Skip to main content

Privacy Policy

Version 6 — in effect from Oct 21, 2026

This policy explains what Thrasos Charalambous ("Rantevo", "we", "us") does with personal data when you sign up for Rantevo, run your business on it, work in a shop's admin area, or visit rantevo.com or a booking site we run.

It is not about your customers' data. When somebody books an appointment with a business that uses Rantevo, that business decides what happens to their details and we act on its instructions. We are the processor there, not the controller. If you have booked an appointment and want to ask about your data, ask the business you booked with — their own privacy notice is on their booking site. The terms we work under are in our DPA. The one exception is how a booking site is used, which we measure for ourselves: see "When someone visits a booking site we run" below.

Who is responsible

The controller for the data described here is:

Thrasos Charalambous Kopaidos 2, 4152, Limassol, Cyprus support@rantevo.com

What we collect, and why

When you create an account

Your name, email address and password. We need them to give you an account and to let you back into it. The password is stored only as a hash — we cannot read it.

Lawful basis: performance of a contract. Without these there is no account.

When you set up your business

Business name, address, phone number, contact email, opening hours, staff names and photos, your service menu and prices, and any images you upload. Most of this is published on your booking site, because that is the point of it.

Some of it is personal data about your staff. You are responsible for telling them their name and photo will appear on a public website.

Lawful basis: performance of a contract.

When you take payment online

To have your customers pay online, you connect a Stripe account of your own. To start its sign-up for you, we send Stripe your business's name, contact email and phone number, its website, its country and trade, and the name your customers will see on their card statements. Stripe asks you for the rest itself — who owns the business, proof of identity, your bank details. You give those to Stripe, and we do not store them.

After that, Stripe tells us whether your account can take payments and pay out, what it still needs from you, and which country the account is in, and that is all we keep, so your admin area can tell you where things stand. Your Payments page reads your balance and payouts from Stripe each time you open it, and we do not store those either.

Stripe is not one of our processors. It works for you, under the agreement you accept with it, and it is a controller in its own right for what it collects from you; its own privacy policy applies. What reaches Stripe when your customers pay is in our DPA (section 5).

Lawful basis: performance of a contract — you asked us to connect your payments.

When you pay

Billing name, address, country and VAT number where you give one, plus a record of what you bought and when. Card details go straight to our payment provider and never reach us.

Lawful basis: performance of a contract, and legal obligation for the tax and invoicing records we have to keep.

When you sign in

Your IP address and browser user-agent string, recorded with each sign-in: to keep your session secure, to slow down password guessing, and to tell you by email when your account is signed in to from somewhere new.

  • Your session keeps the address and user-agent for as long as it lasts. When it ends — you sign out, or it expires after 7 days unused — they are deleted within a day.
  • Sign-in alerts show you the address and browser a sign-in came from. To recognise the device next time we keep only a keyed hash of the two, never the address itself, so we can tell "this is the same device as yesterday" without keeping a list of where you have been. Each is deleted 90 days after the last alert about that device. You can switch these alerts off in your settings.
  • The sign-in form counts attempts by IP address to slow down password guessing, and the counts are deleted within two days.

Lawful basis: legitimate interests — keeping your account secure and telling you about access to it is something you would expect, and there is no less intrusive way to do it.

When you contact support

Everything in the conversation: what you write, any files you attach, what we write back, and the email address you wrote from.

The first reply usually comes from an automated assistant, which runs on Anthropic's model. When it answers, Anthropic receives the conversation — your messages, our replies, the names of any files attached, and the images in your latest message — along with your business's name, your plan and whether it is paid up, and our help articles.

When you ask from your admin area, it can also look things up in your account — the same figures your admin area shows you — and what it looks up reaches Anthropic too:

  • your SMS balance, your subscription or free trial with the dates your account shows for it, and your domains
  • your services, with their prices and durations and who can be booked for each
  • your team: each person's name, the services they offer and the hours they work
  • closures and time off, with their dates and times, but not any reason typed for them
  • your opening hours and booking rules
  • booking totals over a period: how many, the revenue and the no-shows

These look-ups never give it your customers' names, contact details or booking notes.

