Privacy Policy
Effective from 1 June 2026
ORAROS LTD ("Oraros", "we", "us", or "our") provides the Oraros online booking and business-management platform available at https://www.oraros.com and through our mobile applications (together, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it.
This policy applies to everyone who uses Oraros — customers booking appointments, business owners subscribing to the platform, staff members invited by a business, brand ambassadors, and visitors to our website. If more than one section applies to you, all relevant sections apply.
1. Who we are
The data controller for personal information processed through Oraros is ORAROS LTD, a company registered in England and Wales under company number 17227040.
You can contact us about anything in this policy at support@oraros.com.
For users in the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO) — ico.org.uk. For users in Romania and the wider European Union, the supervisory authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP) in Romania — dataprotection.ro — alongside the data protection authority of your country of residence.
Because ORAROS LTD is established outside the European Union, we have appointed a representative in the EU under Article 27 of the GDPR. Data subjects in the EU and EU supervisory authorities — including the Romanian ANSPDCP — may contact our EU representative on any matter relating to the processing of their personal data:
EU Representative: Robert Badea (Romania), Zizinului 84 sc B ap 18, Brașov, Romania, 500414 — support@oraros.com.
ORAROS LTD remains the data controller; contacting the representative does not change who is responsible for your personal data.
2. Information we collect
We collect only what we need to run the Service. The categories below are exhaustive — if something is not listed, we do not collect it.
Identity and contact information. Your full name, email address, telephone number, and a password (stored only as a one-way salted hash — we never see or store your password in plain text).
Account and profile information. Account identifier, role (customer, business owner, staff, ambassador, or platform administrator), preferred language, country, and profile photo where you choose to upload one. For business owners, we also hold your business name and trading details.
Booking and appointment information. The service selected, the business and staff member chosen, the appointment date and time, any notes you provide at booking, your cancellation and reschedule history, no-show records, and visit-frequency patterns we compute to help businesses re-engage customers.
Location information. The city or general area you select when searching, and — only if you grant browser permission — your approximate device location. We do not continuously track your precise location.
Payment and financial information. For business owners: your subscription plan, billing currency, Stripe customer identifier, Stripe Connect account identifier, subscription status, invoice history, and payment-method metadata (card brand, last four digits, billing country). We never see or store full card numbers — those are held by Stripe. For brand ambassadors: your payout method, the bank or transfer details you provide for payouts, your commission ledger, and your payout history. For customers paying online: your payment is processed directly by Stripe on behalf of the business — Oraros does not see your card details.
Communications. Emails between you and us, support tickets, in-app messages between customers and businesses, and engagement metadata for transactional emails we send.
Technical information. Your IP address, browser type and version, device type, operating system, time zone setting, language preferences, referring URL, pages visited, session identifiers, and error logs.
Consent and preferences. Your cookie preferences, your marketing email opt-in status, your acceptance of our terms (with version, timestamp, and IP), and your language and currency preferences.
Ambassador-specific information. Your referral code, recruitment code, ambassador tier, network position (the ambassador who recruited you, if any), the businesses attributable to you, your commission ledger, and your declared promotion channels.
We do not intentionally collect special categories of personal data (such as data revealing health, religion, ethnicity, sexual orientation, or biometric data). If you voluntarily include such information in a free-text field — for example, a booking note about a skin condition — we treat it with the same security as other personal data, but please consider whether sharing it is necessary.
3. How we collect your information
We collect information directly from you when you sign up, book an appointment, message a business, apply to be an ambassador, or contact our support team. We also collect information automatically through cookies, device data, and usage logs as described in our Cookie Policy. We receive information from third parties — from Stripe (subscription and payment events), from our email provider (delivery events), from a business owner where they invite you as staff, and from another ambassador where they recruit you. For our ambassador "leads near me" feature, we use publicly available business directory data which we vet before display.
4. How we use your information and our lawful bases
We rely on the lawful bases set out in Article 6 of the UK GDPR and the EU GDPR.
To provide the Service — creating and managing your account, processing your bookings or subscriptions, routing bookings to businesses, taking payment for subscriptions, allowing in-app messaging, and sending transactional communications such as booking confirmations and reminders. Lawful basis: performance of a contract with you.
