Back to home

Privacy Policy

Servinka

Last updated: 2026-06-26 · Effective date: [Effective date]

1. Who we are

This Privacy Policy explains how Solvinka AB (organisation number 5595946707), a company registered in Sweden with its registered address at Södra Storgatan 69, 267 40 Bjuv ("Servinka", "we", "us", "our"), collects, uses, and protects personal data in connection with the Servinka platform at www.servinka.com and www.servinka.se and related services (the "Platform").

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Swedish Data Protection Act (SFS 2018:218).

Contact for data-protection matters: privacy@servinka.com — or by post at Solvinka AB, Södra Storgatan 69, 267 40 Bjuv.

We have not appointed a statutory Data Protection Officer, as we are not required to under Article 37 GDPR.

2. The two roles we play

Servinka is a multi-tenant platform. Service providers ("Providers") use it to run a public storefront, take bookings, manage their own customers, and get paid. End customers ("Customers") book and pay Providers through those storefronts. Our role under the GDPR depends on whose data is processed:

SituationOur roleController
Data about Providers (account holders) and website visitorsControllerServinka
Data about a Provider's Customers managed through the Platform (name, phone, bookings, notes, purchases)ProcessorThe Provider is the controller; we process it on the Provider's instructions

This Policy describes our processing as a controller. Where we act as a processor for a Provider, our Data Processing Agreement applies and the Provider's own privacy notice governs how Customer data is used. If you are a Customer of a Provider and want to exercise your rights, contact that Provider directly; we will support them in responding.

3. Personal data we collect (as controller)

When a Provider signs up and uses the dashboard: name, email, password (stored hashed — never in plain text); business/legal name, organisation number, VAT number, address, phone, email, website, social handles, logo/cover images, descriptions; subscription plan, trial status, billing period, and our Stripe customer reference. Card details are collected and stored by Stripe, not by us (see Section 6). We also keep your support messages and our replies.

When anyone visits the Platform: IP address, browser, device and operating system, language, referring URL, pages viewed, and timestamps; cookies and similar technologies (Section 9); product-analytics events and diagnostic/error data used to operate, secure, and improve the Platform.

Customer data processed on a Provider's behalf (Section 2): name, phone, optional email, language, booking/purchase details, address for at-location services, free-text notes, and — for company customers — company name, organisation number, VAT number, and billing address.

We do not intentionally collect special categories of personal data (Article 9 GDPR). Please do not enter sensitive information into free-text fields unless strictly necessary.

4. Why we process data and our legal bases (as controller)

PurposeLegal basis (Art. 6 GDPR)
Create and operate your Provider account; provide the PlatformContract (6(1)(b))
Bill you; manage subscriptions and trials; prevent payment fraudContract (6(1)(b)); legal obligation for accounting (6(1)(c))
Send transactional emails (booking, billing, security notices)Contract (6(1)(b))
Keep the Platform secure; prevent abuse; debug errorsLegitimate interests (6(1)(f))
Product analytics to understand and improve the PlatformConsent (6(1)(a)) where required for non-essential cookies; otherwise legitimate interests (6(1)(f))
Comply with bookkeeping, tax, and other legal obligationsLegal obligation (6(1)(c))
Marketing emails to Providers (if any)Consent (6(1)(a)) or legitimate interests with opt-out in every message
Establish, exercise, or defend legal claimsLegitimate interests (6(1)(f)) / legal obligation

Where we rely on legitimate interests, we have balanced them against your rights; you may object (Section 10). Where we rely on consent, you may withdraw it at any time without affecting prior processing.

5. Who we share data with (sub-processors)

We do not sell personal data. We share it only with the service providers needed to run the Platform, each bound by a data-processing agreement and appropriate safeguards:

ProviderPurposeData location
SupabaseDatabase, authentication, storageEU — Stockholm, Sweden
VercelApplication hosting and deliveryEU/global edge; functions in Stockholm
StripePayment processing (subscriptions and Customer↔Provider payments via Connect)EU/US — see Section 6
ResendTransactional email deliveryEU — Ireland
UpstashRate-limitingUK — London
PostHogProduct analytics and session replayUS
SentryError and performance monitoringEU — Germany

We keep an up-to-date list of sub-processors and notify Providers of material changes. We may also disclose data where required by law or a competent authority, and to professional advisers or in connection with a merger or asset sale (subject to this Policy).

