Privacy Policy
Servinka
Last updated: 2026-06-26 · Effective date: [Effective date]
1. Who we are
This Privacy Policy explains how Solvinka AB (organisation number 5595946707), a company registered in Sweden with its registered address at Södra Storgatan 69, 267 40 Bjuv ("Servinka", "we", "us", "our"), collects, uses, and protects personal data in connection with the Servinka platform at www.servinka.com and www.servinka.se and related services (the "Platform").
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Swedish Data Protection Act (SFS 2018:218).
Contact for data-protection matters: privacy@servinka.com — or by post at Solvinka AB, Södra Storgatan 69, 267 40 Bjuv.
We have not appointed a statutory Data Protection Officer, as we are not required to under Article 37 GDPR.
2. The two roles we play
Servinka is a multi-tenant platform. Service providers ("Providers") use it to run a public storefront, take bookings, manage their own customers, and get paid. End customers ("Customers") book and pay Providers through those storefronts. Our role under the GDPR depends on whose data is processed:
| Situation | Our role | Controller |
|---|---|---|
| Data about Providers (account holders) and website visitors | Controller | Servinka |
| Data about a Provider's Customers managed through the Platform (name, phone, bookings, notes, purchases) | Processor | The Provider is the controller; we process it on the Provider's instructions |
This Policy describes our processing as a controller. Where we act as a processor for a Provider, our Data Processing Agreement applies and the Provider's own privacy notice governs how Customer data is used. If you are a Customer of a Provider and want to exercise your rights, contact that Provider directly; we will support them in responding.
3. Personal data we collect (as controller)
When a Provider signs up and uses the dashboard: name, email, password (stored hashed — never in plain text); business/legal name, organisation number, VAT number, address, phone, email, website, social handles, logo/cover images, descriptions; subscription plan, trial status, billing period, and our Stripe customer reference. Card details are collected and stored by Stripe, not by us (see Section 6). We also keep your support messages and our replies.
When anyone visits the Platform: IP address, browser, device and operating system, language, referring URL, pages viewed, and timestamps; cookies and similar technologies (Section 9); product-analytics events and diagnostic/error data used to operate, secure, and improve the Platform.
Customer data processed on a Provider's behalf (Section 2): name, phone, optional email, language, booking/purchase details, address for at-location services, free-text notes, and — for company customers — company name, organisation number, VAT number, and billing address.
We do not intentionally collect special categories of personal data (Article 9 GDPR). Please do not enter sensitive information into free-text fields unless strictly necessary.
4. Why we process data and our legal bases (as controller)
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Create and operate your Provider account; provide the Platform | Contract (6(1)(b)) |
| Bill you; manage subscriptions and trials; prevent payment fraud | Contract (6(1)(b)); legal obligation for accounting (6(1)(c)) |
| Send transactional emails (booking, billing, security notices) | Contract (6(1)(b)) |
| Keep the Platform secure; prevent abuse; debug errors | Legitimate interests (6(1)(f)) |
| Product analytics to understand and improve the Platform | Consent (6(1)(a)) where required for non-essential cookies; otherwise legitimate interests (6(1)(f)) |
| Comply with bookkeeping, tax, and other legal obligations | Legal obligation (6(1)(c)) |
| Marketing emails to Providers (if any) | Consent (6(1)(a)) or legitimate interests with opt-out in every message |
| Establish, exercise, or defend legal claims | Legitimate interests (6(1)(f)) / legal obligation |
Where we rely on legitimate interests, we have balanced them against your rights; you may object (Section 10). Where we rely on consent, you may withdraw it at any time without affecting prior processing.
5. Who we share data with (sub-processors)
We do not sell personal data. We share it only with the service providers needed to run the Platform, each bound by a data-processing agreement and appropriate safeguards:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, storage | EU — Stockholm, Sweden |
| Vercel | Application hosting and delivery | EU/global edge; functions in Stockholm |
| Stripe | Payment processing (subscriptions and Customer↔Provider payments via Connect) | EU/US — see Section 6 |
| Resend | Transactional email delivery | EU — Ireland |
| Upstash | Rate-limiting | UK — London |
| PostHog | Product analytics and session replay | US |
| Sentry | Error and performance monitoring | EU — Germany |
We keep an up-to-date list of sub-processors and notify Providers of material changes. We may also disclose data where required by law or a competent authority, and to professional advisers or in connection with a merger or asset sale (subject to this Policy).
