Privacy Policy

Last updated: November 19, 2025

This Privacy Policy explains what personal data we collect, how we process and protect it, and what rights users have in connection with the use of the MeUp service.

We comply with the requirements of the laws of Ukraine, as well as with the general principles of the GDPR (where applicable), and internationally recognized data protection standards.

1. Who We Are

MEUP is a platform for managing appointments, staff schedules, and client databases for organizations.

Data Controller for companies (MEUP clients):

FOP (Sole Proprietor) Ivanenkov Serhii

Tax Number (RNOKPP): 3401412557

Email: sergeyi.design@gmail.com

2. Roles in Data Processing

2.1. Data of Organizations (MEUP clients)

We act as the Data Controller for organizations that use our service.

We determine what organizational data is collected, stored, and used to provide the service.

2.2. Data of Clients of These Organizations (Individuals Making Bookings)

We act as a Data Processor.

The organization (salon, professional, clinic, etc.) using MeUp acts as the Data Controller for the personal data of its own clients.

This means:

  • client data belongs to the organization itself;
  • the organization is responsible for accuracy, lawfulness, and deletion of this data;
  • we only provide the technical infrastructure for storage and processing.

3. Data We Collect

3.1. Data of Organizations

  • full name of the account owner
  • email address
  • phone number (optional)
  • company name
  • staff data added by the organization
  • schedules, services, rooms
  • questionnaire fields
  • images and text content uploaded to the CRM

3.2. Data of Clients of Organizations

Collected on behalf of the organization acting as Data Controller:

  • name
  • phone number
  • email
  • selected service
  • booking date and time
  • questionnaire answers
  • notes provided by the user

This data is not used by MEUP for marketing, advertising, or analytics.

3.3. Technical Data

  • IP address
  • device and browser type
  • interface language
  • cookies (strictly necessary only)
  • anonymized usage and page visit data

3.4. Integrations

3.4.1. Google Calendar

We use Google Calendar API to synchronize bookings with users’ calendars.

What data is transmitted to Google:

  • Event title (client name, service)
  • Booking date and time
  • Service duration
  • Description (optional: client contacts, notes)
  • Booking status (new, confirmed, canceled)

How data is used:

  • Creating events in Google Calendar when a booking is created
  • Updating events when booking time, date, or status changes
  • Deleting events when a booking is canceled or removed
  • Reading calendar list to select a calendar for synchronization

Data storage:

  • Google stores events in the user’s calendar according to its privacy policy
  • We do not store calendar data separately — we only use it for synchronization
  • Access tokens (OAuth) are stored in encrypted form on our servers

Access rights:

  • Calendar access is granted only with explicit user consent through OAuth
  • Users can revoke access at any time through Google Account settings
  • We use only necessary permissions: create, read, update, and delete events

Security:

  • All requests to Google Calendar API are executed through secure HTTPS connection
  • Access tokens are stored in encrypted form
  • API access is limited to necessary calendar event operations only

4. How We Use Data

We use data for:

  • registering and servicing an organization’s account
  • displaying and managing bookings
  • Synchronization with Google Calendar (creating, updating, and deleting events based on bookings)
  • sending system email notifications
  • providing technical support
  • ensuring the security of the service
  • improving MeUp functionality

We do not use data for advertising, profiling, or sharing with third parties unless required for service operation.

5. Cookies

We use minimal and strictly technical cookies:

  • for authentication
  • for proper functioning of the admin panel
  • for interface language settings
  • for correct operation of the public booking widget

We do not use advertising, analytical, or marketing cookies.

6. Sharing of Personal Data with Third Parties

We do not sell or disclose personal data to third parties except where required to operate the service:

  • hosting providers (for data storage)
  • email service providers (for sending booking notifications)
  • Google (if organization has connected Google Calendar):
    – Only booking data is transmitted for creating/updating calendar events
    – Data is stored in the user’s calendar according to Google’s privacy policy
    – We do not access other calendar data except events created by our service
    – Users can revoke access at any time

All third-party providers adhere to appropriate data protection standards.

7. Data Retention

7.1. Data of Organizations

Stored as long as the account is active or until the organization requests deletion.

7.2. Data of Clients of Organizations

Stored until the organization (Data Controller) deletes it.
MEUP deletes client data only upon the organization’s instruction.

8. Data Deletion

8.1. Deletion of Clients’ Data

Responsibility lies with the organization that owns the data.

If a client wishes to delete their personal data, they should contact:

  • the organization where the booking was made, or
  • MeUp support, providing their contact details and the relevant organization.

We will forward the request to the organization or delete the data if the organization is no longer active in the system.

8.2. Deletion of Organizational Data

A full deletion of an account and all associated data is possible upon request.

9. Data Security

We use:

  • SSL encryption
  • restricted database access
  • secure server environments
  • regular backups
  • continuous security monitoring

We constantly improve our security measures.

10. Rights of Data Subjects

Every user has the right to:

  • access their personal data
  • correct their data
  • request deletion
  • restrict processing
  • withdraw consent
  • contact a supervisory authority (where applicable)

Requests can be made via: support@meup.space

11. Children

The service is not intended for independent use by children under the age of 16.
We do not knowingly collect personal data from children.

12. Changes to this Policy

We may update this Privacy Policy.
The date of the last update appears at the top of the document.

13. Contact Information

For questions regarding personal data processing, please contact:

FOP Ivanenkov Serhii

Email: support@meup.space