It can also draft a change for you — to a service, your opening hours, a closure, a booking rule, or whether a colleague takes bookings. Nothing changes until you approve it.

Anthropic process all of this on our instructions and do not use it to train models. Anything the assistant cannot answer goes to a person here.

If you would rather no automated assistant read a conversation, write "no AI" in your message. It goes straight to a person without the assistant seeing it, and the assistant stays out of that conversation from then on. It will already have read any earlier messages it answered.

Lawful basis: performance of a contract for support about the service, and legitimate interests in answering common questions quickly.

When you use the product

Which pages you open and which features you use, recorded through PostHog, on its EU infrastructure, tied to your account. We use it to work out what to build and what is confusing. The same goes for your staff when they use your admin area.

It runs only if you accept analytics when we ask, and you can change your answer at any time from Cookie settings: at the foot of rantevo.com, and in the account menu of your dashboard and your admin area.

Lawful basis: consent — given when we ask, and withdrawn from Cookie settings, which stops the recording from then on.

When someone visits a booking site we run

How the site is used: which pages are opened, and the visitor's browser and device. One visit in ten that reaches the booking pages, chosen at random, is recorded as a replay, with everything typed and every word on the screen hidden. We use it to see where people get stuck, so that booking gets easier on every site we run.

Nobody is identified. The IP address is discarded before anything is recorded, no profile is built, and nothing is stored on the visitor's device, which is why booking sites carry no cookie banner. We decide what is measured and keep it for ourselves, so for this we are the controller, not the shop; the shop's own privacy notice says so and points here. Because nothing we record says who a visitor was, we cannot find or delete one person's visits afterwards.

Lawful basis: legitimate interests — ours, in booking that works, measured without recording who anybody is. Questions or objections go to support@rantevo.com.

When you visit rantevo.com

The same product analytics as above, plus a cookie that remembers your language and, if you fill in the contact form on our About page, what you sent us.

If you accept advertising cookies, we also record how you reached us — the campaign parameters on the link you followed, and Meta's click identifier if you came from an ad on Instagram or Facebook — and we tell Meta when that visit becomes an account, a trial or a subscription.

What Meta receives is your email address in hashed form, that click identifier, which of those three things happened, when, and for a subscription its value. It never receives your name, your phone number, your business, or anything about your customers. We do it to find out which advertising is worth paying for.

We do not load Meta's tracking pixel. Nothing on rantevo.com reports to Meta from your browser. The three events above are sent from our own servers, after the thing they describe has already happened.

Analytics and advertising are asked separately and refusing either takes one click. You can change your answer at any time from Cookie settings, and withdrawing stops us sending anything further about you — including from the billing events that would otherwise follow weeks later. Meta is a controller in its own right for what it does with what it has already received, and its own privacy policy applies to that.

Lawful basis: consent for the analytics and, separately, for the advertising measurement; legitimate interests for the language cookie; and performance of a contract for the reply.

Product update emails

When something ships, we email you about it, at most once a week. These emails are on unless you turn them off, and you can do that at any time: in Settings → Notifications; from the unsubscribe link in every one, whose page asks you to confirm before it changes anything; or with your email app's own unsubscribe button.

Lawful basis: legitimate interests — telling the people who use Rantevo what has changed in the service they use. You can object at any time by turning them off in any of those ways.

Notices about changes to these documents are not product updates. They go to every account holder, including anybody who has turned product updates off, because a contract change has to be told to the person bound by it. Lawful basis: legal obligation and performance of a contract.

Who else sees it

We use other companies to run Rantevo. Each one gets only what it needs, under a contract that requires it to protect the data and act only on our instructions.

