Official Privacy & Data Protection Statement

Privacy Policy for KAAT Booking

Your privacy is our top priority. Learn how KAAT Booking collects, uses, protects, and gives you complete control over your personal data.

Effective Date: August 18, 2026App Store & Google Play Compliant

1. Scope & Applications

This Privacy Policy applies to all users interacting with the KAAT Booking platform, including:

KAAT Customer App

iOS & Android app for clients to find beauty centers, barbershops, wellness salons, view staff schedules, and book appointments.

KAAT Business & Dashboard

iOS, Android & Web management system for business owners, receptionists, and staff to manage appointments, rosters, and services.

2. Information We Collect

We collect only the minimal information required to provide reliable booking services:

A. Personal Identification & Authentication

Full name, normalized phone number (E.164 standard, e.g. +964XXXXXXXXXX) for OTP verification and login, and optional profile pictures.

B. Booking & Appointment Data

Selected services, combo packages, appointment date/time, selected staff member, total price, booking status (pending, confirmed, completed, cancelled), and cancellation reasons.

C. Device & Push Notification Tokens

Device platform (ios / android / web), APNs and Firebase Cloud Messaging (FCM) device tokens, and language tags (en, ckb, ar) to deliver localized appointment reminders.

D. Reviews & Customer Feedback

Ratings (1 to 5 stars) and optional textual reviews submitted for completed visits to ensure community trust.

3. Location Data & Maps

With your explicit authorization via system dialogs, KAAT collects device GPS coordinates to:

  • Calculate exact distances and travel times to nearby salons and barbershops.
  • Display interactive map pins and provide directions via mapping apps (Apple Maps / Google Maps).
  • Filter services and businesses within your city or district.

Location Control: Location access is 100% optional. You can disable location permissions at any time in your device settings. KAAT will continue to operate normally using manual city/district searches.

4. How We Use Data

We process personal data strictly under legitimate legal bases to fulfill our services:

Service Fulfillment

Transmitting booking requests to selected businesses and syncing calendar schedules.

Operational Notifications

Sending booking confirmations, time slot reminders, cancellations, and status updates.

Fraud Prevention & Safety

Preventing fake appointments, verifying phone numbers, and maintaining community standards.

No Third-Party Ad Selling

We never sell, rent, or monetize your personal information to third-party advertising brokers.

5. Account Deletion & GDPR Rights

In full compliance with Apple App Store, Google Play, and international GDPR regulations, KAAT provides instant, self-service account deletion.

What happens when you delete your account:

  • Your normalized phone number is permanently removed and anonymized in the database.
  • Your uploaded profile picture is purged from cloud storage (Cloudflare R2).
  • All future scheduled appointments are automatically cancelled to notify merchants.
  • Your saved favorites list and device push tokens are deleted immediately.

How to initiate deletion: Open the KAAT Customer App > Profile > Settings > Delete Account, or send an email to privacy@kaatbooking.com with your registered phone number.

6. Storage & Infrastructure Partners

We work with world-class cloud infrastructure partners to keep your data secure:

Database & Auth

Supabase (PostgreSQL)

Enterprise-grade database hosting, encryption-at-rest, and Row Level Security.

Media Hosting

Cloudflare R2 Storage

Fast, distributed object storage for business galleries and profile pictures.

Push Delivery

Apple APNs & Google FCM

Official native operating system channels for instant push alerts.

Geospatial

PostGIS & Map Engines

Accurate spatial query calculations and street-level routing.

7. Security & Safeguards

We enforce strict industry standards to protect your data from unauthorized access:

  • End-to-end transport layer encryption (TLS 1.3 / HTTPS).
  • Database Row Level Security (RLS) ensuring merchants and customers only access their own authorized records.
  • Strict rate limiting on authentication and OTP requests to prevent brute force abuse.

8. Contact Us & Data Officer

If you have any questions, feedback, or privacy-related requests, our team is available to assist you: