Privacy & Cookie Policy
NailPro — BlueDot S.r.l.
Commpany address: Via Giacinto Collegno 53, 10138 Torino, Italia
C.F. / P.IVA: IT013456190019
Website: https://nailpro.ai
Privacy-related issue email address: [email protected]
ENGLISH
1. Introduction
This Policy explains how BlueDot S.r.l. (hereafter, the "Company" or "we") collects, uses, retains, and protects personal data and manages cookies in the context of NailPro.
NailPro is used by three main user categories:
- Beauty professionals (nail technicians, independent studios) — "Professionals"
- Clients of Professionals — "Clients"
- Website visitors (nailpro.ai) — "Visitors"
This Policy describes how we treat data under GDPR (EU 2016/679), Italian privacy law (D.Lgs. 196/2003), and ePrivacy regulations (Legislative Decree 70/2003).
PART A: PRIVACY POLICY
2. Data Controller and Privacy Contact
Data Controller: BlueDot S.r.l., Via Giacinto Collegno 53, 10138 Torino, Italy.
Privacy Contact: [email protected]
3. Data Collected — Professionals
3.1 Registration and Profile
When a Professional registers with NailPro, we collect:
- Full name, email, phone
- Business/studio name and address
- VAT ID / Fiscal ID
- Bank details (IBAN for Stripe Connect)
- Password (hashed, never plaintext)
- Avatar / personalized logo
Legal Basis: Contract (Art. 6(1)(b) GDPR).
3.2 Business Content (CRM, Bookings, Messages)
The Professional uploads: service catalog, work photos, operating hours, Client data, messages, booking history.
Legal Basis: Contract (Art. 6(1)(b) GDPR) and Legitimate Interest (Art. 6(1)(f) GDPR).
NailPro is a Data Processor for Client data (Professional is Controller). Detailed DPA Appendix available upon request at [email protected].
3.3 Subscription and Payments
Device ID, subscription renewal history, transaction IDs, subscription status.
Legal Basis: Contract (Art. 6(1)(b) GDPR) and Legal Obligation (Art. 6(1)(c) GDPR).
3.4 Client Payments (Stripe)
Professional authorizes NailPro to link bank account to Stripe. Full Client payment data (card number, CVV) is never stored by NailPro. Stripe is the Data Processor.
Legal Basis: Contract and Legal Obligation.
3.5 App Diagnostics
Technical device info, error logs, crash reports, access timestamps, connection speed.
Legal Basis: Legitimate Interest (Art. 6(1)(f) GDPR).
3.6 Push Notifications
If Professional enables push notifications, we store device push token.
Legal Basis: Consent (Art. 6(1)(a) GDPR) and Contract.
4. Data Collected — Clients
4.1 Registration and Profile
Name, email, phone, address (optional), avatar, communication preferences, personal notes.
Legal Basis: Contract (Art. 6(1)(b) GDPR).
4.2 Bookings and History
Date, time, duration, service, payment amount, booking status.
Legal Basis: Contract.
4.3 Communications and Payment Data
Messages exchanged with Professional; payment data (tokenized via Stripe).
Legal Basis: Contract.
4.4 Push Notifications
Device push token if Client enables notifications.
Legal Basis: Consent (Art. 6(1)(a) GDPR).
4.5 App Diagnostics
Technical device info, error logs, features used.
Legal Basis: Legitimate Interest (Art. 6(1)(f) GDPR).
5. Data Collected — Website Visitors
5.1 Public Website (nailpro.ai)
IP address, User-Agent, pages visited, referrer, access timestamps.
Legal Basis: Legitimate Interest (Art. 6(1)(f) GDPR).
5.2 Founder Program Form
Name, email, phone (optional).
Legal Basis: Consent (Art. 6(1)(a) GDPR).
5.3 Google Analytics 4
Loaded only after Visitor accepts analytics cookies.
Legal Basis: Consent (Art. 6(1)(a) GDPR).