To run our business safely — detecting and preventing fraud, abuse, and no-show patterns; investigating security incidents; debugging; analysing platform usage in aggregate; improving our product; and providing customer support. Lawful basis: our legitimate interests in operating a secure and reliable platform, balanced against your rights.
To comply with the law — keeping tax records, responding to lawful requests from authorities, maintaining records required by anti-money-laundering rules where applicable, and demonstrating compliance with data protection law. Lawful basis: legal obligation.
To send marketing communications — only where you have opted in, or where you are an existing business customer and we are sending marketing about closely related products, in which case we rely on the soft opt-in permitted by the Privacy and Electronic Communications Regulations and (for Romanian users) Law 506/2004. You can unsubscribe at any time using the link in any marketing email. Lawful basis: consent (or PECR soft opt-in where applicable).
To run the brand ambassador programme — calculating, approving, and paying commissions; showing network hierarchy to ambassadors above you; preventing self-referral fraud; and meeting our tax obligations on payments to you. Lawful basis: performance of a contract with you and legal obligation for the tax-records component.
To show the leads-near-me feature to ambassadors — sourcing publicly listed business contact information from public directories, displaying it to ambassadors, and respecting any objection received from a listed business. Lawful basis: our legitimate interests in growing the platform, balanced against the listed business's right to object (which we honour on request).
5. Our role: controller versus processor
For most of the personal information described above, ORAROS LTD is the controller — we decide why and how it is processed.
However, when a business owner uses Oraros to manage their customer relationships, ORAROS LTD acts as a processor for the customer data the business uploads or stores in the platform. The business owner is the controller of that data and is responsible for the lawful basis on which it is processed. The contract that governs this relationship is our Data Processing Agreement, available at https://www.oraros.com/legal/dpa.
When a customer books an appointment, the booking details are shared with the business so the service can be delivered. From that point on, the business is also a controller of the customer's data and has its own responsibilities under data protection law.
6. Who we share your information with
We do not sell your personal data. We share it only with the recipients below, each bound by appropriate contractual safeguards.
Infrastructure providers. Supabase Inc. hosts our database, authentication, file storage, and backend services. Vercel Inc. hosts our web application and content-delivery network. Both operate primarily within the European Union and United Kingdom with limited operational metadata transiting the United States under standard contractual clauses.
Payment providers. Stripe Payments UK Ltd handles subscription billing for our UK business customers and Stripe Payments Europe Ltd handles subscription billing for our EU business customers. For customer-to-business payments, Stripe Connect is used; the business is the merchant of record and Stripe is an independent controller of cardholder data.
Email and messaging providers. Resend, Inc. delivers our transactional and operational emails. Where a business has enabled SMS reminders, those are delivered by Twilio.
Analytics and advertising — only after your consent. Google Ireland Limited (Google Analytics 4) helps us understand how the website is used. Meta Platforms Ireland Limited (Meta Pixel) helps us measure the effectiveness of our advertising. Neither loads before you accept the relevant cookie category.
Maps and geocoding. OpenStreetMap Foundation / Nominatim is used to convert business addresses into map coordinates. Map base tiles are served by CARTO (CartoCDN); MapTiler may be used as an alternative basemap provider. When a map is displayed, the tile provider receives your IP address and the map area (viewport and tile requests) needed to render it. We do not collect precise GPS location in the Android app, which requests no location permission.
Approximate location (IP-to-country). To set sensible regional defaults and to provide a fallback for the "near me" feature, we send your IP address to country.is (api.country.is), which returns only an approximate, country-level location. We do not derive a precise position from it.
Authorities, advisers, and acquirers. We may share information with HM Revenue & Customs, the Romanian tax authority (ANAF), law enforcement, courts, or regulators where required by law. We may share information with our professional advisers (accountants, auditors, lawyers) under strict confidentiality. If Oraros is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; if so, we will tell you and your rights under this policy will be preserved.
A current list of our processors and the locations in which they operate is maintained on our website.
7. International transfers
Oraros is established in the United Kingdom. Some of our service providers operate in the European Economic Area, the United Kingdom, or the United States. Where we transfer personal data outside the UK or the EEA to a country without a UK or EU adequacy decision, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum, the EU–US Data Privacy Framework where the recipient is certified, and supplementary technical measures including encryption in transit and at rest.
8. How long we keep your information
We keep your information for no longer than necessary for the purposes for which it was collected. In summary:
- An active customer or business account is kept while it remains active.
- Booking records are retained for 6 years from the date of the appointment and then anonymised or deleted.
- Cancelled subscriptions and the associated billing records are retained for 6 years from termination (UK tax obligation) or 10 years for accounts associated with Romanian businesses (Romanian accounting obligation). After that, personal identifiers are removed.
- Ambassador commission and payout records are retained for the same periods for tax reasons and then anonymised.
- Marketing email subscriptions are kept until you unsubscribe; we then retain a hashed record of your email indefinitely so we do not contact you again by mistake.
- Cookie consent records are kept for 24 months and then we ask again.
- Support tickets are kept for 3 years after closure.
- Web server access logs are kept for 90 days; authentication logs are kept for 24 months.
- Accounts that have not been signed into for 24 months are emailed, given a 30-day grace period, and then anonymised.
We may retain information longer where it is needed for an active legal claim, a fraud investigation, or a regulatory request — and only for as long as that need exists.
9. Your rights
Under the UK GDPR and the EU GDPR you have the right to access the personal information we hold about you; to ask us to correct anything inaccurate; to ask us to delete your information (subject to legal retention obligations); to ask us to restrict our processing; to receive your information in a portable, machine-readable format where applicable; to object to processing based on legitimate interests; and to withdraw consent where we rely on consent. You also have the absolute right to object to direct marketing — we will stop on request.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Our automated features (such as the slot-fill engine that suggests cancelled slots to interested customers, and the retention engine that helps businesses re-engage dormant customers) do not deny you a service, raise your prices, or change your legal rights.
To exercise any of these rights, email support@oraros.com. We will respond within one month. We may extend by up to two further months for complex requests, and we will tell you if we do. We may need to verify your identity before fulfilling a request.
If you are not satisfied with how we have handled your information, you have the right to complain to the Information Commissioner's Office (ICO) in the United Kingdom or to the National Supervisory Authority for Personal Data Processing (ANSPDCP) in Romania. We would prefer the chance to address your concern first — please write to us at support@oraros.com.
10. How to delete your account
You can delete your account at any time from the account settings in the app, or by emailing support@oraros.com. The full process is described at https://www.oraros.com/legal/account-deletion.
11. Security
We protect your information using encryption in transit (TLS 1.2 or higher) and at rest (AES-256 at the database storage layer); row-level security in our database so that one tenant cannot access another tenant's data; role-based access controls; audit logging of administrative access to personal data; one-way salted password hashing; vendor due diligence for every service provider we use; penetration testing prior to material releases; and a breach-response process that allows us to notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach, and to notify you without undue delay where required.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will tell you in line with our legal obligations.
12. Children
Oraros is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. Where a business uses Oraros to book a service for a child — for example, a haircut for a minor — the business is responsible for obtaining the appropriate parental consent under its own lawful basis. If you believe a child has provided personal information to us without appropriate consent, please contact support@oraros.com and we will delete it.
13. Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy at https://www.oraros.com/legal/cookies. No non-essential cookies are set before you give your consent through our cookie banner. You can change your preferences at any time through the "Cookie settings" link in the website footer.
14. Marketing communications
We will only send you marketing emails where you have opted in, or where you are an existing business customer of Oraros and we are sending marketing about similar products under the soft opt-in permitted by PECR (UK) and Law 506/2004 (Romania). You can unsubscribe at any time using the link in any marketing email or by contacting support@oraros.com.
15. Changes to this policy
We will update this policy when our practices change. The effective date at the top of this page always reflects the current version. For material changes we will notify registered users by email at least 30 days before the change takes effect. Older versions are kept on file and are available on request.
16. Contact
For any question about this policy or your personal information, email support@oraros.com.