1. Scope and responsible operator
This Policy explains how personal data is processed in the Majster iOS and Android application, majsterstudio.com and support (the “Service”). It covers professionals, clients, website visitors and people whose details a professional enters into their client database.
The operator is individual entrepreneur Фринцко Сергій Михайлович (FOP), Ukrainian taxpayer number (РНОКПП): 3154608370, Ukraine. Contact: support@majsterstudio.com. Personal data is information identifying a person directly or indirectly.
This Policy is a notice, not blanket consent to processing or international transfers. Use of the Service alone does not provide such consent. See our Terms of Use for the rules of use.
2. Majster’s and the professional’s roles
We act as controller for account, access, subscription, security and support data, determining the purposes and means of that processing.
The professional determines why they keep their own CRM records, what client information to include and the lawful basis. For those records, Majster provides technical processing on their instructions. Professionals must also inform clients without a Majster account and uphold their rights. This Policy does not replace the professional’s own notice or any required data processing agreement.
3. Data categories and sources
Information comes from you, the professional associated with your appointment or CRM record, your chosen sign-in provider, app stores and operation of the Service.
- Account: internal ID, name, email, phone and verification status, sign-in methods, roles, language, time zone, selected country, region and city, and settings.
- Professional’s work: name or business name, selected avatar, services, prices, working hours, client records and contacts, private notes, appointments and change history, cancellation and rescheduling reasons, income and expenses.
- Purchases: store, product, purchase and transaction identifiers, subscription or trial status and dates. We do not receive complete payment card details.
- Technical information: IP addresses and request metadata, account and installation IDs, push tokens, device, OS and app version, crash reports, usage events and security logs.
- Support: reply email, subject, message, language and request ID; deletion requests also include the account contact and confirmation.
Required fields enable the relevant feature; without them sign-in, connecting to a professional or a support reply may be unavailable. A normal profile does not require a home address or postal code.
4. Contacts, photos, location and device protection
Contact import is initiated by the professional. Only the selected contact’s name and phone number are copied to CRM when saved; the whole address book is not uploaded. Manual entry is available.
You select an avatar through the system image picker. It is cropped and compressed before the processed copy is stored in Firebase Storage. This feature neither uploads the entire photo library nor uses the camera. You can replace or remove the picture.
Country, region and city are entered in the profile. These features do not use GPS or background movement tracking. Device settings let you change permissions, which may limit the corresponding feature.
Face ID, Touch ID and other biometrics are checked by the device operating system. We receive the result, not biometric templates. Local PIN protection data remains on the device. Do not send support your PIN, external account password or one-time codes.
5. Purposes and legal bases
We provide accounts, calendar, CRM, appointments, synchronisation, reminders, support and subscription verification to perform our contract. Professionals must establish their own appropriate legal basis for client CRM data.
Abuse prevention, security checks, incident investigation and evaluating features may rely on our legitimate interest in a secure and reliable Service, where applicable law allows and your rights do not override that interest. Statutory recordkeeping and lawful requirements rely on legal obligations.
Where consent is legally required, it must be obtained separately and may be withdrawn for the future. Operating-system permissions are not a substitute for a legal basis. We do not sell personal data or use private CRM records for advertising. Marketing messages are not a condition of use.
Do not enter unnecessary sensitive information, including health information, without an appropriate basis. Majster is not intended to maintain medical records.
6. Who can see profiles and shared records
The professional directory is enabled by default. Signed-in clients can see a professional’s name, country, region, city, avatar and identifier; they cannot see the professional’s phone, private CRM or finances through the directory. Turning directory visibility off does not disconnect existing clients.
Avatars also appear in invitations and connected-professional lists. Anyone with a direct avatar image URL can open it without signing in to Majster. Do not choose confidential images.
When connecting through search, the client shares their name and verified phone number with the professional for a CRM record. An invitation links an account to a specific professional’s record. Both parties see necessary shared appointment details and change messages, including cancellation or rescheduling reasons. Private CRM notes and internal appointment notes are not shown to clients.
Disconnecting does not itself delete the professional’s CRM record or service history. Requests concerning those records take both parties’ rights and lawful bases into account.
7. Providers and other recipients
Infrastructure, authentication, payment, messaging and support providers and authorised staff receive only the information needed for their work.
- Google Firebase and Google Cloud: authentication, database, server processing, photo storage, backups, request protection, FCM push delivery, logs and Crashlytics. Firebase privacy information.
- Apple and Google: chosen sign-in method, App Store or Google Play purchases and restoration, and platform messaging. We receive a provider identifier and profile information available under your choices; Apple may supply a relay email. Apple Privacy Policy; Google Privacy Policy.
- RevenueCat: user ID, purchase, device and subscription information to manage access. RevenueCat Privacy Policy.
- Website hosting and email providers: request metadata, email addresses, delivery of sign-in codes and support requests. Google reCAPTCHA processes web-form security data as described below.
Stores and sign-in providers may act as independent controllers for their own purposes. Installing Majster does not give us access to all email, contacts or files in your Google or Apple account. Facebook and Telegram sign-in are disabled in the current configuration; enabling them requires updated information.
Disclosure to authorities requires a lawful request. A change of operator or business transfer requires a lawful basis, limited disclosure and appropriate notice; this does not authorise unrestricted sale of client databases.