6. QR / Personal Link Landing Pages (/u, /b, /link)
When a Client accesses via QR code or Professional's personal link:
- No Google Analytics: GA4 not loaded, even after consent
- Client-Professional Attribution: We record the association
- Cookie Consent: No GA or third-party tracking if Client hasn't accepted
Legal Basis: Contract (Art. 6(1)(b) GDPR).
7. Service Providers (Sub-processors)
| Provider | Role | Data Transferred | Transfer Basis | |---|---|---|---| | Supabase | Database, Auth, Hosting | Account data, CRM, messages, bookings | EU Standard Contractual Clauses | | Stripe / Stripe Connect | Payments, Bank Transfers | Professional bank details, tokenized Client transactions | EU Standard Contractual Clauses | | RevenueCat | IAP subscription management | Device ID, subscription status | EU Standard Contractual Clauses | | Apple App Store | App distribution, IAP | Device ID, app version, purchases | Apple Privacy Policy + SCCs | | Google Play Store | App distribution, IAP | Device ID, app version, purchases | Google Privacy Policy + SCCs | | Resend | Transactional email | Email, tokens, password reset links | EU Standard Contractual Clauses | | Google Analytics 4 | Website analytics | Anonymized IP, Session ID, pages visited | EU Standard Contractual Clauses | | Expo / EAS | Build, distribution, push notifications | App ID, device token | EU Standard Contractual Clauses |
8. International Data Transfers
Some providers are located in the USA. We ensure:
- Standard Contractual Clauses (EU Model Clauses) in place with each provider
- Continuous compliance monitoring
- Supplementary security measures where applicable
9. Data Retention
| Data Category | Retention Duration | |---|---| | Active Professional account | For subscription duration | | Deleted Professional account | 90 days | | Active Client CRM | For relationship duration | | Completed bookings | 3 years | | Professional bank details (IBAN) | Until end of subscription + 90 days | | Push tokens | Until disabled | | Error logs / crashes | 90 days | | IP / Analytics (GA4) | 26 months | | Founder Form | Up to 2 years |
10. Data Subject Rights (GDPR Art. 15-22)
10.1 Right of Access (Art. 15)
Email [email protected] with subject "GDPR Access Request".
Response time: Within 30 days (extendable by 60 days).
10.2 Right of Rectification (Art. 16)
Contact [email protected] with description of inaccuracy.
10.3 Right to Erasure (Art. 17)
Contact [email protected] with reason for request.
10.4 Right to Data Portability (Art. 20)
Contact [email protected] with "Data Portability" request.
10.5 Right to Object (Art. 21)
Object to processing for legitimate interest or marketing.
10.6 Automated Decision-Making Rights (Art. 22)
NailPro does not use automated decision-making with legal effects.
11. Children
NailPro is not intended for users under 18. If a Professional uploads data of a minor Client, she must obtain explicit parental/guardian consent.
12. Data Security
12.1 Technical Measures
- Encryption in transit (HTTPS / TLS 1.2+)
- Encryption at rest (passwords, IBANs, tokens)
- Daily backups (retained 30 days)
- Access control (RBAC)
- Monitoring and logging
12.2 Organizational Measures
- Only authorized staff have backend access
- All providers signed confidentiality agreements
- Data Protection Impact Assessment (DPIA) available upon request
12.3 Breach Notification
Upon data breach, we notify Garante within 72 hours.
PART B: COOKIE POLICY
13. What Are Cookies?
A cookie is a small text file stored on your device when you visit a website. Cookies allow the site to remember your preferences and track browsing behavior.
14. Cookie Categories Used by NailPro
14.1 Strictly Necessary Cookies
Essential for site functionality. Remain always active and do not require explicit consent.
Purposes: Consent preference management, authentication, session, CSRF protection.
14.2 Analytics Cookies
Collect anonymous information about visitor behavior.
Purpose: Improve service through traffic statistics.
Consent required: YES. These cookies load only if you accept analytics cookies via banner.
Tool: Google Analytics 4 (GA4), provided by Google Ireland Limited and Google LLC.
