
The Service isn’t directed at children, and we don’t knowingly collect personal data from children. If you believe a child has provided us data, contact us and we’ll remove it.
9. Changes to this policy
We may update this policy from time to time. If we make a material change, we’ll update the date at the top of this page and, where appropriate, notify Businesses by email.
Questions about this policy or your data? Email [email protected].
