Legal

Privacy Policy

Effective: June 1, 2026 · Last updated: August 2026

1. Who We Are

CompanyTHREE GUYS s. r. o.
Registered seatNová Vieska 243, 943 41 Nová Vieska, Slovakia
Company ID (IČO)54558123

Xenla is a studio management and booking platform. This policy explains how we handle personal data when you use the website (xenla.app), the Admin app (app.xenla.bookings), and the Guest app (app.xenla.guest). One privacy URL covers all three.

Admin accounts are for studio operators who run their business on Xenla; Guest accounts are for clients who book. The same privacy commitments apply to both roles.

2. Data We Collect

Account & sign-in

Email, password (hashed), business name, business category, and billing details (payments are processed by Stripe — we never see your card number). You may also sign in with Google or Sign in with Apple; we receive the name and email you choose to share. With Apple you can use Hide My Email; in that case we only see Apple’s relay address.

Business operational data

Client names, emails, phone numbers, appointment history, and booking data you enter into the platform. That data belongs to you; we act as a processor for it.

Push notifications (optional)

If you enable them, we store a device token so we can deliver alerts: APNs on iOS and FCM/Firebase on Android. You can turn notifications off anytime in system settings or in the app.

Apple Wallet / Google Wallet / QR pass

If you add a pass to Apple Wallet, we generate a .pkpassfile. If you add it to Google Wallet, we generate a signed "Save to Google Wallet" link. The pass barcode / QR encodes the pass id, so the studio can validate it at check-in.

Usage data

Pages visited, features used, browser type, IP address, and device type — to improve the product and diagnose issues.

3. How We Use Your Data & Legal Bases

  • Provide and operate Xenla — contract performance (GDPR Art. 6(1)(b))
  • Transactional email (booking confirmations, reminders, receipts) — contract
  • Customer support — legitimate interest (Art. 6(1)(f))
  • Product improvement, security, and bug fixes — legitimate interest
  • Legal obligations (e.g. accounting) — legal obligation (Art. 6(1)(c))

We do not sell your data. We do not use your client data for advertising.

4. Data Storage & Security

  • On the primary market (xenla.app), data is stored on US East servers (AWS us-east-1, Virginia).
  • Encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Daily backups retained for 30 days; access limited to authorized personnel.
  • Payment data is handled exclusively by Stripe (PCI DSS Level 1).

5. Processors & Third-Party Services

We use specialized providers to run Xenla. Each processes only what their role requires:

  • AppleSign in with Apple, APNs, Apple Wallet · privacy
  • GoogleGoogle sign-in; optional Calendar sync; Google Wallet · privacy
  • Firebase / FCMAndroid push (optional) · privacy
  • AnthropicAI booking assistant (chat receptionist) · privacy
  • StripePayments & billing · privacy
  • SupabaseDatabase & authentication · privacy
  • VercelHosting & CDN · privacy
  • ResendTransactional email · privacy

6. Cookies

We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. You can disable non-essential cookies anytime through the cookie banner.

7. Your Rights

You have the right to access, correct, delete, restrict, object to processing, export your data, and opt out of marketing.

Contact the controller, THREE GUYS s. r. o., at hello@xenla.app. We respond within 30 days. For account deletion, see section 8.

California residents may request access, correction, or deletion of personal information via the same email. We do not sell personal information.

If you are in the EU/EEA, you may lodge a complaint with your local supervisory authority, or with the lead authority in Slovakia, where THREE GUYS s. r. o. is established.

8. Account Deletion

You can request deletion of your Xenla account (operated by THREE GUYS s. r. o.) at any time. This applies to Guest accounts in the app and on the web.

How to delete your account in the app

  1. Open Xenla and sign in
  2. Go to My bookings
  3. Open the Profile tab
  4. Under Your data, tap Delete my account
  5. Confirm deletion

Email alternative

If you cannot use the app, email hello@xenla.app from the address linked to your account, with the subject “Account deletion request”. We process email requests within 30 days.

What is deleted

  • Your sign-in account and credentials
  • App profile (name, username, phone, bio, photo, and account preferences)
  • Points, redemptions, and invite data tied to your account
  • Push tokens and other app account data associated with your authentication user

What is retained and why

  • Booking history and client records at each business — studios manage these as independent controllers; they are not automatically erased when you delete your Xenla account. Contact the business, or email hello@xenla.app and we will help route the request.
  • Payment and billing records — may be retained where required by law or accounting obligations (e.g. via Stripe).
  • Backups — daily backups may retain residual copies for up to 30 days, after which they are purged.

When you delete your account in the app, access and account data are removed immediately. Residual copies in backups are purged within 30 days, except where longer retention is required by law.

9. Data Retention

We retain your data while your account is active. Upon deletion, data is purged within 30 days except where retention is required by law. Details are in section 8.

10. Children's Privacy

Xenla is not directed to children under 13. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email before significant changes take effect.