6. Payments

Payments are processed by Stripe. We use Stripe Connect (Standard), so Customer payments are made to the Provider's own Stripe account — Servinka is not a party to, and does not take custody of, money in those Customer↔Provider transactions. Provider subscription payments to us use a separate standard Stripe billing relationship.

We never receive or store full card numbers. Stripe processes cardholder data directly as an independent controller for its own compliance (PCI-DSS) and fraud prevention, governed by the Stripe Privacy Policy (stripe.com/privacy). We store only non-sensitive references (e.g. a payment-intent ID, card brand, last four digits) and the amounts, VAT breakdown, and status of transactions.

7. International transfers

Most data stays within the EU/EEA (Supabase in Sweden, Resend in Ireland, Sentry in Germany). Some sub-processors process data outside the EU/EEA: PostHog in the United States; Upstash in the United Kingdom (covered by a UK adequacy decision); Stripe and Vercel may process limited data in the United States.

Where data is transferred outside the EU/EEA to a country without an adequacy decision, we rely on appropriate safeguards under Chapter V GDPR — primarily the European Commission's Standard Contractual Clauses, supplemented by additional measures, and/or the EU–U.S. Data Privacy Framework where the recipient is certified. Request a copy of the relevant safeguards at privacy@servinka.com.

8. How long we keep data

DataRetention
Provider account & business dataLife of the account, then deleted or anonymised within 90 days of closure unless a longer period is legally required
Billing, invoices, accounting records7 years after the end of the financial year (Bokföringslagen)
Customer/booking data processed for ProvidersAs long as the Provider keeps it; deleted on Provider instruction or account closure
Server, security, and access logsTypically 30–90 days
Analytics & error dataPer sub-processor defaults, generally up to 12 months
Inactive free/trial slugsReleased after 90 days of inactivity, with prior warning

When we no longer need personal data, we delete or irreversibly anonymise it.

9. Cookies and similar technologies

We use strictly necessary cookies for authentication, security, and core functionality (no consent required), and analytics/functional technologies (e.g. PostHog) only with your consent where required by the ePrivacy rules and the Swedish Electronic Communications Act. You can manage non-essential cookies through our cookie settings and your browser. Blocking strictly necessary cookies may break parts of the Platform.

10. Your rights under the GDPR

Where we are the controller, you have the right to: access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); data portability (Art. 20); object to processing based on legitimate interests, and to direct marketing at any time (Art. 21); withdraw consent (Art. 7(3)); and not be subject to solely automated decisions with legal or similarly significant effects (Art. 22) — we do not carry out such automated decision-making or profiling.

To exercise any right, email privacy@servinka.com. We respond within one month (extendable by two further months for complex requests, with notice). We may verify your identity first. Exercising your rights is free unless requests are manifestly unfounded or excessive.

If you are a Customer of a Provider, the Provider is the controller of your booking data — direct your request to them; we will assist.

Right to complain: you can lodge a complaint with the Swedish data-protection authority, Integritetsskyddsmyndigheten (IMY) — imy.se — or with the supervisory authority in your country of residence.

11. Data Processing Agreement (for Providers)

When a Provider uses the Platform to process their Customers' personal data, Servinka acts as a processor and the Provider as controller. The Article 28 GDPR terms are set out in our Data Processing Agreement, incorporated into the Terms & Conditions for every Provider.

12. How we protect data

We apply appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, row-level security and tenant isolation, least-privilege access, secrets management, a tuned Content-Security-Policy and other security headers, rate-limiting on public endpoints, and continuous monitoring. We will notify the relevant authority and affected individuals of a personal-data breach where legally required (Art. 33–34).

13. Children

The Platform is intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from children under the applicable age of digital consent. If you believe a child has provided us data, contact privacy@servinka.com and we will delete it.

14. Changes to this Policy

We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, notify Providers by email or in-app. Continued use after changes take effect constitutes acceptance.

15. Contact

Solvinka AB · Södra Storgatan 69, 267 40 Bjuv · privacy@servinka.com