8. Website, forms and Google reCAPTCHA
The website has no separate user account. Hosting processes IP addresses, request times, requested pages and browser information to deliver pages and maintain security. We have no proprietary advertising trackers or advertising profiling tools on the website.
Essential session and CSRF cookies protect forms and maintain their operation. The session lasts up to two hours of inactivity; cookies are not used for advertising. Server session records and rate-limit counters are temporary and subject to scheduled cleanup.
Google reCAPTCHA v2 loads on support and account-deletion pages. Google may receive IP, browser and device details, interaction signals and cookies including _GRECAPTCHA. Processing can start when the challenge loads, before a form is submitted. The Google Privacy Policy and Google Terms apply.
After verification, the server sends your request to support by email. CAPTCHA tokens are used for verification and excluded from the email. Do not send unnecessary personal information or secrets. To contact us without web forms or CAPTCHA, email support@majsterstudio.com directly.
9. Diagnostics, events and messages
Crashlytics in user release builds receives crash reports and technical context that may be linked to an internal account ID. Product events, such as creating an appointment or changing a subscription, include time, event type and internal identifiers. These are pseudonymous, not necessarily anonymous. Note text, names and phone numbers are not product-event fields.
Push tokens deliver notifications to your device. Reminder content may appear on the lock screen; manage permissions and previews in OS settings. Email codes and phone-verification SMS are service messages. Appointment reminders use push notifications, not paid SMS.
Automated checks determine slot availability, subscription status and abuse indicators. They are not used for advertising profiling or solely automated decisions producing legal or similarly significant effects. You can ask support to review a disputed access restriction.
10. International transfers
Cloud, payment and email providers may process data in Ukraine, the European Economic Area, the United States and other countries where their systems and support operate. A European server region does not mean all data stays exclusively in Europe.
Transfers must use mechanisms permitted by applicable law. Where GDPR applies, these may include adequacy decisions or appropriate safeguards such as standard contractual clauses. Ask support about a particular recipient and applicable safeguards. Reading this Policy does not replace a necessary transfer basis.
11. Retention periods
Profile and work data remain while the account exists and they are needed for the relevant functions, subject to deletion requests. Subscription expiry alone does not delete data. After 12 months without active professional access, a warning may be sent; inactivity deletion may occur no earlier than 30 days after that warning.
Main-database backups are designed for a 30-day retention cycle from creation. Deletion from the live database is not immediate removal from backups. Completed notification service records are scheduled for cleanup after 30 days; used, revoked or expired invitations after 3 days, on the next scheduled cleanup run.
Support retention depends on resolving the issue and retaining evidence of its outcome; security and diagnostic logs on incident investigation and remediation; product events on the need to analyse the relevant feature. Payment and claim records may be kept for mandatory periods and protection of rights. Ask support about the periods and bases applicable to your data. A record being in a log does not justify indefinite retention.
12. Account and data deletion
Start deletion in application settings or use the deletion request form. We may verify account ownership. The web form submits a request and does not instantly delete an account. Whole-account deletion covers both roles if you are both a professional and a client.
The process ends account access and removes the profile and push tokens. For professionals, it also covers their avatar, services, schedule, CRM and expenses, cancelling future appointments and stopping associated reminders. Related data is processed in stages; this is not a promise of immediate erasure of every copy.
Appointment history, change events, service logs and provider data may require a separate deletion review. Removing a name or account link alone does not make all such records anonymous. On request we explain what remains, why and for how long; further retention needs a lawful basis.
After a client account is deleted, a professional may retain their own CRM record and service history under an independent lawful basis. Contact the professional or us for help exercising your rights. This does not remove your data-protection rights. Uninstalling the app does not delete the account, and deleting the account does not cancel a store subscription.
13. Your rights and requests
You may request information on processing, sources and recipients, access and a copy, correction or deletion. Depending on applicable law, rights also include restriction, objection, portability and withdrawing consent without affecting prior lawful processing.
You can edit some information in your profile and export available data in the app. For incomplete exports or assistance, email support@majsterstudio.com or use support. Identity checks are proportionate to risk. We respond within applicable legal deadlines; under GDPR this is generally one month, with notice of a justified extension.
You may complain to the Ukrainian Parliament Commissioner for Human Rights or the competent data-protection authority in your country where the relevant law applies. Contacting us first is not a condition for a complaint.
14. Security
We use protected transmission, authentication, access controls and checks on critical operations. Authorised personnel have access according to their duties. No system guarantees absolute security; this does not remove our duties to protect data and report incidents where required by law.
Protect your device, email and exported copies. External links lead to services with their own policies; those links do not remove our responsibility for processing we organise.
15. Age requirements
Majster is intended for users aged 18 or over. People under 18 must not create accounts or use the Service. Report such an account or unlawful entry of a child’s data to support for investigation and appropriate action, including deletion where required.
The account age limit does not mean a professional can never hold a minor client’s information in their own CRM. The professional is responsible for a lawful basis, required notice and involvement of a legal representative where necessary.
16. Policy changes
We update this Policy when features, providers or legal requirements change and display the update date. Where required, we notify you of material changes through the app, website or available contact before they apply. Publishing a new text alone does not authorise a new purpose requiring consent.
All language versions describe the same processing practices. Ukrainian is the original version; translations do not limit mandatory rights under applicable law. Policy contact: support@majsterstudio.com.