  • Supabase — hosts the database, so it holds everything above. Hosted in Frankfurt, Germany.
  • Vercel — hosts and serves the application, and holds server logs containing IP addresses for up to 30 days.
  • Polar — billing and invoicing. Holds your billing details and purchase history. Polar is the merchant of record, so it is also a controller in its own right for the tax records it must keep; its own privacy policy applies to those.
  • Resend — sends and receives our email, and keeps a copy of what was sent.
  • Sinch — delivers SMS. Holds the recipient's number and the text of the message. Sent through their EU region.
  • Cloudflare — object storage for the images you upload.
  • Porkbun — the domain registrar. Holds the contact details on a domain registration.
  • Anthropic — runs the model behind the support assistant. Sees the support conversation and, when the assistant looks something up, the account details listed above, including your team's names, hours and time off.
  • Google — address lookup when you type your business address, our own mailboxes, and search-performance data for rantevo.com.
  • PostHog — measures how Rantevo and the booking sites we run are used, on its EU infrastructure.
  • Meta — only if you accept advertising cookies. Receives your email address in hashed form, the click identifier from the ad you followed if there was one, and the fact that you created an account, started a trial or subscribed. Meta Platforms Ireland is the recipient and the data reaches Meta in the United States. Meta is not our processor: it is a controller in its own right for what it does with this, and its own privacy policy applies.
  • Stripe — if you take payment online, the provider you take it through. Receives the business details listed above when you connect. Stripe is not one of our processors: it works for you, under your own agreement with it, and is a controller in its own right for what it collects; its own privacy policy applies.

We do not sell personal data. The only advertising we share anything for is our own, it is the Meta measurement described above, it happens only if you accept advertising cookies, and it stops when you withdraw.

We will hand over data if we are legally required to — a court order, a tax authority, a regulator — and we will tell you when we are allowed to.

Where it is

We keep data in the European Union wherever the provider offers it, and we chose several of these providers for that reason. Some of the companies above are established outside the EU. Where data reaches them, the transfer is covered by the European Commission's Standard Contractual Clauses together with the technical measures those clauses require.

Meta is the one recipient that holds personal data of yours in the United States. That transfer happens only if you accept advertising cookies, it carries your email address in hashed form and nothing that names you directly, and it is covered by the same Standard Contractual Clauses together with Meta's certification under the EU–US Data Privacy Framework. Refusing advertising cookies means no data about you leaves Europe.

Identifying you to somebody who complains

If you buy a domain through us, we are its registered holder and you hold a licence to use it. The rules the registrar operates under require the holder to either take on liability for harm caused through the domain or disclose the identity and contact details of the licensee within seven days of a proper request.

So: if somebody presents reasonable evidence that your site is being used to cause harm, we will give them your name and contact details, and tell you that we have, unless we are prevented from telling you.

Lawful basis: legitimate interests — ours in not carrying liability for a site we do not run, and a complainant's in being able to reach the person responsible. It is also a condition of the registration you asked us to make.

Abuse reports go to support@rantevo.com.

A site we build before a business asks

To show a business what its booking site would look like, we sometimes build one first and offer it afterwards. It is built only from information about the business that is already public: mostly what it publishes itself, on its website, its social media profiles and its Google listing, and otherwise what directories and other websites show about it. That can include its name, address, phone number, email address, opening hours, prices, logo and photos, and the first names of the people who work there. Where a business publishes no prices, the preview shows prices usual for its trade, marked on the site as indicative, until the business sets its own.

The preview is a real site on a rantevo.com address, but it is not open for business: it takes no bookings, sends no email or text messages, and is marked so that search engines do not index it. We do not link to it from anywhere; the business is sent the address by the person who made it. When we send it, we say where the details came from and when the site is deleted.

It is deleted 90 days after we build it, and sooner if the business asks, at support@rantevo.com. Creating an account through the link we send binds that account to the site and does nothing else: the site stays a preview — taking no bookings, sending nothing, not indexed — and the 90 days keep running. It becomes the business's own site under these terms when a subscription starts, and from that day its data is the account's.

An account created through the link and left without a subscription is closed 90 days after we built the site, and the site is deleted with it. We email 30 days and 7 days before, the same two emails any account that never starts a subscription gets.

Lawful basis: legitimate interests — ours in showing a business what we would build for it, using only information that is already public, for a fixed time, and with nothing done in its name. You can object at any time by asking us to delete the preview, which we will do.