6. Payments
Payments are processed by Stripe. We use Stripe Connect (Standard), so Customer payments are made to the Provider's own Stripe account — Servinka is not a party to, and does not take custody of, money in those Customer↔Provider transactions. Provider subscription payments to us use a separate standard Stripe billing relationship.
We never receive or store full card numbers. Stripe processes cardholder data directly as an independent controller for its own compliance (PCI-DSS) and fraud prevention, governed by the Stripe Privacy Policy (stripe.com/privacy). We store only non-sensitive references (e.g. a payment-intent ID, card brand, last four digits) and the amounts, VAT breakdown, and status of transactions.
7. International transfers
Most data stays within the EU/EEA (Supabase in Sweden, Resend in Ireland, Sentry in Germany). Some sub-processors process data outside the EU/EEA: PostHog in the United States; Upstash in the United Kingdom (covered by a UK adequacy decision); Stripe and Vercel may process limited data in the United States.
Where data is transferred outside the EU/EEA to a country without an adequacy decision, we rely on appropriate safeguards under Chapter V GDPR — primarily the European Commission's Standard Contractual Clauses, supplemented by additional measures, and/or the EU–U.S. Data Privacy Framework where the recipient is certified. Request a copy of the relevant safeguards at privacy@servinka.com.
8. How long we keep data
| Data | Retention |
|---|---|
| Provider account & business data | Life of the account, then deleted or anonymised within 90 days of closure unless a longer period is legally required |
| Billing, invoices, accounting records | 7 years after the end of the financial year (Bokföringslagen) |
| Customer/booking data processed for Providers | As long as the Provider keeps it; deleted on Provider instruction or account closure |
| Server, security, and access logs | Typically 30–90 days |
| Analytics & error data | Per sub-processor defaults, generally up to 12 months |
| Inactive free/trial slugs | Released after 90 days of inactivity, with prior warning |
When we no longer need personal data, we delete or irreversibly anonymise it.
9. Cookies and similar technologies
We use strictly necessary cookies for authentication, security, and core functionality (no consent required), and analytics/functional technologies (e.g. PostHog) only with your consent where required by the ePrivacy rules and the Swedish Electronic Communications Act. You can manage non-essential cookies through our cookie settings and your browser. Blocking strictly necessary cookies may break parts of the Platform.
10. Your rights under the GDPR
Where we are the controller, you have the right to: access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); data portability (Art. 20); object to processing based on legitimate interests, and to direct marketing at any time (Art. 21); withdraw consent (Art. 7(3)); and not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — we do not carry out such automated decision-making or profiling.
To exercise any right, email privacy@servinka.com. We respond within one month (extendable by two further months for complex requests, with notice). We may verify your identity first. Exercising your rights is free unless requests are manifestly unfounded or excessive.
If you are a Customer of a Provider, the Provider is the controller of your booking data — direct your request to them; we will assist.
Right to complain: you can lodge a complaint with the Swedish data-protection authority, Integritetsskyddsmyndigheten (IMY) — imy.se — or with the supervisory authority in your country of residence.
11. Data Processing Agreement (for Providers)
When a Provider uses the Platform to process their Customers' personal data, Servinka acts as a processor and the Provider as controller. The Article 28 GDPR terms are set out in our Data Processing Agreement, incorporated into the Terms & Conditions for every Provider.
12. How we protect data
We apply appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, row-level security and tenant isolation, least-privilege access, secrets management, a tuned Content-Security-Policy and other security headers, rate-limiting on public endpoints, and continuous monitoring. We will notify the relevant authority and affected individuals of a personal-data breach where legally required (Art. 33–34).
13. Children
The Platform is intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from children under the applicable age of digital consent. If you believe a child has provided us data, contact privacy@servinka.com and we will delete it.
14. Changes to this Policy
We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, notify Providers by email or in-app. Continued use after changes take effect constitutes acceptance.
15. Contact
Solvinka AB · Södra Storgatan 69, 267 40 Bjuv · privacy@servinka.com