Privacy Policy
Version: 2026-08-10
Last updated: 10 August 2026
This Privacy Policy explains how Vindy MB (“Vindy”, “we”, “us”) processes personal data when you use the Vindy platform (the “Service”).
Controller: Vindy MB, legal entity code 307193971, Ašmenėlės g., LT-11330 Vilnius, Lithuania.
Contact: info@vindy.lt
We do not currently appoint a Data Protection Officer. Privacy requests go to the contact above.
1. Data we process
Depending on how you use the Service, we may process:
- Account data – name, email, phone, role, profile details, authentication identifiers;
- Business data – company name, legal entity code, VAT number, address, bank details where needed for invoicing or payouts;
- Booking and event data – registrations, spot selections, leisure bookings, messages related to participation;
- Payment data – payment status, amounts, invoice references, and limited payment metadata from our payment provider (we do not store full card numbers);
- Technical data – device/browser information, IP address, logs, and essential cookies or similar technologies needed for security and operation (see Cookie Policy);
- Analytics data (optional) – if you accept analytics cookies, aggregated usage events such as page/screen views and related technical metadata via Google Analytics 4 (Firebase Analytics);
- Support data – content of support requests and related correspondence;
- Google Calendar integration data (leisure providers only) – if you connect a Google account, the calendar availability (busy/free) times or events we read to block slots, the booking events we create, your Google account email (for display), and the access/refresh tokens needed to keep the connection;
- Legal acceptance records – Terms/Privacy/Cookie policy version accepted, timestamp, and acceptance source (for example registration or checkout).
2. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide accounts, authentication, and role access | Art. 6(1)(b) contract |
| Process bookings, registrations, and checkout | Art. 6(1)(b) contract |
| Process payments and payouts via Stripe | Art. 6(1)(b) contract; Stripe may be an independent controller for card data |
| Sync leisure availability and bookings with your Google Calendar (optional) | Art. 6(1)(a) consent (connect/disconnect at any time); Art. 6(1)(b) contract |
| Issue invoices and meet accounting/tax duties | Art. 6(1)(c) legal obligation |
| Store Terms/Privacy acceptance evidence | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (proof of agreement) |
| Service notices (booking confirmations, security alerts) | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests |
| Prevent fraud, abuse, and security incidents | Art. 6(1)(f) legitimate interests; Art. 6(1)(c) where required by law |
| Diagnose errors and improve reliability of the Service | Art. 6(1)(f) legitimate interests (stable, secure product) |
| Optional product analytics (Firebase Analytics / GA4) | Art. 6(1)(a) consent (banner; essential-only option) |
| Optional marketing emails | Art. 6(1)(a) consent (withdraw anytime) |
| Respond to lawful requests from authorities | Art. 6(1)(c) legal obligation |
Where we rely on legitimate interests, you may object under Art. 21 GDPR where applicable. We balance our interests against your rights; details are available on request.
3. Sharing and processors
We share data only as needed to run the Service, including with:
- Google Firebase / Google Cloud – hosting, authentication, database, storage, and related infrastructure (processor);
- Google Analytics (Firebase Analytics / GA4) – optional measurement after cookie consent (processor / measurement services under Google’s terms);
- Google Calendar API – when a leisure provider connects a Google account, we access that account's Google Calendar to read availability and to create, update, and delete booking events (processor acting under your instructions; you can disconnect at any time);
- Stripe – payment processing (often independent controller for payment methods; otherwise processor under our instructions for platform settlement data);
- Email and messaging providers – transactional notifications (processors);
- Other users – limited profile or booking details necessary for an event or leisure transaction (for example organizer seeing a merchant registration);
- Professional advisers or authorities – when required by law or to protect rights.
We do not sell your personal data.
3.1 Google Calendar integration (optional, leisure providers)
Leisure providers can connect a Google account to keep their listing availability and bookings in sync with Google Calendar. When you connect, and only while the connection stays active, we:
- read your calendar's busy/free times (or events) to block unavailable slots in the Service;
- create, update, and delete calendar events that correspond to bookings for the connected listing;
- store your Google account email (for display) and encrypted access/refresh tokens on our servers to maintain the connection — these are never stored on your device.
Vindy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data solely to provide and improve this calendar-sync feature; we do not transfer it to others except as needed to provide the feature or as required by law; we do not use it for advertising; and we do not allow humans to read it except with your consent, for security or to comply with law, or where the data has been aggregated and anonymized. You can disconnect at any time in the app, which stops future sync and removes the stored tokens.
4. International transfers
Our processors may process data in the EU/EEA and in other countries. Where data is transferred outside the EEA, we use appropriate safeguards required by applicable law (such as Standard Contractual Clauses), where required.
5. Retention
| Data category | Typical retention |
|---|---|
| Account profile | While the account is active, then up to 24 months after closure for security and dispute handling (unless longer required) |
| Booking / registration records | Duration of the relationship plus up to 24 months; longer if a dispute is open |
| Invoices and accounting records | As required by Lithuanian accounting/tax law (commonly up to 10 years) |
| Payment metadata | As needed for payouts, chargebacks, and accounting (aligned with Stripe and legal limits) |
| Security / application logs | Typically 30–180 days, unless needed longer for an incident investigation |
| Support correspondence | Up to 24 months after the ticket is closed |
| Legal acceptance records | For the life of the account plus up to 24 months (or longer if needed to evidence the contract) |
| Marketing consent records | Until withdrawal, then evidence of withdrawal kept as needed |
Exact periods may vary where law or an ongoing claim requires longer storage.
6. Your rights
Subject to applicable law (including the GDPR), you may have the right to:
- access your personal data;
- rectify inaccurate data;
- erase data in certain cases;
- restrict or object to certain processing;
- data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with the State Data Protection Inspectorate (VDAI) in Lithuania or another competent supervisory authority.
To exercise these rights, contact info@vindy.lt. We may need to verify your identity before responding. We aim to respond within one month.
7. Children
The Service is not directed at children under 16. If you believe we have collected such data, contact us so we can delete it where appropriate.
8. Security
We apply technical and organizational measures appropriate to the risk, including access controls and encrypted transport. No method of transmission or storage is completely secure.
9. Changes
We may update this Privacy Policy from time to time. The version and “Last updated” date at the top will change when we do. For material changes that expand processing in a way that requires a new legal basis or fresh consent, we will notify you and/or request acceptance as required by law. Continued use alone is not treated as consent to optional marketing.
10. Contact
Privacy questions: info@vindy.lt
Vindy MB
Legal entity code: 307193971
Ašmenėlės g., LT-11330 Vilnius, Lithuania