How long we keep it

  • Your account and business data — while the account is open, and deleted when it closes. The exception is an account whose email address isn't confirmed within 7 days of sign-up: it is deleted, with no email first, since until the address is confirmed we can't be sure it's yours.
  • A shop whose subscription has ended — its site and admin area go offline 3 days after the end, and 90 days after that the account is closed and its data deleted. We warn you by email first, and your account shows the date whenever you sign in (Terms, section 11). A shop that never went live has nothing to take offline, and is closed on the same timing.
  • An account that never started a subscription — closed 90 days after sign-up, or after we started building your site if that is later, and its data deleted. If we built the site before you asked, the 90 days run from the day we built it, not from the day you signed up. We email you 30 days and 7 days before, and your account shows the date whenever you sign in.
  • A site we built for you — it goes live only once there is a subscription behind it, so no site of yours is ever live on a clock of its own: while the account is open it is kept with the rest of your account's data, and after the subscription ends it goes as "a shop whose subscription has ended" above. The one site that is live with no subscription behind it is a preview we built before you asked, which is the entry below.
  • A preview site we built before you asked — 90 days from the day we built it, then deleted; sooner if you ask. Creating an account through the link does not move that date: with no subscription by then, the account is deleted with the site. Once you subscribe it is your account's data and kept as above.
  • Bookings and customer records on your site — while the account is open. You control these; they are yours, and you can delete them at any time. The exception is a customer's account whose email address isn't confirmed within 7 days: it is deleted, and their customer record stays if they have booked or you had one for them already.
  • Your Stripe connection — the account's status, what Stripe still needs and its country, while your account is open, and deleted when it closes. Closing your Rantevo account does not close your Stripe account; what Stripe holds is kept under your agreement with it.
  • Invoices and tax records — six years, because the law requires it. This is the one thing that survives account deletion.
  • Support conversations — three years from the last message, or until the account closes if that is sooner, so we can pick one up if you come back to it. Then they are deleted, with any files attached.
  • Sign-in sessions, with the IP address and user-agent recorded with them — until the session ends, when you sign out or after 7 days unused, and then deleted within a day.
  • Sign-in alert device records — a keyed hash, never the address itself, deleted 90 days after the last alert about that device.
  • Rate-limit counts, which hold the IP address of whoever used a form — deleted within two days.
  • Server logs — 30 days.
  • Product analytics — 12 months.

When an account closes we delete the database records, the images uploaded to storage, and the customer record held by our payment provider. Backups roll off on their own schedule, within 30 days.

Your rights

You can ask us to:

  • give you a copy of what we hold about you
  • correct anything wrong — most of it you can edit yourself in your settings
  • delete it, which for an account means closing it
  • export it in a portable form — bookings and customers export to CSV from your admin area while it is online, and you can ask us for them after that, until they are deleted
  • restrict or object to processing we do on legitimate interests

You can also withdraw your consent to analytics at any time, from Cookie settings.

Email support@rantevo.com. We reply within one month. We will not charge you, and we will not ask you to explain why.

You can also complain to a data protection authority — the Office of the Commissioner for Personal Data Protection for us, or the one where you live.

Security

Access to the database goes through per-business isolation enforced by the database itself, not only by our code, so one business cannot read another's data even if we make a mistake. Passwords are hashed. Traffic is encrypted in transit. Access to production is limited to people who need it.

No system is perfect. If there is a breach that puts you at risk, we will tell you and the regulator within the deadlines the law sets, and the DPA sets out what we do when the breach involves your customers' data.

Children

Rantevo is for businesses. We do not knowingly collect data about anybody under 16 through our own sign-up. Whether children book appointments on your site is your call and your responsibility as controller.

Changes

Every version of this policy is numbered and dated. This page shows the latest one — during a notice period, the version about to take effect — and we will send you any earlier version if you ask. If we change something that materially affects you, we email you at least 30 days beforehand.

Contact

Thrasos Charalambous Kopaidos 2, 4152, Limassol, Cyprus

support@rantevo.com — one address for privacy requests, abuse reports and everything else.

We use cookies to see how Rantevo is used and for advertising. Read our Privacy Policy.