Legal
Effective: June 1, 2026 · Last updated: August 2026
Xenla is a studio management and booking platform. This policy explains how we handle personal data when you use the website (xenla.app), the Admin app (app.xenla.bookings), and the Guest app (app.xenla.guest). One privacy URL covers all three.
Admin accounts are for studio operators who run their business on Xenla; Guest accounts are for clients who book. The same privacy commitments apply to both roles.
Account & sign-in
Email, password (hashed), business name, business category, and billing details (payments are processed by Stripe — we never see your card number). You may also sign in with Google or Sign in with Apple; we receive the name and email you choose to share. With Apple you can use Hide My Email; in that case we only see Apple’s relay address.
Business operational data
Client names, emails, phone numbers, appointment history, and booking data you enter into the platform. That data belongs to you; we act as a processor for it.
Push notifications (optional)
If you enable them, we store a device token so we can deliver alerts: APNs on iOS and FCM/Firebase on Android. You can turn notifications off anytime in system settings or in the app.
Apple Wallet / Google Wallet / QR pass
If you add a pass to Apple Wallet, we generate a .pkpassfile. If you add it to Google Wallet, we generate a signed "Save to Google Wallet" link. The pass barcode / QR encodes the pass id, so the studio can validate it at check-in.
Usage data
Pages visited, features used, browser type, IP address, and device type — to improve the product and diagnose issues.
We do not sell your data. We do not use your client data for advertising.
We use specialized providers to run Xenla. Each processes only what their role requires:
We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. You can disable non-essential cookies anytime through the cookie banner.
You have the right to access, correct, delete, restrict, object to processing, export your data, and opt out of marketing.
Contact the controller, THREE GUYS s. r. o., at hello@xenla.app. We respond within 30 days. For account deletion, see section 8.
California residents may request access, correction, or deletion of personal information via the same email. We do not sell personal information.
If you are in the EU/EEA, you may lodge a complaint with your local supervisory authority, or with the lead authority in Slovakia, where THREE GUYS s. r. o. is established.
You can request deletion of your Xenla account (operated by THREE GUYS s. r. o.) at any time. This applies to Guest accounts in the app and on the web.
How to delete your account in the app
Email alternative
If you cannot use the app, email hello@xenla.app from the address linked to your account, with the subject “Account deletion request”. We process email requests within 30 days.
What is deleted
What is retained and why
When you delete your account in the app, access and account data are removed immediately. Residual copies in backups are purged within 30 days, except where longer retention is required by law.
We retain your data while your account is active. Upon deletion, data is purged within 30 days except where retention is required by law. Details are in section 8.
Xenla is not directed to children under 13. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will notify you by email before significant changes take effect.