14.3 Marketing Cookies
Category reserved for future advertising campaigns.
Current status: No marketing cookies used.
Consent required: YES (if enabled in future).
15. Detailed Cookie Table
| Cookie Name | Category | Purpose | Duration | Provider |
|---|---|---|---|---|
| consent_preferences | Strictly Necessary | Consent preference | 12 months | BlueDot |
| auth_token | Strictly Necessary | Authentication | Session | BlueDot / Supabase |
| session_id | Strictly Necessary | Session | Session | BlueDot |
| CSRF_token | Strictly Necessary | CSRF protection | Session | BlueDot |
| _ga | Analytics | GA client ID | ~2 years | Google Ireland Limited |
| _ga_<container> | Analytics | GA property data | ~2 years | Google LLC / Google Ireland Limited |
16. Google Analytics 4 — Specific Details
Tool name: Google Analytics 4 (GA4)
Owner: Google Ireland Limited (EU) and Google LLC (USA)
Measurement ID: [TODO: Specify GA4 property Measurement ID]
Data collected: Anonymized IP, browser type, pages visited, session duration, referrer, conversions.
Data transfer: To Google Ireland Limited (EU) and Google LLC (USA) via Standard Contractual Clauses.
When loaded:
- ✅ On nailpro.ai after analytics consent
- ❌ NOT on QR pages (/u, /b, /link)
- ❌ NOT in mobile app
17. Third-Party Cookies (Sub-processors)
17.1 Stripe
If you log in as Professional and link Stripe, Stripe may deposit tracking cookies.
Privacy: https://stripe.com/privacy
17.2 Expo / App Store / Google Play
Apple and Google deposit app-specific cookies. Not controlled by BlueDot.
18. How to Manage Your Cookie Preferences
18.1 Cookie Consent Banner
When you first visit nailpro.ai, a banner appears with:
🔘 Accept All → Enables all cookies (12 months)
🔘 Reject Non-Essential → Only necessary cookies (12 months)
⚙️ Customize → Choose per category; save choices
18.2 Update Preferences Anytime
Visit: https://nailpro.ai/cookie-preferences
18.3 Browser and Operating System
Manage cookies at browser level:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Preferences → Privacy & Security → Cookies
- Safari: Settings → Privacy
- Edge: Settings → Privacy and services
18.4 Do Not Track (DNT)
If your browser has "Do Not Track" enabled, we respect this and do not load GA4.
19. We Do Not Track Your Personal Data with Cookies
NailPro's analytics cookies do not collect or store your identifiable personal data (name, email, address, phone). Visitors are tracked via anonymized session ID only.
20. Cookies on Special Pages
20.1 QR / Personal Link Pages (/u, /b, /link)
QR pages are private pages dedicated to a specific Professional.
Cookie policy:
- ✅ Strictly necessary cookies remain active
- ❌ Google Analytics 4 is not loaded, regardless of consent
- ❌ No advertising tracking cookies
20.2 Mobile App
NailPro mobile app does not use browser cookies. However, it may use unique device identifiers for diagnostic tracking and first-party analytics.
21. Third-Party Data Sharing
The Company does not share cookie-collected data with third parties for advertising. However:
- Google Analytics: Aggregated data shared with Google per their Privacy Policy
- Stripe: Transaction data shared with Stripe
22. Regulatory Compliance
This Policy complies with:
- ePrivacy Regulation (Directive 2009/136/EC, Legislative Decree 70/2003)
- GDPR (Regulation (EU) 2016/679)
- Garante Guidelines
23. Changes to This Policy
We reserve the right to update this Policy anytime. Significant updates will be communicated via email, in-app notification, or site banner.
Contact & Complaints
Privacy Questions: [email protected]
Supervisory Authority:
Garante per la Protezione dei Dati Personali
Piazza di Monte Citorio 121, 00186 Roma, Italy
Tel: +39 06 69677 1
Email: [email protected]
Website: https://www.garanteprivacy.it
Last Updated: August 2026
Status: Production